Latin America Ransomware Activity, Aug. 2026
August saw 281 ransomware or extortion cases in LATAM, with Argentina, Brazil, Mexico, Chile, Peru, and Colombia among the focal points.
Key findings
- Ransomware was the leading threat in the month, with 281 primary cases out of 537 verified incidents in August.
- Argentina had the highest density of victims and claims, with Criba, Flecha Bus, AMCA, Oldelval, Sanatorio Modelo de Caseros, Tecno Acción, and INMAC among the most visible cases.
- The Gentlemen, Qilin, and DragonForce maintained regional pressure, focusing on construction, healthcare, transportation, and manufacturing.
- Most ransomware events in the month landed in visible extortion or leak-site territory, with 187 cases whose exact classification could not be determined from the material.
- The jump from 1 to 16 critical CVEs mentioned suggests greater perimeter exploitation density and abuse of remote access in the August material.
- Public confirmation was uneven: several incidents had solid claims, but few included full institutional or technical detail.
- Regional risk should be considered high due to volume, sector diversity, and the persistence of RaaS groups across multiple countries.
Monthly reference modules
These modules are completed automatically with the verified dated facts within the period. Each one states its basis and counting criterion so the figures reconcile across modules. They are the recurring month-to-month readout, and the analysis that follows expands on the cases without repeating this summary.
Indicator window: 541 dated facts in August 2026 · 61 from prior months (comparative frame, not monthly volume) · 14 without confirmed date (excluded from the indicators). Facts from prior months are used only as a comparative frame in the analysis, never as volume for this period.
Executive summary for the month
August 2026 closed with ransomware as the dominant threat in Latin America, based on 537 verified incidents and 281 cases where the primary focus was ransomware or extortion. The month combined confirmed victims, leak site claims, targeted exfiltrations, and several incidents that were not classified, with Argentina, Brazil, Mexico, Chile, Peru, and Colombia among the most exposed countries in the material reviewed.
The clearest reading of the period is the consolidation of groups able to operate in parallel across multiple sectors. Qilin, The Gentlemen, DragonForce, CoinbaseCartel, BLACKWATER, and Kazu appear in different cases during the month, with a particular concentration in construction, healthcare, transportation, manufacturing, professional services, and public administration. In several incidents, the material confirms at least one leak site claim, but not always the encryption or exfiltration, so the month is defined more by visible extortion pressure than by a single, uniform method.
Argentina was the country with the largest number of specific brands in the sample for the period. Reported there were, among others, Criba, Flecha Bus, Tecno Acción, INMAC Ingeniería y Arquitectura, Sanatorio Modelo de Caseros, AMCA, and Oldelval. Brazil also appears repeatedly, both through the mention of Intranet Gov Brasil and through the regional context in which DragonForce and The Gentlemen concentrated part of their activity. Mexico, meanwhile, continues to show a broad surface of victims claimed by different groups, although this report counts only the incidents dated in August and not historical maps without a confirmed date.
The month also produced two technical signals that help frame the state of the ecosystem. On one hand, The Gentlemen remained one of the most prolific actors globally and kept a presence in Latin America with victims in Argentina and Brazil, along with a cross-sector campaign targeting manufacturing, professional services, and healthcare. On the other hand, material on its attack chain reinforces abuse of exposed perimeter devices, privilege escalation, and EDR evasion techniques, which increases risk for organizations with poorly managed remote exposure.
In operational severity terms, the month was high. Not only because of the number of verified incidents, but also because of the mix of disruptions, leak claims, and victims with sensitive data or administrative impact. Sanatorio Modelo de Caseros, Criba, Flecha Bus, AMCA, and Oldelval each show different profiles, but all reveal the same tension, extortion-driven groups, heterogeneous attack surfaces, and public confirmation that arrives in fragments or does not arrive at all.
Regional overview for the month
August brought high regional activity, with sustained pressure on corporate and public sectors, and Argentina and Brazil standing out as visible centers of confirmed activity. The mix of 281 cases with ransomware or extortion as the primary focus, 104 unclassified incidents, and 25 documented fraud or phishing events points to a broad attack surface, not a single isolated outbreak.
There was no single dominant actor in absolute terms in the material, but campaigns were concentrated around groups with RaaS offerings, active leak sites, and double extortion capability. The Gentlemen emerges as the most visible regional actor by volume and persistence in South America under the comparative framework of previous months, while Qilin and DragonForce maintain a steady presence in Argentina, Brazil, and Chile. That continuity matters more than any individual leak headline, because it points to iterative campaigns rather than sporadic strikes.
Regional risk can be assessed as high. The reason is not a single telemetry figure, which is excluded from this report’s volume, but the density of verified incidents with direct source confirmation, the persistence of ransomware actors across multiple verticals, and the presence of critical or public-interest organizations among the victims or claims. The regional pattern remains one of multi-vector extortion, with the leak site often serving as the first visible sign rather than the final step in a fully resolved incident.
The sector picture is also consistent with the previous month. Construction, healthcare, transportation, manufacturing, and professional services appear frequently again, and in some cases energy and administrative infrastructure are added to the list. That reinforces a simple operational hypothesis, groups prioritize organizations with high dependence on continuity, greater willingness to pay in certain markets, and exposure through remote access or distributed perimeters.
Period indicators
The table below reproduces exactly the indicators provided for August 2026, based on 537 verified events in the period and the time window declared by the source itself. The figures describe the signal for the axis, not the research process.
| Indicator | August 2026 | Previous month | Change |
|---|---|---|---|
| Verified events in the period (base for all indicators) | 537 | 241 | +296 |
| Time window for the indicators | 541 events dated in August 2026 · 61 from previous months (comparative frame, not monthly volume) · 14 without confirmed date (excluded from the indicators) | ||
| Unclassified incidents (breaches or outages) | 104 | 46 | +58 |
| Cases with ransomware or extortion as the primary focus | 281 | 162 | +119 |
| Confirmed asset encryption | 26 | ||
| Exfiltration without encryption (pure extortion) | 22 | ||
| Leak site mention only | 46 | ||
| Type could not be determined from the material | 187 | ||
| Documented fraud or phishing cases | 25 | 7 | +18 |
| Documented regulatory moves | 1 | 3 | -2 |
| Critical CVEs mentioned | 16 | 1 | +15 |
| Sectors with at least one documented event | 8 | 8 | unchanged |
| Dominant threat for the month | Ransomware (281 of 537 events) | Ransomware (162 of 241 events) | |
| Events with direct source confirmation | 85% | ||
| Aggregated telemetry figures excluded from the volume | 4 | aggregated attempts or blocks, not incidents with confirmed impact |
The most important reconciliation in these indicators is methodological. The ransomware or extortion block totals 281 events, but within that set there are 26 confirmed encryption cases, 22 cases of exfiltration without encryption, 46 that only reach a leak site mention, and 187 that the material does not allow to be classified precisely. This means the visible extortion noise exceeds the technically confirmable impact subset, which is expected in ecosystems where the leak site appears before public confirmation.
The rise in critical CVEs mentioned, from 1 to 16, should not be read as evidence of more effective exploitation in the region. It instead reflects a higher density of technical references in the material reviewed. At the same time, the 85% direct source confirmation suggests a relatively solid documentary base, although not homogeneous in terms of institutional verification.
Relevant incidents
The most useful cases this month are the ones that connect actor, vertical, and type of impact with enough precision to guide defense and response. In August, the material shows a mix of leak site claims, breaches with quantified data, and a few incidents with clearer operational disruption.
Sanatorio Modelo de Caseros, Argentina
The Sanatorio Modelo de Caseros case is one of the month’s most visible, because of how many sources mention it and because the Qilin group appears repeatedly in different trackers. MedRisk, Darkfield, GalaxyWarden, RecentBreaches and Ransomware.live agree that Qilin added it to its leak site on 26 August, although the material itself makes clear that the claim was still unverified independently and that there was no public detail on the exact volume of leaked data.
That distinction matters. There are consistent signs of extortion and leak site publication, but the available evidence does not go far enough to say, without reservation, that the impact was only a claim or a fully confirmed breach. Hendry Adrian reported encryption of critical files and operational disruption, but the source does not provide an official statement from the sanatorium. In cases like this, the leak site is the strongest indicator, but it does not replace institutional confirmation.
