CiberLATAMbywhalemate
Intelligence reportAug 7, 202626 min read

Latin America Ransomware Activity, July 2026

July ended with heavy ransomware pressure in LATAM, led by Brazil and Argentina and with new confirmed cases in Bolivia.

Latin America Ransomware Activity, July 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are completed automatically with verified dated facts within the period. Each one states its basis and counting criterion, so the figures reconcile across modules. They are the recurring reading each month, and the later analysis develops the cases without repeating this summary.

Indicator window: 248 dated facts in July 2026 · 26 without confirmed date (excluded from the indicators). Facts from previous months are used only as comparative context in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Monthly Verified Signal Dashboard July 2026 · Latin America Dominant threat: Ransomware (162 of 241 incidents). Coverage: 248 dated incidents in July 2026 · 26 undated co… VERIFIED INCIDENTS 241 period base: all counts measured from below against this total RANSOMWARE / EXTORTION 162 21 asset encryption confirmed · 8 exfiltration unencrypted (simple extortion) UNCLASSIFIED INCIDENTS 46 breaches or outages without declared threat type FRAUD / PHISHING 7 documented fraud campaigns documented REGULATION 3 regulations, rulings, or sanctions UNIQUE CVEs 1 CVE-2023-20269
Monthly Verified Signal Dashboard — Base: 241 verified dated incidents for Latin America.
MONTHLY FIXED MODULE Threat-axis distribution July 2026 · Latin America Each event counts on only one axis, so the total is exactly 241. "Unclassified incidents" is the remainder. Ransomware 162 Incidents 46 Unclassified 20 Fraud 7 Vulnerabilities 3 Regulation 3
Threat-axis distribution — Each event is assigned to a single axis based on its classification; the total reconciles with the 241 events in the period.
FIXED MONTHLY MODULE Sectoral Distribution of Signals July 2026 · Latin America Base: 241 incidents in the period · total 300 because 49 incidents are classified in more than one sector. Public sector / OES 92 Other / no sector identified… 88 Health 61 Telecom 21 Technology 17 Energy 9 Finance 8 Retail / Consumer 4
Sectoral Distribution of Signals — Heuristic sector classification by victim sector. One incident may affect more than one sector, so the total can exceed the base.
MONTHLY FIXED MODULE Geographic Distribution of Signals July 2026 · Latin America Each fact is assigned to a single country or to regional coverage, so the total is exactly 240 of 241 facts … Brazil 90 USA 44 Mexico 40 Colombia 20 Regional 16 Argentina 15 Peru 10 Uruguay 3 Bolivia 2
Geographic Distribution of Signals — Verified facts from the period grouped by country or regional coverage; each fact is counted once.

Executive monthly summary

July 2026 showed sustained and visible ransomware pressure across Latin America, with a mix of confirmed cases, claims on leak sites, and heavy extortion activity whose exact classification could not always be verified from the available material. The clearest figure from the month is that ransomware remained the dominant theme, with 162 of 241 verified incidents in the period concentrated in that category. Within that set, there were 21 cases with confirmed asset encryption, 8 with exfiltration only and no encryption, 5 mentioned only on a leak site, and 128 incidents for which the source did not allow the exact impact to be determined.

The month also marked a shift in how the region is read. Brazil continued to appear as the most pressured country, both by cumulative volume and by its sector-wide centrality in healthcare. ESET reported more than 100 victims in Brazil in the first half of 2026, while Mexico approached 80, Argentina recorded 39 and Colombia 33. That pattern does not point to a single outbreak, but to the persistence of campaigns across multiple families and groups, with a special focus on public organizations, healthcare providers and entities with exposed perimeters.

Argentina accounted for one of the month’s most visible cases, with Qilin claiming the Ejército Argentino on its leak site on July 24. The ransomware.live source and coverage from IntelFusions and Dexpose agree that there was at least infostealer activity linked to more than 200,000 compromised users, which raises concern about credential reuse, but does not allow a fully verified primary intrusion to be asserted beyond the public listing. In parallel, Mercado Libre Argentina appeared on The Gentlemen’s radar, though with an important caveat, public evidence did not confirm a successful intrusion or data theft as of July 9.

