Ransomware Activity in Latin America, September 2026
Ransomware led the regional signal with 157 verified incidents; Argentina and Brazil concentrated the clearest extortion cases
Key findings
- Ransomware was the month’s leading threat, with 157 cases out of 399 verified incidents.
- Argentina and Brazil concentrated the strongest incidents, with Jujuy, Hospifar, Vitar Group, K3G Solutions, and Receita Federal as key references.
- Most of the signal continued to rely on leak site claims rather than public confirmations from victims.
- Panzer stood out for quantifiable exfiltration in Brazil, while Emperador combined sensitive claims involving justice and tax agencies.
- Health care, government, and technology remained the sectors under the most visible pressure in the region.
- The comparison with August shows lower volume but not lower risk: incidents and critical CVEs declined, while regulatory activity increased.
- This month’s material requires careful separation of confirmed encryption, exfiltration without encryption, and leak site mentions alone.
Monthly reference modules
These modules are completed automatically with the verified facts dated within the period. Each one states its source and counting criterion so the figures reconcile across modules. They are the recurring month-to-month readout; the later analysis develops the cases without repeating this summary.
Indicator window: 401 dated facts in September 2026 · 102 from prior months (comparative frame, not monthly volume) · 14 without confirmed date (excluded from the indicators). Facts from prior months are used only as a comparative frame in the analysis, never as volume for this period.
Monthly executive summary
September 2026 closed with ransomware as the dominant signal in Latin America, built on 399 verified incidents during the period and 157 cases with ransomware or extortion as the primary focus. The region showed a mix of leak-site listings, confirmed exfiltration, and some episodes involving encrypted assets, with Argentina and Brazil the most represented countries in the material analyzed.
The month was not defined by a single, uniform campaign, but by several simultaneous operations at different levels of verification. In the best documented cases, Emperador left behind an already publicized incident against the Jujuy Judiciary and also claimed responsibility for a case involving Receita Federal do Brasil. Panzer targeted K3G Solutions Brazil, with an estimated 300 GB exfiltrated and explicit pressure to negotiate. Qilin stayed active in the region with new references to Argentina, including the Grupo Hospifar case and the publication of Vitar Group.
The quality of the evidence was uneven. Seventy-five percent of the incidents had direct source confirmation, but many of the month’s ransomware records remain claims from groups or leak-site monitors, without public confirmation from the affected organizations. That means three distinct layers have to be kept separate: confirmed encryption, exfiltration without verified encryption, and mere mention on a leak portal. In September, all three appeared in the material, although the last was the most common.
Argentina was the country with the highest density of concrete incidents in the material, especially because of the Jujuy case and mentions of Hospifar, Vitar Group, and the Ministry of Education. Brazil showed greater diversity of actors, from Panzer to Emperador, as well as cases in healthcare, telecom, and tax administration. Mexico added relevant signals in the final stretch of August and in comparisons published during September, but the volume of events dated strictly within the month was more concentrated in Argentina and Brazil.
The month also brought a methodological shift in coverage. The total number of verified incidents fell from August, the number of cases with ransomware or extortion as the primary focus dropped sharply, and the critical CVEs mentioned declined. At the same time, documented regulatory moves increased, suggesting a more visible institutional response, although still fragmented. Regional risk remains high because of the persistence of active groups, the recurring targeting of healthcare and government, and the continued posting on leak sites with potential operational and reputational impact.
Regional overview for the month
September’s regional signal was high, not because of a uniform surge in confirmed incidents, but because of the mix of volume, sector-level repetition, and the presence of groups with sustained activity across several countries. The material analyzed shows particular pressure on government, healthcare, technology, and telecommunications, with cases where extortion was explicit even if the operational damage was not always confirmed by the victim or a regulator.
Latin America remained exposed to a familiar pattern, but with better attribution detail. The groups most frequently appearing in the month’s corpus, Emperador, Panzer, Qilin, Titan and TheGentlemen, operate through a leak-site logic that prioritizes public pressure over technical disclosure. That means the most verifiable fact is often not the intrusion itself, but the posting of the claim, the data estimate, and the taxonomy used by the monitor that records it.
The sector reading is equally clear. Healthcare remained a recurring target, both because of its operational sensitivity and the value of the exposed information. Government and defense appeared in specific cases in Argentina, while telecom and IT were repeated in Brazil. This month’s material also shows again that small and mid-sized organizations, and entities with public-facing systems, remain especially attractive targets for rapid extortion campaigns.
The region enters September with high qualitative risk. This assessment is based not on a made-up index, but on the presence of 157 events in which ransomware or extortion was the primary focus within 399 verified events, plus the variety of active groups and the continued presence of critical sectors on the radar. Although the total number of events fell from August, the qualitative severity remains high because the month left leaks, unconfirmed claims, sensitive data mentioned and, in some cases, evidence of significant exfiltration.
Period indicators
The table below reproduces exactly the indicators provided for September 2026, with the same base, the same time window, and the month-over-month comparison reported. The reading should be based on the signal at the axis, not on a raw count of actual operations across the region.
| Indicator | September 2026 | Previous month | Change |
|---|---|---|---|
| Verified events for the period, base for all indicators | 399 | 537 | -138 |
| Time window for the indicators | 401 events dated September 2026, 102 from prior months as a comparative frame, 14 without confirmed date excluded from the indicators | ||
| Untyped incidents, breaches or outages | 101 | 104 | -3 |
| Cases with ransomware or extortion as the primary focus | 157 | 281 | -124 |
| Confirmed asset encryption | 12 | n/d | n/d |
| Exfiltration without encryption, simple extortion | 18 | n/d | n/d |
| Leak site mention only | 27 | n/d | n/d |
| Typing could not be determined from the material | 100 | n/d | n/d |
| Documented fraud or phishing cases | 19 | 25 | -6 |
| Documented regulatory actions | 6 | 1 | +5 |
| Critical CVEs mentioned | 4 | 16 | -12 |
| Sectors with at least one documented event | 8 | 8 | unchanged |
| Dominant threat of the month | Ransomware (157 of 399 events) | Ransomware (281 of 537 events) | relative decline |
| Events with direct source confirmation | 75% | n/d | n/d |
| Aggregate telemetry figures excluded from the volume | 2, aggregate attempts or blocks, not incidents with confirmed impact |
The interpretive base for the month is the same for all indicators, 399 verified events for the period. The time window includes 401 events dated September 2026, 102 events from prior months as a comparative frame, and 14 without a confirmed date that were left out of the indicators. That distinction matters because the coverage published in September does not always equal activity that occurred in September.
The ransomware taxonomy also became more clearly defined this month. Of the 157 cases with ransomware or extortion as the primary focus, 12 had confirmed encryption, 18 were sustained by exfiltration without encryption, 27 were only mentioned on a leak site, and 100 did not allow the impact to be determined precisely. That spread shows why each group claim should not be read as a fully validated breach.
