Latin America Ransomware Activity, July 2026
July ended with heavy ransomware pressure in LATAM, led by Brazil and Argentina and with new confirmed cases in Bolivia.
Key findings
- Ransomware was the month’s dominant threat, accounting for 162 of the 241 verified incidents in the period.
- Brazil remained the regional epicenter, especially in healthcare, with SPDM and Global Secret Group among the most sensitive cases.
- Argentina concentrated public and technical pressure with Qilin targeting the Argentine Army and an unconfirmed threat against Mercado Libre.
- Bolivia added a confirmed case with Krybit and SEPREC, showing extortion also affects registry agencies.
- The most repeated attack surface was remote access, with VPNs, stolen credentials, and hypervisors as recurring vectors.
- July showed strong criminal fragmentation, with Qilin, LockBit 5, Akira, DragonForce, The Gentlemen, and other groups active.
- The jump from June was marked, in verified volume and in extortion cases with data posted on leak sites.
Monthly reference modules
These modules are completed automatically with verified dated facts within the period. Each one states its basis and counting criterion, so the figures reconcile across modules. They are the recurring reading each month, and the later analysis develops the cases without repeating this summary.
Indicator window: 248 dated facts in July 2026 · 26 without confirmed date (excluded from the indicators). Facts from previous months are used only as comparative context in the analysis, never as volume for this period.
Executive monthly summary
July 2026 showed sustained and visible ransomware pressure across Latin America, with a mix of confirmed cases, claims on leak sites, and heavy extortion activity whose exact classification could not always be verified from the available material. The clearest figure from the month is that ransomware remained the dominant theme, with 162 of 241 verified incidents in the period concentrated in that category. Within that set, there were 21 cases with confirmed asset encryption, 8 with exfiltration only and no encryption, 5 mentioned only on a leak site, and 128 incidents for which the source did not allow the exact impact to be determined.
The month also marked a shift in how the region is read. Brazil continued to appear as the most pressured country, both by cumulative volume and by its sector-wide centrality in healthcare. ESET reported more than 100 victims in Brazil in the first half of 2026, while Mexico approached 80, Argentina recorded 39 and Colombia 33. That pattern does not point to a single outbreak, but to the persistence of campaigns across multiple families and groups, with a special focus on public organizations, healthcare providers and entities with exposed perimeters.
Argentina accounted for one of the month’s most visible cases, with Qilin claiming the Ejército Argentino on its leak site on July 24. The ransomware.live source and coverage from IntelFusions and Dexpose agree that there was at least infostealer activity linked to more than 200,000 compromised users, which raises concern about credential reuse, but does not allow a fully verified primary intrusion to be asserted beyond the public listing. In parallel, Mercado Libre Argentina appeared on The Gentlemen’s radar, though with an important caveat, public evidence did not confirm a successful intrusion or data theft as of July 9.
Bolivia also recorded a confirmed case, with Krybit claiming an attack against the Servicio Plurinacional de Registro de Comercio and ransomware.live marking the victim seprec.gob.bo on July 7. That episode matters because it combines a public claim and a victim entry on an intelligence platform, but the material does not detail the technical scope of the compromise or whether there was encryption, exfiltration or both. In editorial terms, July reaffirmed that the region is not only facing massive leaks or isolated disruptions, but also a constant layer of extortion that mixes public pressure, claims on leak sites and occasional confirmed intrusions.
Brazil, meanwhile, remained the region’s main operational hub, especially in healthcare. Different sources cited in the material agree that Brazil’s health sector accounts for a disproportionate share of regional activity, with 51% of ransomware occurrences in healthcare in Latin America. July also brought SPDM, a major Brazilian hospital provider, listed by Global Secret Group with 847 GB of claimed data. That figure broadens the visible scope of the incident from simple victimization to announced exfiltration, although the available coverage still does not publicly confirm effective encryption or ransom payment.
The month’s operational reading is high risk. Not because of a single family or a single sector, but because of the persistence of multiple active groups, the breadth of victims, credential exposure and the continuing weight of perimeter environments, especially VPNs, hypervisors and systems accessible from the Internet. The comparison with June shows a clear acceleration in volume, with 241 verified incidents versus 74 the previous month, and 162 cases with ransomware or extortion as the primary focus versus 56. The signal does not depend on aggregated telemetry, but on incidents, claims and verified coverage from the period.
Regional Threat Picture for the Month
July did not show a single coordinated regional campaign, but simultaneous pressure across several countries and sectors, with a strong tilt toward health care, government, and service organizations. In the material reviewed, Latin America appears as a space where the most active groups in the global ecosystem find targets with enough public visibility, perimeter weaknesses, and uneven response capacity. The result is a mix of leak site pressure, announced exfiltration, and attacks whose technical scope is not always fully disclosed.