Bolivia also recorded a confirmed case, with Krybit claiming an attack against the Servicio Plurinacional de Registro de Comercio and ransomware.live marking the victim seprec.gob.bo on July 7. That episode matters because it combines a public claim and a victim entry on an intelligence platform, but the material does not detail the technical scope of the compromise or whether there was encryption, exfiltration or both. In editorial terms, July reaffirmed that the region is not only facing massive leaks or isolated disruptions, but also a constant layer of extortion that mixes public pressure, claims on leak sites and occasional confirmed intrusions.

Brazil, meanwhile, remained the region’s main operational hub, especially in healthcare. Different sources cited in the material agree that Brazil’s health sector accounts for a disproportionate share of regional activity, with 51% of ransomware occurrences in healthcare in Latin America. July also brought SPDM, a major Brazilian hospital provider, listed by Global Secret Group with 847 GB of claimed data. That figure broadens the visible scope of the incident from simple victimization to announced exfiltration, although the available coverage still does not publicly confirm effective encryption or ransom payment.

The month’s operational reading is high risk. Not because of a single family or a single sector, but because of the persistence of multiple active groups, the breadth of victims, credential exposure and the continuing weight of perimeter environments, especially VPNs, hypervisors and systems accessible from the Internet. The comparison with June shows a clear acceleration in volume, with 241 verified incidents versus 74 the previous month, and 162 cases with ransomware or extortion as the primary focus versus 56. The signal does not depend on aggregated telemetry, but on incidents, claims and verified coverage from the period.

Regional Threat Picture for the Month

July did not show a single coordinated regional campaign, but simultaneous pressure across several countries and sectors, with a strong tilt toward health care, government, and service organizations. In the material reviewed, Latin America appears as a space where the most active groups in the global ecosystem find targets with enough public visibility, perimeter weaknesses, and uneven response capacity. The result is a mix of leak site pressure, announced exfiltration, and attacks whose technical scope is not always fully disclosed.

Brazil remains the region's main reference point. In several sources, the country appears as Latin America's ransomware epicenter in health care and as one of the most important global targets in that vertical. Material from ESET, SINDPD, Portal Information Management, Cafe com Bytes, Cloud Security Resource and Brandefense points in the same direction: high exposure, heavy pressure, and a fragmented criminal market. There is no single dominant gang. LockBit 5, The Gentlemen, Qilin, Akira, DragonForce, Global Secret Group and Krybit appear across different materials, suggesting a competitive environment in which affiliates move between brands and the target matters more for availability than loyalty to any specific cartel.

The month's qualitative severity is high for three reasons. First, the verified volume rose sharply compared with June. Second, confirmed cases included health care, defense, retail and the public sector, all verticals with sensitive data and operational dependence. Third, several cases involved public exposure of claimed data or credential compromise, even when encryption could not always be verified. That combination raises remediation costs, amplifies reputational pressure and complicates the legal classification of the incident.

From a tactical perspective, the month reinforced familiar patterns, but they remain highly relevant. Attackers continue to exploit remote access, stolen credentials, weak VPN configurations and exposed hypervisors. Sources from CSO Online, ransomware.live, Brandefense and Infosecurity Magazine point to the same perimeter, with VPNs, Cisco AnyConnect, Fortinet, Palo Alto GlobalProtect, Citrix, SonicWall and VMware ESXi as recurring surfaces. That does not prove that all incidents in Latin America used those vectors, but it does explain why organizations with poorly managed remote access kept appearing among the most vulnerable.

Visible pressure by countryQualitative reading of the verifiable material from July 2026BrazilArgentinaBoliviaColombiaHealthDefenseRegistryContext
Countries with the highest visible pressure in the material — Qualitative reading based on verifiable facts from the month, not aggregated telemetry.