Relevant Incidents
Judiciary of Jujuy, Emperador
The case involving the Judiciary of the Province of Jujuy was one of the month’s most concrete incidents because it combines a leak site posting, consistent attribution across monitors, and a relatively precise description of the exposed data. Darkfield classifies it as a data leak attributed to Emperador, in Argentina’s Government and Defense sector, with a data leaked status and critical severity. RecentBreaches, meanwhile, keeps it as an uncorroborated claim.
The most useful source for operational reading is Darkfield, which indicates compromise of WordPress databases, access credentials for internal systems, and email credentials. TechWalrus adds an important nuance, noting that at the time of publication there was no public technical analysis detailing the intrusion or the forensic evidence. That means the case has a highly visible extortion and leak component, but still lacks full independent validation.
For government teams, the key issue is not only the victim name, but the pattern. Emperador is a new actor, first observed in August 2026 and financially motivated, which fits short-maturity operations that try to capitalize on rapid publication. In this case, the exposure of credentials and databases raises the risk of lateral movement, internal impersonation, and credential reuse across other judicial services.
K3G Solutions Brazil, Panzer
K3G Solutions Brazil was one of the month’s strongest cases in terms of estimated exfiltration and extortion pressure. Ransomware.live lists it as a Panzer victim with discovery and attack date estimated for September 18, 2026, and reports 300 GB of exfiltrated data, along with references to employees, compromised users, and third-party credentials. Dexpose confirms that Panzer claimed the attack on September 18 and threatened to publish the full leak if there was no contact.
Sector coverage identifies K3G Solutions as a Brazilian telecom and IT consultancy with network engineering, ISP support, monitoring, call center, CDN, and colocation services. That profile makes it a high-value target because of its proximity to third-party infrastructure. Although the group also places it within broader categories, the real critical attack surface is that of a provider that can drag risk onto customers and technical dependencies.
This is not just a mention on a portal. It is a combination of publication, estimated stolen volume, and an explicit threat of further disclosure. Operationally, this fits the category of exfiltration without confirmed encryption, or at least a breach where the strongest verifiable element is theft and extortion, not encryption. For Brazil, the case reinforces the risk facing technology service firms that support telecommunications functions and third parties.
Receita Federal do Brasil, Emperador
The appearance of Receita Federal do Brasil on Emperador’s portal was one of the month’s most sensitive institutional records, although public confirmation of the incident is still absent. Ransomware.live published the reference with an alleged 6.3 GB exfiltration and mention of documents containing staff and customer data, as well as gov.br users and passwords. IntelFusions and TechStart agree that the group used the post as a claim, but found no official communication validating the intrusion.
This case matters because it combines two traits that usually raise the potential impact. First, the symbolic and operational value of Brazil’s tax authority. Second, the possibility that an unconfirmed claim creates reputational pressure before there is public verification of scope. For that reason, it should be treated as a leak site mention with an alleged exfiltration, not as a leak validated by the affected entity.
For Brazil’s risk picture, the signal is serious even if incomplete. If the attribution were confirmed, the impact could affect credentials, internal documentation, and potentially other connected state services. For now, the material only supports saying that Emperador included Receita Federal on its portal and that the claim was not confirmed by an official body by the close of the reviewed coverage.
Judiciary of Jujuy and Receita Federal, Emperador, combined reading
The two Emperador-linked cases in September should not be read as isolated events. The campaign shows an ability to select high-visibility public entities and sustain pressure through publications, even if the available evidence does not always reach the threshold needed to validate actual access or the claimed data volume. The group appears focused on government and defense, which explains the recurring institutional victims.
For a regional reader, the operational signal is twofold. On one side, the provincial judiciary in Argentina was exposed to credentials and databases. On the other, a Brazilian tax authority was placed under public claim on an extortion portal. The coincidence of both events in the same month shows that state targets remain attractive to new actors seeking immediate resonance.
Grupo Hospifar S.R.L., Titan
Hospifar is the Argentine case where coverage was both more restrained and more limited. APJ One included it among Titan’s victims recorded on September 22 and classified it as a healthcare-sector organization in Argentina, but clarified that this is a ransomware activity record and not a confirmation of the affected entity. Ransomware.live also published it on its leak site.
Kalir described the inclusion as an active and urgent incident for Argentine healthcare entities, although it acknowledged there was no Hospifar statement, no data volume, and no public forensic evidence. That combination suggests an early claim, likely still in an observation phase. Taxonomically, the case currently falls into the category of a leak-site mention only, because independent confirmation of impact is not available in the material.
Even so, the analytical value is clear. Titan is using public exposure of its leak site to apply pressure on an Argentine healthcare provider. For the regional healthcare sector, the episode confirms that extortion against clinics and providers does not necessarily depend on large hospitals or national networks, but also on mid-sized organizations with sensitive data and fragile operational continuity.
Argentina Ministry of Education, weekly monitoring publication
Argentina’s Ministry of Education appeared in a weekly ransomware summary as one of the victims recorded between September 14 and 20. The available material provides no technical details, no group, no impact, and no public confirmation from the agency. For that reason, the case is useful for tracking presence in the monitoring ecosystem, but not for inferring real scope.
From an editorial standpoint, this is the kind of fact that can inflate perceptions if read out of context. The correct reading is that a weekly list included an Argentine victim from the education sector, not that there was a confirmed breach with encryption or validated exfiltration. It remains relevant because it keeps the public sector in view and adds to Argentina’s heavy monthly volume.
Vitar Group, Qilin
Qilin published Argentine company Vitar Group on its leak site, according to dark web monitoring. The available source does not provide data volume or a company statement, so the case remains classified as a leak site mention. What it does show is continued Qilin activity in the country and the persistence of its public pressure model.
This case matters more for context than for technical detail. Qilin remained active in Latin America during September and in the comparable August period. The presence of another Argentine company name on its leak site reinforces that the country remains a frequent target for groups that combine extortion, publication, and, in some cases, encryption.
Active Threats and Campaigns
Ransomware and Extortion
The month’s dominant campaign remains ransomware-linked extortion, but verification levels vary widely. Most of the 157 primary cases never reached a closed technical classification. Of that total, only 12 had confirmed asset encryption, 18 showed exfiltration without encryption, 27 were limited to a leak site mention, and 100 did not allow the impact to be determined with precision.
That breakdown reflects how the signal is actually consumed now. Groups publish first, and defenders, authorities, or the media, if they show up at all, arrive later. That is why leak site claims have to be read carefully. A publication claim does not, by itself, amount to ransomware with confirmed encryption. Nor does a figure for stolen GB automatically validate an intrusion with the same scope the actor suggests.
Emperador, Panzer, Qilin, Titan and TheGentlemen make up the visible core of September. Emperador had the most sensitive pieces tied to the public sector in Argentina and Brazil. Panzer showed measurable exfiltration in Brazil. Qilin kept adding victims in Argentina. Titan appeared in Argentine healthcare. TheGentlemen also remained relevant in the regional comparison, although some of its clearest cases closed in late August and are useful here as context, not as September volume.
Fraud and Phishing
The September material documents 19 fraud or phishing cases, down from 25 in the previous month. That does not signal disappearance, only a lower visible density in the reviewed archive. The most useful example for understanding the relationship between phishing, deception and ransomware is the Brazilian case cited by Convergência Digital, which describes an attempt to persuade employees to hand over passwords so ransomware could be installed.