Brazil remains the region's main reference point. In several sources, the country appears as Latin America's ransomware epicenter in health care and as one of the most important global targets in that vertical. Material from ESET, SINDPD, Portal Information Management, Cafe com Bytes, Cloud Security Resource and Brandefense points in the same direction: high exposure, heavy pressure, and a fragmented criminal market. There is no single dominant gang. LockBit 5, The Gentlemen, Qilin, Akira, DragonForce, Global Secret Group and Krybit appear across different materials, suggesting a competitive environment in which affiliates move between brands and the target matters more for availability than loyalty to any specific cartel.
The month's qualitative severity is high for three reasons. First, the verified volume rose sharply compared with June. Second, confirmed cases included health care, defense, retail and the public sector, all verticals with sensitive data and operational dependence. Third, several cases involved public exposure of claimed data or credential compromise, even when encryption could not always be verified. That combination raises remediation costs, amplifies reputational pressure and complicates the legal classification of the incident.
From a tactical perspective, the month reinforced familiar patterns, but they remain highly relevant. Attackers continue to exploit remote access, stolen credentials, weak VPN configurations and exposed hypervisors. Sources from CSO Online, ransomware.live, Brandefense and Infosecurity Magazine point to the same perimeter, with VPNs, Cisco AnyConnect, Fortinet, Palo Alto GlobalProtect, Citrix, SonicWall and VMware ESXi as recurring surfaces. That does not prove that all incidents in Latin America used those vectors, but it does explain why organizations with poorly managed remote access kept appearing among the most vulnerable.
Period indicators
| Indicator | July 2026 | Previous month | Change |
|---|---|---|---|
| Verified events in the period | 241 | 74 | +167 |
| Time window for the indicators | 248 dated events in July 2026, 26 without confirmed date excluded from the indicators | 74 dated events in June 2026, no undated events confirmed in the comparable base | N/A |
| Unclassified incidents | 46 | 11 | +35 |
| Cases with ransomware or extortion as the primary focus | 162 | 56 | +106 |
| Confirmed asset encryption | 21 | N/D | N/D |
| No encryption, simple extortion, exfiltration only | 8 | N/D | N/D |
| Leak site mention only | 5 | N/D | N/D |
| Classification cannot be determined from the material | 128 | N/D | N/D |
| Documented fraud or phishing cases | 7 | 1 | +6 |
| Documented regulatory moves | 3 | 1 | +2 |
| Critical CVEs mentioned | 1 | no comparable data from the previous month | N/D |
| Sectors with at least one documented event | 8 | 8 | unchanged |
| Dominant threat of the month | Ransomware (162 of 241 events) | Ransomware (56 of 74 events) | N/A |
| Events with direct source confirmation | 86% | N/D | N/D |
| Aggregated telemetry figures excluded from the volume | 7 | N/D | N/D |
The base for the period is 241 verified events. The indicators' time window excludes 26 events without a confirmed date. The 7 aggregated telemetry records are not included in the volume because they correspond to automated attempts or blocks, not incidents with confirmed impact.
Relevant incidents
Argentine Army and Qilin
On July 24, Qilin added Ejército Argentino to its leak site and posted a public claim against the Argentine Army’s official domain. The available material supports one clear conclusion, the group listed the victim on the leak site and applied public extortion pressure, but the main intrusion itself is not fully verified with independent technical documentation. That distinction matters, because in ransomware, the claim and the actual impact do not always align in timing or depth.
Ransomware.live provides a specific entry for the victim, with reference to the official domain and a note about infostealer activity tied to associated accounts. IntelFusions and Dexpose add context by describing Qilin as a ransomware-as-a-service operation active since 2022, with strong global activity and a technical bias toward VMware ESXi servers. That pattern matters for the region, because environments with exposed virtualization, network-accessible backups and incomplete MFA often have weaker containment once an attacker gets in with valid credentials.
The analytical value of this case is not only the target, but the type of signal. Qilin does not appear here as an isolated curiosity, but as a highly active operator in July, with 27 listings between July 22 and 25 and more than 120 claims in the last month, according to IntelFusions. In other words, the Argentine case was embedded in the group’s global operational spike, which raises the likelihood that this was an affiliate campaign with real monetization capacity, not just a criminal reputation exercise.
Mercado Libre Argentina and The Gentlemen
Mercado Libre Argentina was named by The Gentlemen as a presumed ransomware victim and possible data leak target. Here the standard for caution is even higher. Fortuna y Poder’s own coverage makes clear that as of July 9 there was no public evidence confirming a successful intrusion or information theft. Escudo Digital also refers to a listing on the group’s leak page, but does not provide proof of encryption or samples of exfiltrated data.
The case should be read as an extortion threat, not a confirmed breach. That does not make it minor. In the current ecosystem, a simple mention on a leak site can trigger negotiation pressure, legal stress and reputational noise, especially when the target is a highly visible regional company. Methodologically, though, the material for the month does not support elevating the case to a confirmed ransomware incident with impact on assets or data.
The analytical value of the episode is different. The Gentlemen is described as one of the most active groups at the moment, with a leak page on the dark web. That kind of actor seeks to maximize reputational leverage before showing technical evidence. From a defense perspective, that means early mentions, escape routes, forums and extortion sites need to be monitored, because brand damage can start before there is technical proof of compromise.
