Retail, E-commerce and Consumer Goods, July 2026
July brought ransomware, fraud, and extortion to LATAM retail and consumer goods, with a focus on Brazil, Argentina
Key findings
- July combined extortion, fraud, and exposure from vulnerabilities, creating a high regional risk for retail and consumer goods.
- Brazil had the month’s most visible operational case, with Caixa lottery outlets, losses, and temporary operating restrictions.
- Argentina faced pressure from leak sites and ransomware, with Micropack and Mercado Libre standing out for reputational impact.
- Colombia delivered the period’s most sensitive leak with Ecopetrol, marked by exfiltration, cloud exposure, and public pressure.
- Uruguay showed the more traditional side of fraud, with card theft, fraudulent transactions, and a formal criminal case.
- Active exploitation of CVEs in SharePoint, Fortinet, and ColdFusion reinforces the risk of intrusion into shared corporate systems.
- Phishing remained the region’s most common vector, making it necessary to integrate security and antifraud into a single response.
Monthly reference modules
These modules are filled automatically with verified dated facts from the period. Each one states its source and counting rule, so the figures reconcile across modules. They are the recurring monthly read; the later analysis develops the cases without repeating this summary.
Indicator window: 69 dated facts in July 2026 · 6 without confirmed date (excluded from the indicators). Facts from earlier months are used only as comparative context in the analysis, never as volume for this period.
Monthly executive summary
July 2026 closed with a sharp warning for retail, e-commerce, and mass consumer goods in Latin America, even though the month was not dominated by any single type of event. The period produced 67 verified incidents, with 13 uncategorized cases, 13 where ransomware or extortion was the main focus, 8 documented fraud or phishing episodes, and 4 critical vulnerabilities mentioned. The operational picture is clear, the exposure surface combined extortion group claims, payment and lottery incidents, third-party-attributed leaks, and an active backdrop of exploitation of enterprise software flaws that likely fueled much of the pressure on corporate environments in the sector.
The loudest case tied to the vertical involved Caixa lottery outlets in Brazil, where reporting confirmed fund diversion of close to R$ 1 million in Piauí and containment measures that limited financial operations to R$ 2,000 per transaction. That was joined by accounts of terminals going down, unauthorized payments, and unrecognized transfers across several units linked to Caixa systems, with reach reported in at least five states. Although the episode was not classified with precision in every detail, it still sent a significant signal for the in-person payments and cash collection segment, reconciliation systems, authorization controls, and business continuity can be targeted by both fraud and technical attacks with immediate financial impact.
In parallel, the extortion and leak-site front produced two especially sensitive items for the regional industry. LockBit 5.0 claimed an attack on Micropack, a food and retail products distributor in Argentina, and threatened to publish data if negotiations did not move forward. The Gentlemen, meanwhile, added Mercado Libre Argentina to its leak portal and said it had compromised the company’s systems, but the available coverage makes clear there is no public evidence confirming a successful intrusion, data theft, or operational impact. In other words, the month delivered both extortion claims with reputational damage potential and leak-site pressure that, based on the material available, still has not translated into a verified breach.
Colombia provided one of the period’s most important cases for sector risk analysis, even if it is not a pure retailer in the strict sense. Ecopetrol confirmed unauthorized access, the download of data tied to about 3,300 accounts, and exposure of cloud environments for approximately 15 subsidiaries. The Gentlemen claimed responsibility and spoke of up to one terabyte and more than 327,000 files, with bank data, biometrics, medical histories, payroll records, and VPN credentials among the material allegedly exposed. The company also said it had not identified compromise of its transaction systems or those of its subsidiaries, while working with Fiscalía and MinTIC to remove the illegally published information. The value of this case for retail and mass consumer goods is not the identity of the victim, but the shape of the incident, because it shows how a complex leak can touch supplier chains, customers, financial partners, and shared storage environments.
The rest of the month reinforced two conclusions. First, phishing and social engineering remain the most common vector in Latin America, according to ESET, with 73% of organizations surveyed affected in its 2026 report. Second, vulnerability exploitation remains a persistent entry channel in widely used enterprise software, with CISA’s KEV adding multiple actively exploited CVEs during July, including flaws in Fortinet FortiSandbox, SonicWall SMA1000, Microsoft SharePoint, and Adobe ColdFusion. For retail and mass consumer goods, where e-commerce platforms, back office systems, CRM, payments, and logistics tools all coexist, that combination raises the risk of initial compromise, credential theft, and the hijacking of peripheral services that later affect commercial operations.
