CiberLATAMbywhalemate
Intelligence reportJul 10, 202624 min read

Latin America Ransomware Activity, June 2026

June ended with 28 incidents in the region, including 20 ransomware or extortion cases, with hotspots in private healthcare, finance, Brazil

Latin America Ransomware Activity, June 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are filled in automatically with verified facts and sources from the period. They are the recurring reading from month to month, and the follow-up analysis develops the cases without repeating this summary.

CIBERLATAM / WHALEMATE Verified Signal Monthly Dashboard June 2026 · Latin America INCIDENTS 28 breaches or leaks with source RANSOMWARE 20 documented cases CVEs 0 no single CVE FRAUD 3 documented phishing REGULATION 2 rules or sanctions TOP THREAT Incidents 28 incidents
Verified Signal Monthly Dashboard — Fixed-period summary for Latin America.
MONTHLY FIXED MODULE Threat Axis Distribution June 2026 · Latin America Incidents 28 Ransomware 20 Fraud 3 Regulation 2
Threat Axis Distribution — Heuristic classification of verified events by threat type.
MONTHLY FIXED MODULE Sectoral breakdown of signal June 2026 · Latin America Other 12 Public sector / OES 9 Healthcare 6 Finance 2 Telecom 2 Technology 2 Energy 1
Sectoral breakdown of signals — Heuristically classified verified facts by affected or mentioned sector.
MONTHLY FIXED MODULE Geographic distribution of signal June 2026 · Latin America Regional 18 Brazil 7 Paraguay 7 Mexico 2
Geographic distribution of signal — Verified events grouped by country or regional coverage.

Executive monthly overview

The month’s most concrete event was the shutdown of systems at private clinics and private health companies in Paraguay, an incident that forced Migone, Grupo Británico, Reyva, and other entities linked to the same business group to keep operating manually. Available coverage describes the event as a ransomware attack and places it within a broader wave of impact that reached several clinics and the private healthcare chain. That combination of disrupted continuity and a possible shared corporate scope makes it one of the period’s most relevant episodes for Latin America.

At the same time, Brazil continued to stand out as one of the markets under the heaviest ransomware pressure. Valor Econômico, in sponsored content by Pressworks, reported a 25% increase in ransomware attacks in the country and an average of 3,736 cyberattacks per week per organization in February 2026, with year-over-year growth of 37%. Dinamio added that Brazil ranked eighth among the countries most affected by ransomware in March, with 1.8% of reported global attacks, and pointed to vectors consistent with opportunistic campaigns as well as more targeted initial access, such as exposed RDP, VPN and RDWeb, and compromised credentials.

The regional signal was not limited to a single country. Daniel Donda’s weekly radar for the June 15 to 22 interval recorded 100 affected organizations globally and placed LockBit5 as the most active group, with 22 observed publications during that span. Although that radar does not break down specific victims in Brazil or other Latin American countries, it does reinforce a backdrop of sustained extortion activity throughout the month. Added to that is El Heraldo de Puebla’s reference to a Qilin campaign that, in the first week of June, would have included a clinic in Chile and a food company in Brazil, suggesting a transnational campaign logic with heterogeneous but operationally sensitive targets.

June’s balance shows a region under high and uneven pressure, where the private healthcare sector appears repeatedly, industry and managed services remain at risk, and the criminal business model continues to be funded through familiar initial access techniques, exposed credentials and data-leak extortion. ITware Latam’s data from the Fortinet 2026 Report help read that risk surface from the defensive demand side. Fifty percent of surveyed industrial leaders in Latin America identify ransomware as one of the most concerning attack vectors, while 76% mention phishing and 89% expect more regulation over the next five years. The picture is not one of a single outbreak, but of sustained exposure, with very concrete impacts on continuity, reputation and operational response.

The month’s reading is that the dominant signal did not come from a single family or one geography. Rather, it reflected an overlap of extortion incidents, global campaigns reaching the region, and evidence of structural pressure on organizations with less tolerance for interruptions, such as clinics, private health companies and regulated sectors. In qualitative terms, the regional risk remains high, because of the documented volume, the presence of confirmed victims and the repeated appearance of critical sectors such as healthcare and finance in several of the verified pieces.