SEPREC in Bolivia and Krybit
Bolivia had a more solid case in July from a confirmation standpoint. Dexpose reported that Krybit claimed an attack against the Servicio Plurinacional de Registro de Comercio, while ransomware.live recorded seprec.gob.bo as a victim discovered on July 7. Unlike the Mercado Libre story, here there is a match between the public claim and the victim listing.
The material, however, does not specify whether there was encryption, exfiltration or both. It also does not describe affected systems, recovery time or compromised data. That forces the classification to remain in an intermediate zone, between claim and possible real incident, without inflating the scope. For regional analysis, the case is valuable because it shows the targets are not limited to hospitals or major corporations, trade registries and state entities are also in the crosshairs when they offer exposed attack surface and weaker defensive capacity.
SPDM and Global Secret Group in Brazil
SPDM is one of the month’s most sensitive cases because of the type of victim and the volume of data claimed. Galaxy Warden reported that on July 26 the Brazilian health provider was listed on Global Secret Group’s leak site with a claim of 847 GB of stolen data, equivalent to 871.912 files in 76.047 folders. Ransomware.live also recorded the organization under Hospitals & Clinics in Brazil, with incident discovery on the same day.
Here, the difference between a listing and an announced exfiltration matters. The available coverage does speak of claimed stolen data, which strengthens the extortion with exfiltration hypothesis. But it does not provide public evidence of effective encryption or payment. For that reason, the case belongs in the category of an incident with announced data exposure, not a fully closed, technically verified attack session.
The value of the SPDM case is that it confirms pressure on Brazil’s health supply chain. The group is not targeting only large public hospitals or laboratories, but also large providers with thousands of employees and heavy data flows. In a sector where the cited reports point to 51% of regional incidents and very high breach costs, publishing hundreds of gigabytes on a leak site has legal, continuity and trust consequences far beyond the initial incident.
Brazilian health care and Global Secret Group
Ransomware.live’s entry for Global Secret Group as a victim in Brazil reinforces that the attack on SPDM was not an isolated case on the health care radar. The monitoring project added the organization to its Hospitals & Clinics activity and marks July 26 as the discovery date. That timing, aligned with the leak site publication, suggests public pressure and intelligence tracking moved in sync.
The regional reading is clear. Brazil does not just concentrate volume, it concentrates sector sensitivity. When health becomes the dominant vertical, extortion becomes more profitable because the cost of disruption is high and the urgency to restore services is greater. That does not mean every attack ends in encryption, but it does mean the threat adapts to an environment where downtime has immediate economic and political value.
Layers of pressure on the Argentine state
The Ejército Argentino case should not be read in isolation. It fits into a July sequence showing rising pressure on public institutions across the region, from the Bolivian registry to mentions of governments and official entities in ESET’s half-year analysis. The fact that ransomware.live observes infostealer activity involving more than 200.000 users associated with the case adds a secondary risk, the reuse of credentials to move into other accounts or services.
That kind of exposure is especially sensitive in defense or government organizations. It is not enough to close a listing or deny a claim. If credentials were exposed, the problem can persist in the form of residual access, valid tokens, persistent sessions or reused keys in other domains. The material does not confirm those extremes, but it does justify a broad internal investigation into identity and access.
Active Threats and Campaigns
Confirmed asset encryption
The month recorded 21 cases with confirmed asset encryption among the verified incidents. The material does not allow each one to be tied to a specific victim in this note without repeating the underlying base unnecessarily, but it does offer a useful tactical reading. Where encryption was confirmed, the problem stops being only extortion and becomes operational, with direct effects on availability, recovery, and reliance on backups.
The sources that frame this activity point to repeated vectors. CSO Online and Brandefense highlight the use of vulnerable VPNs and valid credentials, while Infosecurity Magazine and AhnLab underscore the weight of the most active groups and perimeter environments. In Latin America, that matches organizations that still maintain poorly segmented remote access and lack strong authentication at every sensitive point.
Exfiltration without encryption, simple extortion
The 8 cases classified as exfiltration without encryption confirm that extortion no longer depends on locking systems. It is enough to get in, copy data, and apply pressure with publication threats or secondary sale. In sectors such as healthcare, retail, and government, that model can be more profitable than encrypting everything, because it allows the victim to keep operating while public pressure increases.
The SPDM case fits that logic in part, since the material reports 847 GB of data claimed. So does, in another sense, the mention of Ejército Argentino with related infostealer activity. In both cases, the risk is not only the initial intrusion, but the later circulation of credentials or sensitive data.
Simple exfiltration requires defenses different from those built for classic ransomware. Protecting backups is not enough if the attacker has already left with information. DLP, egress control, sensitive data inventory, transfer logs, and the ability to detect mass dumping or abnormal compression matter here.
Leak site mention only
The 5 incidents that appeared only as leak site mentions are a reminder that criminal pressure also operates at the narrative level. A public claim alone can force the victim to respond, even when there is not enough evidence of actual access. The Gentlemen and the Mercado Libre Argentina case illustrate this clearly.