The sector relevance is also clear. Health care remains a recurring ransomware target in the region, and this case fits that pattern. When a medical center appears as a listed victim, the risk is not only reputational or privacy-related. It also opens the possibility of disruption to appointments, medical records, internal coordination, and dependency on administrative systems, even if the material does not yet detail the exact scope.
Criba, Argentina and the DragonForce campaign
Criba brings together several attributes that make the case especially useful for operational analysis. BreachSense quantified the leak at approximately 188,25 GB, while Ransomware.live and Security Arsenal identified DragonForce as the party responsible for the publication within a 24-hour window that also included another victim in Brazil. In addition, the group’s public description mentions financial and customer documentation that would cover Argentina, Uruguay and other countries.
Unlike other claims this month, here there is an estimate of data volume. That does not validate the authenticity of the material, but it does point to a leak large enough to support serious extortion pressure. The combination of construction and project management with financial documentation suggests that the value of the haul was not limited to internal operations, but also extended to customer relationships, accounts and contracts.
The DragonForce campaign is also significant for its cross-border component. Security Arsenal noted concentrations in South America, with publications in Argentina and Brazil within the same window. That pattern suggests the ability to publish in batches and choose targets by opportunity, not by country alone. For regional defense, that means exposure at a subsidiary, contractor or business unit can be enough to turn the entire organization into an extortion target.
Flecha Bus, Argentina
Flecha Bus appears as a listed victim by CoinbaseCartel on 22 August, with transportation and logistics as the sector and Argentina as the country in the Dexpose material. Security Arsenal adds to the signal by noting that the group published 13 victims in 24 hours, including the Argentine company. According to the sources, the company did not publicly confirm the attack or the volume of data compromised.
The value of the case lies in the sector. Transportation and logistics remain frequent targets because the operational pressure is immediate and service visibility is high. Even if the material does not clarify whether there was encryption, exfiltration or only a leak site mention, the fact of appearing as an exposed victim already creates commercial and reputational impact.
There is also a regional continuity angle. The same month shows other targets in construction, health care and financial services. That suggests the groups are not limited to a single vertical, but look for organizations where the urgency to operate and the sensitivity of the haul give them room to negotiate. In transportation, that room is usually larger because of the cascading effect on users and customers.
AMCA, Argentina
AMCA, the Asociación Mutual de Conductores de Automotores, appears in Breachsense as a victim of the BLACKWATER group, with a discovery date of 17 August. Security Arsenal and FalconFeeds.io also place it in Argentina, and the material describes it as an entity tied to auto insurance, roadside assistance and financial benefits for drivers. That broadens the victim profile beyond a generic professional services label.
The case is useful because it sits at the intersection of financial services, insurance and mobility. There is no public confirmation from the organization in the sources provided, but there is a leak site publication and a consistent sector characterization. In this kind of operation, pressure on member data, policy information or internal documentation can matter as much as system unavailability.
The operational relevance is twofold. First, because BLACKWATER continues to show an appetite for targets with sensitive data and end-user exposure. Second, because the material indicates that opportunistic targeting can also land on mid-sized organizations, not just large corporations. That requires reviewing remote access controls, exposure inventory and segmentation, even in mutual associations and insurers at intermediate scale.
Oldelval, Argentina
Oldelval represents a different kind of incident, closer to administrative disruption than to a pure leak site case. The company informed CNV that it suffered a cybersecurity incident in its administrative systems and classified it as a RaaS ransomware attack. It also said that crude transport was not interrupted and that the affected systems were restored.
The case matters for two reasons. The first is sectoral, because this is critical energy infrastructure in Argentina. The second is attribution, because secondary sources and material on social networks mention The Gentlemen and INC RANSOM at different points, but the company did not publicly confirm a specific author. In this report, that means caution, there is a confirmed incident, but not a definitive attribution supported by the victim itself.
What Oldelval leaves behind is the signal of an attack with limited impact on physical operations, but real impact on administrative systems. That is enough to affect billing, document control, internal support or the availability of certain processes. In infrastructure sectors, that kind of disruption can be the prelude to greater pressure if containment is not fast.
Tecno Acción and INMAC Ingeniería y Arquitectura, Argentina
Tecno Acción was reported by HookPhish as a victim of The Gentlemen group, with a breach date of 28 August and a discovery date of 30 August, under the data breach label. INMAC Ingeniería y Arquitectura S.A., meanwhile, appeared on 31 August in a FalconFeeds.io notice that pointed to a supposed Qilin victim, with intent to publish data in seven or eight days.
Both cases matter for the same reason. They show that the threat ecosystem is not limited to victims already leaked or to high-volume incidents, but also to early claims on intelligence portals and social channels. In neither case does the provided material include public confirmation from the affected organization, so the right approach is to treat them as claims with different levels of confidence, not as equivalent findings.
The analytical value lies in the sector and geography. Construction and architecture appear again in Argentina, this time under the orbit of Qilin and The Gentlemen. That repetition is more informative than the specific group name, because it suggests the local market still offers enough surface area for extortion campaigns that combine publication, leak threats and time pressure around payment.
Instituto Ferrero de Neurología y Sueño, Argentina
Kazu claimed responsibility on 23 August for an attack against Instituto Ferrero de Neurología y Sueño, threatening to release sensitive data if there was no negotiation. Dexpose recorded it as a ransomware incident against a specialized medical center in Argentina, but the material does not publicly detail the volume of data or confirm institutional involvement by the facility.
The value of the case is that it reinforces pressure on health care beyond large hospitals. Specialized centers, clinics and diagnostic services are also in the crosshairs because they hold highly sensitive data and depend on continuous availability to operate. At that point, simple extortion can be as effective as encryption, because the reputational cost of disruption is high.
Kazu appears several times in this month’s archive in other countries in the region, which reinforces its status as an active actor in sensitive verticals. The pattern is not new, but it is persistent: a group can publish several health care victims in a short period and use the accumulated noise as leverage to accelerate payments or open negotiations.
Active Threats and Campaigns
August showed a ransomware and extortion ecosystem dominated by multi-target campaigns, with a strong presence of leak sites and a subset of incidents in which the material does allow a distinction between encryption, exfiltration, or simple victim publication.
Ransomware and extortion with confirmed or probable impact
Qilin was the most visible actor in Argentina during the month, with Sanatorio Modelo de Caseros, INMAC Ingeniería y Arquitectura, and the Tecno Acción case in the incident tracking environment. In Sanatorio Modelo de Caseros, there are signs of encryption and operational disruption in one source, but other sources are limited to the leak site claim and the unconfirmed breach category. That contrast is typical of August, the material confirms extortion pressure before the full technical detail.
DragonForce led a regional campaign that left Criba as a victim in Argentina and another publication in Brazil. In Criba, there is a specific estimate of leaked data, which moves the case from a mere mention to exfiltration with publication pressure. The group also appears as one of the actors maintaining a sustained presence in South America, according to the analysis cited by Security Arsenal.
The Gentlemen remained active across several countries and verticals, with a strong presence in manufacturing, construction, professional services, healthcare, and transportation. In the region, its relevance is not limited to the month’s victims. The comparative framework places it among the most prolific actors in South America in the first half of 2026, and the technical material on its attack chain describes abuse of exposed perimeters, network reconnaissance, and EDR evasion.
CoinbaseCartel, BLACKWATER, and Kazu round out the picture with victims in transportation, insurance, healthcare, and professional services. Not every case allows for a confirmation of encryption. In several, the real signal is publication on a leak site and the threat of disclosure. In others, there are descriptions of stolen data or quantified leakage. That mix confirms that extortion value no longer depends only on locking systems, but on making a credible claim visible.
Documented fraud and phishing
The 25 documented fraud or phishing incidents in the period confirm that malicious activity was not limited to ransomware. The available material does not concentrate these events in a single regional campaign, but it does present them as part of the same risk climate, with deception, initial access, and credential abuse techniques that can later feed an extortion incident.
For defensive teams, this category matters because it is often the step before intrusion. The month repeatedly shows chains that begin with remote access, firewall exposure, or compromised credentials. Although the report separates fraud and phishing from ransomware, the coexistence of both axes in the same period suggests a shared and reusable entry surface.
APT and hacktivism
The August material does not show a clear block of APT or hacktivism with confirmed Latin American victims within the scope of this report. There are external references to campaigns and alerts in other contexts, but they are not enough to classify a regional trend for this period under that axis. The verifiable focus of the month remains ransomware and extortion.
