Retail, E-Commerce, and Consumer Goods, August 2026
August closed with 71 incidents and a rise in retail ransomware and incidents, with Mexico, Argentina, and Brazil as key hotspots.
Key findings
- August closed with 71 verified incidents and a sharp increase in unclassified incidents, which became the month’s leading threat.
- Ransomware and extortion gained ground versus July, with 21 cases as the primary focus and multiple claims still lacking public forensic closure.
- Mexico showed the highest visible density of retail and consumer goods activity, followed by Argentina and Brazil.
- SAP Commerce Cloud CVE-2026-58231 was the only critical CVE mentioned and had a very short exploitation window after patching.
- The supply chain was again a weak point, with the ShipMonk case exposing data from Latin American customers even though the main brand did not suffer a compromise of its own systems.
- Smishing fraud remained active, though at lower volume than in July, and used mass-market consumer brands to capture banking data.
- The month left several gray-area cases, so distinguishing encryption, exfiltration, and mere mention on a leak site remains key to response prioritization.
Monthly Reference Modules
These modules are filled automatically with the verified dated facts in the period. Each one states its basis and counting criterion so the figures reconcile across modules. They are the recurring month-to-month readout, and the analysis that follows develops the cases without repeating this summary.
Indicator window: 71 dated facts in August 2026. Facts from prior months are used only as comparative context in the analysis, never as volume for this period.
Monthly executive summary
August 2026 produced 71 verified events across retail, e-commerce, and mass consumer goods in Latin America, with 25 uncategorized incidents and 21 ransomware or extortion cases as the main driver. The monthly picture points to more operational pressure and more public exposure for victims than in July, especially in Mexico, Argentina, and Brazil.
The most notable shift in the month was the change in tone of the dominant threat classification. In the previous month, the leading category was "Unclassified," with 17 of 67 events. In August, "Incidents" became the largest category, with 25 of 71. That does not mean attackers were less sophisticated, but rather that breaches, outages, and criminal claims were mixed together in ways that affected organizations have not yet confirmed consistently.
Ransomware remained highly active and left several cases at different stages of verification. APSA Internacional confirmed exfiltration without encryption, Qilin claims were attributed to Open Sports, Price Shoes, and Inmac, and SEARS, Sanborns, and Tecno Accion were mentioned on leak portals or third-party records. In several of those events, the source does not specify whether assets were encrypted, so the legal and reputational risk is clear, but the operational impact cannot always be reconstructed with precision.
The month also brought a critical vulnerability in SAP Commerce Cloud, with exploitation observed just days after the patch and direct risk to online sales platforms. That technical issue matters for this vertical because SAP Commerce Cloud is part of the infrastructure of large online retailers and because the window between disclosure and attempted exploitation was very short. For retail operators dependent on cloud services or e-commerce integrations, August was more a signal of urgency than of routine patch management.
Fraud and phishing were also present, though at lower volume than in July. The clearest case was a campaign of fake SMS messages impersonating Netflix in Uruguay to steal banking data, showing how mass-market brands continue to be used as lures against end users. On the other side of the map, alerts about printed ransom notes in Mexico and Colombia show that extortion no longer depends only on digital channels, it now combines physical and digital pressure to raise the odds that victims will respond.
Regional snapshot for the month
August’s regional reading is one of high risk, not because of a single campaign, but because of the combination of volume, range of impacts, and sector concentration in highly sensitive commercial assets. Regional retail and e-commerce were exposed to breaches, extortion, fraud, and a critical exploitable vulnerability in a key e-commerce component.
Mexico accounted for much of the visible signal, with Price Shoes, SEARS, Sanborns, and references to other targets on leak sites and monitoring radars. Argentina also appeared with Open Sports, APSA Internacional, Inmac, and an auto dealer listed as a possible victim, while Brazil added the Shopping Cidade case in Belo Horizonte and Uruguay reported a phishing attempt impersonating Netflix. These are different countries, but they share the same underlying trait, retail exposure combines personal information, logistics, payment gateways, and customer service systems, all highly valuable for extortion and fraud.
