CiberLATAMbywhalemate
Intelligence report

Ransomware Activity in Latin America, September 2026

Ransomware led the regional signal with 157 verified incidents; Argentina and Brazil concentrated the clearest extortion cases

Oct 1, 202627 min read
Ransomware Activity in Latin America, September 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are completed automatically with the verified facts dated within the period. Each one states its source and counting criterion so the figures reconcile across modules. They are the recurring month-to-month readout; the later analysis develops the cases without repeating this summary.

Indicator window: 401 dated facts in September 2026 · 102 from prior months (comparative frame, not monthly volume) · 14 without confirmed date (excluded from the indicators). Facts from prior months are used only as a comparative frame in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Monthly Verified Signal Dashboard September 2026 · Latin America Primary threat: Ransomware (157 of 399 incidents). Coverage: 401 dated incidents in September 2026 · 102 from the month… VERIFIED INCIDENTS 399 period base: all counts all values below are measured against this total RANSOMWARE / EXTORTION 157 12 encrypted assets confirmed · 18 exfiltration unencrypted (simple extortion) UNCLASSIFIED INCIDENTS 101 breaches or outages without declared threat type FRAUD / PHISHING 19 documented fraud campaigns REGULATION 6 rules, resolutions, or penalties UNIQUE CVEs 4 CVE-2026-0257 / CVE-2026-20079
Monthly Verified Signal Dashboard — Base: 399 verified incidents dated within the period for Latin America.
FIXED MONTHLY MODULE Threat Axis Distribution September 2026 · Latin America Each event is counted in only one axis, so the total is exactly 399. "Unclassified incidents" is the remainder. Ransomware 157 Unclassified 112 Incidents 101 Fraud 19 Regulation 6 Vulnerabilities 4
Threat Axis Distribution — Each event is assigned to a single axis based on its classification; the total reconciles to the 399 events in the period.
FIXED MONTHLY MODULE Sectoral Signal Breakdown September 2026 · Latin America Base: 399 incidents in the period · total 518 because 97 incidents are classified in more than one sector. Public sector / OIV 186 Other / no sector identi… 125 Health 78 Telecom 42 Finance 34 Technology 24 Energy 15 Education 14
Sectoral Signal Breakdown — Heuristic sector classification by victim. One incident may affect more than one sector, so totals may exceed the base.
MONTHLY FIXED MODULE Geographic Distribution of Coverage September 2026 · Latin America Each event is assigned to a single country or to regional coverage, so the total is exactly 394 out of 399 events … USA 135 Brazil 89 Regional 45 Mexico 35 Chile 28 Colombia 22 Argentina 18 Uruguay 12 Peru 10
Geographic Distribution of Coverage — Verified events from the period grouped by country or regional coverage; each event is counted once.

Monthly executive summary

September 2026 closed with ransomware as the dominant signal in Latin America, built on 399 verified incidents during the period and 157 cases with ransomware or extortion as the primary focus. The region showed a mix of leak-site listings, confirmed exfiltration, and some episodes involving encrypted assets, with Argentina and Brazil the most represented countries in the material analyzed.

The month was not defined by a single, uniform campaign, but by several simultaneous operations at different levels of verification. In the best documented cases, Emperador left behind an already publicized incident against the Jujuy Judiciary and also claimed responsibility for a case involving Receita Federal do Brasil. Panzer targeted K3G Solutions Brazil, with an estimated 300 GB exfiltrated and explicit pressure to negotiate. Qilin stayed active in the region with new references to Argentina, including the Grupo Hospifar case and the publication of Vitar Group.

The quality of the evidence was uneven. Seventy-five percent of the incidents had direct source confirmation, but many of the month’s ransomware records remain claims from groups or leak-site monitors, without public confirmation from the affected organizations. That means three distinct layers have to be kept separate: confirmed encryption, exfiltration without verified encryption, and mere mention on a leak portal. In September, all three appeared in the material, although the last was the most common.