That kind of tactic shows why phishing and ransomware often overlap in practice. The initial access vector may be social, and the later extortion phase may be technical, but the month’s material does not allow a full chain to be built for every case. The key point is that coercion against users and administrators remains part of the ecosystem, especially in sectors with many contact points and low tolerance for disruption.
APT and Hacktivism
The period’s material does not include a clearly attributable APT campaign tied to the ransomware axis in Latin America, but it does show hybrid pressure on public infrastructure. The note about government websites hijacked to display betting and illegal activity, while not ransomware, again shows that the state surface is still being used for reputational damage and traffic diversion. That does not count toward the axis, but it does help frame the threat environment.
Telemetry also shows clusters using AI tools and campaigns aimed at government, transportation, water and financial services in Mexico, Ecuador and Brazil. That measurement reflects attempts and operational support, not an incident with confirmed impact. It therefore serves as defensive context, not as a basis for increasing the intrusion count. In campaign terms, the region continues to receive operations that combine automation, social engineering and extortion-driven monetization.
Critical vulnerabilities
No critical CVEs were recorded in the analyzed material for September 2026 as facts of the period. That does not mean critical vulnerabilities were absent from the region, only that the file received did not document them as part of the verifiable monthly volume.
| CVE | Software | Exploitation | Source |
|---|---|---|---|
| No critical CVEs were recorded in the analyzed material | n/a | n/a | Monthly indicator provided for September 2026 |
The comparison with August does show a clear shift. The previous month had mentioned 16 critical CVEs, while in September the verifiable material leaves only four critical references in total within the indicator. That drop suggests the month was driven more by leak site posts and group claims than by technical exploitation of critical vulnerabilities described in the sources received.
Regulation and Compliance
September saw more documented regulatory activity than August, with six moves compared with one in the prior month. This is not yet a uniform regulatory shift across the region, but it does point to more institutional reaction to incidents, claims, or risk conditions. The correct reading is that authorities and agencies are showing up more often in the conversation, even if they are not always issuing final decisions.
The clearest example of compliance and response was the Colombian case cited by the Ministry of Justice. It reported a technology recovery plan with alternate channels for PQRS and support documents, partial operation of SICOQ, and temporary downtime for MICC. The process also involved support from the Prosecutor General's Office, COLCERT, Microsoft’s DART team, and BID partners. That points to a major incident response with real operational impact.
In Argentina and Brazil, the material shows a more uncomfortable contrast. There are multiple complaints and monitoring records, but little visible official confirmation in the most sensitive cases. That lack of public response does not erase the incident, but it does make the regulatory picture harder to frame. In the case of Receita Federal, IntelFusions and TechStart specifically note the absence of an official statement at the close of their coverage.
The compliance signal is twofold. On one hand, teams need to be ready to report and document any exfiltration or outage quickly. On the other, they should assume that a post on a leak site may come before formal validation of the incident. Crisis management and evidence preservation remain more important than public disputes over terminology.
Most affected countries in Latin America
Argentina
Argentina concentrated several of the clearest cases this month. The Jujuy Judiciary was the strongest incident in terms of the data cited and sustained attribution, while Hospifar and Vitar Group added pressure on the health care and business sectors. The Ministry of Education also appeared in a weekly roundup, along with the August case of Sanatorio Modelo de Caseros, which helps frame the persistence of the risk even if it does not count toward September volume.
The Argentine pattern combines government, health care, and education, three verticals that are especially sensitive to ransomware. The main operational takeaway is that the groups are not only after money, but also visibility and public pressure on systems with little tolerance for downtime. The range of actors, Emperador, Titan, and Qilin, also shows that no single group is monopolizing the country.
Brazil
Brazil showed greater diversity across sectors and groups. Panzer hit K3G Solutions Brazil with significant exfiltration and a threat to publish everything, while Emperador added Receita Federal to its leak site. The country also appears in the health care, telecom, and IT context, and in the monthly comparison with several references to extortion activity in critical sectors.
Brazil stood out in September not only for the number of references, but also for the nature of the victims. K3G Solutions operates close to technology and connectivity infrastructure, and Receita Federal has a highly sensitive state profile. That places Brazil at a more complex intersection of operational and reputational risk than other regional markets. For local CISOs, the message is that vendors and public agencies can be equally attractive targets.
Mexico
Mexico appeared prominently in the material, although some of the more visible context comes from late-August posts or weekly comparisons. In September, it remains on the radar because of actors such as TheGentlemen in the regional analysis and references to agricultural and technology sectors in monitoring sources. The country remains one of the region's most closely watched hubs for extortion and ransomware.
The most cautious reading is that Mexico still holds a high position in the region, but the strictly September-dated volume in the provided material is not the highest in the month's table. That does not reduce the risk. It does indicate that public attention was spread across several countries, with greater visibility for Argentina and Brazil in the best documented cases.
Chile
Chile did not have a new September ransomware case with the same density of evidence as Argentina or Brazil within the month-dated material, but it still appears in the nearby comparison through the August case of Hospital Clínico Universidad de Chile. That matters because it shows sector continuity in health care and helps explain the intensity of the regional close to the previous month.
For September, Chile functions more as a reference country than as a main source of verified incidents. Even so, prior exposure in its health sector remains relevant for the regional assessment, especially because groups watch how hospitals and clinics respond in order to adapt pressure tactics.
Colombia
Colombia had a significant presence in regulation and response, rather than in new confirmed ransomware cases within the September material provided. The Ministry of Justice reported a technology recovery with clear operational impact, and that places the country at the more advanced end of public response maturity for the month.
Colombia's case is useful because it introduces a contrast with other countries in the report. There, the incident is not reduced to a post on a leak site, but instead escalates into containment, alternate channels, and institutional support. For regional teams, that is the kind of response worth emulating when service continuity is at risk.
Paraguay and Bolivia
The September material did not include enough verifiable facts to build a reading comparable to Argentina, Brazil, or Colombia. There are peripheral mentions in the threat ecosystem and in contextual coverage, but they are not part of the month's ransomware volume. As a result, the regional signal for these countries is secondary in September.
Peru and the U.S.
Peru and the United States appear mainly in comparative material and in the ecosystem of regional campaigns, but they do not account for the dated facts that support this report. They serve as context for groups with broader reach, not as the basis for the month. In a regional ransomware report, that distinction is key to avoiding overstatement of secondary signals.
Trends and signals to watch
The main trend in September is a drop in verified incidents compared with August, but not a proportional drop in risk. Verified incidents for the period fell from 537 to 399, cases with ransomware or extortion as the primary focus dropped from 281 to 157, and critical CVEs mentioned declined from 16 to 4. At the same time, regulatory moves rose from 1 to 6, suggesting a more visible institutional response.
The first signal to watch is the persistence of active groups with different profiles. Emperador is new and aggressive, Panzer combines exfiltration and pressure, Qilin keeps showing up repeatedly in Argentina, and Titan appears in Argentine healthcare. That diversity complicates defense because no single TTP is enough to explain the entire month.