Period indicators

Indicator July 2026 Previous month Change
Verified events in the period 241 74 +167
Time window for the indicators 248 dated events in July 2026, 26 without confirmed date excluded from the indicators 74 dated events in June 2026, no undated events confirmed in the comparable base N/A
Unclassified incidents 46 11 +35
Cases with ransomware or extortion as the primary focus 162 56 +106
Confirmed asset encryption 21 N/D N/D
No encryption, simple extortion, exfiltration only 8 N/D N/D
Leak site mention only 5 N/D N/D
Classification cannot be determined from the material 128 N/D N/D
Documented fraud or phishing cases 7 1 +6
Documented regulatory moves 3 1 +2
Critical CVEs mentioned 1 no comparable data from the previous month N/D
Sectors with at least one documented event 8 8 unchanged
Dominant threat of the month Ransomware (162 of 241 events) Ransomware (56 of 74 events) N/A
Events with direct source confirmation 86% N/D N/D
Aggregated telemetry figures excluded from the volume 7 N/D N/D

The base for the period is 241 verified events. The indicators' time window excludes 26 events without a confirmed date. The 7 aggregated telemetry records are not included in the volume because they correspond to automated attempts or blocks, not incidents with confirmed impact.

Relevant incidents

Argentine Army and Qilin

On July 24, Qilin added Ejército Argentino to its leak site and posted a public claim against the Argentine Army’s official domain. The available material supports one clear conclusion, the group listed the victim on the leak site and applied public extortion pressure, but the main intrusion itself is not fully verified with independent technical documentation. That distinction matters, because in ransomware, the claim and the actual impact do not always align in timing or depth.

Ransomware.live provides a specific entry for the victim, with reference to the official domain and a note about infostealer activity tied to associated accounts. IntelFusions and Dexpose add context by describing Qilin as a ransomware-as-a-service operation active since 2022, with strong global activity and a technical bias toward VMware ESXi servers. That pattern matters for the region, because environments with exposed virtualization, network-accessible backups and incomplete MFA often have weaker containment once an attacker gets in with valid credentials.

The analytical value of this case is not only the target, but the type of signal. Qilin does not appear here as an isolated curiosity, but as a highly active operator in July, with 27 listings between July 22 and 25 and more than 120 claims in the last month, according to IntelFusions. In other words, the Argentine case was embedded in the group’s global operational spike, which raises the likelihood that this was an affiliate campaign with real monetization capacity, not just a criminal reputation exercise.

Mercado Libre Argentina and The Gentlemen

Mercado Libre Argentina was named by The Gentlemen as a presumed ransomware victim and possible data leak target. Here the standard for caution is even higher. Fortuna y Poder’s own coverage makes clear that as of July 9 there was no public evidence confirming a successful intrusion or information theft. Escudo Digital also refers to a listing on the group’s leak page, but does not provide proof of encryption or samples of exfiltrated data.

The case should be read as an extortion threat, not a confirmed breach. That does not make it minor. In the current ecosystem, a simple mention on a leak site can trigger negotiation pressure, legal stress and reputational noise, especially when the target is a highly visible regional company. Methodologically, though, the material for the month does not support elevating the case to a confirmed ransomware incident with impact on assets or data.

The analytical value of the episode is different. The Gentlemen is described as one of the most active groups at the moment, with a leak page on the dark web. That kind of actor seeks to maximize reputational leverage before showing technical evidence. From a defense perspective, that means early mentions, escape routes, forums and extortion sites need to be monitored, because brand damage can start before there is technical proof of compromise.

SEPREC in Bolivia and Krybit

Bolivia had a more solid case in July from a confirmation standpoint. Dexpose reported that Krybit claimed an attack against the Servicio Plurinacional de Registro de Comercio, while ransomware.live recorded seprec.gob.bo as a victim discovered on July 7. Unlike the Mercado Libre story, here there is a match between the public claim and the victim listing.

The material, however, does not specify whether there was encryption, exfiltration or both. It also does not describe affected systems, recovery time or compromised data. That forces the classification to remain in an intermediate zone, between claim and possible real incident, without inflating the scope. For regional analysis, the case is valuable because it shows the targets are not limited to hospitals or major corporations, trade registries and state entities are also in the crosshairs when they offer exposed attack surface and weaker defensive capacity.

SPDM and Global Secret Group in Brazil

SPDM is one of the month’s most sensitive cases because of the type of victim and the volume of data claimed. Galaxy Warden reported that on July 26 the Brazilian health provider was listed on Global Secret Group’s leak site with a claim of 847 GB of stolen data, equivalent to 871.912 files in 76.047 folders. Ransomware.live also recorded the organization under Hospitals & Clinics in Brazil, with incident discovery on the same day.