Argentina was the country with the highest density of concrete incidents in the material, especially because of the Jujuy case and mentions of Hospifar, Vitar Group, and the Ministry of Education. Brazil showed greater diversity of actors, from Panzer to Emperador, as well as cases in healthcare, telecom, and tax administration. Mexico added relevant signals in the final stretch of August and in comparisons published during September, but the volume of events dated strictly within the month was more concentrated in Argentina and Brazil.

The month also brought a methodological shift in coverage. The total number of verified incidents fell from August, the number of cases with ransomware or extortion as the primary focus dropped sharply, and the critical CVEs mentioned declined. At the same time, documented regulatory moves increased, suggesting a more visible institutional response, although still fragmented. Regional risk remains high because of the persistence of active groups, the recurring targeting of healthcare and government, and the continued posting on leak sites with potential operational and reputational impact.

Regional overview for the month

September’s regional signal was high, not because of a uniform surge in confirmed incidents, but because of the mix of volume, sector-level repetition, and the presence of groups with sustained activity across several countries. The material analyzed shows particular pressure on government, healthcare, technology, and telecommunications, with cases where extortion was explicit even if the operational damage was not always confirmed by the victim or a regulator.

Latin America remained exposed to a familiar pattern, but with better attribution detail. The groups most frequently appearing in the month’s corpus, Emperador, Panzer, Qilin, Titan and TheGentlemen, operate through a leak-site logic that prioritizes public pressure over technical disclosure. That means the most verifiable fact is often not the intrusion itself, but the posting of the claim, the data estimate, and the taxonomy used by the monitor that records it.

The sector reading is equally clear. Healthcare remained a recurring target, both because of its operational sensitivity and the value of the exposed information. Government and defense appeared in specific cases in Argentina, while telecom and IT were repeated in Brazil. This month’s material also shows again that small and mid-sized organizations, and entities with public-facing systems, remain especially attractive targets for rapid extortion campaigns.

The region enters September with high qualitative risk. This assessment is based not on a made-up index, but on the presence of 157 events in which ransomware or extortion was the primary focus within 399 verified events, plus the variety of active groups and the continued presence of critical sectors on the radar. Although the total number of events fell from August, the qualitative severity remains high because the month left leaks, unconfirmed claims, sensitive data mentioned and, in some cases, evidence of significant exfiltration.

TIMELINE Verified events for the period 1/9 SecurityArsenalreportedthat 1/9 At theGovernor’sOffice of 1/9 Security Arsenalidentified a 1/9 Security Arsenalreported that 1/9 Kalir Pulserecorded a 1/9 ItaltelPeru wasincluded
Verified events timeline, September 2026 — Milestones with confirmed dates within September 2026. Events from earlier months are excluded from the timeline and used only as comparative context.

Period indicators

The table below reproduces exactly the indicators provided for September 2026, with the same base, the same time window, and the month-over-month comparison reported. The reading should be based on the signal at the axis, not on a raw count of actual operations across the region.

Indicator September 2026 Previous month Change
Verified events for the period, base for all indicators 399 537 -138
Time window for the indicators 401 events dated September 2026, 102 from prior months as a comparative frame, 14 without confirmed date excluded from the indicators
Untyped incidents, breaches or outages 101 104 -3
Cases with ransomware or extortion as the primary focus 157 281 -124
Confirmed asset encryption 12 n/d n/d
Exfiltration without encryption, simple extortion 18 n/d n/d
Leak site mention only 27 n/d n/d
Typing could not be determined from the material 100 n/d n/d
Documented fraud or phishing cases 19 25 -6
Documented regulatory actions 6 1 +5
Critical CVEs mentioned 4 16 -12
Sectors with at least one documented event 8 8 unchanged
Dominant threat of the month Ransomware (157 of 399 events) Ransomware (281 of 537 events) relative decline
Events with direct source confirmation 75% n/d n/d
Aggregate telemetry figures excluded from the volume 2, aggregate attempts or blocks, not incidents with confirmed impact

The interpretive base for the month is the same for all indicators, 399 verified events for the period. The time window includes 401 events dated September 2026, 102 events from prior months as a comparative frame, and 14 without a confirmed date that were left out of the indicators. That distinction matters because the coverage published in September does not always equal activity that occurred in September.