The second signal is the consolidation of the leak site model as the main vehicle for pressure. In September, many of the most important incidents are not backed by public forensic evidence, but by listings, claims, and data estimates. That forces teams to measure not only the intrusion, but also the risk of public exposure, credential management, and possible reuse of access.
The third signal is sector concentration. Healthcare and government remain at the top of the risk list, but telecom and IT show a particular exposure because of the cascading effect they have on third parties. When a consultancy or connectivity provider goes down, the incident can have more impact downstream than on the victim itself. That is one of the clearest lessons from K3G Solutions.
The fourth signal is that visible activity is down in volume, but not in variety. September had fewer incidents than August, although the range of groups, countries, and sectors remained broad. That points to a more fragmented threat environment, not a safer one.
Recommendations for security teams
Teams in Latin America should assume that the dominant pattern is still extortion with publication, not necessarily visible encryption. That changes priorities. The first is to harden credential management, especially in public agencies, healthcare, and technology providers. Where the material showed access to databases and email, the potential impact multiplies if passwords are not rotated and tokens are not revoked quickly.
The second recommendation is to prepare specific procedures for claims on leak sites. Waiting for public confirmation from the victim is not enough. Teams should have a playbook that includes evidence preservation, review of privileged access, blocking suspicious accounts, backup validation, and coordination with legal and communications. Reaction time is often shorter than confirmation time.
The third is to strengthen segmentation and least privilege in healthcare and government environments. This month’s cases show internal credentials, WordPress databases, and, in Brazil, sensitive tax documents. That means an initial intrusion can spread fast if access is too tightly connected. Segmentation does not stop the attempt, but it limits the blast radius.
The fourth is to review vendor exposure. K3G Solutions is a clear reminder that a telecom and IT consultancy can become an entry point, or an impact point, for many downstream organizations. Teams should assess MFA, secret rotation, log visibility, and restore testing across the full digital supply chain.
The fifth is not to neglect training against phishing and credential abuse. Although the monthly indicator is down, the material still refers to deception tactics, impersonation, and password harvesting. That means the human surface remains part of the problem. Useful training is not generic, it is training that forces employees to report unusual access requests, MFA fatigue, and out-of-cycle changes.
The sixth is to watch operational recovery, not only detection. The Colombian case involving the Ministry of Justice shows that alternate channels need to be ready before an incident, not after. If a critical service goes down, the ability to keep operating through manual or semi-automated paths is part of real resilience. That applies to justice, healthcare, taxes, and education.
Frequently Asked Questions
What changed most between August and September in the regional ransomware signal?
Verified volume fell, and the number of cases with ransomware or extortion as the primary focus also dropped sharply, from 281 to 157. At the same time, documented regulatory moves increased, from 1 to 6. The detailed reading is in Period indicators and Trends and signals to monitor.
Which country had the strongest cases in the month, and why?
Argentina and Brazil concentrated the clearest events. Argentina had the Jujuy Judicial Branch and mentions tied to health and education. Brazil showed significant exfiltration at K3G Solutions and a sensitive claim involving Receita Federal. The country-by-country comparison is in Most affected countries in Latin America.
How should I read a leak site listing when there is no public confirmation?
It should be treated as a claim or assertion, not a validated breach. In September there were 27 leak-site-only cases and 100 cases that could not be determined. The correct taxonomy is in Period indicators and in Active threats and campaigns.
Which cases this month involved clearer exfiltration than encryption?
K3G Solutions Brazil is the clearest exfiltration case with extortion pressure, with an estimated 300 GB and a threat of further publication. Receita Federal was a claim with alleged exfiltration, but without official confirmation. The detail is in Relevant incidents.
Why does health keep appearing so often in these reports?
Because it combines highly sensitive data, the need for nonstop availability, and reputational pressure. In September there were references to Hospifar in Argentina and to K3G Solutions in a profile close to third-party infrastructure, along with regional health-related precedents. The sector view is in Regional overview of the month and Most affected countries in Latin America.
What should a CISO monitor this week if operating in the region?
Credentials, leak-site postings, activity around suppliers, changes in privileged accounts, and the actual ability to restore. It is also worth watching for claims involving justice, health, or taxes, because those are the sectors that repeat most often in the material. Suggested actions are in Recommendations for security teams.
Material limitations
This report was built exclusively from the material provided and the stated time window for September 2026. The 399 verified facts from the period are the basis for all indicators, while the 102 facts from earlier months were used only as a comparative frame and the 14 with no confirmed date were excluded from the counts.
An indicator at 0, especially critical CVEs when none are recorded in the material analyzed, means they did not appear in this document set, not that no critical vulnerabilities are being exploited in the region. The same caution applies to categories with undetermined classification, which were numerous this month.
The distinction between telemetry and incidents is also central. Counts of attempts, blocks, or vendors’ weekly averages were not added to any confirmed impact total. If they are mentioned in the readout, they should be understood as automated noise or aggregated measurement, not validated intrusion.
The material analyzed excluded, by design, unavailable sources from the authorized list and social media posts not allowed as evidence. Facts without a confirmed date were also left out of the indicators. For that reason, this report describes the verifiable signal for the month, not a complete inventory of everything that may have happened in Latin America during September.