Critical vulnerabilities
The material from the period mentions 16 critical CVEs, but it does not allow for a complete list of confirmed exploitation against Latin American victims with the same level of detail for every case. The presence of CVEs in the source does not, by itself, prove attribution or successful impact in the region.
| CVE | Software | Exploitation | Source |
|---|---|---|---|
| CVE-2026-50751 | Check Point Security Gateway | Cited as the most likely primary vector in The Gentlemen campaign | Security Arsenal |
| CVE not specified in the material | VPN gateways, firewalls and remote access tools | Abuse of exposed perimeter devices as the intrusion vector | Security Arsenal |
| CVE not specified in the material | Fortinet FortiOS and FortiProxy | Exploitation of critical vulnerabilities by ransomware groups, according to a cited advisory | The Hacker News, CISA and related sources in the material |
| CVE not specified in the material | SonicWall SMA1000 | Flaws exploited by ransomware gangs, according to a cited advisory in the material | BleepingComputer and CISA, cited in the material |
| CVE not specified in the material | OT devices and exposed operational technology | Exposure of remote interfaces and internet-connected devices | The Register, Tenable and related sources in the material |
The most useful signal here is the perimeter attack surface. The material repeatedly points to abuse of VPNs, firewalls and remote access, and The Gentlemen appears tied to a specific CVE in Check Point. That does not mean every case in the month can be explained by the same vector, but it does show that perimeter exposure remains an especially profitable entry point for RaaS crews.
Regulation and compliance
August saw few strict regulatory moves in the verified material, but compliance impact was not absent. Only one documented regulatory action appeared in August, compared with three in the prior month, pointing to a quieter agenda on rules or formal notices and a greater weight on operational incidents.
The Oldelval case is the clearest example in this chapter, because it included a filing with the CNV and company reporting on the incident, the scope of the impact on administrative systems, and the continuity of crude transport. That kind of notification matters for both compliance and crisis management, since it establishes an early corporate account and leaves less room for speculation.
In the health sector, the material also points to compliance tension, though not always through formal regulatory statements. Sanatorio Modelo de Caseros and Instituto Ferrero de Neurología y Sueño appear in the context of leak sites and breach trackers. When public confirmations do not arrive, regulatory pressure often shifts to internal audits, notification obligations, and reviews of third-party contracts.
Countries Most Affected in Latin America
The month’s geographic distribution shows concentration in Argentina and Brazil, with Mexico, Chile, Peru, and Colombia included as part of the comparative context and the regional victim coverage, although this report only weighs facts dated in August 2026.
Argentina
Argentina recorded the highest density of verifiable incidents during the period. The list includes Criba, Flecha Bus, AMCA, Sanatorio Modelo de Caseros, Tecno Acción, INMAC Ingeniería y Arquitectura, Oldelval, and Instituto Ferrero de Neurología y Sueño, spanning sectors from construction and transportation to health care, insurance, and energy.
The key takeaway in Argentina is not just volume, but variety. The country concentrated victims claimed by Qilin, DragonForce, CoinbaseCartel, BLACKWATER, Kazu, and, incidentally, references to The Gentlemen and INC RANSOM in Oldelval’s environment. That mix of actors suggests there is no single entry point or one vulnerable sector.
There is also a pattern of uneven transparency. Oldelval offered a clearer corporate account than other cases, while leak site posts and breach trackers dominate the reporting for Sanatorio Modelo de Caseros and Criba. For local teams, that means combining reputation monitoring, perimeter hardening, and response protocols that do not depend on a third party confirming the incident.
Brazil
Brazil appears mainly as the regional counterpart to campaigns that also affected Argentina. The Gentlemen and DragonForce concentrated posts in South America, and the month’s material confirms victims in Brazil within the same analyzed windows. In addition, the semester’s comparative coverage still places it among the region’s most exposed countries.
Brazil’s relevance in August is not limited to the number of events. What matters is that it appears as a jurisdiction with enough density of actors, leak sites, and published victims to support ongoing campaigns. In practice, that makes the country a major barometer for regional ransomware activity.
Mexico
Mexico does not concentrate dated facts within the main incident block for the period at the same level as Argentina, but the available material keeps it among the countries with broad historical exposure. For August, the comparative context still shows a heavily targeted market, with the public sector, health care, manufacturing, and business services among the recurring targets.
The useful reading for the month is that Mexico’s attack surface remains broad, although many undated historical records were left out of the indicators. That prevents historical volume from being mixed with monthly volume. Even so, Mexico’s ecosystem remains a regional reference point for ransomware monitoring because of the number of victims publicly claimed in tracking sources.
Chile
Chile appears as a reference country for the expansion of Qilin and The Gentlemen in the comparative frame, and as a territory where other groups also maintained activity in previous months. In August, the material does not show a block of dated incidents as large as Argentina’s, but it does confirm that the threat remains spread across technology, energy, and health care.
Chile’s significance lies in the type of targets, not in a single count. When ransomware actors manage to surface in sensitive or high-value verticals, the country becomes a point of interest for regional campaigns. That means looking not only at visible volume, but also at the persistence of the same groups across different jurisdictions.
Peru
Peru appears in the comparative material and in some events from nearby months, especially through monitoring of health care and the public sector. In August, the report does not record a density of dated facts comparable to Argentina’s, but it does confirm that the Andean region remains under pressure from extortion actors.
Peru’s analytical value this month is as a reminder that groups extend campaigns across countries and sectors. Although the bulk of verifiable activity is concentrated in Argentina and Brazil, the regional pattern does not leave Peru or its most sensitive verticals out.
Colombia
Colombia appears in the file as a country of concern due to incidents in the justice system and public services, although much of that material corresponds to previous weeks or comparative coverage. For August, the underlying message is that the public sector remains a viable target and that administrative disruption incidents retain political and operational relevance.
Other countries in the region
Paraguay and Bolivia do not show enough verified incidents in the August material to warrant a separate section. The rest of Latin American countries also do not present, in this set, a specific signal above the level of isolated mention. That does not mean there is no activity, only that there is no verifiable material within the scope of this report.
Trends and signals to watch
The main trend in August is the rise in visible extortion pressure, not necessarily a linear increase in all technical impacts. Compared with the previous month, verified incidents rose from 241 to 537, cases with ransomware or extortion as the primary focus went from 162 to 281, and fraud or phishing incidents increased from 7 to 25. The change is not only quantitative, it also reflects denser documentation.
The other major takeaway is sector diversification. The previous month already showed eight sectors with at least one documented incident, and August keeps that number unchanged. Far from signaling stagnation, that points to a troubling consistency. There is no single dominant vertical, but rather sustained spread across construction, health care, transportation, manufacturing, professional services, insurance, energy, and public administration.
The third signal is technical. The jump from 1 to 16 critical CVEs mentioned shows that August’s material includes more references to vulnerability exploitation and perimeter abuse. The Gentlemen, in particular, reappears tied to VPN gateways, firewalls, remote tools, and CVE-2026-50751. That combination suggests that perimeter hardening remains a high-return line of defense.
The shift in the ratio between claims and confirmations is also worth watching. Although 85% of the incidents have direct source confirmation, much of the technical damage still sits somewhere between the leak site and independent verification. For defensive intelligence, that requires three parallel layers of work: monitoring publications, institutional verification, and assessment of the likely operational impact.
Security team recommendations
The first step is to immediately harden any exposed VPN, firewall, or remote access. This month’s material and the technical analysis of The Gentlemen both point to exposed perimeter systems as a profitable intrusion path. Strong authentication, a review of exposed rules, an inventory of remote services, and accelerated patching should be at the top of the work queue.
The second priority is to improve the ability to detect early exfiltration. Several cases this month rest on leak site claims or partial leaks. That requires monitoring for unusual movement to storage services, file-sharing domains, and uncommon external accounts, along with alerts on large outbound volumes from administrative servers and privileged user workstations.
The third is to strengthen the response to compromised credentials. According to the material, The Gentlemen abuses network reconnaissance, privilege escalation, and tools designed to neutralize endpoint defenses. A useful response plan should include mass credential resets, token invalidation, service account reviews, and verification of persistent administrative access.
The fourth measure is to separate operational continuity from administrative availability. Oldelval showed that an incident can leave the main physical process untouched and still affect critical administrative systems. Energy, health care, logistics, and transportation organizations should have manual and contingency procedures for billing, shifts, dispatch, traceability, and internal coordination.