Regional monthly overview
July's regional signal was severe and varied in form. No single vector dominated, but extortion, payment fraud, vulnerability exploitation, and leaks with reputational impact all gained ground. For the segment under review, the month showed that retail and mass consumer businesses can no longer be treated as isolated sales perimeters. They are increasingly exposed to banking systems, lotteries, distributors, marketplace platforms, cloud environments owned by subsidiaries, and third parties that support the supply chain.
The month’s qualitative risk reading is high. This is not only about the number of events, but about their combination. There are 13 cases where ransomware or extortion was the main focus, 8 incidents of fraud or phishing, 13 events with insufficient classification, and several references to active exploitation of critical vulnerabilities. That mix is especially sensitive for the vertical, because it allows different vectors to be chained against the same business, for example, a credential-based intrusion, lateral movement toward payment systems, exfiltration followed by extortion pressure, and finally a public narrative on a leak site. The material does not show that all of those steps happened together in each case, but it does show that the regional ecosystem has them available and active.
Geographic distribution also matters. Brazil, Argentina, Colombia, and Uruguay concentrated the most visible cases for this segment, with Brazil especially prominent because of the lotteries episode and the scale of cyberattacks reported in FortiGuard Labs coverage. Argentina contributed the Micropack case and the mention of Mercado Libre. Colombia had Ecopetrol and, in addition, a context of high weekly cyberattack frequency. Uruguay added several fraud cases and police responses, with gangs dedicated to cards, marketplace scams, and computer fraud. The regional picture, then, is not only one of technical attacks, but of digital crime that crosses payments, distribution, marketplaces, and mass consumer operations.
The prevention layer is still showing gaps. ESET again placed phishing and social engineering as the most common vector. That helps explain why several incidents during the month, including some not described as classic cyberattacks, share the same underlying pattern: stolen credentials, unauthorized payments, fraud schemes, and abuse of trust in commercial interfaces. The retail sector often has high user turnover, a heavy third-party presence, promotion campaigns, and a large digital-channel attack surface. All of that makes simple entry paths easier if there is no robust authentication, transactional monitoring, and strict segregation between payment and administrative environments.
Period indicators
| Indicator | Value |
|---|---|
| Verified facts in the period | 67 |
| Indicator time window | 69 facts dated in July 2026 · 6 with unconfirmed date (excluded from indicators) |
| Unclassified incidents (breaches or outages) | 13 |
| Cases with ransomware or extortion as the primary focus | 13 |
| Confirmed asset encryption | 2 |
| Leak site only mention | 3 |
| Unclassifiable based on available material | 8 |
| Documented fraud or phishing cases | 8 |
| Documented regulatory moves | 2 |
| Critical CVEs mentioned | 4 |
| Sectors with at least one documented fact | 5 |
| Dominant threat of the month | Unclassified (17 of 67 facts) |
| Facts with direct source confirmation | 90% |
| Aggregated telemetry figures excluded from the volume | 2 (aggregated attempts or blocks: not incidents with confirmed impact) |
Relevant incidents
Caixa lottery outlets in Brazil
The Caixa lottery outlet case was the clearest operational impact incident affecting the in-person payments and collections ecosystem this month. Yogonet Brasil reported that the Federal Police was called in and was assessing the case as a technology incident. In Piauí, estimated losses reached R$ 1 million across two lottery outlets, with losses of about R$ 750,000 at one unit and R$ 250,000 at another, according to the local union cited in the coverage. Folha de S.Paulo added that Caixa temporarily capped financial transactions at lottery outlets at R$ 2,000 and that contingency measures would affect deposits and the receipt of bills from other banks until July 27.
The significance of this case for retail and mass consumer sectors does not depend only on the Caixa brand. The lottery outlet channel works as a financial touchpoint in areas where cash, bill payments and physical convenience still matter commercially. When those terminals go down or funds are diverted, the damage is not limited to the financial institution. It extends to associated merchants, customers paying for services, reconciliation systems and the channel's reputation. BNLData also reported unauthorized bill payments, down terminals and unrecognized transfers at units linked to Caixa Econômica Federal banking systems. Defender360 said the incident affected lottery outlets in at least five states, São Paulo, Minas Gerais, Santa Catarina, Rio Grande do Sul and Piauí.