For a CISO, these mentions matter for three reasons. First, because they may signal escalation. Second, because they require a quick check against logs, EDR, authentication, and internal telemetry. Third, because they can trigger questions from the press, customers, and regulators before there is a complete technical picture.
Unclear typology based on the material
The largest category of the month, with 128 incidents, was unclear typology. That is not a minor flaw in the report. It is part of the phenomenon. Much of the journalism and threat intelligence coverage in July mentions ransomware, extortion, or leak sites without documenting sufficiently whether there was encryption, exfiltration only, or just a claim of responsibility.
That ambiguity should worry security teams. When external communications do not distinguish the impact mode, internal response tends to blur as well. That leads to prioritization errors, for example treating a case that first requires identity containment and exfiltration evidence as an availability incident, or the other way around.
Fraud and phishing
There were 7 documented fraud or phishing cases during the period. They do not compete with ransomware as the dominant theme, but they do feed it. Material from ESET, Aufiero Informática, and other sources recalls that initial access still often depends on fake email, compromised credentials, and outdated software. Operationally, phishing and fraud remain the prelude to many ransomware claims.
APT and hacktivism
The month did not show a predominance of APT or hacktivism in the sample, but it did leave signs consistent with persistent pressure campaigns against public agencies and defense-related entities. The Ejército Argentino case and some records involving critical infrastructure outside the region help frame the risk, although they do not substitute for local evidence of a pure APT actor. In July, the material points more to organized cyber extortion than to sophisticated espionage.
Critical vulnerabilities
The number of critical CVEs mentioned was 1. That means the analyzed material included a single reference to a critical issue of this kind, not that there are no other exploited vulnerabilities in the region. The absence of more CVEs in this sample should not be read as an absence of technical risk.
| CVE | Software | Exploitation | Source |
|---|---|---|---|
| CVE-2023-20269 | Cisco AnyConnect SSL VPN | Brandefense identified it as one of Akira's most consistent initial access vectors in environments without MFA | Brandefense, https://brandefense.io/blog/top-5-ransomware-groups-q2-2026/ |
The reference to CVE-2023-20269 fits a broader pattern of perimeter exposure. This month's sources also mention VPNs from Ivanti, Fortinet, Cisco, Citrix, SonicWall, GlobalProtect and edge devices such as NetScaler ADC. Although not all appear as critical CVEs in the material, the operational read is the same, the perimeter remains the preferred entry point when organizations do not harden remote access and do not require MFA.
Regulation and compliance
July also brought regulatory movement in Brazil, and this is not a side note. Portal Information Management reported that Lei nº 15.352/2026 turned the ANPD into an autarquia of special nature with expanded oversight powers over sensitive data, including health data. The same material mentioned Resolução CFM nº 2.454/2026, Brazil's first framework on the use of artificial intelligence in medicine, effective from August.
The regulatory reading is twofold. On one side, Brazilian authorities appear to be responding to the rise in incidents with greater supervisory capacity and specific rules for AI in health care. On the other, that tougher stance comes in a context where attacks are not only sophisticated, but also enabled by basic governance gaps, data traffic over unencrypted channels, and weak cloud configurations.
In compliance terms, Brazil's health sector stands out as the most exposed to friction between security, care continuity, and data protection obligations. This month’s sources insist that much of the current risk comes from operational mistakes, poor segmentation, and the absence of MFA on privileged accounts. That means reviewing not only technical security, but also third-party governance, cloud providers, and data processing agreements.
Most Affected Countries in Latin America
Brazil
Brazil was, by a wide margin, the month’s most visible country in volume, sector recurrence, and the variety of associated groups. The period’s evidence places it at the regional epicenter of ransomware in healthcare and among the biggest global targets in that segment. ESET reported more than 100 victims in the first half of 2026, and other sources from the month reinforced that centrality with 99 accumulated incidents since January, 195 telemetry instances between January and May, and a 51% concentration of regional occurrences in healthcare.
The key point is not just the number. It is the structure. The Brazilian cases in the material involve hospitals and clinics, healthcare providers, cloud setups, hypervisors, and the medical technology ecosystem. SPDM and Global Secret Group illustrate the pressure on large providers. SINDPD and Portal Information Management show a systemic surface where care continuity and data protection are under simultaneous strain. Cafe com Bytes adds that LockBit 5 and The Gentlemen led in victims in the country, a sign of a fragmented and competitive criminal market.
Argentina
Argentina had one of the month’s most visible signals because of the Ejército Argentino case and the mention of Mercado Libre Argentina. ESET placed it at 39 victims in the first half of 2026, and the ransomware trackers cited in the material show between 169 and 174 historical victims in intelligence maps, far above what appears in narrower dashboards. That suggests sustained exposure, not an isolated episode.
The Ejército Argentino case matters because of the target, the group, and the combination with infostealer activity. The mention of Mercado Libre, by contrast, works as an example of extortion pressure without public confirmation of intrusion. Taken together, the two cases show that Argentina combines high-visibility targets with opportunistic criminal pressure, and that public claims can create operational and reputational damage even before the intrusion is technically proven.