The fifth is to formalize monitoring of leak sites and breach trackers. In August, several cases only became visible because a group posted them or an aggregator indexed them. That does not replace internal detection, but it does buy time. It is advisable to establish triage processes with clear thresholds to distinguish a claim, a leak, exfiltration, and confirmed encryption.
What should a CISO prioritize this week?
Perimeter, credentials, and exfiltration monitoring should be the top priorities, because those three fronts appear repeatedly behind this month’s campaigns. If the organization has remote exposure, it should review patches and authentication. If it depends on operational continuity, it should test manual contingencies. If it has already been named on a leak site, the response needs to move from observation to containment.
How can an organization reduce the risk of being listed only as a leak site claim?
The key is to detect the attack before the threat actor publishes. That means segmenting access, limiting privileges, reviewing third-party accounts, alerting on anomalous data خروج, and keeping the inventory of exposed assets up to date. Once publication has already happened, the focus should shift to forensic verification, evidence preservation, and coordinated internal communication.
Frequently Asked Questions
What was the practical difference this month between confirmed encryption, exfiltration, and a leak site?
The difference was central to interpreting August. There were 26 cases with confirmed encryption, 22 with exfiltration without encryption, 46 mentioned only on a leak site, and 187 that the material did not allow to classify. For more detail, see the period indicators and relevant incidents sections.
Which actors stood out most this month in Latin America?
The most visible groups were Qilin, The Gentlemen, DragonForce, CoinbaseCartel, BLACKWATER, and Kazu. The signal comes not from a single source, but from cross-checking relevant incidents, threats and active campaigns, and the most affected countries in Latin America, where victims appear in Argentina, Brazil, and elsewhere.
Which sectors were most exposed in the region?
Health care, construction, transportation, manufacturing, professional services, insurance, and energy appear repeatedly in the August sample. That reading comes from cross-checking incidents by country with the ransomware cases and the indicators table, which shows eight sectors with at least one documented event.
Were critical vulnerabilities clearly exploited in the region?
The material mentions 16 critical CVEs, but it only explicitly links CVE-2026-50751 to a campaign, in the case of The Gentlemen. For the rest, the month’s evidence points more to perimeter exposure and abuse of remote access than to closed, confirmed exploitation of a complete CVE list.
How reliable is the month’s volume for measuring the real damage?
It is useful for measuring signal, not total damage. The report works with 537 verified events in August and excludes 14 without a confirmed date, and it does not add aggregated telemetry to the incidents. The material limitations section explains why a zero count or a leak site claim does not mean there was no real activity.
Material limitations
This report was built exclusively from the material provided and is geographically limited to Latin America. The time window used for the indicators was the one stated in the input, with 541 dated events in August 2026, 61 from earlier months used as a comparative frame, and 14 with unconfirmed dates excluded from the indicators.
A zero value in an indicator, especially for CVEs, means it was not recorded in the material analyzed, not that no critical vulnerabilities were exploited in the region. Likewise, a mention in a leak site does not always mean confirmed encryption or exfiltration. When the material did not allow a distinction, the category remained undeterminable.
Aggregated telemetry figures were also left out of the volume because they refer to attempts, blocks or vendor averages, not to incidents with confirmed impact. The same applies to events with unconfirmed dates, which may serve as qualitative context but do not count toward the month’s indicators or August totals.
Sources not included in the approved list were also excluded, along with consumer social media posts when they were not expressly validated within the available source, and commercial statements or promotional material used only as contextual support in some cases. The result is a useful operational snapshot, but one that is necessarily partial relative to the full ransomware universe in the region.
Sources
- Ransomware Alert: INMAC Ingeniería y Arquitectura S.A. – Qilin ransomwareFalconFeeds.io (Twitter/X)
- Ransomware Group thegentlemen Hits: Tecno AccionHookPhish
- Ransom! Sanatorio Modelo de Caseros (AUG-2026)Hendry Adrian
- Qilin gang claims Buenos Aires hospital breach on leak siteMedRisk.io
- Sanatorio Modelo de Caseros data breach — Qilin ransomware leak (2026)Darkfield (Orizon)
- Sanatorio Modelo de Caseros Listed by Qilin Ransomware GroupGalaxyWarden
- Sanatorio Modelo de Caseros: Unconfirmed Breach Claims & DoxxScan RatingRecentBreaches.com
- Victim: Sanatorio Modelo de CaserosRansomware.live
- CRIBABreachSense
- Victim: CribaRansomware.live
- DRAGONFORCE Ransomware Gang: 4 New Victims Posted in 24 Hours — Cross-Border Campaign Analysis and Detection EngineeringSecurity Arsenal
- Criba — DRAGONFORCE Ransomware AttackBreach House
- Ransomware Group dragonforce Hits: CribaHookPhish
- Criba in Argentina reportedly faces a DragonForce ransomware claimCybersecurity News Everyday (Twitter/X)
- Kazu Ransomware Hits Instituto Ferrero de Neurología y SueñoDexpose
- CoinbaseCartel Targets Argentine Transport Giant Flecha BusDexpose
- COINBASECARTEL Ransomware Gang: 13 Victims Posted in 24 Hours — Financial Services Blitz, Sector Analysis and Detection RulesSecurity Arsenal
- THEGENTLEMEN Ransomware Gang: 5 New Victims in 72 Hours, Cross-Sector Campaign Targeting Defense, Finance, and Critical TransportSecurityArsenal
- Kaspersky alerta sobre la expansión del grupo de ransomware The GentlemenEBiz LATAM
- The Gentlemen Ransomware Threat Hunting Case StudySOC Prime
- Studio di Caso di Threat Hunting del Ransomware The GentlemenSOC Prime
- AMCABreachsense
- BLACKWATER Ransomware Gang: 2 New Victims Posted on Leak Site — India & Argentina Targeting Analysis with Detection RulesSecurity Arsenal
- Emergence and Operations of The Gentlemen RansomwareMallory.ai
- Ransomware Alert: Asociación Mutual de Conductores de Automotores – BLACKWATER ransomwareFalconFeeds.io (Twitter/X)
- Ransomware Threats in the Americas H1 2026: Dissecting the Regional Attack Patterns and Dominant ActorsMalware.news
- Threat report note on The Gentlemen ransomware operationRST Cloud
- Advisory Alert: How The Gentlemen Ransomware Blinds Your EDR DefensesLumu
- La sofisticación de "The Gentlemen": Kaspersky alerta sobre ransomware con backdoors a medida que impacta LatamTecknow News / Kaspersky
- The State of Ransomware Q2 2026Check Point Research
- Bitdefender Threat Debrief | August 2026Bitdefender
- The Gentlemen Ransomware - Threat ActorFortiGuard Labs
- Threat Hunting Case Study: The GentlemenIntel471
- THEGENTLEMEN Ransomware Gang: 25 New Victims Posted, Sector Targeting Analysis and Detection RulesSecurity Arsenal
- Grupo de ransomware Gentlemen desenvolve ferramentas para desativar EDRTechEnet