The qualitative severity rises because the month was marked not only by internet noise or telemetry, but by verifiable events that affected availability, confidentiality, and reputation. There was encryption and temporary unavailability at a shopping center, confirmed exfiltration at an Argentine animal health and nutrition company with a retail-facing domain, leaks of customer order data from Trezor through a third-party logistics provider with affected users in Colombia and Brazil, and a critical CVE in e-commerce software with early exploitation attempts. That combination justifies reading the month as a period of sustained pressure on the regional commercial ecosystem.
The comparison with July also shows concrete signals. Incidents without classification increased, cases with ransomware or extortion as the primary focus increased, and documented fraud or phishing cases declined. The drop in critical CVEs mentioned should not be read as structural relief, because the only critical flaw in the month in the material analyzed was enough to create serious exposure in online sales platforms. In other words, August had fewer visible critical vulnerability types, but a more delicate and more production-adjacent exploitation window.
Period indicators
The table below reproduces exactly the indicators provided for August 2026, including the base, the time window, and the comparison with the previous month when reported. It does not include aggregated telemetry or any derived analysis.
| Indicator | August 2026 | Previous month | Change |
|---|---|---|---|
| Verified events in the period | 71 | 67 | +4 |
| Time window for the indicators | 71 events dated August 2026 | 67 events dated July 2026 | N/A |
| Unclassified incidents (breaches or disruptions) | 25 | 13 | +12 |
| Cases with ransomware or extortion as the primary focus | 21 | 13 | +8 |
| Breakdown of ransomware, non-encrypted exfiltration, simple extortion | 1 | N/D | N/D |
| Breakdown of ransomware, leak site mention only | 2 | N/D | N/D |
| Breakdown of ransomware, classification could not be determined from the material | 18 | N/D | N/D |
| Documented fraud or phishing cases | 5 | 8 | -3 |
| Documented regulatory moves | 2 | 2 | no change |
| Critical CVEs mentioned | 1 | 4 | -3 |
| Sectors with at least one documented event | 5 | 5 | no change |
| Predominant threat of the month | Incidents (25 of 71 events) | Unclassified (17 of 67 events) | change |
| Events with direct source confirmation | 85% | N/D | N/D |
| Calculation base | Verified events in the period: 71 | Verified events in the period: 67 | N/A |
Relevant incidents
August brought a range of incidents with different levels of public confirmation, from breaches involving exfiltrated data to ransomware claims still awaiting public verification. The common thread was exposure across retailers, e-commerce operators, and related services that support inventory, customer service, logistics, or payments.
APSA Internacional and apsanet.com.ar
APSA Internacional emerged as one of the clearest confirmed exfiltration cases of the month, although the material does not include an official company statement or detail the contents of the stolen files. Breachsense estimates a 355,83 GB leak tied to the apsanet.com.ar domain, and Darkfield classifies the case as confirmed data exfiltration based on the publication on Krybit’s leak site.
The timeline is also clear. Hookphish places the breach and discovery on August 11, while Recentbreaches, Galaxy Warden, and Darkfield agree that the group claimed to have obtained a user database with at least one password field. The important point for the sector is not just the volume, but the nature of the material. A user base with partial credentials or password fields increases the value of the leak for follow-on attacks, key reuse, and targeted phishing campaigns.
The case also reflects a frequent classification problem in the month. The source confirms exfiltration, but does not allow us to say whether production systems were encrypted or operationally disrupted. For a risk reader, that means legal and reputational impact already exists, while business continuity impact cannot be estimated with the same precision. In a vertical that depends on trust from customers and suppliers, that difference matters as much as the technical vector.
Open Sports and the Qilin claim
Open Sports saw multiple public references within a few days, which suggests early exposure that was visible enough to trigger aggregators, analysts, and alert accounts. Breach House, Hackmanac, and Dexpose point to a Qilin claim between August 27 and 28, with notification status still undisclosed and no public confirmation from the company on scope.