Bolivia
Bolivia had a single clearly verifiable case in July, but it was not minor. Krybit claimed the attack on SEPREC and ransomware.live recorded the victim on July 7. The signal matters because it shows impact on a state entity with registry functions, that is, a target where extortion may seek not only payment, but also visibility and institutional pressure.
The available evidence does not allow a precise assessment of the compromise. But it does make clear that Bolivia was not outside the regional map and that ransomware operators also target public administration bodies with less redundancy capacity than large private companies.
Colombia
Colombia appears in the material more as context than as a sequence of confirmed incidents in July. ESET placed it at 33 victims in the first half of 2026, and several sources from the period mention it as part of regional pressure on governments and public bodies. In addition, the research material includes references to campaigns and findings from other countries that frame its exposure through remote access and exposed configurations.
There was no Colombian incident in July, within the verifiable material, with the same level of confirmation as Argentina, Brazil, or Bolivia. For that reason, the country reading should be cautious. Colombia appears as a territory with sustained risk and a place on the regional map, but not as the main focus of the month’s documented events.
Mexico
Mexico remained among the region’s most affected countries, with nearly 80 victims in the first half of 2026 according to ESET. In July, however, the material available for this axis did not provide a Latin American ransomware case as clear as those in Argentina, Bolivia, or Brazil. It does provide exposure and regional pressure context, and places Mexico among the persistent targets of global operators.
For the regional reading, Mexico matters because it often combines high exposure among large organizations with regulatory complexity and cross-border reach. Although this report does not assign it a confirmed ransomware case for the month, the country remains on the threat map and should stay high on monitoring priorities.
Paraguay
Paraguay had no confirmed event in the month’s material within the verifiable scope. There is a mention, without confirmed date, of sanatoriums being forced back to paper records, but the source does not allow it to be used as period volume. In practice, that means there is not enough basis to assign it a July incident, even if the regional context suggests exposure to the same types of vectors seen across the Southern Cone.
Peru
Peru also did not record a confirmed ransomware event in July within the verifiable material. The mention of the National Digital Security Center in the source list serves only as documentary context, not as a period incident. The absence of verifiable cases should not be read as low exposure, but as a lack of confirmed signal in the sample analyzed.
Chile
Chile appears more clearly at the telemetry and detection level, with Qilin signals in the first half of 2026 according to ESET, but without a verified July incident in the material for this axis. For that reason, no confirmed monthly volume is assigned to it in this note. Even so, the mention of active families in the country supports the reading of a regional ecosystem where the most active groups operate across borders.
Trends and signals to watch
Compared with June, the verified volume expanded sharply. Moving from 74 to 241 incidents is a jump that cannot be explained by telemetry, because telemetry was excluded from the count. The growth is also reflected in cases where ransomware or extortion was the primary focus, which rose from 56 to 162. In other words, July was not just a month with more reporting, it was a month with more verified extortion signal.
The most important reading is that the criminal market appears fragmented and, at the same time, more professionalized. Qilin, DragonForce, Akira, LockBit 5, The Gentlemen, Global Secret Group and Krybit appear in the material as active or rising brands. That suggests the problem is not concentrated in a single dominant actor, but in several operators able to share infrastructure, methods and affiliates. For defenders, that means blocking one family does not eliminate the risk.
Another signal to watch is the shift toward services and edge infrastructure. CSO Online and Brandefense stressed the use of vulnerable VPNs and the abuse of legitimate credentials. State of Minas material adds that, in Brazil and the region, attackers are targeting hypervisors such as VMware ESXi, Hyper-V and Nutanix, in environments with weak MFA and exposed backups. That combination can turn a relatively routine intrusion into a prolonged operational outage.
Health care remains the most sensitive sector. Not only because of frequency, but because of the reputational and operational cost of each incident. Brazil accounts for 51% of regional occurrences in health care according to several of the sources cited in July, and the country's market data reinforces the sector's criminal appeal. If that relationship between data value, care urgency and technical exposure holds, health care is likely to remain the region's top extortion target.
The other signal to follow is the quality of public attribution. In July, there were many mentions on leak sites and several sources could not verify the exact technical impact. That means security teams need to be more disciplined about internal classification. A claim without encryption is not answered the same way as an intrusion with confirmed exfiltration. Operationally, the difference is enormous.
Security team recommendations
First, treat the remote access perimeter as a critical asset, not an operational convenience. This month’s material keeps pointing to VPNs, missing MFA, stolen credentials, and abuse of legitimate access as entry paths. That means hardening AnyConnect, Fortinet, Ivanti, Palo Alto GlobalProtect, Citrix, SonicWall, and any internet-exposed service with mandatory MFA, role-based segmentation, and the shutdown of obsolete access.
Second, treat hypervisors as a priority attack surface. The references to VMware ESXi, Hyper-V, and Nutanix are not decorative. Many organizations protect workstations and traditional servers well, but leave virtualization layers with too few barriers. Authentication, separation of management networks, offline or immutable backups, and privileged access controls on virtualization consoles all need review.