TIMELINE Verified events in the period 31/3 An itemfromFortinet 31/5 The same sourcedetails 31/5 The MagazineCybersecurity,citing 31/5 The same reportfrom 31/5 According todata from Check 31/5 One newspieceinformationalin
Verified timeline of events, June 2026 — Milestones with confirmed dates in the period’s research material.

Regional monthly overview

Latin America closed June as a region highly exposed to ransomware, but not because of a single cluster of incidents. The clearest signal was the concentration of events in sectors where disruption immediately turns into operational and reputational risk. Private healthcare in Paraguay, financial activity in Mexico, and campaigns with signs of expansion into Brazil and Chile show a mix of high-value targets and environments where pressure to restore services is usually intense. That favors extortion, even when public reports do not mention payments or leaks.

At the regional level, the activity cannot be explained by isolated victims alone. Check Point Research reports published by Itsitio placed Latin America as the most attacked region in the world in May 2026, with 3,149 cyberattacks per week per organization, and Argentina with 2,470. Although those figures are not specific to ransomware, they help explain why extortion campaigns find such a broad attack surface across the region. The overall attack volume creates conditions for operators to select targets where initial access has already been obtained or controls have been weakened.

The pressure on Brazil deserves a separate read. The available material shows it at once as a high-volume market, an economy with a broad digital perimeter, and a country with persistent initial-access vectors. The sponsored note from Valor Econômico does not discuss a specific case, but it does point to a rising trend in attacks and a critical gap in recovery plans, a point that is especially sensitive for ransomware. Dinamio, for its part, links the country to remote service exposure techniques and compromised credentials. That pattern matches the way many extortion groups reach the encryption phase and public pressure.

The other structural fact is the persistence of global campaigns that reach the region without much country-by-country discrimination. Daniel Donda’s radar shows sustained activity and LockBit5 leading observed publications, while references to Qilin point to campaign capacity that can hit a sanatorium in Chile and a food company in Brazil at the same time. That suggests that, in June, the region was not facing an isolated local wave, but the intersection of international operators, Latin American targets, and sectors where the cost of downtime is high.

The risk picture is elevated for three reasons. First, there are confirmed victims with direct operational impact, especially in private healthcare. Second, there is evidence of pressure on countries with large exposed surfaces such as Brazil and Mexico. Third, the available sector reports confirm that ransomware and phishing remain priority threats for industrial organizations in the region. The picture does not point to an exceptional, self-contained event, but to a persistent condition combining extortion, opportunistic initial access, and targets with low tolerance for interruption.

Period indicators

Indicator Value
Documented incidents 28
Documented ransomware or extortion cases 20
Documented fraud or phishing cases 3
Documented regulatory actions 2
Critical CVEs mentioned 0
Sectors with at least one documented event 6
Predominant threat of the month Incidents (28 events)
Events with direct source confirmation 82%

Relevant incidents

Paraguay, private clinics and private medicine

The clearest and best documented incident of the month took place in Paraguay. La Tribuna described a "massive ransomware cyberattack" that affected the computer systems of several health insurance companies, including Migone, Grupo Británico, and Reyva, and clarified that the scope extended to private healthcare companies tied to the same business group. Coverage from El Nacional added that the Migone, Británico, Las Lomas, and Santa Clara sanatoriums were caught up in the event and that key systems were brought to a halt, forcing manual operations while recovery progressed.

The analytical value of the case lies not only in the scale of the impact, but in the organizational structure it exposes. When multiple care units and private healthcare services depend on shared systems, ransomware stops being an IT incident and becomes a disruption to clinical and administrative operations. In those settings, the urgency to restore access to medical records, appointments, billing, and internal coordination increases the pressure on affected teams. The information available does not confirm a ransom payment or a data leak at the time of coverage, so the verifiable fact is the operational disruption and the impact on the group of sanatoriums and private medicine companies.

La Tribuna also noted that the event was not limited to hospital facilities, but hit the entire chain of private medical service delivery. That distinction matters because it suggests the attacker was not targeting a single point of care, but a network of administrative and clinical dependencies. The result is a type of victim that is especially sensitive to ransomware, where damage is measured in both lost hours and patient diversion, delayed procedures, and extra manual workload for staff.