- Industrial Ransomware Analysis for Q2 2026Dragos
- Intranet Gov Brasil Listed by The Gentlemen Ransomware GroupGalaxyWarden
- Ransomware a Oldelval: la gobernanza que le falta a Vaca MuertaDataTrends LATAM
- Ransomware Surges in July After Q2 LullInfosecurity Magazine
- Ransomware Alert: Oldelval reportedly victim of INC RANSOMFalconFeeds.io
- Oldelval Cyberattack Hits Argentina's Top Oil PipelineThe Rio Times
- Argentina's Main Oil Pipeline Was Hacked. The Oil Kept MovingThe Rio Times
- Ciberataque a Oldelval: incidente en Vaca Muerta revela falenciasDefonline
- July 2026 Ransomware Wrap-UpZeroFox
- Denuncian un intento de ciberataque al operador del mayor oleoducto de la ArgentinaÁmbito
- Los ataques de ransomware aumentan un 16% y apuntan a servicios empresariales, manufactura y tecnologíaITSitio / Agencia NVM (citando ESET)
- La Sevillanita — GLOBAL SECRET GROUP Ransomware AttackBreach House
- Qilin Ransomware Group Targets Ejército ArgentinoDexpose
- Ransomware Map – Argentina (mobile view)Ransomware.live
- Ransomware Map – ArgentinaRansomware.live
- Ransomware Victims Tracking | Threat Intelligence Command ...Ransomware.live
- Ransomware.live 👀Ransomware.live
- Group: Global Secret GroupRansomware.live
- Consultores de Seguros: Unconfirmed Breach Claims & DoxxScan RatingRecentBreaches
- Consultores de Seguros data breachBreachSense
- Ransomware Group qilin Hits: Consultores de SegurosHookPhish
- qilin — Ransomware Group Profileervik.as
- Consultores de Seguros Listed by Qilin Ransomware GroupGalaxyWarden
- Qilin Targets Insurance Firm Consultores de Seguros in Ransomware AttackDeXpose
- Ransomware group qilin hits Consultores de Seguros | HackerFeedsHackerFeeds
- Victim: Consultores de Seguros – qilinransomware.live
- Consultores de Seguros — QILIN Ransomware AttackBreach House
- www.neooftalmo.com.br Ransomware Claim (2026) — What’s Alleged & Am I Affected?Recent Breaches
- Victim: www.neooftalmo.com.br (Krybit)Ransomware.live
- Mobilemed sofre ataque de ransomware com roubo de 23,5 TB de dados, diz grupo KazueAgora
- Ransomware Attacks This Week: 287 Victims Across 53 Groups…Scrutex.ai
- Daily Briefing – Monday, 24th August 2026APJ One
- Listado de víctimas atribuidas a KazuIntel and Breaches (X)
- Brazil’s Mobilemed Hit by Ransomware: Healthcare Imaging Services Face Another Dangerous Cybersecurity Test + VideoUnderCode News
- Victim: Brazil Mobilemed: Cloud PACS Platform – kazuRansomware.live
- Ransomware Group kazu Hits: Brazil Mobilemed: Cloud PACS PlatformHookPhish
- Kazu Ransomware Claims Two More Healthcare Targets, Putting Cloud Medical Systems Under Growing Pressure + VideoUnderCode News
- Brazil Mobilemed: Cloud PACS PlatformDragons Community
- Ransomware Group kazu Hits: Meducar: Telemedicine and Patient Management SystemHookPhish
- Qilin Ransomware Claims a Chilean Technology Company as Brazil’s Healthcare Sector Faces Another Ransomware Attack + VideoUnderCode News
- Kazu Ransomware Targets Brazil's MobilemedDexpose
- LockBit 5.0 Compromises Brazilian Defense Contractor ICNDexpose.io
- icnavais.com Ransomware Claim (2026) — What’s Alleged & Am I Affected?Recent Breaches
- Check Point registra 2% das vítimas de ransomware no BrasilIT Section
- Ransomware Alert: Prefeitura Municipal de Arcos reportedly victim of EMPERADORFalconFeeds.io (X)
- Emperador Ransomware Attack on Prefeitura Municipal de ArcosDexpose
- La sofisticación de "The Gentlemen": Kaspersky alerta sobre ransomware con backdoors a medida que impacta LatamTecknow News
- DIREWOLF Ransomware Gang: 10 Victims Posted in 24 HoursSecurityArsenal
- cesmac.edu.br Listed by krybit Ransomware GroupGalaxyWarden
- Latin America's public bodies keep appearing on leak sitesIntelFusions
- Intranet Gov Brasil Listed by thegentlemen Ransomware GroupGalaxyWarden
- LockBit 5.0 Strikes Brazilian Communications Leader Grupo RáiDexpose.io
- rai.com.br Listed by Lockbit5 Ransomware GroupGalaxyWarden
- Brazil ransomware victim mapransomware.live
- Alerta de ransomware sobre nuevas víctimas del grupo Dire WolfFalconFeeds.io (cuenta en X)
- Publicación sobre Hospital Clínico Universidad de Chile listado por DireWolfRansom-DB (cuenta en X)
- Ransomware Group direwolf Hits: Hospital Clnico Universidad de ChileHookPhish
- TheGentlemen Strikes Espinos S.A., a Leading Chilean Energy FirmDeXpose
- Layher Listed by thegentlemen Ransomware GroupGalaxyWarden
- TheGentlemen Ransomware Attack on Layher in ChileDeXpose
- Victim: Difor – qilinRansomware.live
- Difor — QILIN Ransomware AttackBreach House
- TheGentlemen Ransomware Claims Multiple Victims Across ...Mallory.ai
- Qilin ransomware group has added Difor Chile as victimFalconFeeds.io (X)
- Difor in Chile was hit by Qilin ransomwareCybersecurity News Everyday (X)
- Ransomware Group thegentlemen Hits: EspacHookPhish
- Layher Chile Data Breach in 2026BreachSense
- Espac Listed by thegentlemen Ransomware GroupGalaxyWarden
- Alerta de ransomware sobre nuevas víctimas del grupo TheGentlemenFalconFeeds.io (cuenta en X)
- Espac — THEGENTLEMEN Ransomware AttackBreach House
- thegentlemenransomware.live
- “Tu vulnerabilidad es nuestra riqueza”: hackers golpean empresa en ChileReporteDiario.cl
- Ataque a la cadena de suministro de LiteLLM: qué pasó y cómo reaccionarPasquale Pillitteri
- "Tu vulnerabilidad es nuestra riqueza": el ataque de hackers que golpeó a empresa en ChileBioBioChile
- LiteLLM Supply Chain Attack: 2500+ Companies Exposed ...CloudSEK
- ANCI activa alerta preventiva en Chile tras el mayor hackeo a la cadena de suministro de IA del añoRadio Siglo 25
- Ransomware Alert: Servicios Marítimos MG víctima de MS13-089FalconFeeds.io (X)
- LiteLLM CVEs and AI gateway privilege gaps: what breaks first?NHIMG
- Inside the LiteLLM Hack: 153GB and 2,488 OrganizationsGitGuardian
- ANCI activa protocolo preventivo y notifica a veintena de instituciones chilenas por hackeo a LiteLLMBioBioChile
- Una ventana de 40 minutos en PyPI alcanzó 434.000 canalizaciones de compilaciónAgenccy.ai
- The Week In Breach News: August 26, 2026Kaseya
- Minjusticia adopta medida temporal de contingencia para la atención de PQRDSFMinisterio de Justicia y del Derecho de Colombia
- Weekly Threat Bulletin – August 19th, 2026F5
- Los ciberataques a la información de la justicia que el ministro Cancino ha tenido que enfrentarLas2orillas
- Colombia’s Ministry of Justice Hit by Ransomware Attack Disrupting ServicesCyberWarriors Middle East
- 17th August – Threat Intelligence ReportCheck Point Research
- El Ministerio de Justicia explica cómo avanza la recuperación de sus servicios digitales tras ciberataqueEl Tiempo
- Majinahanashi Ransomware Attack on PIO PIO in ColombiaDexpose
- Minjusticia activa plan de seguridad luego de sufrir ataque cibernéticoEl Espectador
- THEGENTLEMEN Ransomware Gang: 15 Victims in a Single-Day Surge — Sector Analysis, CVE Correlation & Detection RulesSecurity Arsenal
- Ransomware Hits Justice Ministy as Colombia Gets New ...Dark Reading
- INC Ransomware Gang Leads Attacks Exploiting Critical ...Codekeeper
- Así se recupera el Ministerio de Justicia tras ciberataque que redujo la disponibilidad de algunos serviciosInfobae
- Los ataques de ransomware aumentan un 16% y apuntan a servicios empresariales, manufactura y tecnologíaTendencia Internacional
- MinJusticia confirmó ataque cibernético que afectó parte de su infraestructura tecnológicaNoticias Caracol
- Comunicado sobre ataque cibernético con virus tipo ransomware al Ministerio de Justicia (publicación en X)El Tiempo