Here, the difference between a listing and an announced exfiltration matters. The available coverage does speak of claimed stolen data, which strengthens the extortion with exfiltration hypothesis. But it does not provide public evidence of effective encryption or payment. For that reason, the case belongs in the category of an incident with announced data exposure, not a fully closed, technically verified attack session.

The value of the SPDM case is that it confirms pressure on Brazil’s health supply chain. The group is not targeting only large public hospitals or laboratories, but also large providers with thousands of employees and heavy data flows. In a sector where the cited reports point to 51% of regional incidents and very high breach costs, publishing hundreds of gigabytes on a leak site has legal, continuity and trust consequences far beyond the initial incident.

Brazilian health care and Global Secret Group

Ransomware.live’s entry for Global Secret Group as a victim in Brazil reinforces that the attack on SPDM was not an isolated case on the health care radar. The monitoring project added the organization to its Hospitals & Clinics activity and marks July 26 as the discovery date. That timing, aligned with the leak site publication, suggests public pressure and intelligence tracking moved in sync.

The regional reading is clear. Brazil does not just concentrate volume, it concentrates sector sensitivity. When health becomes the dominant vertical, extortion becomes more profitable because the cost of disruption is high and the urgency to restore services is greater. That does not mean every attack ends in encryption, but it does mean the threat adapts to an environment where downtime has immediate economic and political value.

Layers of pressure on the Argentine state

The Ejército Argentino case should not be read in isolation. It fits into a July sequence showing rising pressure on public institutions across the region, from the Bolivian registry to mentions of governments and official entities in ESET’s half-year analysis. The fact that ransomware.live observes infostealer activity involving more than 200.000 users associated with the case adds a secondary risk, the reuse of credentials to move into other accounts or services.

That kind of exposure is especially sensitive in defense or government organizations. It is not enough to close a listing or deny a claim. If credentials were exposed, the problem can persist in the form of residual access, valid tokens, persistent sessions or reused keys in other domains. The material does not confirm those extremes, but it does justify a broad internal investigation into identity and access.

Active Threats and Campaigns

Confirmed asset encryption

The month recorded 21 cases with confirmed asset encryption among the verified incidents. The material does not allow each one to be tied to a specific victim in this note without repeating the underlying base unnecessarily, but it does offer a useful tactical reading. Where encryption was confirmed, the problem stops being only extortion and becomes operational, with direct effects on availability, recovery, and reliance on backups.

The sources that frame this activity point to repeated vectors. CSO Online and Brandefense highlight the use of vulnerable VPNs and valid credentials, while Infosecurity Magazine and AhnLab underscore the weight of the most active groups and perimeter environments. In Latin America, that matches organizations that still maintain poorly segmented remote access and lack strong authentication at every sensitive point.

Exfiltration without encryption, simple extortion

The 8 cases classified as exfiltration without encryption confirm that extortion no longer depends on locking systems. It is enough to get in, copy data, and apply pressure with publication threats or secondary sale. In sectors such as healthcare, retail, and government, that model can be more profitable than encrypting everything, because it allows the victim to keep operating while public pressure increases.

The SPDM case fits that logic in part, since the material reports 847 GB of data claimed. So does, in another sense, the mention of Ejército Argentino with related infostealer activity. In both cases, the risk is not only the initial intrusion, but the later circulation of credentials or sensitive data.

Simple exfiltration requires defenses different from those built for classic ransomware. Protecting backups is not enough if the attacker has already left with information. DLP, egress control, sensitive data inventory, transfer logs, and the ability to detect mass dumping or abnormal compression matter here.

Leak site mention only

The 5 incidents that appeared only as leak site mentions are a reminder that criminal pressure also operates at the narrative level. A public claim alone can force the victim to respond, even when there is not enough evidence of actual access. The Gentlemen and the Mercado Libre Argentina case illustrate this clearly.

For a CISO, these mentions matter for three reasons. First, because they may signal escalation. Second, because they require a quick check against logs, EDR, authentication, and internal telemetry. Third, because they can trigger questions from the press, customers, and regulators before there is a complete technical picture.