The ransomware taxonomy also became more clearly defined this month. Of the 157 cases with ransomware or extortion as the primary focus, 12 had confirmed encryption, 18 were sustained by exfiltration without encryption, 27 were only mentioned on a leak site, and 100 did not allow the impact to be determined precisely. That spread shows why each group claim should not be read as a fully validated breach.

Relevant Incidents

Judiciary of Jujuy, Emperador

The case involving the Judiciary of the Province of Jujuy was one of the month’s most concrete incidents because it combines a leak site posting, consistent attribution across monitors, and a relatively precise description of the exposed data. Darkfield classifies it as a data leak attributed to Emperador, in Argentina’s Government and Defense sector, with a data leaked status and critical severity. RecentBreaches, meanwhile, keeps it as an uncorroborated claim.

The most useful source for operational reading is Darkfield, which indicates compromise of WordPress databases, access credentials for internal systems, and email credentials. TechWalrus adds an important nuance, noting that at the time of publication there was no public technical analysis detailing the intrusion or the forensic evidence. That means the case has a highly visible extortion and leak component, but still lacks full independent validation.

For government teams, the key issue is not only the victim name, but the pattern. Emperador is a new actor, first observed in August 2026 and financially motivated, which fits short-maturity operations that try to capitalize on rapid publication. In this case, the exposure of credentials and databases raises the risk of lateral movement, internal impersonation, and credential reuse across other judicial services.

K3G Solutions Brazil, Panzer

K3G Solutions Brazil was one of the month’s strongest cases in terms of estimated exfiltration and extortion pressure. Ransomware.live lists it as a Panzer victim with discovery and attack date estimated for September 18, 2026, and reports 300 GB of exfiltrated data, along with references to employees, compromised users, and third-party credentials. Dexpose confirms that Panzer claimed the attack on September 18 and threatened to publish the full leak if there was no contact.

Sector coverage identifies K3G Solutions as a Brazilian telecom and IT consultancy with network engineering, ISP support, monitoring, call center, CDN, and colocation services. That profile makes it a high-value target because of its proximity to third-party infrastructure. Although the group also places it within broader categories, the real critical attack surface is that of a provider that can drag risk onto customers and technical dependencies.

This is not just a mention on a portal. It is a combination of publication, estimated stolen volume, and an explicit threat of further disclosure. Operationally, this fits the category of exfiltration without confirmed encryption, or at least a breach where the strongest verifiable element is theft and extortion, not encryption. For Brazil, the case reinforces the risk facing technology service firms that support telecommunications functions and third parties.

Receita Federal do Brasil, Emperador

The appearance of Receita Federal do Brasil on Emperador’s portal was one of the month’s most sensitive institutional records, although public confirmation of the incident is still absent. Ransomware.live published the reference with an alleged 6.3 GB exfiltration and mention of documents containing staff and customer data, as well as gov.br users and passwords. IntelFusions and TechStart agree that the group used the post as a claim, but found no official communication validating the intrusion.

This case matters because it combines two traits that usually raise the potential impact. First, the symbolic and operational value of Brazil’s tax authority. Second, the possibility that an unconfirmed claim creates reputational pressure before there is public verification of scope. For that reason, it should be treated as a leak site mention with an alleged exfiltration, not as a leak validated by the affected entity.

For Brazil’s risk picture, the signal is serious even if incomplete. If the attribution were confirmed, the impact could affect credentials, internal documentation, and potentially other connected state services. For now, the material only supports saying that Emperador included Receita Federal on its portal and that the claim was not confirmed by an official body by the close of the reviewed coverage.

Judiciary of Jujuy and Receita Federal, Emperador, combined reading

The two Emperador-linked cases in September should not be read as isolated events. The campaign shows an ability to select high-visibility public entities and sustain pressure through publications, even if the available evidence does not always reach the threshold needed to validate actual access or the claimed data volume. The group appears focused on government and defense, which explains the recurring institutional victims.