- Ministerio de Justicia sufrió ciberataque ransomware, similar al de EcopetrolCaracol Radio
- Comunicado del Ministerio de Justicia y del Derecho a la opinión públicaMinisterio de Justicia y del Derecho de Colombia
- Actualización del comunicado oficial sobre el incidente de ciberseguridadMinisterio de Justicia y del Derecho de Colombia
- Iván Cancino denuncia ciberataque al MinJusticia a días de asumir el cargoEl Colombiano
- コロンビア法務省がランサムウェア被害を公式発表NexSight Cyber
- Ataque cibernético contra el Ministerio de JusticiaInfobae Colombia
- Actualización sobre el ataque cibernéticoMinisterio de Justicia y del Derecho de Colombia
- Colombia's Ministry of Justice Hit by Ransomware AttackNetSecOps
- Ransomware Hits Colombia's Ministry of Justice - dataenforceDataEnforce
- Ransomware Hits Colombian Justice Ministry Ahead of Presidential Transition: Detection, Response, and Hardening GuideSecurityArsenal
- Ataque ransomware inutiliza Ministerio Justicia ColombiaMenteHackers
- Colombia Justice Ministry Hit With Ransomware — 0dayNews0dayNews
- Hacker exige dinero por datosEL MAÑANA SLP
- Ayto. denunciará hackeo en la FGEPulsosLP
- [Intel MX] 2026-08-26 Extorsión a un ayuntamiento en San ...Ransomware.mx
- Mexico's Cybersecurity Plan 2025-2030: Turning Ambition into ActionRecorded Future
- Hacker Allegedly Used Artificial Intelligence to Violate Municipal SystemsGround News
- Tras hackeo intentan extorsionar al Ayuntamiento de San Luis PotosíEl Universal San Luis Potosí
- Federis Abogados Listed by Booba Project Ransomware GroupGalaxyWarden
- Ransomware Group Booba Project Hits: Federis AbogadosHookPhish
- BOOBA PROJECT Ransomware Gang: 2 New Victims Posted — Financial & Professional Services Targeting Analysis with Detection RulesSecurityArsenal
- IQSEC documenta 116 víctimas y 101 filtraciones de datos en México en siete semanasBNamericas
- Federis Abogados — BOOBA PROJECT Ransomware AttackBreach House
- booba project — Ransomware Group Profileervik.as
- Federis Abogados: Unconfirmed Breach Claims & DoxxScan RatingRecentBreaches
- Hacker intentó negociar tras robo de datos al Ayuntamiento de SLPOEM / El Sol de San Luis
- Centro Médico Especializado OSI: Healthcare Solutions — KAZU Ransomware Attack | Breach HouseBreach House
- El hacker y los omisosPulso Diario de San Luis
- Información vulnerada en hackeo al ayuntamiento de SLP era pública, asegura alcaldeEl Universal San Luis Potosí
- Ransomware Group kazu Hits: Centro Médico Especializado OSI: Healthcare SolutionsHookPhish
- Ransom! Quaker State Mexico (AUG-2026)Hendry Adrian
- Tras tercer hackeo, ahora al Cobach, desactivan acceso a datos robadosPulso Diario de San Luis
- Alert on Qilin ransomware targeting CS Shell & Quaker State MéxicoX (FalconFeeds.io)
- Victim: CinépolisRansomware.live
- Cinépolis Ransomware Claim (2026) — What’s Alleged & Am I Affected?RecentBreaches
- Cinépolis — QILIN Ransomware AttackBreach House
- Victim: Quaker State MexicoRansomware.live
- Ahora hackean al AyuntamientoEl Mañana SLP
- Ayuntamiento de San Luis Potosí denunciará ante Fiscalía hackeo y filtración de información de servidores públicosWar Room SLP
- Ayuntamiento de SLP denunciará ante la Fiscalía hackeo y filtración de datos de servidores públicosEl Universal San Luis Potosí
- Alerta sobre dos nuevas víctimas mexicanas de ransomware según ransomware.liveX (CiberBaur)
- Ransomware Alert: Grupo Integraduanas victim of Qilin ransomwareFalconFeeds.io
- Qilin Ransomware Strikes Integraduanas in MexicoDeXpose
- SEARS, posible víctima de hackers spacebears, según ransomware.liveX
- Sears México data breach entryBreachSense
- [Intel MX] 2026-08-16 Grupo spacebears reclama a SEARS de Grupo Sanbornsransomware.mx
- Space Bears Ransomware group adds SEARS (Grupo Sanborns) as victimFalconFeeds.io
- Ransomware Group spacebears Hits: SEARS (Grupo Sanborns)HookPhish
- Victim: SEARS (Grupo Sanborns)ransomware.live
- Qilin ransomware en México: víctimas, recuperación y qué hacerransomware.mx
- Kaspersky warns ransomware abuses BitLocker, prints ransom notes via corporate printersKorea Economic Daily (Biz Chosun)
- The Gentlemen RansomwareBlackpoint Cyber
- Ransomware aumenta 16.5% en 2026; México, entre los países más afectados de América LatinaEITMedia
- July 2026 Ransomware Report: 811 Victims, 66 GroupsBreachSense
- Las VPN se convierten en objetivo prioritario de los ataques de 'ransomware'Computerworld España
- 273 victims for Mexico - Ransomware.liveRansomware.live
- Recent postsRansomlook.io
- Ransomware Payment Trends Q2 2026Veeam
- Panorama de ransomware en MéxicoRansomware Response
- Mapa de víctimas de ransomware – Méxicoransomware.live
- EsSalud retira a dos funcionarios de Lambayeque tras fraude de S/1.4 millonesDiario Correo
- La Contra / Colectivo PAS - bloque sobre transferencias no reconocidas en EsSaludYouTube
- Centro Médico Especializado OSI: Healthcare Solutions — ficha de víctima ransomwareDragons Community
- Centro Médico Especializado OSI: Healthcare Solutions — KAZURansomware.live
- 2026-08-23 Kazu golpea la telemedicina: una plataforma de salud usada en México en la miraIntel MX (ransomware.mx)
- Kazu gang posts eight healthcare targets in one leak dayMedRisk.io
- Kazu Ransomware Targets Centro Médico Especializado OSI in PeruDexpose
- Global Go — KILLSEC Ransomware AttackBreach House
- Ransomware Group killsec Hits: Global GoHookPhish
- Victim: Global Go - KillsecRansomware.live
- Global Go Listed by killsec Ransomware GroupGalaxyWarden
- QILIN Ransomware Gang: 15 New Victims Posted in 72 Hours — Cross-Sector Campaign Targeting Energy, Hospitality & ManufacturingSecurity Arsenal
- Ciberdelincuentes acceden a claves y token bancario de EsSalud Lambayeque para robo millonarioInfobae Perú
- 83 victims for Peruransomware.live
- Así fue el robo de S/1,4 millones de EsSalud Lambayeque: la falsa llamada, el acceso remoto y las transferencias que nadie detuvoInfobae Perú
- Movitecnica Data Breach in 2026BreachSense
- Nota sobre denuncia de EsSalud y sustracción de S/1,4 millones en LambayequeYo Soy Independiente
- EsSalud: Denuncian sustracción de S/1,4 millones mediante transferencias bancariasDiario Correo
- OCURRE AHORA | segmento sobre estafa en EsSalud LambayequeYouTube
- Movitecnica Listed by Qilin Ransomware GroupGalaxyWarden
- Publicación sobre posible víctima de ransomware Movitecnica en PerúVenariX en Español (X)
- Movitecnica — QILIN Ransomware AttackBreach House
- Movitecnica data breach — Qilin ransomware leak (2026)Darkfield (Orizon)
- Ransomware Group Qilin Hits: MovitecnicaHookPhish
- Movitecnica: Unconfirmed Breach Claims & DoxxScan RatingRecentBreaches
- Alerta de monitoreo sobre publicaciones de cibercrimen con menciones a organizaciones de Perú (actividad no confirmada)VECERT (radar público en X/Twitter)
- INKA Group GmbH Co Listed by The GentlemenGalaxy Warden
- Publicación sobre ataque de Krybit a HYMIASA con impacto en operaciones en PerúTweetThreatNews (X)
- Sanatorio Modelo de Caseros — QILIN Ransomware Attack | Breach HouseBreach House
- Hacker pone precio al botín robado al Ayuntamiento - PulsoPulso
- Poder Judicial de SLP admite posible hackeo y cambiará de proveedor de informáticaWar Room SLP
- El hacker y los omisosPulso SLP
- En peligro, información de ciudadanosSan Luis Hoy
- Hacker intentó extorsionar al Ayuntamiento capitalinoCódigo San Luis
- Cobach se vuelve objetivo de hackersPlano Informativo