The secondary source also said a crisis room was set up, although it did not report whether data was compromised or leaked. That distinction matters. The available material confirms transaction impact and partial disruption, but does not support claims of exfiltration or encryption. For the sector, the lesson is broader, a distributed, multi-origin payment environment, with physical terminals and banking dependencies, can be disrupted through authorization manipulation, integration failures or fraudulent activity that does not need to reach a sophisticated intrusion to generate significant losses.
Ecopetrol and its exposure to corporate data
Ecopetrol was one of the month's most complete cases in terms of public chronology. Reuters reported on July 17 that the company had detected unauthorized access to digital resources and data downloads tied to about 3,300 accounts, affecting cloud storage environments for approximately 15 subsidiaries. The same report added that the company warned of a possible material adverse financial impact, although at the time of publication it had not identified a critical interruption or direct financial damage.
El País América Colombia expanded the case on July 30 and said the group claiming the attack, The Gentlemen, said it had up to one terabyte of information and more than 327,000 Ecopetrol and subsidiary files. The data cited included drilling records, payroll, banking data, medical histories, biometric data and VPN credentials. The same outlet said Ecopetrol reported to the SEC through a Form 6-K about a cyberattack involving unauthorized access, downloads of data linked to about 3,300 accounts and impact on cloud environments at 15 subsidiaries.
The company also said it had not identified compromise or impact on its transactional technology solutions or those of its subsidiaries, nor on its network of business and financial partners, suppliers and customers. It also worked with Colombia's Attorney General's Office and MinTIC to try to remove the information illegally published by the attackers. The timeline points to a leak with public exposure and extortion pressure, rather than a massive operational shutdown. For retail and mass consumer sectors, the lesson is useful because it shows the type of damage that matters most today, data, credentials, pressure on third parties and continuity risk in interconnected ecosystems.
Micropack and LockBit 5.0 pressure
LockBit 5.0 publicly claimed an attack against Micropack, a food and retail products distributor in Argentina, and threatened to publish sensitive data if negotiations did not begin. The available material does not document any public confirmation of intrusion, exfiltration or asset encryption. It does, however, record an extortion threat against a distribution-chain actor, which by itself is significant for the mass consumer segment.
Micropack matters because of its place in the chain. A food and retail products distributor relies on multiple dependencies, from logistics and inventory to billing, suppliers, routes and collections. A ransomware or extortion claim against that type of actor can affect shipments, replenishment, inventory visibility and relationships with retail chains. Even without a confirmed intrusion in the material, the appearance of the company's name on a leak site is enough to justify stronger monitoring of access, credentials, backups and third-party system exposure.
Mercado Libre Argentina on a leak site
The Gentlemen included Mercado Libre Argentina on its leak site and said it had compromised its systems, but the available coverage makes clear there is no public evidence confirming a successful intrusion, data theft or operational impact. That distinction matters. In the e-commerce ecosystem, even being named on a leak site can trigger reputational noise, customer inquiries, media pressure and criminal intelligence activity, even if the claim is not technically verified.
Mercado Libre holds a central position in the region's digital commerce infrastructure. For that reason, any mention of compromise has immediate weight. Still, this month's material calls for strict sourcing, there is no confirmed breach here, only an attribution without enough public support. From a defense standpoint, that does not justify ignoring the episode. On the contrary, it suggests that large marketplaces remain a narrative target for extortion groups, and that preventive response has to include domain monitoring, brand watch, fraud controls on accounts and a rapid technical rebuttal capability if correlated malicious activity appears.
Computer fraud and card theft in Uruguay
Uruguay provided a useful sequence for reading the more classic side of fraud. The Ministry of the Interior said two people were formally charged with two counts of aggravated theft and one continuing count of computer fraud, in a case with pretrial detention. The same statement explained that the investigation was handled by the Financial Crimes Investigation Department of the General Directorate for the Fight Against Organized Crime and Interpol, in coordination with the Flagrancy Prosecutor's Office of 4th Shift. El País Uruguay added that both were part of a gang dedicated to card theft for purchases and fraudulent transactions and that they had criminal records in their countries of origin for computer fraud.
The outlet also said the investigation identified a foreign couple linked to bank card theft and computer fraud thanks to security cameras at a café in Montevideo's Centro neighborhood. This case is valuable because it is a reminder that fraud does not always enter through malware or a technical vulnerability. It can arise from physical card theft, credential abuse, cloning, unauthorized purchases and the circulation of payment data in everyday settings. For retail and mass consumer companies, where payment acceptance and in-store promotions remain a significant part of the business, anti-fraud control has to operate in both the digital and physical layers.