For a regional reader, the operational signal is twofold. On one side, the provincial judiciary in Argentina was exposed to credentials and databases. On the other, a Brazilian tax authority was placed under public claim on an extortion portal. The coincidence of both events in the same month shows that state targets remain attractive to new actors seeking immediate resonance.

Grupo Hospifar S.R.L., Titan

Hospifar is the Argentine case where coverage was both more restrained and more limited. APJ One included it among Titan’s victims recorded on September 22 and classified it as a healthcare-sector organization in Argentina, but clarified that this is a ransomware activity record and not a confirmation of the affected entity. Ransomware.live also published it on its leak site.

Kalir described the inclusion as an active and urgent incident for Argentine healthcare entities, although it acknowledged there was no Hospifar statement, no data volume, and no public forensic evidence. That combination suggests an early claim, likely still in an observation phase. Taxonomically, the case currently falls into the category of a leak-site mention only, because independent confirmation of impact is not available in the material.

Even so, the analytical value is clear. Titan is using public exposure of its leak site to apply pressure on an Argentine healthcare provider. For the regional healthcare sector, the episode confirms that extortion against clinics and providers does not necessarily depend on large hospitals or national networks, but also on mid-sized organizations with sensitive data and fragile operational continuity.

Argentina Ministry of Education, weekly monitoring publication

Argentina’s Ministry of Education appeared in a weekly ransomware summary as one of the victims recorded between September 14 and 20. The available material provides no technical details, no group, no impact, and no public confirmation from the agency. For that reason, the case is useful for tracking presence in the monitoring ecosystem, but not for inferring real scope.

From an editorial standpoint, this is the kind of fact that can inflate perceptions if read out of context. The correct reading is that a weekly list included an Argentine victim from the education sector, not that there was a confirmed breach with encryption or validated exfiltration. It remains relevant because it keeps the public sector in view and adds to Argentina’s heavy monthly volume.

Vitar Group, Qilin

Qilin published Argentine company Vitar Group on its leak site, according to dark web monitoring. The available source does not provide data volume or a company statement, so the case remains classified as a leak site mention. What it does show is continued Qilin activity in the country and the persistence of its public pressure model.

This case matters more for context than for technical detail. Qilin remained active in Latin America during September and in the comparable August period. The presence of another Argentine company name on its leak site reinforces that the country remains a frequent target for groups that combine extortion, publication, and, in some cases, encryption.

Active Threats and Campaigns

Ransomware and Extortion

The month’s dominant campaign remains ransomware-linked extortion, but verification levels vary widely. Most of the 157 primary cases never reached a closed technical classification. Of that total, only 12 had confirmed asset encryption, 18 showed exfiltration without encryption, 27 were limited to a leak site mention, and 100 did not allow the impact to be determined with precision.

That breakdown reflects how the signal is actually consumed now. Groups publish first, and defenders, authorities, or the media, if they show up at all, arrive later. That is why leak site claims have to be read carefully. A publication claim does not, by itself, amount to ransomware with confirmed encryption. Nor does a figure for stolen GB automatically validate an intrusion with the same scope the actor suggests.

Emperador, Panzer, Qilin, Titan and TheGentlemen make up the visible core of September. Emperador had the most sensitive pieces tied to the public sector in Argentina and Brazil. Panzer showed measurable exfiltration in Brazil. Qilin kept adding victims in Argentina. Titan appeared in Argentine healthcare. TheGentlemen also remained relevant in the regional comparison, although some of its clearest cases closed in late August and are useful here as context, not as September volume.

Fraud and Phishing

The September material documents 19 fraud or phishing cases, down from 25 in the previous month. That does not signal disappearance, only a lower visible density in the reviewed archive. The most useful example for understanding the relationship between phishing, deception and ransomware is the Brazilian case cited by Convergência Digital, which describes an attempt to persuade employees to hand over passwords so ransomware could be installed.