Third, strengthen exfiltration detection. This month showed cases of data claimed on leak sites and infostealer activity tied to specific victims. That requires DLP, monitoring for large-scale compression, alerts for unusual transfers, egress inspection, and correlation with identity. When the attacker does not encrypt and only steals, backups are no longer the first line of defense.
Fourth, set up a fast verification path for public claims. If an organization appears on a leak site, response time should be measured in hours, not days. There needs to be a clear chain between legal, security, communications, and leadership to compare logs, review EDR, validate authentications, and prepare messages without accepting a criminal narrative that has not yet been proven.
Fifth, segment continuity by critical services, not by administrative domains. In health care and the public sector, the real risk is disruption of essential processes. That is why it is worth validating dependencies among applications, vendors, identity, storage, and backups. The goal is not only to avoid encryption, but also to maintain controlled degradation if one segment goes down.
Sixth, tighten third-party and cloud governance. The July Brazilian material keeps pointing to configuration failures, poorly protected cloud servers, and medical data traffic through unencrypted platforms. That calls for a vendor inventory, contract review, least privilege, encryption in transit and at rest, and periodic recovery tests from clean backups.
Seventh, in health care and public administration, run tabletop exercises focused on extortion with exfiltration. Simulating encryption is not enough. Teams need to practice public threats, media pressure, partial leaks, contact from affiliates, and regulatory coordination. July showed that many campaigns are aimed exactly at that.
Material limits
This report was built exclusively from the material provided for July 2026 and from the verified fact base for the period. That means only the items contained in the research block can support claims about activity during the month. Facts without a confirmed date were excluded from the indicators and could only be used as qualitative context, always with the caveat that their date is not confirmed.
The indicator window covers 248 dated facts in July 2026, with 26 without a confirmed date excluded. The indicator base consists of 241 verified facts from the period. The 7 aggregated telemetry records were not added to the volume, because they correspond to automated attempts or blocks and not to incidents with confirmed impact.
A zero indicator, especially in the case of critical CVEs, means that the element was not recorded in the material analyzed. It does not mean there were no critical vulnerabilities or no exploitation in the region. This month, the material only made it possible to identify one critical CVE mentioned, CVE-2023-20269, and the rest of the technical references remained at the level of vectors or attack surfaces without CVE numbering.
The coverage also excluded sources that were not suitable for supporting trends, such as consumer social media posts and certain promotional or press release materials when they did not provide sufficient evidence. In particular, LinkedIn posts were not used as evidence to assert confirmed incidents, even if they appear in the research block as reading context.
The country-by-country reading included only jurisdictions with verifiable facts within the period or with explicit technical context in the material. Countries without sufficient material were handled in a single aggregate sentence so as not to invent activity. The report does not add victims, URLs, or external figures beyond those provided, and it does not derive its own totals by summing categories that were not designed to be mutually exclusive.
Sources
- Ransomware en el primer semestre de 2026: qué grupos atacan y qué sectores son los más afectadosESET / WeLiveSecurity
- La llegada de los “carteles” al mundo digital: alertan por nuevo modelo de cibercrimen que ya afecta a LatinoaméricaADN Radio / ESET
- Victim: Ejército ArgentinoRansomware.live
- RansomLook — Open ransomware intelligenceRansomLook
- Ransomware.live 👀 — Map ARRansomware.live
- Qilin ransomware lists Argentina's army on its leak siteIntelFusions
- Qilin Ransomware Group Targets Ejército ArgentinoDexpose
- The Gentlemen amenaza con filtrar datos de Mercado Libre Argentina tras presunto ciberataqueFortuna y Poder
- Mercado Libre, afectada por un ataque de ransomwareEscudo Digital
- Krybit Ransomware Strikes Bolivia's SEPRECDexpose
- Victim: seprec.gob.bo - Ransomware.liveRansomware.live
- Ransomware groups are hammering your vulnerable VPNsCSO Online
- Ransomware Groups Increasingly Deploy EDR Killers to Sidestep DefensesInfosecurity Magazine