Sources
- Briefing — 23 September 2026APJ One
- Victim: Grupo Hospifar S.R.L.Ransomware.live
- Ransomware Titan publica al prestador de salud argentino HospifarKalir
- Ransomware Attacks This Week: 221 Victims Across 47 Groups, September 14 to September 20ScrutecX / Scrutex.ai
- El ransomware shadowbyt3$ publica a la ...Pulse (Kalir)
- Alerta por el crecimiento de ciberataques en América Latina - InfobaeInfobae
- Emperador ransomware claims Jujuy court system breachTechWalrus
- Judicial Branch of the Province of Jujuy data breach — Emperador ransomware leak (2026)Darkfield (Orizon)
- Judicial Branch of the Province of Jujuy: Unconfirmed Breach Claims & DoxxScan RatingRecentBreaches
- Judicial Branch of the Province of Jujuy Ransomware Claim (2026) — What’s Alleged & Am I Affected?RecentBreaches
- Victim: Judicial Branch of the Province of Jujuy – emperadorransomware.live
- Cybersecurity News Everyday (@TweetThreatNews) on XTweetThreatNews
- FalconFeeds.io on XFalconFeeds.io
- THEGENTLEMEN Ransomware Gang: 16 Victims Posted in 48 Hours, Sector Targeting Analysis and Detection RulesSecurity Arsenal
- Victim: Nutrypollo – thegentlemenransomware.live
- Dark Web Most Wanted 2026: The Gentlemen RansomwareDarkWebSonar
- Operador de ransomware ejecutó Cursor Agent dentro de diez redes de víctimasUnite.ai
- Qilin gang claims Buenos Aires hospital breach on leak siteMedRisk
- Sanatorio Modelo de Caseros Listed by Qilin Ransomware Group | GalaxyWardenGalaxyWarden
- Victim: Sanatorio Modelo de Caserosransomware.live
- Sanatorio Modelo de Caseros data breach — Qilin ransomware leak (2026)Darkfield (Orizon One)
- Recent postsRansomlook
- Sanatorio Modelo de Caseros — QILIN Ransomware AttackBreach House
- Sanatorio Modelo de Caseros: Unconfirmed Breach Claims & DoxxScan™ RatingRecentBreaches
- Ransomware Group qilin Hits: Sanatorio Modelo de CaserosHookPhish
- Ransom! Sanatorio Modelo de Caseros (AUG-2026)Hendry Adrian
- Brazil's tax agency appears on a young crew's leak siteIntelFusions
- Weekly Intelligence Report - 25 Sep 2026CYFIRMA
- Cyware Weekly Threat Intelligence - September 25, 2026Cyware
- Grupo Caberj — INCRANSOM Ransomware AttackBreach House
- n0n ransomware ameaça destruir backups para ampliar pressão sobre vítimasMinuto da Segurança
- Emerging Ransomware Gang Uses Backup Destruction ThreatsInfosecurity Magazine
- Receita Federal aparece em portal de ransomware grupo ...TechStart
- Victim: RECEITA FEDERAL DO BRASIL – emperadorRansomware.live
- Craisa — THEGENTLEMEN Ransomware AttackBreach House
- Ransomware Group Panzer Hits: Honda (Peru) – with K3G Solutions Brazil alert sectionHookPhish
- Panzer Ransomware Strikes K3G Solutions BrazilDexpose
- Victim: K3G Solutions Brazil – PanzerRansomware.live
- Justiça mantém condenação de hackers que roubaram ...Convergência Digital
- LockBit5 ransomware lists Taiwanese firm tpi.tw - Pulse - Kalir.ioPulse - Kalir.io
- All Records - Breach House (entry for K3G Solutions Brazil)Breach House
- Cyware Daily Threat Intelligence – September 18, 2026 (Panzer ransomware overview)Cyware
- Ransomware Panzer publica a la consultora brasileña K3G SolutionsKalir Pulse
- ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New StoriesThe Hacker News
- K3G Solutions Brazil Ransomware Claim (2026) — What’s Alleged & Am I Affected?Recent Breaches
- Breach HouseBreach House
- Hospitais não pedem pagamentos por telefone; veja como se protegerProjeto Comprova
- INCAN restablece sus servicios de radioterapia tras ciberataqueLa Hora
- K3G Solutions Brazil Listed by Panzer Ransomware GroupGalaxyWarden
- K3G Solutions Brazil ransomware attack — panzer leakKalir Pulse
- Ransomware group Panzer hits K3G Solutions BrazilHackerFeeds
- TJDFT condena hackers por ataque cibernético a hospitalValor Econômico
- Tribunal mantém penas de hackers que invadiram ...Correio Braziliense
- Panzer (Threat actor): news timeline & CVEsZeroHour
- Unit 42 search result for CL-CRI-1163Palo Alto Networks Unit 42
- Hospitais não pedem pagamentos por telefone; veja como se protegerGauchaZH
- Unit 42 search result referencing SockTz and CL-CRI-1163Palo Alto Networks Unit 42
- Hackers hijack government servers to promote illegal gamblingEscudo Digital
- Una red global secuestra webs gubernamentales para mostrar apuestas y descargas ilegales sin tocar la URL oficialInfobae
- Hackers Use Claude and GPT-Powered Tools to Help ...CybersecurityNews
- 553 victims for Brazil - Ransomware.liveRansomware.live
- Brazil Ransomware & Cyber AttacksBreach House
- Tuboaços da Amazônia Ltda. Ransomware Attack by Nightspire (2026)Cyber Threat Intelligence
- Китайские хакеры атакуют госсайты Бразилии через ApacheTechora.ru
- 브라질을 표적으로 삼는 금전적 동기의 공격자 BREEZE COMETGoogle Cloud
- VEXY Ransomware Gang: 3 Technology Sector Victims in 5 Days ...Security Arsenal
- Vexy Ransomware ransomware group - Discover all the ...Breach House
- Unit 42Palo Alto Networks Unit 42
- Slim Spider Steals Crypto Custody Secrets From Brazilian Financial ...The Hacker News
- Thegentlemen ransomware claims Lider AviacaoTechWalrus
- El ransomware crece 25.5% en América Latina y México concentra 17.93% de los ataquesEl Economista
- Los atacantes aprovechan el uso continuo de herramientas de IA para atacar organizaciones en América LatinaUnit 42 (Palo Alto Networks)
- Vexy Ransomware ransomware group — victims, leak site & IOCsDarkfield
- AI-Augmented Intrusions Hit Latin American Government and FinanceCloud Security Alliance (CSA) Labs
- Attacks — AI-Augmented Intrusions in Latin AmericaMachine Speed - AI-Cyber Intelligence
- Ransomware.live victim databaseRansomware.live
- Núcleo de Excelência em OftalmologiaBreachsense
- KRYBIT Ransomware Gang: 13 Victims in 48 HoursSecurity Arsenal
- Fosko mitiga ataque de ransomware con respuesta especializada de EGS LatamTrendTIC
- Fosko mitiga ataque de ransomware con respuesta especializada de Egs-LatamTrendTIC
- Incidente de ciberseguridad afecta sistemas de ForusDiario Financiero
- LockBit 5.0 Ransomware Strikes Chilean Apparel Leader Forus S.A.Dexpose
- forus.cl attaquée par LockBit 5.0Breaches Live
- Victim: forus.clRansomware.live
- forus.cl ransomware attack — lockbit5 leakPulse by Kalir
- Ransomware attacks in September 2026RansomNews
- forus.cl — LOCKBIT5 Ransomware AttackBreach House
- Futuro Forestal — QILIN Ransomware AttackBreach House
- Incidents - Ransomware victims & data breaches - ZeroHourZeroHour
- Forus Was Affected by Cybersecurity IncidentGround.news
- El Estado que financia y el Estado que exigeLinkedIn
- S.A. Chile attaquée par The GentlemenBreaches Live
- TheGentlemen Target S A Chile in Ransomware AttackDexpose
- S A Chile Ransomware Claim (2026) — What’s Alleged & Am I Affected?RecentBreaches
- VenariX en Español (@_venarixES_)VenariX en Español (X)
- Hackmanac on XHackmanac (X/Twitter)