That kind of tactic shows why phishing and ransomware often overlap in practice. The initial access vector may be social, and the later extortion phase may be technical, but the month’s material does not allow a full chain to be built for every case. The key point is that coercion against users and administrators remains part of the ecosystem, especially in sectors with many contact points and low tolerance for disruption.

APT and Hacktivism

The period’s material does not include a clearly attributable APT campaign tied to the ransomware axis in Latin America, but it does show hybrid pressure on public infrastructure. The note about government websites hijacked to display betting and illegal activity, while not ransomware, again shows that the state surface is still being used for reputational damage and traffic diversion. That does not count toward the axis, but it does help frame the threat environment.

Telemetry also shows clusters using AI tools and campaigns aimed at government, transportation, water and financial services in Mexico, Ecuador and Brazil. That measurement reflects attempts and operational support, not an incident with confirmed impact. It therefore serves as defensive context, not as a basis for increasing the intrusion count. In campaign terms, the region continues to receive operations that combine automation, social engineering and extortion-driven monetization.

Critical vulnerabilities

No critical CVEs were recorded in the analyzed material for September 2026 as facts of the period. That does not mean critical vulnerabilities were absent from the region, only that the file received did not document them as part of the verifiable monthly volume.

CVE Software Exploitation Source
No critical CVEs were recorded in the analyzed material n/a n/a Monthly indicator provided for September 2026

The comparison with August does show a clear shift. The previous month had mentioned 16 critical CVEs, while in September the verifiable material leaves only four critical references in total within the indicator. That drop suggests the month was driven more by leak site posts and group claims than by technical exploitation of critical vulnerabilities described in the sources received.

Regulation and Compliance

September saw more documented regulatory activity than August, with six moves compared with one in the prior month. This is not yet a uniform regulatory shift across the region, but it does point to more institutional reaction to incidents, claims, or risk conditions. The correct reading is that authorities and agencies are showing up more often in the conversation, even if they are not always issuing final decisions.

The clearest example of compliance and response was the Colombian case cited by the Ministry of Justice. It reported a technology recovery plan with alternate channels for PQRS and support documents, partial operation of SICOQ, and temporary downtime for MICC. The process also involved support from the Prosecutor General's Office, COLCERT, Microsoft’s DART team, and BID partners. That points to a major incident response with real operational impact.

In Argentina and Brazil, the material shows a more uncomfortable contrast. There are multiple complaints and monitoring records, but little visible official confirmation in the most sensitive cases. That lack of public response does not erase the incident, but it does make the regulatory picture harder to frame. In the case of Receita Federal, IntelFusions and TechStart specifically note the absence of an official statement at the close of their coverage.

The compliance signal is twofold. On one hand, teams need to be ready to report and document any exfiltration or outage quickly. On the other, they should assume that a post on a leak site may come before formal validation of the incident. Crisis management and evidence preservation remain more important than public disputes over terminology.

Most affected countries in Latin America

Argentina

Argentina concentrated several of the clearest cases this month. The Jujuy Judiciary was the strongest incident in terms of the data cited and sustained attribution, while Hospifar and Vitar Group added pressure on the health care and business sectors. The Ministry of Education also appeared in a weekly roundup, along with the August case of Sanatorio Modelo de Caseros, which helps frame the persistence of the risk even if it does not count toward September volume.

The Argentine pattern combines government, health care, and education, three verticals that are especially sensitive to ransomware. The main operational takeaway is that the groups are not only after money, but also visibility and public pressure on systems with little tolerance for downtime. The range of actors, Emperador, Titan, and Qilin, also shows that no single group is monopolizing the country.

Brazil

Brazil showed greater diversity across sectors and groups. Panzer hit K3G Solutions Brazil with significant exfiltration and a threat to publish everything, while Emperador added Receita Federal to its leak site. The country also appears in the health care, telecom, and IT context, and in the monthly comparison with several references to extortion activity in critical sectors.

Brazil stood out in September not only for the number of references, but also for the nature of the victims. K3G Solutions operates close to technology and connectivity infrastructure, and Receita Federal has a highly sensitive state profile. That places Brazil at a more complex intersection of operational and reputational risk than other regional markets. For local CISOs, the message is that vendors and public agencies can be equally attractive targets.