- Top 5 Ransomware Groups in Q2 2026: Who They Are ...Brandefense
- Akira group profileransomware.live
- Brasil lidera ataques de ransomware na américa latina em 2026Cloud Security Resource
- Spdm Listed by Global Secret Group Ransomware GroupGalaxy Warden
- Healthcare sector victims in Brazilransomware.live
- Compliance para Saúde: LGPD, HIPAA, CFM, ANVISAVantico
- Victim: SPDMGlobal Secret Group (ransomware.live)
- Impact Analysis of Ransomware Attacks on EMEA HealthcareFlare.io
- Ransomware avança 17,8% e mira o Brasil e toda a LATAMEstado de Minas
- Brasil vira epicentro de ransomware na saúde na América Latina; especialistas alertam para riscos de IA sem governançaPortal Information Management
- Incidentes cibernéticos crescem em pequenas e medias empresas no paísG1
- Setor de saúde lidera ranking mundial de ataques cibernéticosSINDPD
- Brasil concentra 51% dos ataques de ransomware ao setor ...Brasilia e Aqui
- Brasil lidera ataques de ransomware na américa latina em 2026 e expõe falhasLucas Alcaraz
- Ransomware Wing — víctimas, grupos y patronesPulse (Kalir.io)
- Qilin Leads Global Ransomware Victim Claims Across ...Mallory.ai
- Especialistas revelam por que o Brasil virou alvo prioritário do ransomwareDireto Notícias
- Ransomware Tracker - Derp.caDerp.ca
- Il ransomware cambia bersaglio e assedia la filiera sanitariaTom's Hardware Italia
- Ataque hacker expõe dados de 500 mil pacientes e leva ANPD a investigar falhas na proteçãoO Hoje
- ANPD investiga ataque hacker que atingiu dados de pacientes em AlagoasO Jornal Extra (Alagoas)
- Ataque de ransomware contra o Isac registra vazamento de dados de 500 mil pacientesTI Inside
- Brasil é epicentro de ransomware em saúde na América LatinaCISO Advisor
- Brasil concentra el 51% de los ataques de ransomwareCiberLATAM
- ANPD abre processo contra Isac após ataque hacker expor dados de 500 mil pacientesCyberSec Brazil
- ANPD apura vazamento de dados de 500 mil pacientesPoder360
- Brazil ransomware victims mapransomware.live
- Instituição de saúde que atua no RS é alvo de processo por falhas na proteção de dados de 500 mil pacientesGaúchaZH
- Ataque cibernético vaza dados de 500 mil pacientes e empresa é alvo de investigação federalO Globo
- ANPD investiga ataque hacker contra organização que administra unidades de saúde em ALCada Minuto
- ANPD instaura processo de sanção contra OS por falha na proteção de dados de 500 mil pacientesLegismap
- Elytron aponta alta de ransomware na saúde no BrasilIT Section
- ANPD sanciona a Isac por filtrar 500 mil datos de pacientesLinkedIn (Consejo de Seguridad de la Información y Ciberseguridad)
- Brasil concentra 51% dos ataques de ransomware ao setor de saúde na América LatinaSaúde Digital News
- ¿Qué es el ransomware y cómo proteger tu empresa en 2026?Aufiero Informática
- Brasil concentra maior número de ataques de ransomware ao setor de saúde na América LatinaSantotech
- Vulnerabilidades y ransomware elevan el riesgo operativo para industrias estratégicas, advierte KaseyaITware Latam / Kaseya
- Casos de ciberataques aumentan 38% en México, empresas registran escalada en diversos sectoresInfobae
- Expertos alertan sobre una creciente táctica de ransomware: hackers imprimen demandas de rescate durante ataques en América LatinaTrendTIC
- Errores de configuración que alimentan el ransomware: lecciones de Colombia y MéxicoCarmona.mx
- Extorsión BitLocker: el esquema XEntry con impresorasHelpRansomware
- BitLocker Extortion: The XEntry Printer Ransom SchemeHelpRansomware
- Ciberataque a Ecopetrol: criminales accedieron y extrajeron información de 3.300 cuentas de la empresaInfobae
- Ecopetrol confirma difusión de datos robados tras ataqueLa FM
- Ciberataque a Ecopetrol: 15 empresas del grupo afectadas ...El Colombiano
- Nueva campaña de GodDamn ransomware combina captura de credenciales, acceso remoto y cifrado de sistemasCSIRT Asobancaria
- Publicación de A3Sec - LinkedInA3Sec
- Una inteligencia artificial dirigida a la tecnología operativa examinó una empresa de servicios de agua...Cryptonomist
- https://skyportsystems.net/ransomware-actors-exploit-bitlocker-and-corporate-printers-in-latin-americaSkyport Systems (blog técnico)
- Kaspersky Security Services Identifies Ransomware Actors Using BitLocker and Printers in Latin AmericaTMCnet Insight
- Presunto hackeo al gobierno de Sinaloa habría expuesto cerca de un millón de registros con datos fiscales, bancarios y médicosInfobae México
- Suman siete reportes de posibles ciberataques a sistemas públicos de Sinaloa en julioEl Sol de Sinaloa (OEM)
- New ransomware group uses printers to deliver ransom notesSC World
- Hackeo en Sinaloa: Habrían sido filtrados datos de 4000 pacientes, cuentas bancarias y másDebate
- Hackeo en Sinaloa: Habrían sido filtrados datos de 4,000 pacientes, cuentas bancarias y másDebate