Unclear typology based on the material

The largest category of the month, with 128 incidents, was unclear typology. That is not a minor flaw in the report. It is part of the phenomenon. Much of the journalism and threat intelligence coverage in July mentions ransomware, extortion, or leak sites without documenting sufficiently whether there was encryption, exfiltration only, or just a claim of responsibility.

That ambiguity should worry security teams. When external communications do not distinguish the impact mode, internal response tends to blur as well. That leads to prioritization errors, for example treating a case that first requires identity containment and exfiltration evidence as an availability incident, or the other way around.

Fraud and phishing

There were 7 documented fraud or phishing cases during the period. They do not compete with ransomware as the dominant theme, but they do feed it. Material from ESET, Aufiero Informática, and other sources recalls that initial access still often depends on fake email, compromised credentials, and outdated software. Operationally, phishing and fraud remain the prelude to many ransomware claims.

APT and hacktivism

The month did not show a predominance of APT or hacktivism in the sample, but it did leave signs consistent with persistent pressure campaigns against public agencies and defense-related entities. The Ejército Argentino case and some records involving critical infrastructure outside the region help frame the risk, although they do not substitute for local evidence of a pure APT actor. In July, the material points more to organized cyber extortion than to sophisticated espionage.

Critical vulnerabilities

The number of critical CVEs mentioned was 1. That means the analyzed material included a single reference to a critical issue of this kind, not that there are no other exploited vulnerabilities in the region. The absence of more CVEs in this sample should not be read as an absence of technical risk.

CVE Software Exploitation Source
CVE-2023-20269 Cisco AnyConnect SSL VPN Brandefense identified it as one of Akira's most consistent initial access vectors in environments without MFA Brandefense, https://brandefense.io/blog/top-5-ransomware-groups-q2-2026/

The reference to CVE-2023-20269 fits a broader pattern of perimeter exposure. This month's sources also mention VPNs from Ivanti, Fortinet, Cisco, Citrix, SonicWall, GlobalProtect and edge devices such as NetScaler ADC. Although not all appear as critical CVEs in the material, the operational read is the same, the perimeter remains the preferred entry point when organizations do not harden remote access and do not require MFA.

Regulation and compliance

July also brought regulatory movement in Brazil, and this is not a side note. Portal Information Management reported that Lei nº 15.352/2026 turned the ANPD into an autarquia of special nature with expanded oversight powers over sensitive data, including health data. The same material mentioned Resolução CFM nº 2.454/2026, Brazil's first framework on the use of artificial intelligence in medicine, effective from August.

The regulatory reading is twofold. On one side, Brazilian authorities appear to be responding to the rise in incidents with greater supervisory capacity and specific rules for AI in health care. On the other, that tougher stance comes in a context where attacks are not only sophisticated, but also enabled by basic governance gaps, data traffic over unencrypted channels, and weak cloud configurations.

In compliance terms, Brazil's health sector stands out as the most exposed to friction between security, care continuity, and data protection obligations. This month’s sources insist that much of the current risk comes from operational mistakes, poor segmentation, and the absence of MFA on privileged accounts. That means reviewing not only technical security, but also third-party governance, cloud providers, and data processing agreements.

Most Affected Countries in Latin America

Brazil

Brazil was, by a wide margin, the month’s most visible country in volume, sector recurrence, and the variety of associated groups. The period’s evidence places it at the regional epicenter of ransomware in healthcare and among the biggest global targets in that segment. ESET reported more than 100 victims in the first half of 2026, and other sources from the month reinforced that centrality with 99 accumulated incidents since January, 195 telemetry instances between January and May, and a 51% concentration of regional occurrences in healthcare.

The key point is not just the number. It is the structure. The Brazilian cases in the material involve hospitals and clinics, healthcare providers, cloud setups, hypervisors, and the medical technology ecosystem. SPDM and Global Secret Group illustrate the pressure on large providers. SINDPD and Portal Information Management show a systemic surface where care continuity and data protection are under simultaneous strain. Cafe com Bytes adds that LockBit 5 and The Gentlemen led in victims in the country, a sign of a fragmented and competitive criminal market.