- Hospital Clnico Universidad de Chile Listed by Direwolf ...Galaxy Warden
- Ransomware marca récord en Chile: agosto tuvo la mayor cantidad de ataques registradosEl Morrocotudo
- Ransomware group direwolf hits Hospital Clónico Universidad de Chile | HackerFeedsHackerFeeds
- Victim: Hospital Clnico Universidad de ChileRansomware.live
- Red de Emergencia ONG on XX
- Cybersecurity News Everyday (@TweetThreatNews) on XTweetThreatNews (X/Twitter)
- Ransom-DB on XRansom-DB (X/Twitter)
- Ransomware Group direwolf Hits: Hospital Clnico ...HookPhish
- Direwolf gang posts Turkish and Chilean hospitals on leak siteMedRisk.io
- DIREWOLF Ransomware Gang: 3 Healthcare & Tech Victims Posted in 24 Hours — Sector Targeting Analysis & Detection RulesSecurity Arsenal
- Direwolf Targets Hospital Clínico Universidad de ChileDexpose
- Inversiones Bolívar — QILIN Ransomware AttackBreach House
- UNISALLE-EDU.CO — CLOP Ransomware AttackBreach House
- Agrocampo — THEGENTLEMEN Ransomware AttackBreach House
- Six in 10 Cyberattacks in Colombia Target HospitalsColombiaOne
- Cyberattacks Target 60% of Colombian Healthcare ProvidersBiopharma Curated
- Biofile Finds Health Sector Draws 60% of Colombia’s CyberattacksTMCnet / Insight
- Report finds care providers absorb most Colombian intrusionsMedRisk.io
- Seis de cada 10 ciberataques en Colombia tienen como blanco a hospitales y clínicas del paísPortafolio
- ¿Ciberataques?: Más de 51 millones de historias clínicas, en juegoHSB Noticias
- Ransomware Recovery Services MarketMordor Intelligence
- Perimetral Oriental de Bogotá S.A.S. Ransomware Claim (2026) — What’s Alleged & Am I Affected?RecentBreaches
- Victim: Perimetral Oriental de Bogotá S.A.S.Ransomware.live
- Publicación sobre la posible víctima Perimetral Oriental de Bogotá S.A.S.VenariX en Español
- NightSpire Ransomware Attack on Perimetral Oriental de Bogotá S.A.S.Dexpose
- Ransomware Group emperador Hits: EASY JOB S.A.S.HookPhish
- Ransomware Group thegentlemen Hits: El CarrielHookPhish
- Bitdefender Threat Debrief | September 2026Bitdefender
- TrainMe — DIREWOLF Ransomware AttackBreach House
- MinJusticia activa plan de recuperación tecnológica luego de vulneración cibernética garantizando servicios esencialesMinisterio de Justicia y del Derecho de Colombia
- Activan plan de contingencia en la gobernación de Córdoba tras ataque cibernético a la infraestructura tecnológicaEl Heraldo
- SETTRA Ransomware Hits Six New US and Mexico FirmsVPN.social
- México, segundo país de América Latina con más ataques cibernéticosTribuna de la Bahía
- Documentan 52 ataques a los sistemas de empresas y entidadesLa Jornada
- Settra Ransomware Uses MeshAgent Persistence and Recovery ...Mallory.ai
- Grupo Juste ransomware attack — qilin leakPulse
- Victim: Grupo JusteRansomware.live
- Grupo Juste — QILIN Ransomware AttackBreach House
- Qilin victim pageZeroHour
- Grupo Juste — QILIN Ransomware AttackDark Eye
- Ransomware group qilin hits Grupo JusteHackerFeeds
- Settra Ransomware Attack on SÁNCHEZ Y MARTÍN, S.A. DE C.V.DeXpose
- Krybit ransomware groupBreach House
- sym.com.mx Listed by Settra Ransomware GroupGalaxy Warden
- Mexico Ransomware & Cyber AttacksBreach House
- Qilin Targets Logistics Leader Minmer GlobalDeXpose
- www.tender.mx — KRYBIT Ransomware AttackBreach House
- El ransomware crece 25.5% en América Latina y MéxicoYahoo Noticias / SCILabs
- Settra Ransomware Strikes Mexican MLM Giant Golden Neo LifeDeXpose
- Ciberataque en Tlajomulco: dudas sobre pérdida de datosTelediario (Grupo Multimedios)
- The State of Ransomware: August 2026BlackFog
- KRYBIT Ransomware Gang: 14 Victims Posted in Single-Day Surge, Cross-Sector Campaign Analysis and Detection EngineeringSecurity Arsenal
- tum.com.mx ransomware attack — krybit leakKalir Pulse
- > Delito sin freno> Ciudadanos expuestosPulso SLP
- INCRANSOM Ransomware Gang: 5 New Victims Posted in 72 Hours, Manufacturing and Energy Targeting Analysis with Detection RulesSecurity Arsenal
- Ransomware Attacks This Week: 179 Victims Across 44 Groups — September 7 to 13, 2026ScrutEX
- Presentan exhorto para saber qué pasó tras ciberataque en TlajomulcoMilenio
- Targeted Preventive Alert: alleged breach of Paraguay’s Ministry of HealthVECERT Radar
- Inovapy — PANZER Ransomware AttackBreach House
- Inovapy ransomware attack — panzer leakPulse by Kalir
- PANZER Ransomware Gang: 5 Victims in 4 Days — Technology & Manufacturing Sector Surge, Perimeter CVE Exploitation & Detection RulesSecurityArsenal
- Inovapy Listed by Panzer Ransomware GroupGalaxyWarden
- Ransomware arcusmedia publica a la agroindustrial peruana ...Kalir
- Victim: AGROFRUTO SACRansomware.live
- Arcusmedia ransomware publishes Peruvian agribusiness Agrofruto SACKali Pulse
- Gelarti data breach — Thegentlemen ransomware leak (2026)Darkfield
- Victim: gob.peRansomware.live
- Honda (Peru) — PANZER Ransomware AttackBreach House
- Victim: Honda (Peru)Ransomware.live
- Ransomware group thegentlemen hits GelartiHackerFeeds
- Gelarti PerúBreachSense
- Victim: Italtel PeruRansomware.live
- Ransomware Attacks Reach Record High for 2026Infosecurity Magazine
- Cyber Threat Intelligence 25 September 2026NCSA Thailand Webboard
- Emerging Ransomware Group n0n Threatens Backup Infrastructure to Force Ransom PaymentsTetmo
- ArcusMedia Targets Agroindustrial Leader AGROFRUTO SACDexpose
- H1 2026: Primary initial access vectors used by threat actors in ransomware attacksSCILabs
- ARS Renacer Data Breach in 2026BreachSense
- arsrenacer.com Listed by DragonForce Ransomware GroupGalaxyWarden
- México es segundo lugar en AL como blanco favorito de ciberataques y secuestro de informaciónLa Jornada
- 2026 Updated Recommendations: Before, during and after ransomware attackSCILabs
- DragonForce Compromises ARS Renacer with Massive Data BreachDexpose
- Aumentan los casos de phishing y el abuso de credencialesRevista Byte
- Victim: Taurus Ibérica - Ransomware.liveRansomware.live
- La IA abarata y acelera los ciberataques: una alerta para Costa RicaLa Nación
- Qilin leaks 6.3GB of ATF investigation files, then pulls it all within 24 hoursPasquale Pillitteri
- Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomwareSecurity Affairs
- México concentra el 18% de los ataques de ransomware en LatinoaméricaImagen Radio
- Cisco FMC Zero-Days Exploited by Sandworm and Qilin RansomwareCyberNewsAI
- Instituto Ferrero de Neurología y SueñoBreachSense
- PANZER Ransomware Gang: 4 Victims Posted in 5 DaysSecurity Arsenal
- APAC Threat Landscape Report, August 2026Group-IB
- Instituto Ferrero de Neurología y Sueño Listed by Kazu ...GalaxyWarden
- Instituto Ferrero de Neurología y Sueño Ransomware Claim (2026) — What’s Alleged & Am I Affected?RecentBreaches
- The Gentlemen Ransomware - Threat ActorFortinet FortiGuard Labs
- Victim: Bosnia and Herzegovina Mine Action Center (Emperador)Ransomware.live