Breachsense adds useful business context for understanding the risk. This is a footwear, apparel, and accessories retailer with physical stores and an e-commerce channel, and the record shows 56 @opensports.com.ar email accounts from external breaches, plus 2.346 credentials associated with the domain. The source itself makes clear that it cannot conclusively link those credentials to the specific incident, but the data shows how much identity material can surround a retail brand even before the company confirms an attack.
Here the source does not allow a firm split on the exact technical impact. The material refers to a ransomware claim and a leak threat, but does not establish whether assets were encrypted, only whether there was a leak site mention or already verified exfiltration. That ambiguity is common in August and forces the case to be treated as an active extortion signal, not as a fully closed breach in analytical terms.
Price Shoes and Qilin pressure in Mexico
Price Shoes appears with a more precise timeline than several other cases in the month. ransomware.live places it as a Qilin-claimed victim on August 9, Hookphish fixes the compromise at the same day at 13:31 UTC, and Breachsense sets discovery on August 10. The consistency across sources suggests real, rapid activity, although there is still no public confirmation of full scope.
The significance of the case goes beyond the brand. Price Shoes is a footwear retailer operating in Mexico, and it adds to a run of retail-linked targets in that country during August. That reinforces the reading that the sector is being assessed by attackers as an area with high pressure potential, where operational disruption and customer data exposure can affect sales, compliance, and reputation at the same time.
This incident also lacks documentation that would let us close the final technical classification. The records speak of ransomware claimed by Qilin and unauthorized access or disrupted systems according to a news account on social media, but the formal material available in the set does not confirm how much data left, whether encryption occurred, or whether the organization was notified. For a security team, that calls for monitoring credentials, domains, and leak site mentions, along with reviewing operational continuity.
Shopping Cidade in Belo Horizonte
Shopping Cidade confirmed it was hit by a cyberattack that caused encryption and temporary unavailability of files in its technology environment. Management said it detected the incident on August 6, took containment, restoration, and control hardening measures, and had not found signs of data misuse at that point.
The key operational fact is encryption. Unlike other cases this month where only claims or leak site listings were available, here the company describes an impact on files and temporary availability, which places it in the category of confirmed disruption with a ransomware or destructive malware component, although the material does not identify the attacker group. The type of potentially involved data is also sensitive: personal information from employees, former employees, service providers, suppliers, tenants, and people connected to those relationships.
For the sector, this case is useful because it shows the damage is not limited to pure e-commerce. Shopping centers and malls also concentrate third-party information and maintain infrastructure that, if affected, ends up impacting leases, store operations, support services, and internal communications. That mix broadens the extortion surface.
Inmac and Tecno Accion, still weak claims
Inmac, in Argentina, was identified by Hookphish as a Qilin-attributed ransomware victim on August 31, but the report relies on monitoring ransomware group activity and includes no official statement or impact details. Tecno Accion, also in a ransomware.live entry, appears as a presumed victim with discovery on August 30 and estimated attack date of August 28, with association across several sectors, including retail and e-commerce.
Both cases matter less for their standalone volume than for what they say about the end of the month. The second half of August kept the leak site and victim-record cycle active, with Argentine companies of different profiles appearing on the radar. The available material does not allow us to say whether there was encryption, only a leak site mention or extortion without documented operational impact, so they should be read as exposure signals, not as fully characterized breaches.
SEARS, Sanborns, and the Mexican August package
SEARS and Sanborns were included in multiple lists and alerts during August, with attribution to Space Bears and coverage by media and analysts who tracked the case from August 15. DeXpose describes the attack against sears.com.mx as part of a typical double-extortion scheme, with a threat to publish "AttentionDemo" files, while GalaxyWarden treats it as a listed leak with "Affected: Unconfirmed" status.