Qilin, a campaign reaching Brazil and Chile

El Heraldo de Puebla reported that, during the first week of June, the Qilin group attacked a food company in Brazil and a clinic in Chile as part of a global campaign. The source presents this as one wave, not two isolated incidents, which matters because it reinforces the idea of distributed extortion with target selection based on operational value. At the same time, Revista Ciberseguridad had noted that Qilin was the most active group in May 2026, with 18 victims posted on its leak site, within a global context of 95 ransomware attacks that month.

From a regional perspective, the case shows two kinds of risk. On one hand, a clinic, which shares the sensitivity seen in the Paraguay incident. On the other, a food company, which introduces risk to production and supply chains, even when the event does not lead to a prolonged public disruption. The material provides no technical details, ransom payment, or confirmation of exfiltration. Even so, the link between Qilin and victims in two Latin American countries in the same campaign is a sign of expanded geographic reach and target selection across different levels of operational criticality.

Brazil, rising pressure and persistent exposure

Brazil appears in several items this month, although not always as a single incident case. Valor Econômico, in sponsored content from Pressworks, reported a 25% increase in ransomware attacks in the country and an average of 3,736 cyberattacks per week per organization in February 2026. Dinamio provided another angle, placing Brazil in eighth position among the countries most affected by ransomware in March, with 1.8% of reported global attacks. The two texts do not describe a single intrusion, but they do point to sustained pressure that helps explain why the country keeps showing up as a target for extortion campaigns.

The operational reading of those data is straightforward. Ransomware groups find in Brazil a broad attack surface, with exposure of remote services, large corporate environments, and, according to the sources, uneven recovery practices. Dinamio mentions exposed RDP, VPN, and RDWeb, along with compromised credentials, as vectors of interest. That matches the way operators typically gain initial access before escalating privileges, moving laterally, and executing encryption or exfiltration. In the absence of a single incident reported in detail, the Brazilian regional pattern becomes a sign of structural exposure.

Mexico, financial pressure and observed ransomware families

Mexico's financial system provided another angle. Imagen Radio reported information from Banxico saying that in 2026, through May, eight cyber incidents were recorded at financial institutions in the country, double the four cases for all of 2025. The Banxico document cited in the same coverage also states that among the recorded cases were ransomware attacks associated with the LockBit and Qilin families. That mention matters because it connects the abstract risk facing banking with concrete actors already appearing in other items this month.

The available evidence does not allow us to reconstruct a single financial incident here with detailed victims, but it does show that Mexico is not only a market with a high volume of attempts, it is also a country where ransomware already appears in official reports on the financial system. Radio Fórmula added that Mexico received 237,000 ransomware attacks and that more than 200,000 attempts were reported in Mexican territory between August 2024 and July 2025. Along the same lines, content distributed by Fortinet and picked up by Indigo MTY said the country registered 337 million cyberattack attempts in the first three months of 2026. Even if not all of those figures are ransomware-specific, they help explain the constant pressure on the Mexican environment.

Argentina, a context of high regional exposure

Argentina does not appear in June's material with a widely documented domestic ransomware incident, but it does show up in Check Point Research's regional comparison, published by Itsitio, with an average of 2,470 cyberattacks per organization per week in May 2026. That reference does not prove a local ransomware case, but it does place the country among the most pressured by malicious activity. In practice, that kind of exposure usually raises the risk of initial intrusion, especially when the attack surface includes corporate email, remote access, and connected vendors.

The absence of a specific case should not be read as the absence of risk. On the contrary, the region shows that extortion operators tend to exploit markets with a dense concentration of targets and major differences between the defensive capacity of large organizations and mid-sized ones. Argentina falls into that category of a broad, heavily watched environment with sustained pressure, even though this month it did not produce a ransomware case as clear as Paraguay or the references to Brazil and Mexico.

Chile, clinic affected by transnational campaign

Chile appears in June through El Heraldo de Puebla's reference to a clinic attacked by Qilin. The coverage presents it as part of the same campaign that hit a food company in Brazil. The material does not provide the clinic's name, leak details, or additional confirmation of the victim, so the value of the fact lies in its transnational campaign character and in the presence of a sector highly exposed to operational impact. A clinic is a high-value extortion target because service disruption and pressure to restore systems can be immediate.