- Nova extorsão com BitLocker: abuso de RDP, MSSQL e RMMSecurelist Brasil / Kaspersky
- Ataques de ransomware aumentaron 20% en primera mitad de 2026Fast Company México
- DragonForce Posts Eighteen Victims Across Eight Countries in 48 HoursDaily Security Review
- Panorama de ransomware en México | Ransomware ResponseRansomware Response
- León Investigates Alleged Attack on Citizen Services SystemSecurity Tribune
- El truco del correo falso: el silencioso método con el que los hackers están vulnerando a las víctimasInfobae
- Filtran datos de 400 mil denunciantes tras fallo de seguridad en PresidenciaMaya Comunicación
- Ransomware.live map — ParaguayRansomware.live
- Publicación de Marcela Pallero sobre "Ransomware obliga a sanatorios de Paraguay a volver al papel"LinkedIn
- Respuesta del Centro Nacional de Seguridad Digital ante ciberataques en PerúTu Diario Huánuco
- ESET: 4 de cada 10 empresas en América Latina operan a ciegas ante los ciberataquesESET / CanalNews EC
- Ransomware gangs go after EMEA healthcare's supply chainHelp Net Security
- Presunto Ataque del Grupo 'Qilin' en el Sector de Servicios Profesionales en Costa RicaDevel Group
- DragonForce revendique une cyberattaque contre l'Ifage et menace de publier 850 Go de donneesCyberVeille
- DragonForce ransomware posts more than 20 victims in three daysIntelFusions
- DragonForce: the cartel that absorbed its rivalsRansomNews
- DragonForce: de banda a cartel ransomware en 2026WeLiveSecurity (ESET)
- DragonForce: Data Breaches, Victims & MethodsRecentBreaches.com
- Aumentan ataques de ransomware en primer semestre de 2026 | Agencia NVMAgencia NVM
- Tras ciberataque, BHU gastó $ 12 millones en 'remediación' y 'reconstrucción de sistemas'; no se pagó 'ningún rescate'El País Uruguay
- ********.com.uy Data Breach (2026) — What Leaked & Am I Affected?Recentbreaches
- Country statistics – Uruguayransomware.live
- ********.com.uy — Section9 Ransomware AttackBreach House
- Coordinated Cyberattack Targets 30+ Minnesota Water SystemsThe Hacker News
- Government & Defense — USransomware.live
- Estados Unidos sospecha que Irán pudo estar tras el ciberataque a los sistemas de agua de MinnesotaLa Tercera
- Ransomware Radar - Victim Tracker - ShellCodeXShellCodeX
- Cyberattacks target several Minnesota water facilities, state officials sayFOX 9 Minneapolis-St. Paul
- "Coordinated cyberattack" targeted 30-plus Minnesota water systems; malware shut down Braham water plantCBS News Minnesota
- Ciberataque coordinado afectó a más de 30 sistemas de agua en MinnesotaNivel4
- Более 30 объектов водоснабжения в США пострадали от скоординированной кибератакиXakep
- Victim: American Hospice & Home Health Services (Ahhh Care) – CRPxOransomware.live
- Victim: City of Houston @ Exfilsquadransomware.live
- City of Atlanta Listed by ExfilSquad Ransomware GroupGalaxyWarden
- Ataque cibernético coordenado atinge 30 estações de água nos Estados Unidos e mobiliza força-tarefaTecMundo
- https://nayaritnoticias.com/2026/07/23/washington-acuso-a-hackers-de-iran-por-ataques-a-los-sistemas-de-agua-y-electricidadNayarit Noticias (cita a CISA/FBI y Cybersecurity Dive)
- EEUU alerta: hackers iraníes vinculados al IRGC están atacando infraestructura crítica de agua y energíaWWWhat's New
- Hackers apagan alarmas de emergencia en plantas de EE. UU.Qore
- CISA, FBI warn that Iran-linked hackers are expanding target set for water, energyCybersecurity Dive
- Authorities investigating a coordinated cyberattack against Minnesota community water systemsCybersecurity Dive
- AA26-097A: Ciberdelincuentes vinculados a Irán explotan dispositivos en sectores de infraestructura crítica de EE.UU.CISA
- EE.UU. advierte que operativos rusos atacan los correos electrónicos de científicos nucleares y contratistas de defensaCNN en Español
- Ransomware Attacks Using Corporate Printers Found in LATAMRTM World
- Tesoro de EE.UU. sanciona a First VPN por facilitar ataques ransomware contra hospitalesMoncloa
- Karen Vardanyan se declara culpable de ataques ransomware Ryuk contra hospitales en EE.UU.Moncloa.com
- Cómo un país europeo consiguió derrotar un ciberataque contra sus hospitales gracias al lápiz y al papelYahoo Noticias
- Cómo un país europeo consiguió derrotar un ciberataque contra sus hospitales gracias al lápiz y al papelBBC Mundo
- AHA Statement to Senate HELP Committee on CybersecurityASHRM / American Hospital Association
- US healthcare Archives (cobertura del ataque a Change Healthcare)Security Boulevard
- Recent posts (incluye entrada [DISCLOSED] Prince George County)RansomLook.io
- Data Breaches Announced by Four Hospitals and Surgery CentersUtopiaTS / DataBreaches.net
- 2026 Data Breaches: Cybersecurity Incidents ExplainedPKWARE
- LATAM Malware Variants - 2023 Technical UpdatesCrowdStrike