Mexico

Mexico appeared prominently in the material, although some of the more visible context comes from late-August posts or weekly comparisons. In September, it remains on the radar because of actors such as TheGentlemen in the regional analysis and references to agricultural and technology sectors in monitoring sources. The country remains one of the region's most closely watched hubs for extortion and ransomware.

The most cautious reading is that Mexico still holds a high position in the region, but the strictly September-dated volume in the provided material is not the highest in the month's table. That does not reduce the risk. It does indicate that public attention was spread across several countries, with greater visibility for Argentina and Brazil in the best documented cases.

Chile

Chile did not have a new September ransomware case with the same density of evidence as Argentina or Brazil within the month-dated material, but it still appears in the nearby comparison through the August case of Hospital Clínico Universidad de Chile. That matters because it shows sector continuity in health care and helps explain the intensity of the regional close to the previous month.

For September, Chile functions more as a reference country than as a main source of verified incidents. Even so, prior exposure in its health sector remains relevant for the regional assessment, especially because groups watch how hospitals and clinics respond in order to adapt pressure tactics.

Colombia

Colombia had a significant presence in regulation and response, rather than in new confirmed ransomware cases within the September material provided. The Ministry of Justice reported a technology recovery with clear operational impact, and that places the country at the more advanced end of public response maturity for the month.

Colombia's case is useful because it introduces a contrast with other countries in the report. There, the incident is not reduced to a post on a leak site, but instead escalates into containment, alternate channels, and institutional support. For regional teams, that is the kind of response worth emulating when service continuity is at risk.

Paraguay and Bolivia

The September material did not include enough verifiable facts to build a reading comparable to Argentina, Brazil, or Colombia. There are peripheral mentions in the threat ecosystem and in contextual coverage, but they are not part of the month's ransomware volume. As a result, the regional signal for these countries is secondary in September.

Peru and the U.S.

Peru and the United States appear mainly in comparative material and in the ecosystem of regional campaigns, but they do not account for the dated facts that support this report. They serve as context for groups with broader reach, not as the basis for the month. In a regional ransomware report, that distinction is key to avoiding overstatement of secondary signals.

The main trend in September is a drop in verified incidents compared with August, but not a proportional drop in risk. Verified incidents for the period fell from 537 to 399, cases with ransomware or extortion as the primary focus dropped from 281 to 157, and critical CVEs mentioned declined from 16 to 4. At the same time, regulatory moves rose from 1 to 6, suggesting a more visible institutional response.

The first signal to watch is the persistence of active groups with different profiles. Emperador is new and aggressive, Panzer combines exfiltration and pressure, Qilin keeps showing up repeatedly in Argentina, and Titan appears in Argentine healthcare. That diversity complicates defense because no single TTP is enough to explain the entire month.

The second signal is the consolidation of the leak site model as the main vehicle for pressure. In September, many of the most important incidents are not backed by public forensic evidence, but by listings, claims, and data estimates. That forces teams to measure not only the intrusion, but also the risk of public exposure, credential management, and possible reuse of access.

The third signal is sector concentration. Healthcare and government remain at the top of the risk list, but telecom and IT show a particular exposure because of the cascading effect they have on third parties. When a consultancy or connectivity provider goes down, the incident can have more impact downstream than on the victim itself. That is one of the clearest lessons from K3G Solutions.

The fourth signal is that visible activity is down in volume, but not in variety. September had fewer incidents than August, although the range of groups, countries, and sectors remained broad. That points to a more fragmented threat environment, not a safer one.

Recommendations for security teams

Teams in Latin America should assume that the dominant pattern is still extortion with publication, not necessarily visible encryption. That changes priorities. The first is to harden credential management, especially in public agencies, healthcare, and technology providers. Where the material showed access to databases and email, the potential impact multiplies if passwords are not rotated and tokens are not revoked quickly.