- AbacoViaggi Listed by The Gentlemen Ransomware GroupGalaxy Warden
- Veradigm Listed by The Gentlemen Ransomware GroupGalaxy Warden
- BlackCat / ALPHV Campaign Expands — 352+ Victims Across 22 ...Insomnia
- Acronis: Färre upptäckta skadeprogram men fler dataintrangITbranschen / Acronis
- Ataque cibernético golpea al instituto contra el cáncer en Guatemala: 194 pacientes, datos clínicos encriptados y un enlace en la deep web para negociarInfobae
- Extraoficial: reportan ataque en sistema informático del Incan que afecta a pacientesLa Hora
- Aurora Ransomware Hackers Use Cursor AI Agent for Hands-On Exploitation and ESXi AttacksGBHackers
- Victim: Tecno Accion – thegentlemenransomware.live
- ESB Puerto Rico Ransomware Claim (2026) — What’s Alleged & Am I Affected?RecentBreaches
- Aurora Ransomware Affiliate Exposed Using AI Attack PlanningInside Telecom
- CHAOS Ransomware Gang: 3 Victims Posted in 48 HoursSecurity Arsenal
- Ferretornillos, S.A.Breachsense
- Sanatorio Modelo de CaserosBreachSense
- Hackean y filtran 300 GB de información de un estudio jurídico y contable uruguayoEl Observador
- Así opera Gunra, un nuevo grupo cibercriminal que está bajo la mira del FBI y que ya atacó tres empresas uruguayasEl Observador
- Blanco & Etcheverry Data Breach in 2026BreachSense
- Gunra Ransomware Hits Three Uruguayan Firms in Three MonthsThe Rio Times
- Blanco & Etcheverry Listed by Gunra Ransomware GroupGalaxy Warden
- Victim: Blanco & EtcheverryRansomware.live
- Blanco & Etcheverry Ransomware Claim (2026) — What’s Alleged & Am I Affected?Recent Breaches
- Victim: Electrolux & OnTracRansomware.live
- Electrolux & OnTrac Listed by Emperador Ransomware GroupGalaxy Warden
- Emperador claims U.S. parcel carrier OnTracDaily Dark Web
- California critical access hospital says files stolen in cyberattackBecker's Hospital Review
- emperador Ransomware: 4 Victims, Tactics & IntelligenceThe Hacker Wire
- OnTrac Listed by Emperador Ransomware GroupGalaxy Warden
- Victim: OnTracRansomware.live
- Alabama Women's Health Care Data Breach LawsuitClass Action U
- UnitedHealth CEO Admits Paying $22 Million to Change Healthcare HackersVCPost
- Two Years After the Change Healthcare Cyberattack, Healthcare Still Has a Clearinghouse Redundancy ProblemMedCity News
- ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New StoriesThe Hacker News
- BlackCat: hackers rusos en América Latina y el engaño ...Infobae
- Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix ...The Hacker News
- Cyware Weekly Threat Intelligence - September 12Cyware
- qilin ransomware group: victims, TTPs, profile · ZeroHourZeroHour
- Hacking Group Claims Attack on Cedar County Memorial HospitalHIPAA Journal
- Settra Ransomware Uses MeshAgent Against WindowsCyPro UK
- Interlock claims responsibility for Fort Smith computer system attackTalk Business & Politics
- QILIN Ransomware Gang: 19 Victims Posted in 72 Hours — Manufacturing & Agri-Food Surge, Detection Rules InsideSecurity Arsenal
- Statement Regarding Cyber IncidentTown of Sutton
- Anne Arundel patients sue Luminis Health after cyberattack exposes medical dataThe Banner
- Grafton City Hospital Data Breach: What Patients Should KnowWilshire Law Firm
- Fort Smith computer attack investigation nearing an endTalk Business & Politics
- Cedar County Memorial Hospital Data Breach - McShane & BradyMcShane & Brady
- Cybersecurity incident affects Sutton town, school networksWCVB
- Sutton town officials, public school system investigating cybersecurity incidentBoston Globe
- CISA: Critical VMware RCE flaw now exploited by ransomware gangsBleepingComputer
- VMware vCenter CVE-2026-59310: Ransomware Gangs Join Unauth Syslog RCE - CyberExperts.comCyberExperts.com
- Ransomware group claims Fort Smith attack as city nears end of probeKUAF (Ozarks at Large)
- Springfield Public Schools Listed by Interlock Ransomware GroupGalaxyWarden
- Interlock Strikes Springfield Public Schools in Major Ransomware AttackDexpose
- Ransomware Alert: City of Fort Smith, Arkansas – INTERLOCK ransomwareFalconFeeds.io
- interlock ransomware group: victims, TTPs, profileZeroHour
- City of Fort Smith Arkansas Ransomware Claim (2026) — What’s Alleged & Am I Affected?RecentBreaches
- City of Fort Smith Arkansas data breach — Interlock ransomware leak (2026)Darkfield
- Cybersecurity expert assesses Interlock claim to Fort Smith city dataSouthwest Times Record
- Victim: City of Fort Smith ArkansasRansomware.live
- INTERLOCK Ransomware Gang: Education & Municipal Government Hits Posted — Campaign Analysis & Detection RulesSecurity Arsenal
- Eudora's just-terminated IT administrator says foreign ransomware is behind 'big mess' with city's and sheriff's computer systemsLawrence Journal-World
- Grafton City Hospital Data Breach Affects 1,215 UsersClaimDepot
- RST Cloud on X: "#threatreport #LowCompleteness SETTRA RANSOMWARE | 14-09-2026 ...RST Cloud
- 医療分野 週次セキュリティニュース|あめむAmenomu
- Global Ransomware Group Attacks Town of Sutton, MassachusettsDexpose
- Incident Response PrioritiesSecurity Arsenal
- Ransomware Group global Hits: TOWN OF SUTTONHookPhish
- 2026-09-11 Briefing – Ukrainian Conti ransomware coder sentenced to 4 yearsalobbs.com
- Abogado ucraniano que programó para Conti recibe cuatro años de prisión en EE. UU.DiarioBitcoin
- Beyond ransomware: 5 healthcare cyber risks to knowBecker's Hospital Review
- Ukrainian hacker gets four years in US prison over ContiThe Record
- Ukrainian National Sentenced to Four Years in Prison for Conti Ransomware RoleGround News
- Ukrainian Conti ransomware member gets 4 years for hospital-linked attacksBecker's Hospital Review
- What to know about the Luminis Health cyberattackThe Banner
- Luminis Health MyChart, phones remain offline amid cyberattackBecker's Hospital Review
- Four extortion gangs add care providers to their leak sitesMedRisk
- CHAOS Ransomware Gang: 4 New US Victims Posted — Manufacturing & Healthcare Targeting Analysis With Detection RulesSecurity Arsenal
- FBI investigating hospital IT disruption that took EHR offline for 2 weeksBecker's Hospital Review
- FBI investigating hospital IT disruption that took EHR offline for 2 weeksBecker's Hospital Review
- Nutex Health updates on cyber incident data post - NUTXStockTitan
- Ukrainian Conti Ransomware Developer Sentenced to 4 Years in US PrisonSecurityWeek
- Form 8-K filing by Nutex Health Inc. dated September 10, 2026SEC
- Ransomware claim follows Missouri hospital IT outageDysruptionHub
- Luminis is the latest health system hacked: 'Everybody's at risk'WTOP News
- Live Ransomware TrackerTheSolutioners.ca
- Standard Tool & Die Listed by Storm Ransomware Group (includes WindRose Health Network context)GalaxyWarden
- Hospital operator Nutex Health says data stolen in cyberattackWestern Networks Inc.