The case matters for three reasons. First, it involves two brands from the same conglomerate, which amplifies reputational exposure. Second, the material suggests a concrete ten-day deadline for data leakage, which is consistent with modern extortion practices. Third, several sources agree that the event became visible on public portals before there was any official confirmation of scope.
Here again, the source does not say whether assets were encrypted. The public narrative focuses on victim publication and the threat to expose customer data, including a reference to a password field, but without independent proof of full internal damage. For defensive planning, that means covering both fronts at once, infrastructure and identity exposure.
Trezor, ShipMonk, and the regional effect on Latin American customers
Although it is not a Latin American retailer, the Trezor case belongs in the report because of the documented impact on customers in Colombia and Brazil and the supply chain logic it shares with regional retail. Trezor reported that its logistics provider ShipMonk suffered unauthorized access on August 8, notified Trezor on August 10, and public disclosure came on August 13.
The breach exposed names, emails, phone numbers, and shipping addresses for 13.689 customers, with 11.742 full exposures and 1.947 partial ones. Trezor’s 90-day retention policy limited the affected order set to the period from May 10 to August 8, and the company itself clarified that private keys, seeds, and hardware devices were not compromised. Even so, the risk of follow-on phishing and impersonation was explicitly flagged by several sources.
For Latin America, the point of interest is the value chain. A logistics or fulfillment provider can become the weak point that exposes end customers even when the primary brand keeps control of its own infrastructure. That is exactly the kind of scenario regional retail and e-commerce teams need to map across third parties, from warehouses and couriers to CRM and analytics.
Threats and active campaigns
August combined extortion, leaks, and fraud, but the dominant signal across the board was ransomware with varying levels of verification maturity. The range of public status, from confirmed exfiltration to a mere mention on a leak site, requires a careful separation of completed facts from claims that have not yet been validated.
Ransomware and extortion
The ransomware or extortion category was one of the most active of the month, with 21 cases as the primary focus according to the period’s material. Within that set, only one case was clearly classified as exfiltration without encryption, two were left as a simple mention on a leak site, and 18 could not be determined with precision by the source.
That distribution matters because not every criminal claim produces the same effect. When encryption is confirmed, the main damage is operational. When there is exfiltration without encryption, legal and privacy exposure becomes more important. And when there is only publication on a leak site, the incident may still be in the pressure or criminal propaganda phase. August was full of that mix, especially in Open Sports, Price Shoes, SEARS, Inmac, Tecno Accion, and APSA Internacional.
A notable feature is that several of the most visible cases relied on aggregators or tracking platforms, not victim statements. That does not invalidate the finding, but it does mean they should be treated as operational intelligence signals rather than forensic closures. For response teams, the implication is direct: strengthen monitoring of domains, credentials, leak site mentions, and anomalous access behavior at third parties.
Fraud and phishing
Fraud and phishing appeared less often than in July, but they did not disappear. The clearest case was the SMS campaign in Uruguay that impersonated Netflix to lure victims to a fake site and collect personal and banking data. The note also advised not to open the link or share passwords or card information.
The logic behind that campaign is simple and effective. It relies on a well-known mass-market brand, creates urgency around a supposed payment issue, and pushes the user to a site designed to capture credentials and financial data. The target does not have to be a large company for the damage to matter, because the impact shifts to the end consumer and the payments ecosystem.
August suggests that phishing remained a useful tool to complement extortion attacks. Attackers do not need every campaign to be technically sophisticated to get results. It is enough to imitate everyday services, exploit trust, and collect card details, account data, and contact numbers.
APT and hacktivism
This month’s material did not include a classic APT campaign in this vertical or a hacktivist episode with solid attribution comparable to those involving ransomware and phishing. What did appear were alerts and mentions in monitoring channels, but nothing that supports a trend of a persistent actor targeting retail or mass consumer businesses in the region.