- KAZU Ransomware Gang: 9 Healthcare & Professional Services Victims Posted in Single-Day Surge — Targeting Analysis & Detection RulesSecurity Arsenal
- Flecha Bus NEW Listed by Coinbase Cartel Ransomware GroupGalaxyWarden
- Prefeitura Municipal de Arcos data breach claim (2026) — unverified leak-site allegationDisclosureLens
- Emperador Ransomware Targets Prefeitura Municipal de Arcos, Raising Fresh Concerns for Public Sector CybersecurityUNDERCODE NEWS
- Victim: Prefeitura Municipal de ArcosRansomware.live
- Prefeitura Municipal de Arcos Listed by EmperadorGalaxyWarden
- The Gentlemen ransomware: Inside one of the fastest-growing extortion operationsBarracuda
- Ransomware Threats In The Americas H1 2026: Deep DiveCyble
- AnMed Investigating Ransomware Group's Data Theft ClaimsHIPAA Journal
- El 'ransomware' se dispara un 87 % a nivel global y España sufre 2.068 ciberataques semanalesInfobae
- Ransomware attacks reach highest volume in the last 12 months.TI Inside
- Gunra ransomware targets hospitals: CISA, FBI issue new warningBecker's Hospital Review
- CISA Warns of Gunra RaaS Targeting Critical InfrastructureNetSecOps Cyber
- QILIN Ransomware Gang: 26 New Victims Posted in 100- Posting Window, APAC Expansion, Government Targeting and Detection RulesSecurity Arsenal
- The Gentlemen: Kaspersky alerta sobre su expansión en ransomwareInfosertecla
- US and South Korea warn of Gunra ransomware targeting ...BleepingComputer
- Cybersecurity and Infrastructure Security Agency on XCISA
- Agencies warn of attacks by Gunra ransomwareAmerican Hospital Association (AHA News)
- Empresas bajo amenaza: el secuestro digital crece 16,5% y ya golpea a LatinoaméricaEcuador Today Media
- AIG activa Centro de Operaciones de Ciberseguridad para vigilar ataques a instituciones públicasTVN-2
- CISA: SonicWall SMA1000 flaws now exploited by ransomware gangsBleepingComputer
- #StopRansomware: Gunra RansomwareCybersecurity and Infrastructure Security Agency (CISA)
- Gunra Ransomware Hit Hospitals and Governments; Linux Victims Should Not Pay RansomTechTimes
- Gunra Ransomware: Six-Agency Advisory Targets Fortinet ...Cybersecurity Journal Canada
- Gunra Ransomware Exploits Fortinet FortiOS, FortiProxy ...The Hacker News
- CISA, FBI and Partners Warn Organizations of Gunra Ransomware Actors Targeting Multiple Critical Infrastructure SectorsCybersecurity and Infrastructure Security Agency (CISA)
- CISA, FBI Warn Gunra Ransomware Targets Critical InfrastructureMeritalk
- Ransomware Gammax publica a AguAseo, empresa de servicios públicos de PanamáKali Linux / Pulse (Kali Radar)
- Global Ransomware Group Compromises Vigilia in UruguayDexpose
- Victim: Vigilia – globalransomware.live
- [Intel MX] 2026-08-07 Ciberataque a la Caja Virtual de la UASLP; datos educativos de menores en la mira regionalransomware.mx
- Filtran datos de más de 1 millón de niños en Uruguay: los venden en la dark webDiario Bitcoin
- And where does the newborn go from here? The net is vast and infinite. — SECTION9 Ransomware AttackBreach House
- Ransomware Group Section9 Hits: And where does the newborn go from here? The net is vast and infinite.Hookphish
- Section9ransomware.live
- Section9 Ransomware Breach Tracker (12 incidents)Galaxy Warden
- Section9: Data Breaches, Victims & MethodsRecentBreaches
- And where does the newborn go from here? The net is vast and infinite. data breach — Section9 ransomware leak (2026)Darkfield / Orizon One
- Russian-Speaking Hackers Used Cursor AI in Attacks on ...eSecurityPlanet
- Russian-Speaking Cybercriminals Used SpaceX's AI Tool ...Claims Journal
- Russian-speaking cybercriminals used SpaceX's Cursor AI ...Reuters
- wmiemporium.com — KRYBIT Ransomware AttackBreach House
- Victim: Lockheed Architectural Solutions, Inc. – Global Secret Groupransomware.live
- mswalker.com: Unconfirmed Breach Claims & DoxxScan™ RatingRecentBreaches
- mswalker.com Ransomware Claim (2026) — What’s Alleged & Am I Affected?RecentBreaches
- GLOBAL SECRET GROUP Ransomware: 3 US Victims Posted in 24 HoursSecurity Arsenal
- New crew Storm goes after US clinics, banks and factoriesIntelFusions
- Victim: Tiseo Paving – Global Secret Groupransomware.live
- mswalker.com — CHAOS Ransomware AttackBreach House
- Victim: mswalker.com – chaosransomware.live
- CHAOS Ransomware Gang: 3 New Victims Posted in 24 HoursSecurity Arsenal
- StormEncrypter Ransomware: IOCs, MITRE TTPs & DetectionManageEngine
- KRYBIT Ransomware Gang: 13 Victims in 48 HoursSecurity Arsenal
- METAENCRYPTOR Ransomware Gang: 7 Victims in 24 HoursSecurity Arsenal
- BARRACUDA Ransomware Gang: 3 New Victims PostedSecurity Arsenal
- Group: Dark ProjectRansomware.live
- Government Agencies Updates Warning Against MedusaThe National Law Review
- STORM Ransomware Gang: 7 New Victims Posted in 72 HoursSecurity Arsenal
- Storm gang claims Indiana acute care hospital in fresh leak postMedRisk
- RXPE Group Ransomware Claim (2026) — What’s Alleged & Am I Affected?RecentBreaches
- Ransomware group coinbasecartel hits Integrated Health SystemsHackerFeeds
- Victim: Integrated Health SystemsRansomware.live
- CoinbaseCartel Breaches Integrated Health SystemsMalware.news
- Integrated Health Systems Ransomware Claim (2026) — What’s Alleged & Am I Affected?RecentBreaches
- Coinbase Cartel lists medical billing firm Integrated Health SystemsMedRisk
- Satine Sentinel: August 21, 2026SatineTech
- Troutman Pepper Locke Silent as Threat Actors Leak Client Data, Tens of Thousands of SSNsDatabreaches.net
- Weekly Intelligence Report - 21 Aug 2026Cyfirma
- Ransomware attacks surge in 2026 with bold new extortion tacticsQUE.com
- Kingston Technology: Unconfirmed Breach Claims & DoxxScan™ RatingRecentBreaches
- Kingston Technology Listed by Everest Ransomware GroupGalaxyWarden
- Kingston Technology — EVEREST Ransomware Attack | Breach HouseBreach House
- CISA Warns Medusa Ransomware Threatens Critical InfrastructureGovly
- Число жертв Medusa в США превысило 500: под ударом ...Techora.ru
- Grupo DT Listed by Everest Ransomware Group | GalaxyWardenGalaxyWarden
- EVEREST Ransomware Gang: 4 New Victims Posted in Single-Day Surge — Tech & Professional Services Targeting Analysis with Detection RulesSecurity Arsenal
- Kingston Technology Ransomware Claim (2026) — What’s Alleged & Am I Affected?RecentBreaches
- Kingston TechnologyBreachSense
- Kingston Technology: Exclusive: RAM maker Kingston Technology investigating ransomware claimsRankiteo
- Victim: Kingston Technology - Ransomware.liveRansomware.live
- Third Coast Bancshares Data Breach in 2026BreachSense
- CISA Warns Medusa Ransomware Has Hit 500 Critical-Infrastructure Orgs, Tags Two TrueConf Server Flaws as Actively ExploitedTech-Quire
- Lansing Urgent Care Data Breach in 2026BreachSense
- CISA flags healthcare as frequent Medusa ransomware victimTech Informed
- HHS, FBI warn hospitals as Medusa ransomware tops 500 victimsBecker's Hospital Review
- Agencies issue update on Medusa ransomware activityAmerican Hospital Association
- #StopRansomware advisory on Medusa ransomware (social media post)FBI Jacksonville
- Medusa Ransomware Hit Over 500 Critical Infrastructure Organizations2W Tech
- SWK Cybersecurity News Recap August 2026SWK Technology
- Protect Against Medusa Ransomware AttacksAmpcus Cyber
- Medusa: more than 500 organisations hit - BerigoBerigo (resumen de advisory CISA/FBI/HHS)
- Notice of Data IncidentAOL
- CISA, FBI and HHS Update Joint Cybersecurity Advisory on Medusa RansomwareCISA (US DHS)