Argentina

Argentina had one of the month’s most visible signals because of the Ejército Argentino case and the mention of Mercado Libre Argentina. ESET placed it at 39 victims in the first half of 2026, and the ransomware trackers cited in the material show between 169 and 174 historical victims in intelligence maps, far above what appears in narrower dashboards. That suggests sustained exposure, not an isolated episode.

The Ejército Argentino case matters because of the target, the group, and the combination with infostealer activity. The mention of Mercado Libre, by contrast, works as an example of extortion pressure without public confirmation of intrusion. Taken together, the two cases show that Argentina combines high-visibility targets with opportunistic criminal pressure, and that public claims can create operational and reputational damage even before the intrusion is technically proven.

Bolivia

Bolivia had a single clearly verifiable case in July, but it was not minor. Krybit claimed the attack on SEPREC and ransomware.live recorded the victim on July 7. The signal matters because it shows impact on a state entity with registry functions, that is, a target where extortion may seek not only payment, but also visibility and institutional pressure.

The available evidence does not allow a precise assessment of the compromise. But it does make clear that Bolivia was not outside the regional map and that ransomware operators also target public administration bodies with less redundancy capacity than large private companies.

Colombia

Colombia appears in the material more as context than as a sequence of confirmed incidents in July. ESET placed it at 33 victims in the first half of 2026, and several sources from the period mention it as part of regional pressure on governments and public bodies. In addition, the research material includes references to campaigns and findings from other countries that frame its exposure through remote access and exposed configurations.

There was no Colombian incident in July, within the verifiable material, with the same level of confirmation as Argentina, Brazil, or Bolivia. For that reason, the country reading should be cautious. Colombia appears as a territory with sustained risk and a place on the regional map, but not as the main focus of the month’s documented events.

Mexico

Mexico remained among the region’s most affected countries, with nearly 80 victims in the first half of 2026 according to ESET. In July, however, the material available for this axis did not provide a Latin American ransomware case as clear as those in Argentina, Bolivia, or Brazil. It does provide exposure and regional pressure context, and places Mexico among the persistent targets of global operators.

For the regional reading, Mexico matters because it often combines high exposure among large organizations with regulatory complexity and cross-border reach. Although this report does not assign it a confirmed ransomware case for the month, the country remains on the threat map and should stay high on monitoring priorities.

Paraguay

Paraguay had no confirmed event in the month’s material within the verifiable scope. There is a mention, without confirmed date, of sanatoriums being forced back to paper records, but the source does not allow it to be used as period volume. In practice, that means there is not enough basis to assign it a July incident, even if the regional context suggests exposure to the same types of vectors seen across the Southern Cone.

Peru

Peru also did not record a confirmed ransomware event in July within the verifiable material. The mention of the National Digital Security Center in the source list serves only as documentary context, not as a period incident. The absence of verifiable cases should not be read as low exposure, but as a lack of confirmed signal in the sample analyzed.

Chile

Chile appears more clearly at the telemetry and detection level, with Qilin signals in the first half of 2026 according to ESET, but without a verified July incident in the material for this axis. For that reason, no confirmed monthly volume is assigned to it in this note. Even so, the mention of active families in the country supports the reading of a regional ecosystem where the most active groups operate across borders.

Compared with June, the verified volume expanded sharply. Moving from 74 to 241 incidents is a jump that cannot be explained by telemetry, because telemetry was excluded from the count. The growth is also reflected in cases where ransomware or extortion was the primary focus, which rose from 56 to 162. In other words, July was not just a month with more reporting, it was a month with more verified extortion signal.

The most important reading is that the criminal market appears fragmented and, at the same time, more professionalized. Qilin, DragonForce, Akira, LockBit 5, The Gentlemen, Global Secret Group and Krybit appear in the material as active or rising brands. That suggests the problem is not concentrated in a single dominant actor, but in several operators able to share infrastructure, methods and affiliates. For defenders, that means blocking one family does not eliminate the risk.

Another signal to watch is the shift toward services and edge infrastructure. CSO Online and Brandefense stressed the use of vulnerable VPNs and the abuse of legitimate credentials. State of Minas material adds that, in Brazil and the region, attackers are targeting hypervisors such as VMware ESXi, Hyper-V and Nutanix, in environments with weak MFA and exposed backups. That combination can turn a relatively routine intrusion into a prolonged operational outage.