That relative absence also tells a story. In August, the main noise came from the extortion economy and the opportunistic exploitation of commercial platforms, not from operations with an ideological signature or sustained espionage. For a sector CISO, that means prioritizing resilience, third-party exposure, and response to leaked credentials before more complex hypotheses that the material does not support.
Critical vulnerabilities
The month produced a single critical CVE mentioned in the material reviewed, a flaw in SAP Commerce Cloud with direct impact on e-commerce platforms. Being the only case did not make it any less severe, because the gap between patching and exploitation was very short and the software is part of the sales infrastructure used by major retailers.
| CVE | Software | Exploitation | Source |
|---|---|---|---|
| CVE-2026-58231 | SAP Commerce Cloud, Data Hub Adapter component | Exploitable by an unauthenticated remote attacker, through abuse of default authentication and with potential for arbitrary code execution; active attempts and exploitation were observed in honeypots just days after the patch | SAP, Cloud Security Alliance, Servola / Defused, SecurityWeek, TecMundo |
This vulnerability matters to retail in two ways. First, SAP placed it in COM_CLOUD 2211 and 2211-JDK21 versions, with a CVSS score of 10.0 and a critical rating. Second, third-party analysis agreed that exploitation could compromise affected instances without prior authentication, a particularly sensitive issue in environments that concentrate catalogs, orders, and customer data.
Early exploitation also offers a tactical lesson. When a critical flaw appears in an e-commerce component, the window between disclosure and real pressure can be measured in days, not weeks. That forces faster patching, tighter asset inventory, and compensating controls while the update cycle runs its course.
Regulation and compliance
August brought two documented regulatory moves, but the material does not describe sanctions, rulings, or broad sector-wide regulatory changes. The regulatory signal points more to compliance pressure than to new rules, especially because of the type of data exposed in several incidents.
The Open Sports breach, the exfiltration attributed to APSA Internacional, and the ShipMonk leak affecting customers in Colombia and Brazil all bring notification duties, personal data handling, and vendor traceability back to the center of the discussion. In Trezor's case, the company itself clarified that the incident happened at the logistics third party, but that does not remove the need to review contracts, security SLAs, and international data transfer mechanisms.
In retail and e-commerce, compliance issues do not end at the leak site. When leaked material includes names, emails, phone numbers, shipping addresses, or password fields, the discussion shifts to retention, lawful processing, notification, and customer response. The month showed that this front can be triggered by either a company’s own breach or a fulfillment, analytics, or logistics provider.
Countries and most affected subsegments
August’s geographic spread supports a country-by-country read, with the caveat that several incidents cut across more than one sector or overlapped with international supply chains. The map is not uniform, but it does show clear hotspots in Mexico, Argentina, and Brazil.
Mexico
Mexico had the highest visible density of incidents tied to the vertical. Price Shoes, SEARS, Sanborns, and references to other targets on ransomware portals marked an intense sequence in the second half of the month. That was joined by the BRILLONCONSUMER.COM case on the Mexican ransomware.live map and Expansión’s note on ransom messages printed at companies in Mexico and Colombia.
The mix of consumer retail, major brands, and extortion pressure points to a particularly exposed ecosystem. Criminals are not only interested in customer data, they can also magnify reputational damage through leak sites and combine physical and digital channels. For the subsegment, August leaves a clear signal of elevated risk in commercial retail, footwear, supermarkets, large chains, and mass-market consumer brands.
Argentina
Argentina concentrated several cases at different stages of maturity. Open Sports appeared with a claim attributed to Qilin, APSA Internacional with confirmed exfiltration, Inmac with a mention of Qilin, and an auto dealer listed as a possible Krybit victim. Not every event is comparable, but together they point to a busy month for the country.
The common thread is the visibility of brands tied to retail, e-commerce, or adjacent consumer segments. Open Sports and Inmac fit squarely in the core. APSA Internacional, while not pure retail, falls in through consumer logic and user-data exposure. The auto dealer adds another commercial angle. Taken together, Argentina was well represented in the layer of leaks and criminal claims.