Section9 and a Uruguayan food and services entity
A public ransomware intelligence site listed a .com.uy domain associated with Uruguay as a claimed victim by the Section9 group. The available coverage says there was no official confirmation from the victim or from Uruguayan authorities. It was also noted that the case was linked to a Uruguayan food and services entity, with a threat to publish data if the company did not contact the attackers.
The value of this event lies in the signal, not in confirmation. The material allows it to be read as a claim on a leak site or public ransomware intelligence site, but not as a verified intrusion. Even so, it is a pattern the sector should watch closely. Attackers know that a food and services company may face greater pressure around operational continuity, especially if it handles distribution, supply or high-volume consumption. In that context, extortion by narrative can be as damaging as the technical incident if it forces resources away from crisis and reputation management.
Threats and Active Campaigns
Ransomware and extortion
The month produced 13 cases with ransomware or extortion as the main focus, but only in some of them does the material clearly identify the exact type of impact. That distinction matters. It is not a good idea to lump together asset encryption, exfiltration without encryption, and a simple mention on a leak site, because each form calls for different responses and carries different operational consequences.
In the verifiable cases, asset encryption was confirmed in 2 cases. The material available on Ecopetrol indicates that a ransomware attempt was blocked by the company’s cybersecurity controls and those of its subsidiaries, which does not mean encryption succeeded. In the case of Caixa lottery outlets, there is also no public evidence in the material of encryption on the systems, but rather rerouted activity, offline terminals, and unauthorized transactions. For that reason, the month’s dominant pattern was not classic mass-encryption ransomware, but a mix of extortion with pressure over data and, to a lesser extent, transactional disruption.
A mere mention on a leak site appears in 3 cases. Micropack was claimed by LockBit 5.0, Mercado Libre Argentina was listed by The Gentlemen without public proof of a successful intrusion, and a Uruguayan food and services entity was claimed by Section9 without official confirmation. That set is especially relevant for retail because leak sites work as a pressure tool on companies with high reputational and operational exposure. Often, the damage does not begin with encryption, but with the public threat of data exposure, which can affect customers, suppliers, and payment channels even before any technical confirmation.
Cases that cannot be classified with the available material reach 8. That is not a weakness in the report, but a sign of how much extortion activity is published today. Attackers announce, but do not always show. Secondary media report the claim, but do not provide enough evidence to distinguish between encryption, exfiltration, or simple pressure. For a retail CISO, this means not stopping at the ransomware label. The key questions are what type of damage is already visible, what could materialize later, and which controls activate at each phase of the attack.
Fraud and phishing
The fraud and phishing block was led by 8 documented cases and by confirmation that phishing remains the most frequent vector in Latin America according to ESET, with 73% of surveyed organizations affected in its Security Report 2026. Although that figure comes from a survey and not from incidents during the period, it helps explain why so many events in the month revolve around payments, credentials, and misuse of interfaces.
Brazil showed a particularly telling variant with reported use of fake payment PDFs that imitated e-commerce brands and banking institutions to target boleto payments. Cointelegraph Brasil’s secondary coverage does not allow that description to be taken as a confirmed broad trend, but it does support a plausible attack hypothesis consistent with the local payments ecosystem. In retail and mass consumer markets, fraud of this kind is highly effective because it exploits familiar user habits, payment urgency, and trust in document formats people recognize.
Uruguay, meanwhile, showed computer fraud in a more traditional form, with card theft, fraudulent transactions, and an international gang dismantled. For the vertical, that is a direct warning. Not every loss enters through an endpoint. Part of the risk comes through the point of sale, the physical card, the marketplace, and last-mile logistics. Anti-fraud defenses need to look at the full cycle, from authentication to financial reconciliation.
APT and hacktivism
In July, there was not a large volume of classic APT campaigns solidly attributed to the retail and mass consumer axis, but there was pressure from extortion actors with an organized narrative and a broader campaign that Kaspersky described as StrikeShark, observed against organizations in Latin America, Asia, and Europe, with cases in Colombia among the countries mentioned. The available material does not tie it directly to retail, but it does point to a regional climate of more persistent operations and greater use of malicious artifacts and evasion.