The incident also fits the broader pattern that repeats throughout the month. In several pieces, healthcare, public or private, appears as a highly exposed sector. Although the source linking Qilin to Chile is an external report and does not break down the victim, the consistency between that report, the Paraguay incident, and the global context in May offers a strong signal of continuing criminal interest in healthcare organizations in the region.

Mexican financial sector, incidents and used families

Banxico appears indirectly but importantly as a source of institutional context. The document cited by Imagen Radio indicates that there were ransomware cases involving LockBit and Qilin at Mexican financial institutions. That raises the relevance of the sector because it shows a convergence between very visible extortion families and regulated entities where the cost of disruption is usually high. The data also suggests the problem is not limited to low-volume opportunistic campaigns, but is already affecting organizations under greater scrutiny.

Without extrapolating beyond what the sources say, the reading is that the Mexican financial system shares the regional risk surface, but also faces a challenge of traceability and coordination because of its criticality. The public information available in June does not document a specific leak here, but it does show ransomware in official incidents in the financial system during 2026. That is enough to place it among the month's main areas of concern.

Active threats and campaigns

Ransomware and extortion

The month’s dominant threat was ransomware used for extortion with operational impact. The 20 documented ransomware or extortion cases were split between incidents with confirmed victims, mentions of campaigns, and global activity reports reaching Latin America. The most consistent pattern was pressure on services where recovery is costly, especially nursing homes, private healthcare companies, clinics, and, in Brazil’s case, organizations with broad corporate exposure.

Qilin emerged as one of the month’s most visible names. Revista Ciberseguridad ranked it as the most active group in May globally, and El Heraldo de Puebla linked it to incidents in Brazil and Chile during the first week of June. That does not allow all regional attacks to be attributed with certainty to a single campaign, but it does show an operator with enough momentum to maintain a continuous presence at the start of the month. LockBit5 also appears as a relevant actor on Daniel Donda’s radar, with 22 observed posts in one week of June and 100 organizations affected globally in that period.

The mix of actors and sectors points to extortion that prioritizes the victim’s response time. The attack on Paraguayan nursing homes forced manual operations. That detail is decisive, because it indicates that the intended effect was not just file encryption, but disruption of the operating flow. In private healthcare, that impact has a direct cost for patient care, scheduling, billing, and coordination across departments. In practice, that raises the likelihood of pressure for faster recovery, even when payment is not publicly confirmed.

Fraud, phishing, and initial access

Although this report centers on ransomware, the month’s material shows that initial access still relies on fraud and phishing. ITware Latam, citing the Fortinet 2026 Report, said phishing accounts for 76% and ransomware for 50% of the attack vectors identified by industrial organizations in Latin America. CronUp, meanwhile, reported campaigns distributing infostealers through fake Spotify Premium promotions and pirated games, affecting Spanish-speaking users, including in Latin America. These are not ransomware incidents in the strict sense, but they are part of the funnel that leads to stolen credentials and later intrusion.

The signal matters because extortion campaigns do not end with the final encryption step. Credential theft, abuse of remote access, and social engineering remain preparation mechanisms. The sources available for June show an ecosystem where phishing, impersonation of services, and distribution of information-stealing malware coexist with ransomware operations. From a defensive standpoint, that requires treating email, browsing, authentication, and remote exposure as part of the same risk chain.

APT and hacktivism

There was no verifiable material during the period that would allow a precise description of an APT or hacktivist campaign directly tied to the ransomware focus in Latin America. The dominant reading remains criminal, centered on extortion, leakage, and operational pressure. For that reason, this subsection does not expand further, beyond noting that the month did not provide enough evidence to add a technical narrative distinct from ransomware and its initial-access precursors.

Critical Vulnerabilities

No verifiable critical CVEs were recorded in the provided material for June 2026.

Regulation and Compliance

During the month, there were two documented signals on the regulatory front. ITware Latam reported that 89% of industrial leaders surveyed in Latin America expect cybersecurity regulations to increase over the next five years. That is not a rule or a specific provision, but it does reflect expectations of a tougher compliance environment, driven by repeated incidents and by pressure on industrial and infrastructure sectors.

The second signal comes from the corporate and sector reading that accompanies the risk. The Fortinet report cited by ITware Latam says that 71% of industrial cybersecurity leaders in Latin America reported between one and nine intrusions in the past year, up from 47% in the previous period. The same analysis adds that only 24% saw simultaneous impact on IT and OT, down from 60% of 2025, and attributes the decline to better network segmentation. In compliance terms, that suggests regulatory pressure and the push for segmentation are beginning to turn into technical decisions.