Brazil
Brazil contributed one confirmed-impact case at Shopping Cidade de Belo Horizonte and another type of signal in the Trezor case, because Brazilian customers were affected through ShipMonk. The first event showed encryption and temporary file unavailability in a shopping center. The second involved exposure of buyers’ personal data through an external logistics chain.
That dual record matters because Brazil often combines market scale with very broad digital and physical infrastructure. For malls, brands, and support providers, the lesson is that an incident in one technology environment can affect personal data across multiple stakeholder groups, not just end customers.
Uruguay
Uruguay had a smaller volume signal, but a very concrete threat pattern. The fake SMS campaign impersonating Netflix aimed directly at stealing local consumers’ banking data. Although this is not retail in the strict sense, it does fall within mass consumption and the digital subscription economy.
The read for the country is that low-cost fraud remains effective when it uses everyday brands. For the vertical, that means monitoring brand impersonation, smishing campaigns, and fraudulent redirects to fake sites that can end up affecting payments, reputation, and customer support.
Subsegments of the vertical
The hardest-hit subsegment was footwear and fashion retail, with Price Shoes, Open Sports, SEARS, Sanborns, and the possible case of another auto dealer under the retail and e-commerce umbrella. Shopping centers also appeared, with Shopping Cidade, as did large-scale digital commerce, with the SAP Commerce Cloud vulnerability and the Trezor logistics chain as examples of critical third parties.
That suggests August’s risk was not evenly distributed by business type. Brands with both physical stores and e-commerce were exposed to extortion and leaks. Shopping centers felt the impact on continuity. And digital commerce platforms bore the weight of a critical vulnerability and its early exploitation.
Trends and signals to watch
Compared with July, August showed a sharper mix of operational pressure and extortion rather than a broader spread of noise. Uncategorized incidents rose from 13 to 25, ransomware or extortion cases increased from 13 to 21, and documented fraud or phishing fell from 8 to 5. The result was a tougher month for response and classification than for simple monitoring.
The drop in critical CVEs mentioned, from 4 to 1, does not mean lower technical exposure. The only critical flaw visible in the material was SAP Commerce Cloud CVE-2026-58231, with very rapid exploitation against a high-value e-commerce component. From a defensive standpoint, that suggests a single well-placed vulnerability can put pressure on an entire sector.
Another signal to watch is the persistence of extortion in hybrid formats. In August, claims appeared from groups such as Qilin and Space Bears, leaks were published on leak sites, and more physical tactics such as printed ransom notes also surfaced. Attackers are no longer relying on a single pressure point. They are using whichever one fits the victim’s context best.
Third parties also deserve attention. Trezor showed how a logistics provider can expose regional personal data even when the main brand has not suffered a compromise of its systems. In retail, that means fulfillment, hosting, CRM, analytics, support, and distribution channels need the same level of scrutiny as the company’s own perimeter.
Recommendations for security teams
Security teams in the sector should focus on concrete steps across three fronts, extortion, third parties, and e-commerce platforms. August showed that the issue is not one layer of defense alone, but the combination of valuable data, high public exposure, and very short exploitation windows.
First, urgently review the SAP Commerce Cloud attack surface and any equivalent internet-facing e-commerce component. This includes applying August patches, validating secure versions, and checking whether compensating controls are in place while remediation is completed. If operations depend on SAP or similar middleware, the vulnerability should be treated as a continuity priority, not just a hardening issue.
Second, tighten management of logistics, fulfillment, and analytics vendors. The ShipMonk case made clear that a breach at a third party can expose names, phone numbers, and shipping addresses for thousands of customers. Organizations should require segmentation, least privilege, contractual auditing, encryption of sensitive data, and early notification procedures that do not rely only on the vendor.
Third, review credentials and historical exposure. Open Sports showed how much domain information can circulate outside the company before any public confirmation. When credentials tied to the domain appear in external databases, the risk of password reuse and unauthorized access increases. Identity hygiene, MFA, and leaked-credential detection need to be continuous.