The useful reading for this vertical is that campaigns that look less noisy can still reach back office systems, suppliers, or corporate accounts that support sales platforms. When attention is focused only on the cash register endpoint or the public website, it is easy to overlook that many of the more serious intrusions begin through email, documents, fake updates, or vulnerabilities in collaboration and administration software.
Critical vulnerabilities
| CVE | Software | Exploitation | Source |
|---|---|---|---|
| CVE-2026-48282 | Adobe ColdFusion | Actively exploited, included in CISA KEV | CISA, Cronup, Elite Center Blog |
| CVE-2026-25089 | Fortinet FortiSandbox | Actively exploited, included in CISA KEV | CISA |
| CVE-2026-39808 | Fortinet FortiSandbox | Actively exploited, included in CISA KEV | CISA |
| CVE-2026-58644 | Microsoft SharePoint | Actively exploited, included in CISA KEV | CISA, Sophos |
The material analyzed did record critical CVEs mentioned during July, so it would not be accurate to say there was no technical exposure. What can be said is that the period featured several alerts about active exploitation in products widely used in corporate environments. CISA added CVE-2026-48282 in Adobe ColdFusion to the KEV catalog, and later incorporated flaws in Fortinet FortiSandbox and Microsoft SharePoint. In addition, Microsoft’s July 2026 bulletin confirmed by the Uruguayan government said that CVE-2026-56155 in Active Directory Federation Services and CVE-2026-56164 in SharePoint Server were actively exploited and included in KEV, although those facts are not part of the critical CVE count for the period because the indicator provided sets the figure at 4 mentions.
For retail and mass consumer environments, the message is straightforward. Many platforms that support promotions, supplier portals, intranets, document management, and internal publishing rely on products like SharePoint, Office, .NET, SQL Server, or federated access components. If those services are exposed, attackers have an entry point that does not require extraordinary creativity. Automation, a proven exploit, and a slow patch window are enough. The risk is not only the initial intrusion, but also the possibility that a compromise in enterprise software can spread to credentials, internal documents, and systems that support the business.
Regulation and Compliance
July also brought two developments with regulatory and institutional coordination implications. In Ecopetrol's case, the company worked with Colombia's Attorney General's Office and MinTIC to try to remove information illegally published by the attackers. That step reflects a response that is no longer purely technical, but also legal, reputational, and content management related. In incidents involving exfiltration, the ability to coordinate with authorities and data distribution platforms becomes part of containment.
The other front was Uruguay, where the Ministry of the Interior reported that two people were formally charged with aggravated theft and computer fraud, with pretrial detention ordered. The case is valuable because it shows coordination between financial investigations, prosecutors, and evidence obtained in physical spaces. For retail and mass consumer companies, the signal is that anti-fraud units must be ready to work with prosecutors, banks, and investigative bodies. It is not just a matter of reporting losses, but of preserving evidence, reconstructing payment paths, and safeguarding logs, cameras, and access records.
At the compliance level, the month also reinforced pressure from incident reporting and management frameworks. Ecopetrol's filing reports with the SEC underscores that events involving exfiltration or potential material impact cannot remain within the internal sphere. For companies with regional presence and mixed retail, distribution, or payments operations, coordination with reporting frameworks in each jurisdiction remains an operational requirement, not a legal formality.
Countries and most affected subsegments
Brazil
Brazil posted the most visible signal in this axis during July, mainly because of the Caixa lottery terminal incident. The mix of terminals going down, unauthorized payments, unrecognized transfers, and temporary operating restrictions points to a specific risk around physical payment channels and close-range payment infrastructure. The impact across at least five states broadens the read from a local incident to a platform weakness.
Regional media coverage also placed Brazil as the country with the most ransomware victims in the first half of 2026, and as the most affected in FortiGuard Labs telemetry cited by Infobae México. Those figures are not incidents from the month, but they do reinforce the Brazilian market’s priority within the regional map.
Argentina
Argentina was defined by two different signals. The first was Micropack, a food and retail goods distributor claimed by LockBit 5.0. The second was the listing of Mercado Libre Argentina on The Gentlemen’s leak portal without public proof of a successful intrusion. Between the two, the month showed both supply chain exposure and narrative pressure on a central digital commerce platform.
The most exposed subsegment in the country is not only e-commerce, but distribution and marketplace operations. That pairing puts continuity of logistics, customer trust, account availability, and protection of internal and commercial data at the center of the risk picture. When a major player such as Mercado Libre appears in an extortion attribution, even if unconfirmed, the noise spreads to users, sellers, and platform partners.