There were no national regulatory moves specifically tied to ransomware in June in the available material, no sanctions, and no new concrete obligations detailed by country. The valid reading is that the month brought expectations of more regulation and a more mature discussion about resilience, but not an identified set of rules that can be unambiguously attributed to the evidence provided.

Countries Most Affected in Latin America

Brazil

Brazil accounts for much of the month’s risk surface. In the report sponsored by Valor Econômico, the country shows a 25% rise in ransomware attacks and an average of 3,736 cyberattacks per week per organization in February. Dinamio places it among the most affected countries by ransomware in March, with 1.8% of all global attacks reported. Added to that is Qilin’s mention in a Brazilian food company as part of a transnational campaign.

The picture for Brazil is that of a highly exposed market, where the risk is not limited to a single incident. The available material points to exposure of remote services, compromised credentials, and broad pressure on large and midsize organizations. The mix of scale, connectivity, and persistent attacks makes the country a natural target for extortion operators looking for a quick return.

Mexico

Mexico appears with two layers of signals. The first is attack volume and the mention of mass attempts, with 237,000 ransomware attacks reported by Radio Fórmula and 337 million cyberattack attempts in 90 days reported by Fortinet and Indigo MTY. The second is more specific and comes from Banxico, which in its report on the financial system noted cyber incidents in 2026, including ransomware families such as LockBit and Qilin.

That puts Mexico under dual pressure, with high overall volume and a concrete ransomware presence in financial entities. The June information does not allow all of those data points to be tied to a single victim or one campaign, but it does make clear that the country combines a large attack surface, sector-critical assets, and the presence of actors already seen elsewhere in the region. For security teams, that means the risk is not only in banking, but also in vendors and connected supply chains.

Paraguay

Paraguay was the country with the month’s most operational incident in the available material. Local coverage describes a massive ransomware cyberattack that affected several private clinics and private healthcare companies, with impact on Migone, Grupo Británico, Reyva, Las Lomas and Santa Clara. The forced manual operation is a sign of material disruption, not just theoretical exposure.

The Paraguayan case also shows that private healthcare organizations can be highly interdependent, even when the incident appears across different brands or locations. For ransomware, that amplifies the effect of a compromised access point. If an attacker reaches shared systems, the damage spreads from digital infrastructure to day-to-day operations. In June, Paraguay did not just have a case, it had a case that directly altered how several healthcare entities worked.

Chile

Chile appears through the reference to a clinic affected in the campaign attributed to Qilin. The material does not allow the victim to be identified or the scope to be expanded with other local incidents in the month, but it does confirm that the country was within the group’s reach. For a clinic, the impact logic is clear, because ransomware in healthcare disrupts scheduling, care, records and internal coordination.

Although the number of documented incidents in Chile is lower than in Brazil, Mexico or Paraguay, the signal matters because of the nature of the sector involved. In June, Chile does not fall outside the regional extortion map, it simply appears with a lower density of verifiable public information.

Argentina

Argentina remains a country under high regional pressure according to Check Point Research data distributed by Itsitio, with 2,470 cyberattacks per week per organization in May. There is no sufficiently detailed Argentine ransomware victim in the June package to build a standalone case, but the overall exposure is significant. In environments like this, ransomware risk rises through the accumulation of attack surface and the likelihood of initial compromise through email, VPNs or exposed services.

The absence of a concrete case does not reduce the country’s importance on the regional map. It suggests instead that in June, public visibility concentrated on other fronts, while Argentina continued to carry underlying pressure.

Colombia

There was no verifiable material in June that allows Colombia to be assigned a confirmed ransomware or extortion case within this axis. The reading must remain limited to that absence of documented facts in the evidence provided.

Bolivia

There was no verifiable material in June that allows Bolivia to be assigned a confirmed ransomware or extortion case within this axis. The reading must remain limited to that absence of documented facts in the evidence provided.

Peru

There was no verifiable material in June that allows Peru to be assigned a confirmed ransomware or extortion case within this axis. The reading must remain limited to that absence of documented facts in the evidence provided.