Fourth, prepare incident response plans specifically for leak-site extortion. Not every August victim faced the same type of impact, and that ambiguity should translate into playbooks with separate criteria for encryption, exfiltration, and simple mention. If an incident is still in the claim phase, the team should know what to review, whom to notify, and how to preserve evidence without amplifying reputational damage.
Fifth, strengthen phishing and smishing prevention for consumers and employees. The Netflix campaign in Uruguay is a clear example of how consumer brands are used to capture banking data. Teams that operate retail brands should monitor lookalike domains, fraudulent SMS messages, deceptive templates, and customer support, because these campaigns often lead to spikes in inquiries and real fraud.
FAQ
What changed between July and August in the risk for Latin American retail?
August saw more unclassified incidents and more ransomware or extortion cases than July, while fraud or phishing cases and the critical CVEs mentioned declined. In practice, the month was tougher on operational response and event classification than on simply monitoring isolated campaigns.
Which August case carried the most sensitive technical signal for e-commerce?
The most sensitive case was CVE-2026-58231 in SAP Commerce Cloud, because it affected a component used by major online retailers and allowed unauthenticated remote exploitation. What mattered for the sector was not only the CVE itself, but also that active attempts were seen a few days after the patch, according to technical and security sources.
Which countries concentrated the most retail and mass-consumption signals?
Mexico concentrated the highest visible density of incidents, with Price Shoes, SEARS, Sanborns, and other mentions in ransomware portals. Argentina also had several appearances, with Open Sports, APSA Internacional, Inmac, and a possible additional case, while Brazil added a ransomware attack on Shopping Cidade and Uruguay a phishing campaign.
How does a leak site claim differ from a confirmed breach?
A leak site claim means a group says it compromised a victim or will publish data, but it does not always prove real encryption or exfiltration. A confirmed breach, by contrast, is backed by evidence from the organization or by sources that verify the impact. August had many gray-area cases, so they should be read cautiously.
What should teams running physical stores and e-commerce look at first?
They should look at three things at once, third-party exposure, credential hygiene, and patches for commercial platforms. The Open Sports, ShipMonk, and SAP Commerce Cloud cases show that retail can be hit through its own perimeter, a supplier, or an e-commerce component with rapid exploitation.
Were there signs of APT or hacktivism during the month?
The material analyzed did not show a classic APT campaign or a hacktivist episode with the same visibility as ransomware, leaks, or phishing. The month was driven mainly by the criminal economy of extortion and the opportunistic exploitation of commercial infrastructure.
Material limitations
This report was built exclusively from the material provided for August 2026 and from the time window stated in the indicators, which covers 71 events dated in August 2026. No internet was used, and no facts outside that set were added. When a source did not specify whether there was encryption, exfiltration, or only a mention on a leak site, that ambiguity was preserved in the text.
A zero indicator does not mean the region did not experience that phenomenon. In particular, if a critical CVE had not appeared in the material analyzed, that would only indicate a lack of record in this corpus, not the actual absence of critical vulnerabilities exploited in Latin America. A critical CVE was mentioned this month, but the clarification remains valid for the methodological reading.
Consumer social networks and LinkedIn posts were also excluded as evidence, along with any material that was not on the list of enabled sources. Aggregated telemetry figures were not used because they were not provided. As a result, the report describes verified incidents, claims, breaches, and campaigns, not blocks, attempts, or background scans.