Colombia
Colombia concentrated the most complex corporate leak case, with Ecopetrol at the center. Even though it is not a retailer, the incident matters for mass consumption because it affects cloud environments, vendors, financial partners, and customer networks. The country also appears in regional attack-frequency coverage, with more than 3.000 cyberattacks per week reported by Infobae Colombia and with a presence in Kaspersky’s StrikeShark campaign.
The sector reading for Colombia points to corporate environments with deep third-party integration and a high risk of sensitive data exfiltration. In the retail axis, that translates into close attention to supplier portals, loyalty systems, integrations with partners, and cloud platforms that support commercial operations.
Uruguay
Uruguay delivered the most visible face of digital fraud. The formal charges against two people for aggravated theft and computer fraud, along with the investigation into card theft for purchases and fraudulent transactions, show a criminal economy that combines physical presence with digital abuse. At the same time, an unconfirmed claim appeared about a food and services entity linked to Section9.
For mass consumption, Uruguay sends a clear signal about the value of physical and transactional evidence. Cameras, purchase traceability, usage pattern monitoring, and cooperation with authorities were key. In a country with a smaller market than others in the region, response efficiency can be an advantage, but it does not reduce the need for stronger anti-fraud controls in merchants, marketplaces, and payment points.
Mass consumption and commerce subsegments
The most exposed subsegments of the month were food distribution, marketplaces, payment points, lotteries, and close-range payments. Micropack represents the supply chain. Mercado Libre reflects the digital platform and seller economy. Caixa lottery terminals show the risk in physical payment channels. Uruguay points to card and purchase fraud. Taken together, the vertical was shaped by the same logic, high-volume business with heavy transaction turnover and third-party dependencies.
Trends and signals to watch
There is no month-over-month baseline, because this is the first archived period with this indicator format for Latin America. That makes it impossible to say whether July rose or fell versus June within the same framework. What can be said is that the month brought a particularly dense mix of extortion, fraud and vulnerability exposure, with geographic spread across Brazil, Argentina, Colombia and Uruguay.
The first signal to watch is the shift from mass encryption to pressure over data and reputation. In July, the most visible side of ransomware was not a wave of confirmed encryption, but mentions on leak sites, threats to publish data, and exfiltration with potential legal and financial damage. For retail and mass consumer businesses, that shift is critical because attackers know the sector depends on trust, availability and transaction volume. They do not need to destroy everything to force a negotiation.
The second signal is the persistence of fraud as a parallel layer to cyberattacks. Brazil, with boleto payments and lotteries, Uruguay, with card theft, and references to fake payment PDFs show that criminal business does not make much distinction between hacking and fraud if the outcome can be monetized. For the sector, that means security and anti-fraud teams have to work together. They are different disciplines, but in July they behaved like a single risk surface.
The third signal is the exploitation of enterprise software. Even if the vertical does not always appear at the top of KEV reports, its infrastructure still depends on SharePoint, ColdFusion, Fortinet, Microsoft and other components that are not specific to retail, but do support the business. The risk is not only at the cash register or in the online store. It also sits in the collaboration, authentication and management layer that connects employees, vendors and partners.
The fourth signal is the fragility of in-person payments and intermediary channels. Caixa lottery outlets show that disruption to terminals and authorizations can create direct losses and affect deposits, tickets and transfers. In Latin America, where a large share of mass retail still relies on mixed payment schemes, that fragility becomes a business continuity issue, not just a cybersecurity one.
Security team recommendations
First, strictly separate payment, authentication, administration and analytics domains. This month showed that a disruption in a payment channel or a collaboration layer can escalate quickly if permissions are mixed. In retail and mass consumer goods, that means reviewing network segmentation, privileged identities, access federation and data egress paths. The goal is not only to prevent intrusion, but to contain the blast radius if a vendor, user or credential is compromised.
Second, strengthen fraud detection at the point of sale and in digital channels with rules that correlate transactional and behavioral signals. The cases in Brazil and Uruguay are a reminder that fraud can come through unauthorized payments, card theft, duplicate receipts or ticket manipulation. Teams should review anomalous patterns by geography, time of day, amount, terminal, source account and device. Where there is a marketplace, it is also worth monitoring sessions, password changes, account takeovers and promotional abuse.