United States

There was no verifiable material in June that allows the United States to be assigned a case within the regional scope of this report. The mention remains only as a country included in the requested taxonomy, with no documented facts in the material provided for this period.

There is no month-over-month baseline, because this is the first archived period using this indicator format for Latin America. That makes it impossible to read monthly variation as a formal historical series. Even so, the June material points to three signals worth monitoring now.

The first is the consolidation of private healthcare as a sensitive sector. Paraguay provided the clearest case, but the reference to a clinic in Chile and the broader read on Qilin show the sector remains a priority target. Wherever there are schedules, clinical systems, billing, and patient care, downtime is costly and extortion is highly incentivized.

The second is the continued pressure on Brazil and Mexico. Brazil combines a reported rise in attacks, exposure of services, and vulnerable remote access. Mexico combines the volume of attempts, incidents in the financial system, and ransomware families already seen in official reports. For both countries, the main signal is not a single episode but the persistence of a broad attack environment.

The third is the weight of campaigns that mix phishing, stealers, and initial access with later extortion. CronUp and ITware Latam show that phishing remains a central vector, while fake promotions and pirated games are used to collect credentials or install malware. That means ransomware defense in the region cannot focus only on backup and recovery. It has to start earlier, with identity, email, remote exposure, and endpoint control.

Security team recommendations

The first priority is to review remote exposure and privileged credentials. The June material again points to classic attack paths such as exposed VPN, RDP and RDWeb, along with compromised credentials. For security teams, that means a full inventory of published services, mandatory MFA wherever possible, a review of legacy access, and validation that privileged accounts do not reuse passwords or carry excessive privileges.

The second priority is to segment critical environments for real. The Fortinet report cited by ITware Latam suggests that stronger segmentation helped reduce the simultaneous impact on IT and OT. That finding is useful because it connects an architecture measure with a concrete reduction in damage. In health care, industrial or service organizations, segmentation is not just a network decision, it is also a way to limit lateral movement and protect processes that cannot be taken offline.

The third priority is to improve operational response for manual-work scenarios. The Paraguay case showed that several sanatoriums had to fall back to paper or manual procedures. That kind of contingency must be rehearsed before an incident. Forms, approval workflows, backup phone lines, criteria for clinical continuity and billing procedures need to exist and be exercised. Otherwise, manual backup turns into improvisation under pressure.

The fourth priority is to harden email, browsing and targeted training on phishing and stealers. This month’s ecosystem continues to show campaigns using lures tied to well-known services, pirated software and fake offers. The issue is not generic training, but specific technical and behavioral controls, such as blocking executable attachments, checking links, isolating risky browsing and alerting users to fake installers or updates.

The fifth priority is to review restoration capability, not just backup. The fact that a country records more attacks or that an organization has backups does not guarantee fast recovery. Full restores need to be tested, rebuild times validated, backup integrity checked and backup credentials kept separate from the production network. June’s data suggests the gap between having copies and getting back online remains a significant weak point.

The sixth priority is to strengthen monitoring for data leaks and extortion sites. Even though publication of data was not confirmed in several cases this month, the current ransomware model depends heavily on the threat of exposure. Teams should watch for mentions of their brand, locations, suppliers and corporate groups, because incidents with a conglomerate structure, such as the private health care case in Paraguay, often spread from one entity to another.

Material limitations

This report is based exclusively on the material provided for June 2026. No external sources or internet browsing were used. That creates concrete limits on attribution of victims, techniques, and groups in some cases that appear only as partial references or indirect coverage.

Several items mention groups and countries without full victim details, technical scope, or additional independent confirmation. In those cases, the wording was kept to what could be verified. There are also pieces that describe cyber incidents or broader pressure on the region, but do not allow each case to be classified as ransomware with complete precision. When that happened, the explicit source data took priority over any inference.

Social media sources were not included as evidence, even though some appeared in the research package, because editorial policy excludes them from the citation list. IoCs were also not included, because the material available for June does not provide hashes, domains, or IPs that were published by a source suitable for this report.

Finally, the indicator showing 82% of facts with direct source confirmation describes the quality of the month’s documentary signal, not an operational measurement of the phenomenon itself. The 28 documented incidents and the 20 ransomware or extortion cases reflect the verified universe in this file, not the real total of activity in the region.

Sources