Sources
- Ransomware Group qilin Hits: InmacHookphish
- Grupo Open Sports Data Breach in 2026Breachsense
- Victim: Tecno Accionransomware.live
- Cyber Alert on Qilin claim against Open SportsHackmanac (X)
- Open Sports — QILIN Ransomware AttackBreach House
- Qilin Targets Open Sports in Ransomware AttackDexpose
- Victim: automotoresrosedal.com.ar – krybitransomware.live
- APSA Internacional data breach (apsanet.com.ar)Breachsense
- apsanet.com.ar Listed by Krybit Ransomware GroupGalaxy Warden
- apsanet.com.ar Ransomware Claim (2026) — What’s Alleged & Am I Affected?Recentbreaches
- www.apsanet.com.ar data breach — Krybit ransomware leak (2026)Darkfield
- Ransomware Group krybit Hits: www.apsanet.com.arHookphish
- Brecha de segurança crítica em sistema de vendas online da SAP vira alvo de ataquesTecMundo
- SAP Commerce Cloud CVE-2026-58231: Guidance for DefendersCloud Security Alliance
- SAP Commerce Cloud: falha de gravidade máxima explorada em três diasServola / Defused
- SAP Security Notes: August 2026 Patch Day - OnapsisOnapsis
- SAP Security Patch Day - August 2026SAP
- SAP August 2026 Security Notes: 4 Critical, 8 High and 17 MediumSAPSecurityExpert
- SAP Patches Critical Code Injection, Memory Corruption VulnerabilitiesSecurityWeek
- Shopping de BH sofre ataque virtual e tem dados pessoais ...Diário do Comércio
- Data Breach Roundup (August 7 - 13, 2026)PrivacyGuides
- Cyber Alert – Trezor third‑party data breach at ShipMonkHackmanac (X)
- Trezor Data Breach: 13689 Customers Exposed via ShipMonkPasquale Pillitteri
- Supply Chain Attack: The Trezor Leak ExplainedBit.com Knowledge Hub
- Trezor discloses data breach affecting 13,689 customersCrypto Briefing
- Trezor, SafePal Breaches Expose 53487 Wallet OwnersShattered.io
- Trezor Data Breach Exposes 13689 Customers via ShipMonkOurCryptoTalk
- CoinDesk on Trezor-ShipMonk breach alertCoinDesk (X)
- Trezor discloses data breach affecting about 14,000 customersInvesting.com
- Trezor shipping provider breach exposes personal data of nearly 14,000 customersThe Block
- IQSEC revela ciberataques y filtraciones masivas en MéxicoIndice Corporativo / IQSEC
- Mexico is suddenly all over the ransomware leak sitesIntelFusions
- Radar CTI | Vulnerabilidades críticas y ciberataques del 11-17 agosto 2026Smartekh
- Nuevo 'modus operandi' del cibercrimen en MéxicoExpansión
- Nuevo 'modus operandi' del cibercrimen en MéxicoExpansión
- SEARS, posible víctima de hackersX (Ignacio Gómez Villaseñor)
- Victim: SEARS (Grupo Sanborns)ransomware.live
- Victims map for Mexicoransomware.live
- SpaceBears Ransomware Attack on SEARS MexicoDeXpose
- SEARS (Grupo Sanborns) Listed by Space BearsGalaxyWarden
- Space Bears adds Sears Mexico and Sanborns to leak siteFalconFeeds.io
- Price Shoes Data Breach in 2026Breachsense
- Qilin ransomware claims Price Shoes in MexicoCybersecurity News Everyday (X)
- Victim: Price Shoesransomware.live
- Ransomware Group Qilin Hits: Price ShoesHookPhish
- Pintando Commercial Portal (Mexico) sector Commercial/RetailVECERTRadar (X)
- Alertan en Uruguay por mensajes falsos de Netflix para robar datos bancariosEl Telégrafo
- Trezor Confirms ShipMonk Data Breach Exposed Nearly 14,000 CustomersBreach.news
- Trezor alerta sobre una filtración de datos de clientes a través del proveedor ShipMonkSecurityLab
- 14,000 Trezor Customers Impacted by Data Breach at ShipMonkSecurityWeek
- 2026 Trezor — ShipMonk fulfillment breach; 13,689 customers (addresses/phones; Metabase path)BreachHistory
- Trezor: ShipMonk breach exposed data of 13689 buyersCryptodaily