Third, treat any mention on a leak site as a first-class event, even if the intrusion has not been confirmed. Micropack, Mercado Libre and the Uruguayan entity claimed by Section9 show that public exposure is already an operational risk. The response plan should include technical validation, internal communication, brand monitoring, searches for exposed credentials and coordination with legal and communications teams. Lack of public confirmation does not mean lack of risk.
Fourth, prioritize patching and hardening for the products that appear with active exploitation in KEV. SharePoint, ColdFusion and Fortinet are not technical anecdotes. They are potential initial access surfaces for corporate environments, and the vertical depends on them for internal workflows, collaboration and service exposure. The recommendation here is operational: live inventory, short patching SLA, minimal exceptions and post-patch validation of external exposure.
Fifth, prepare the business for continuity without blind dependence on third parties. The case of Caixa lottery retailers and the exposure across multiple Ecopetrol subsidiaries indicate that third parties, subsidiaries and distributed channels can be the weak point. The continuity plan should include manual contingencies, alternative payment routes, SLA review, terminal outage drills and the ability to operate with controlled degradation for several hours or days.
Sixth, preserve evidence from the first minute. Uruguay showed that cameras, traceability and coordination with financial investigations were useful in dismantling a fraud ring. In retail cyber incidents, that translates into preserving authentication logs, payment records, terminal images, tickets, branch cameras and change traceability. If evidence is lost, the ability to recover funds or reconstruct the attack sequence is lost as well.
Seventh, bring together security, anti-fraud, operations, legal and customer experience teams. In this vertical, an intrusion rarely stays in the SOC. It ends up affecting sales, payments, reputation and customer service. That is why the crisis committee should be able to decide quickly whether the issue is an outage, extortion or fraud, and should have ready-made communication guidelines for each scenario.
Material limitations
This report was built exclusively from the material provided for July 2026 and with a thematic scope covering retail, e-commerce, and mass consumption in Latin America. There was no access to the internet or to sources outside the authorized list. That means the picture is accurate with respect to what was verified in the material, but it does not capture everything that happened in the region during the month.
The time window for the indicators is limited to events dated in July 2026. The 6 events without confirmed dates were excluded from the indicators, although they may have been used as qualitative context. Aggregated telemetry figures were also left out, because they represent attempts, blocks, or weekly vendor averages, not incidents with confirmed impact. They were not counted in any event totals for the period.
An indicator of 0 does not mean the event did not occur in the region. It means only that it did not appear in the analyzed material with the required classification or confirmation. This distinction is especially important for CVEs and for categories such as ransomware, where part of the activity may have fallen outside the available corpus or the public evidence collected.
The material also excluded consumer social networks and sponsored content or press releases that were not suitable for supporting trend analysis. When any statement came from secondary coverage or from an unconfirmed attribution, it was treated as such and not as a fully verified technical fact. In several ransomware or leak site cases, the available coverage made it possible to record the claim, but not to verify intrusion, exfiltration, or encryption. That limit is deliberate and part of the report’s integrity.
Final Operational Notes
The month showed that risk for retail and mass consumer businesses in Latin America is not concentrating in a single vector. Physical fraud, manipulated payments, extortion narratives, data leaks, enterprise software exploitation, and pressure on third parties are all present at once. Defense that looks only at the e-commerce portal or only at the checkout endpoint arrives too late. The real exposure sits in the combination of identities, payments, vendors, cloud, and reputation.