- Medusa Ransomware (CISA AA25-071A): 500+ victims, 24h patching window, and exploited CVEsChors Security
- Troutman Pepper Locke LLP Data Theft Extortion by SilentRansomGroup (Repeat Attack Including Physical Intrusion) — Threat ID TL-2026-2103Threadlinqs Intelligence
- Feds update guidance on Medusa Ransomware after healthcare attacksPaubox
- SILENTRANSRANSOMGROUP: 3 New Victim Postings on Dark Web Leak Site — US Professional Services Targeting Analysis & Detection EngineeringSecurity Arsenal
- Over 500 Critical Infrastructure Organizations Hit by Medusa RansomwareInfosecurity Magazine
- Medusa Ransomware Hit 500 Critical Sites, FBI Says in New AlertTech Debrief
- Medusa Ransomware Hits 500 Critical Infrastructure OrgsCybersecurity Insiders
- Third Coast Bancshares Listed by Inc Ransom ...GalaxyWarden
- Lansing Urgent Care Data Breach? Lawyers Investigate ...ClassAction.org
- Missouri hospital hit by ransomware attackBecker's Hospital Review
- INCRANSOM Ransomware Gang: 7 New Victims Posted in 72 Hours — Cross-Sector Campaign Analysis and Detection Engineering BriefSecurity Arsenal
- Interim HealthCare — ANUBIS Ransomware AttackBreach House
- Victim: Interim HealthCareransomware.live
- Interim HealthCare Ransomware Claim (2026) — What’s Alleged & Am I Affected?RecentBreaches
- Ransomware Group Claims Attack on Interim HealthCareBreachLetter
- XPL0ITRS Ransomware Gang: 3 New Victims PostedSecurity Arsenal
- DIREWOLF Ransomware Gang: 6 Victims Posted in 48 Hours — Healthcare & Tech Targeting Analysis with Detection RulesSecurity Arsenal
- Ransomware: anubis claims Interim Healthcare (US) — HealthcareMatproof
- Ransomware Group anubis Hits: Interim HealthCareHookphish
- Ransomware Group Storm Hits: Rood and Riddle Equine HospitalHookphish
- Brecha en gestor de salud expuso datos de 3,8 millones de personas en EE.UU.NIVEL4 Labs
- Rood & Riddle Equine Hospital Ransomware Claim (2026) — What’s Alleged & Am I Affected?RecentBreaches
- Victim: Rood & Riddle Equine Hospitalransomware.live
- COINBASECARTEL Ransomware Gang: 4 New Victims Posted in 48 Hours — Professional Services, Agriculture and Manufacturing Targeting Analysis with Detection RulesSecurity Arsenal
- Suisun City Ransomware AttackTechTimes
- The Ripple Effect: Massive Data Breach at Unlimited Technology Systems Highlights Vulnerability in Healthcare Supply ChainHealth Recovery Support
- Weekly Cyber Threats & Breaches Report: 10–16 Aug 2026FireCompass
- Gunra Shifts Ransomware to Perimeter Break-ins · PlainSec briefing, 2026-08-12PlainSec
- Cybercrime News For Aug. 11, 2026. Hackers Cripple 911 In California City.WCYB Digital Radio
- Healthcare Orgs Warned About Gunra Ransomware AttacksHIPAA Journal
- Ransomware Hits 911 Systems and Government Services Across Five StatesProtect Computer
- Federal Agencies Warn of Gunra Ransomware Targeting Healthcare, Government and Critical ServicesObiaks
- Ransomware breach at health IT vendor tops 3.8 million patientsBecker's Hospital Review
- Tienen que desenchufar literalmente la ciudad para frenar a los hackers: el ataque que ha dejado sin red al 911 en CaliforniaLa Razón
- Unlimited Technology Systems updates recent data breach to 3.8M victimsPaubox
- US healthcare software giant Unlimited Technology Systems admits hackers may have stolen sensitive data of 3.8 million peopleTechRadar
- Risky Bulletin: Pwnie Awards 2026 winnersRisky Business
- How Prepared Are We for Cyberattacks on Cities, Water Systems?NPR / KQED Forum
- Ransomware breach at health IT vendor tops 3.8 million patientsBecker's Hospital Review
- Experts say healthcare faces cybersecurity crisis: 'These are patient ...Cybersecurity Dive
- Una ciudad del norte de California declaró el estado de emergencia tras un ciberataque que afectó el sistema 911 y otros servicios claveInfobae
- Cyber attack targets California city's 911 systemABC News
- Suisun City Declares State of Emergency After CyberattackKQED
- Chaos as California city declares state of emergency after hackers ...Yahoo News / NewsNation
- Suisun City Council Declares State of Emergency in response to Cybersecurity IncidentSuisun City
- Nueva York destina USD $9 millones para blindar 153 sistemas de agua contra ciberataquesDiario Bitcoin
- Suisun City declares state of emergency after cyberattackTelemundo Area de la Bahia
- Suisun City declares state of emergency after IT systems breachKCRA
- Cidade dos EUA declara emergência após ciberataque atingir sistemas do 911 e da políciaTargetW
- Did Iran hack water systems in at least seven US states?BBC
- Oleada de 'hackeos' a los sistemas de agua potable de EEUU: la guerra moderna que apunta a Irán como sospechosoEl Español
- Unlimited Technology Systems data breach exposes information of 3.8M patientsTop Class Actions
- City of Coweta, Oklahoma Hit by Anubis Ransomware AttackThreadlinqs Intelligence
- City of Coweta Hit by Ransomware: Oklahoma Community Faces Major Digital Disruption as Recovery BeginsUNDERCODE News
- Coweta Ransomware Attack Locks City Computers As Officials Refuse To Pay HackersRadio Oklahoma News
- City of Coweta Refuses Ransom After CyberattackGovly
- Coweta, Okla., Confronts Systemwide Ransomware AttackGovTech
- DRAGONFORCE Ransomware Gang: 4 US Victims in Single Day Leak BatchSecurity Arsenal
- Minnesota & other US Water Cyber Attacks, CISA AA26-097ATenable
- El FBI alerta de un ciberataque contra sistemas de agua en siete estados de EE.UU.Moncloa
- INCRANSOM Ransomware Gang: 10 Victims in 5 Days — Cross-Sector Campaign Hits Healthcare, Energy & Quantum TechSecurity Arsenal
- Interlock Ransomware Strikes Gardiner Family ChiropracticDexpose
- Gardiner Family Chiropractic Ransomware Claim (2026) — What’s Alleged & Am I Affected?Recent Breaches
- Interlock and Clop Ransomware Claims Put Two Businesses Under Fresh Dark Web Pressure + VideoUNDERCODE NEWS
- Hackers targeted municipal water systems in 7 states this week, FBI and EPA warnYahoo News
- Investigators probing possible Iran connection to Minnesota water system cyberattacksABC News
- Michigan joins Minnesota in reporting cyberattacks, with FBI investigatingAl Jazeera
- US cyber defense agency warns hackers are increasingly targeting water systemsReuters
- US authorities probe cyberattack on water systems in MinnesotaAl Jazeera
- Estados Unidos sospecha que Irán pudo estar tras el ciberataque a los sistemas de agua de MinnesotaLa Tercera
- Federal Regulators Settle HIPAA Enforcement Action with OSF HealthcareLeadingAge
- FBI investiga ciberataques contra sistemas de abastecimiento de agua en Míchigan y MinnesotaEl Nuevo Día
- Iran-linked CyberAv3ngers suspected in attacks on Minnesota water systemsThe Register
- FBI Investiga ciberataque contra sistemas de agua en Minnesota; señalan a hacker iraníesExcélsior
- Cyberattack targets more than 30 Minnesota water systemsUSA Today
- Ciberataque coordinado afectó a más de 30 sistemas comunitarios de agua en MinnesotaNivel4
- El FBI investiga ciberataques a los sistemas de agua de Michigan y MinnesotaUnivision
- Qué hay detrás de los ciberataques contra sistemas de agua en 7 estados de EEUU y por qué muchos apuntan a IránEl Observador
- Hackers targeted municipal water systems in 7 states this week, FBI saysNBC News
- Minnesota cyberattack has hallmarks of Iran-backed hackers, source saysNBC News
- Ataque cibernético coordenado atinge 30 estações de água nos Estados Unidos e mobiliza força-tarefaTecmundo
- New cybersecurity committee follows years of attacks on Mississippi’s public sectorMississippi Independent