The second recommendation is to prepare specific procedures for claims on leak sites. Waiting for public confirmation from the victim is not enough. Teams should have a playbook that includes evidence preservation, review of privileged access, blocking suspicious accounts, backup validation, and coordination with legal and communications. Reaction time is often shorter than confirmation time.

The third is to strengthen segmentation and least privilege in healthcare and government environments. This month’s cases show internal credentials, WordPress databases, and, in Brazil, sensitive tax documents. That means an initial intrusion can spread fast if access is too tightly connected. Segmentation does not stop the attempt, but it limits the blast radius.

The fourth is to review vendor exposure. K3G Solutions is a clear reminder that a telecom and IT consultancy can become an entry point, or an impact point, for many downstream organizations. Teams should assess MFA, secret rotation, log visibility, and restore testing across the full digital supply chain.

The fifth is not to neglect training against phishing and credential abuse. Although the monthly indicator is down, the material still refers to deception tactics, impersonation, and password harvesting. That means the human surface remains part of the problem. Useful training is not generic, it is training that forces employees to report unusual access requests, MFA fatigue, and out-of-cycle changes.

The sixth is to watch operational recovery, not only detection. The Colombian case involving the Ministry of Justice shows that alternate channels need to be ready before an incident, not after. If a critical service goes down, the ability to keep operating through manual or semi-automated paths is part of real resilience. That applies to justice, healthcare, taxes, and education.

Frequently Asked Questions

What changed most between August and September in the regional ransomware signal?

Verified volume fell, and the number of cases with ransomware or extortion as the primary focus also dropped sharply, from 281 to 157. At the same time, documented regulatory moves increased, from 1 to 6. The detailed reading is in Period indicators and Trends and signals to monitor.

Which country had the strongest cases in the month, and why?

Argentina and Brazil concentrated the clearest events. Argentina had the Jujuy Judicial Branch and mentions tied to health and education. Brazil showed significant exfiltration at K3G Solutions and a sensitive claim involving Receita Federal. The country-by-country comparison is in Most affected countries in Latin America.

How should I read a leak site listing when there is no public confirmation?

It should be treated as a claim or assertion, not a validated breach. In September there were 27 leak-site-only cases and 100 cases that could not be determined. The correct taxonomy is in Period indicators and in Active threats and campaigns.

Which cases this month involved clearer exfiltration than encryption?

K3G Solutions Brazil is the clearest exfiltration case with extortion pressure, with an estimated 300 GB and a threat of further publication. Receita Federal was a claim with alleged exfiltration, but without official confirmation. The detail is in Relevant incidents.

Why does health keep appearing so often in these reports?

Because it combines highly sensitive data, the need for nonstop availability, and reputational pressure. In September there were references to Hospifar in Argentina and to K3G Solutions in a profile close to third-party infrastructure, along with regional health-related precedents. The sector view is in Regional overview of the month and Most affected countries in Latin America.

What should a CISO monitor this week if operating in the region?

Credentials, leak-site postings, activity around suppliers, changes in privileged accounts, and the actual ability to restore. It is also worth watching for claims involving justice, health, or taxes, because those are the sectors that repeat most often in the material. Suggested actions are in Recommendations for security teams.

Material limitations

This report was built exclusively from the material provided and the stated time window for September 2026. The 399 verified facts from the period are the basis for all indicators, while the 102 facts from earlier months were used only as a comparative frame and the 14 with no confirmed date were excluded from the counts.

An indicator at 0, especially critical CVEs when none are recorded in the material analyzed, means they did not appear in this document set, not that no critical vulnerabilities are being exploited in the region. The same caution applies to categories with undetermined classification, which were numerous this month.

The distinction between telemetry and incidents is also central. Counts of attempts, blocks, or vendors’ weekly averages were not added to any confirmed impact total. If they are mentioned in the readout, they should be understood as automated noise or aggregated measurement, not validated intrusion.

The material analyzed excluded, by design, unavailable sources from the authorized list and social media posts not allowed as evidence. Facts without a confirmed date were also left out of the indicators. For that reason, this report describes the verifiable signal for the month, not a complete inventory of everything that may have happened in Latin America during September.

Sources