Attention indicators
| Signal | Operational reading |
|---|---|
| Ransomware or extortion | Pressure on data and leak sites outweighed verified encryption. |
| Fraud and phishing | It remained a highly effective way to monetize business access. |
| KEV vulnerabilities | Widely used enterprise products continued to appear as an entry point. |
| Payments and lotteries | Transaction disruption generated direct losses and affected continuity. |
| Subsidiary and third-party data | Cloud services and subsidiaries widened the exposure radius. |
Sources
- LockBit 5.0 Targets Argentina's Leading Retail Groceries Distributor MicropackD-Expose
- The Gentlemen amenaza con filtrar datos de Mercado Libre Argentina tras presunto ciberataqueFortuna y Poder
- Incidente cibernético desvia cerca de R$ 1 milhão de lotéricas da Caixa no PiauíYogonet Brasil
- Caixa limita operações em lotéricas após incidente tecnológicoFolha de S.Paulo
- Ataque orquestrado às lotéricas da Caixa desvia R$ 1 milhão e expõe fragilidade nos sistemas de pagamentoDefender360
- Ataque cibernético simultâneo atinge lotéricas da Caixa em vários estadosBNLData
- Empresa brasileira diz ter bloqueado ataque hacker de seis horasCointelegraph Brasil
- Un ciberataque a Ecopetrol expone información del negocio y de sus empleadosEl País América Colombia
- Ecopetrol confirma publicación de información robada de 15 empresas tras ciberataqueRadio Hoy
- ¿Ciberataque a Ecopetrol? Publican información de 15 empresas del grupo y la compañía pide intervención de las autoridadesEl Colombiano
- Colombia's Ecopetrol says cyberattack stole data tied to 3,300 accountsReuters
- Ecopetrol Reports Cybersecurity IncidentYahoo Finance / PRNewswire
- Colombia's Ecopetrol says cyberattack stole data tied to 3,300 accountsReuters
- Aumentan ataques de ransomware en primer semestre de 2026 | Agencia NVMAgencia NVM
- Casos de ciberataques aumentan 38% en México, empresas registran escalada en diversos sectoresInfobae México
- Empresas en Colombia enfrentan más de 3.000 ciberataques semanales y pérdidas millonariasInfobae Colombia
- Weekly CISA KEV Updates: 28 July 2026HackerStorm
- Vulnerabilidades y ransomware elevan el riesgo operativo para industrias estratégicas, advierte KaseyaITware Latam / Kaseya
- Expertos alertan sobre una creciente táctica de ransomware hackers imprimen demandas de rescate durante ataques en América LatinaTrendTIC
- Weekly Threat Bulletin – July 22nd, 2026F5 Labs
- Vulnerability Summary for the Week of July 20, 2026CISA
- CISA KEV Catalog Update July 14 2026: Four VulnerabilitiesQUASA
- Boletín Semanal de Ciberseguridad, 25-31 de julioTelefónica Tech
- Panorama de Ciberseguridad: Semana del 06 al 10 de julio de 2026Cronup
- Resumen de noticias sobre ciberseguridad – 10 de julio de 2026Integrity360
- Before, during and after ransomware attackSCILabs
- Phishing y documentos maliciosos ponen a América Latina como la segunda región más expuesta a ciberamenazas industrialesTrendTIC
- CISA Adds Two Known Exploited Vulnerabilities to CatalogCISA
- CVE críticos julio 2026: ColdFusion, Ivanti y Fortinet | Elite Center BlogElite Center Blog
- Weekly CVE Report: 6 Exploited Bugs Hit CISA KEVSecurityOnline
- July 2026 Patch Tuesday: 570 Flaws, 2 Zero-Days ExploitedSecurityOnline
- ESET Security Report 2026: el estado de la ciberseguridad de las empresas de LatinoaméricaWeLiveSecurity
- Actualizaciones de seguridad de Microsoft – Julio 2026Gobierno de Uruguay (CERTuy / AGESIC)
- ESET: 4 de cada 10 empresas en América Latina operan a ciegas ante los ciberataquesCanal News Ecuador
- July Patch Tuesday only feels endlessSophos
- Accionar policial permite formalización de dos personas por delitos de hurto y fraude informáticoMinisterio del Interior de Uruguay
- Robo con un sobretodo en una cafetería permitió desbaratar banda extranjera dedicada a fraude informáticoEl País Uruguay
- Section9 Targets Uruguayan Food & Services EntityDExpose
- Detienen y condenan a hombre por fraude con maquinaria de panadería en SorianoSan José Ahora
- Condenaron a un hombre de 26 años por estafa a vendedor de maquinaria a través de MarketplaceTelenoche
- Banda extranjera cayó por robar en comercio del Centro de Montevideo con extraña modalidadMontevideo Portal
- El retail enfrenta una nueva era de ciberataquesTrendTIC
- The Gentlemen amenaza con filtrar datos de Mercado Libre Argentina tras presunto ciberataqueFortuna y Poder
- THEGENTLEMEN Ransomware: Global Surge in Critical Infrastructure Targeting and Exploitation of Firewall VulnerabilitiesSecurityArsenal
- The State of Ransomware: July 2026BlackFog
- TheGentlemen Ransomware Targets Mercado Libre in ArgentinaDexpose
- Mercado Libre hit by ransomware attackEscudo Digital
- Mercado Libre, afectada por un ataque de ransomwareEscudo Digital