- Ransomware Wing — víctimas, grupos y patronesKalir.io Pulse
- Krybit ransomware group: victims, status, activityRansomnews
- Ransomware Groups - Tracked Threat Actors | Invaders CybersecurityInvaders Cybersecurity
- incransom - Dragons Eye Ransomware TrackerDragons Eye Ransomware Tracker
- QILIN Ransomware Gang: 4 New Victims PostedSecurity Arsenal
- Did the BlackByte ransomware attack the city of Augusta?SECnews
- Ormond Beach Ransomware: 5 Critical Facts for Local GovernmentsNextekit
- El ransomware crece 25.5% en América Latina y México concentra 17.93% de los ataquesRadioUno911 / SCILabs
- DaVita Reaches Preliminary Settlement Class Agreement Following Ransomware Attack - DaVita (NYSE:DVA)Benzinga
- Five Healthcare Providers Report Ransomware-Related Data BreachesHIPAA Journal
- LockBit ransomware: Claimed responsibility for cyberattack on Wichita citySECnews
- City of Ormond Beach Data Breach in 2026Breachsense
- DaVita agrees to pay $15M to settle claims from data breachMedTech Dive
- INCRANSOM Ransomware Gang: 11 New Victims in 5 Days, Manufacturing and Healthcare Surge, Detection Rules InsideSecurity Arsenal
- uicc.org data breach — Krybit ransomware leak (2026)Darkfield (Orizon)
- September 2, 2026 Cybersecurity News SummaryNote.com (centervil)
- Ransomware Group krybit Hits: tum.com.mxHookPhish
- Cadena hospitalaria de EEUU confirma brecha de datos y robo de informaciónNivel4
- Nutex Health Data Breach: Edelson Lechtzin LLP Investigates Theft of Patient and Employee DataMorningstar / PR Newswire
- The Gentlemen come calling as Nutex confirms sensitive data theftThe Register
- tum.com.mx data breach — Krybit ransomware leak (2026)Darkfield (Orizon)
- Krybit Ransomware Impacts TUM Transportistas Unidos MexicanosDexpose
- WALLSTREET Ransomware: US Healthcare and Education Victims Posted on Leak SiteSecurityArsenal
- Healthcare cyberattacks hit pacemakers and millions of patient recordsThe Register
- Ransomware Group Wallstreet Hits: Cedar County Memorial HospitalHookPhish
- Victim: Cedar County Memorial Hospital – WallstreetRansomware.live
- Cedar County Memorial Hospital: Unconfirmed Breach Claims & DoxxScan RatingRecentBreaches
- Cedar County Memorial Hospital Ransomware Claim (2026) — What’s Alleged & Am I Affected?RecentBreaches
- Wallstreet Strikes Cedar County Memorial HospitalDexpose
- Healthcare company McKesson discloses cyberattack after third-party app breachHelp Net Security
- Deep dive into the Boston Scientific cyberattackShieldWorkz
- Victim: Northwest Trophy – thegentlemenransomware.live
- Hackers secuestran información del Incán, exigen dinero y afectan radioterapias de 194 pacientes con cáncerPrensa Libre
- wittmann — INCRANSOM Ransomware Attack | Breach HouseBreach House
- Oilquip Inc Listed by INC Ransom Ransomware GroupGalaxyWarden
- Oilquip Inc data breach — Incransom ransomware leak (2026)Darkfield (Orizon)
- Northwest Trophy: Unconfirmed Breach Claims & DoxxScan™ RatingRecentBreaches
- Northwest Trophy Listed by The Gentlemen Ransomware ...Galaxy Warden
- Valley Health Team: Unconfirmed Breach Claims & DoxxScan RatingRecentBreaches
- Ruby Seven Studios Data Breach in 2026BreachSense
- RST Cloud en X: #threatreport #HighCompleteness Caught in 4K: The Aurora FilesRST Cloud
- Ransom! Northwest Trophy (AUG-2026)Hendry Adrian
- Victim: Valley Health Team – Rhysidaransomware.live
- RaaS gang Anubis claims Signature Healthcare data theftGovernment Information Security
- Ransomware Alert: Valley Health Team ...FalconFeeds.io
- EMPERADOR Ransomware Gang: 4 New Victims Posted — Energy Sector Targeting, Edge Device Exploitation and Detection RulesSecurity Arsenal
- LOCKBIT5 Ransomware: 5 Victims Posted in 24 Hours — Healthcare & Tech Sector Surge with Detection RulesSecurity Arsenal
- Cyberattack Halts Boston Scientific's Global Operations – AlertHamerIntel
- Update on recent cybersecurity incidentBoston Scientific
- US officials backpedal on claims that government agencies were hacked by Chinese group QTFYReuters
- Bencivil Ransomware Claim (2026) — What’s Alleged & Am I Affected?RecentBreaches
- Victim: Ruby Seven Studiosransomware.live
- Bencivil Listed by incransom Ransomware GroupGalaxyWarden
- Ruby Seven Studios Listed by incransom Ransomware GroupGalaxyWarden
- Ruby Seven Studios Ransomware Claim (2026) — What’s Alleged & Am I Affected?RecentBreaches
- FBI, DOJ announce disruption of China-linked hacking group targeting hospitals and other critical infrastructureAmerican Hospital Association
- Victim: wmiemporium.comransomware.live
- McKesson discloses breach after ShinyHunters claims patient data theftBleepingComputer
- Cyberattack on Boston Scientific causes global ops disruptionpharmaphorum
- Newsroom - Maryland Department of HealthMaryland Department of Health / The Daily Record (referenciado)
- The Hugging Face Incident, Explained for HealthcareOnHealthcare.tech
- ハッキング集団、Cedar County Memorial Hospitalへの攻撃を主張Black Hat News Tokyo
- Why Cybersecurity Is Now a Healthcare Security PriorityHealthcare.digital
- Luminis cybersecurity incident highlights 'concerning' rise in attacks ...The Daily Record
- Why Cybersecurity Is Now a Healthcare Security Priorityhealthcare.digital