Health care remains the most sensitive sector. Not only because of frequency, but because of the reputational and operational cost of each incident. Brazil accounts for 51% of regional occurrences in health care according to several of the sources cited in July, and the country's market data reinforces the sector's criminal appeal. If that relationship between data value, care urgency and technical exposure holds, health care is likely to remain the region's top extortion target.

The other signal to follow is the quality of public attribution. In July, there were many mentions on leak sites and several sources could not verify the exact technical impact. That means security teams need to be more disciplined about internal classification. A claim without encryption is not answered the same way as an intrusion with confirmed exfiltration. Operationally, the difference is enormous.

Security team recommendations

First, treat the remote access perimeter as a critical asset, not an operational convenience. This month’s material keeps pointing to VPNs, missing MFA, stolen credentials, and abuse of legitimate access as entry paths. That means hardening AnyConnect, Fortinet, Ivanti, Palo Alto GlobalProtect, Citrix, SonicWall, and any internet-exposed service with mandatory MFA, role-based segmentation, and the shutdown of obsolete access.

Second, treat hypervisors as a priority attack surface. The references to VMware ESXi, Hyper-V, and Nutanix are not decorative. Many organizations protect workstations and traditional servers well, but leave virtualization layers with too few barriers. Authentication, separation of management networks, offline or immutable backups, and privileged access controls on virtualization consoles all need review.

Third, strengthen exfiltration detection. This month showed cases of data claimed on leak sites and infostealer activity tied to specific victims. That requires DLP, monitoring for large-scale compression, alerts for unusual transfers, egress inspection, and correlation with identity. When the attacker does not encrypt and only steals, backups are no longer the first line of defense.

Fourth, set up a fast verification path for public claims. If an organization appears on a leak site, response time should be measured in hours, not days. There needs to be a clear chain between legal, security, communications, and leadership to compare logs, review EDR, validate authentications, and prepare messages without accepting a criminal narrative that has not yet been proven.

Fifth, segment continuity by critical services, not by administrative domains. In health care and the public sector, the real risk is disruption of essential processes. That is why it is worth validating dependencies among applications, vendors, identity, storage, and backups. The goal is not only to avoid encryption, but also to maintain controlled degradation if one segment goes down.

Sixth, tighten third-party and cloud governance. The July Brazilian material keeps pointing to configuration failures, poorly protected cloud servers, and medical data traffic through unencrypted platforms. That calls for a vendor inventory, contract review, least privilege, encryption in transit and at rest, and periodic recovery tests from clean backups.

Seventh, in health care and public administration, run tabletop exercises focused on extortion with exfiltration. Simulating encryption is not enough. Teams need to practice public threats, media pressure, partial leaks, contact from affiliates, and regulatory coordination. July showed that many campaigns are aimed exactly at that.

Material limits

This report was built exclusively from the material provided for July 2026 and from the verified fact base for the period. That means only the items contained in the research block can support claims about activity during the month. Facts without a confirmed date were excluded from the indicators and could only be used as qualitative context, always with the caveat that their date is not confirmed.

The indicator window covers 248 dated facts in July 2026, with 26 without a confirmed date excluded. The indicator base consists of 241 verified facts from the period. The 7 aggregated telemetry records were not added to the volume, because they correspond to automated attempts or blocks and not to incidents with confirmed impact.

A zero indicator, especially in the case of critical CVEs, means that the element was not recorded in the material analyzed. It does not mean there were no critical vulnerabilities or no exploitation in the region. This month, the material only made it possible to identify one critical CVE mentioned, CVE-2023-20269, and the rest of the technical references remained at the level of vectors or attack surfaces without CVE numbering.

The coverage also excluded sources that were not suitable for supporting trends, such as consumer social media posts and certain promotional or press release materials when they did not provide sufficient evidence. In particular, LinkedIn posts were not used as evidence to assert confirmed incidents, even if they appear in the research block as reading context.

The country-by-country reading included only jurisdictions with verifiable facts within the period or with explicit technical context in the material. Countries without sufficient material were handled in a single aggregate sentence so as not to invent activity. The report does not add victims, URLs, or external figures beyond those provided, and it does not derive its own totals by summing categories that were not designed to be mutually exclusive.

Sources