CiberLATAMbywhalemate
Intelligence report

Retail, E-Commerce and Mass Consumer, Sep 2026

Fraud, ransomware, and a critical CVE shaped September in LATAM retail and e-commerce, with focus on Brazil, Argentina

Oct 1, 202630 min read
Retail, E-Commerce and Mass Consumer, Sep 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are populated automatically with the verified, dated facts within the period. Each one states its basis and counting criterion so the figures reconcile across modules. They are the recurring month-to-month reading, and the analysis that follows develops the cases without repeating this summary.

Indicator window: 54 dated facts in September 2026. Facts from prior months are used only as a comparative frame in the analysis, never as part of this period’s volume.

CIBERLATAM / WHALEMATE Monthly verified signal dashboard September 2026 · Latin America Leading threat: Unclassified (24 of 53 facts). Coverage: 54 facts dated in September 2026 VERIFIED FACTS 53 period baseline: total count measured from the bottom against this total RANSOMWARE / EXTORTION 6 2 exfiltration without encryption (simple extortion) · 1 only leak site mention · 3 UNCLASSIFIED INCIDENTS 11 breaches or outages without declared threat type FRAUD / PHISHING 3 documented fraud campaigns documented REGULATION 1 rules, resolutions, or penalties UNIQUE CVEs 1 CVE-2026-75650
Monthly verified signal dashboard — Base: 53 verified facts dated within the period for Latin America.
MONTHLY FIXED MODULE Threat-axis distribution September 2026 · Latin America Each event counts in only one axis, so the total is exactly 53. "Unclassified incidents" is the remainder. Unclassified 24 Incidents 11 Vulnerabilities 8 Ransomware 6 Fraud 3 Regulation 1
Threat-axis distribution — Each event is assigned to a single axis based on its classification; the total reconciles to the 53 events in the period.
FIXED MONTHLY MODULE Sector distribution of activity September 2026 · Latin America Base: 53 incidents in the period · total 76 because 19 incidents are classified in more than one sector. Public sector / OIV 18 Other / unidentified sector… 16 Retail / consumer 12 Finance 11 Technology 10 Telecom 7 Healthcare 1 Energy 1
Sector distribution of activity — Heuristic sector classification of the victim. One incident may affect more than one sector, so the total may exceed the base.
MONTHLY FIXED MODULE Geographic Distribution of Signals September 2026 · Latin America Each event is assigned to a single country or regional coverage, so the total is exactly 53 of 53 events… Regional 19 Argentina 8 Brazil 8 Chile 6 Mexico 6 USA 6
Geographic Distribution of Signals — Verified period events grouped by country or regional coverage; each event is counted once.

Executive summary

By the end of September 2026, retail, e-commerce, and mass consumer goods in Latin America were shaped by three distinct risk layers that need to be separated carefully: critical vulnerabilities in digital commerce platforms, payment fraud embedded in checkout pages, and a series of extortion and ransomware claims against sector brands that, in several cases, never received independent public confirmation. That distinction matters because it changes the operational response for security teams, patch prioritization, and, above all, legal and business continuity planning. The period included an unusual mix: on one side, a high-impact flaw in Adobe Commerce and Magento with active exploitation and an official recommendation to patch immediately; on another, campaigns that altered QR and copy-and-paste Pix codes on Brazilian stores; and also posts on leak sites or ransomware aggregators naming Argentine and Chilean retailers, although without enough independent verification to treat them as confirmed intrusions.

The key takeaway for CISOs in the sector is that the attack surface is no longer limited to the transaction core or the datacenter perimeter. A store checkout page, the plugin layer, the template engine, and even QR payment logic became high-value manipulation points. At the same time, incidents reported by companies such as Forus show that the impact can appear as partial disruption of digital channels without necessarily affecting physical stores, which means resilience has to be maintained by channel, not just by organization. The month also left an uncomfortable reminder: when a group claims to have published data on a leak site or an aggregator lists a victim, that does not automatically mean confirmed exfiltration or encryption. This report keeps that distinction strict.

Panorama

The month’s snapshot shows a Latin American retail ecosystem under pressure on three fronts at once. First, the technical front: CVE-2026-75650 affected Adobe Commerce and Magento Open Source, with active exploitation acknowledged by the vendor itself and alerts from cybersecurity agencies that urged organizations to identify vulnerable versions and apply fixes without delay. Second, the transaction fraud front: Kaspersky and alerts from Procon-SP reported a campaign that replaced Pix payment codes on Brazilian e-commerce sites and redirected money to accounts controlled by criminals. Third, the reputational and extortion front: different monitoring platforms recorded allegations against Diarco, Librería Santa Fe and Forus, but in several of those cases the available material did not publicly confirm either encryption or exfiltration.

What matters for reading the month is that these three fronts should not be treated as isolated events. A vulnerability exploited in Magento can be both an intrusion vector and an enabler of web fraud. A checkout tampered with on a store may have no encrypted systems at all, yet still suffer immediate financial loss. A leak site can list a brand without proving that a successful breach occurred. Retail also has a structural weakness, it relies on multiple third parties, gateways, integrators, agencies, hosting providers, analytics tools, marketing suites and, in some cases, custom development, which makes supply-chain risk structural rather than exceptional.

Geographically, Brazil accounted for the clearest and most actionable part of the month for two reasons. The first is technical: that is where the Pix campaign was observed, with the payment element altered on small and mid-sized e-commerce sites. The second is operational: Google Threat Intelligence Group and Mandiant described BREEZE COMET activity against Brazilian financial services, retail and e-commerce organizations, with a focus on payment-system manipulation and banking software. Chile contributed a corporate case with operational impact reported by Forus, while Argentina appeared mainly in the form of ransomware allegations against Diarco and Librería Santa Fe. Mexico stood out for an investigation into the alleged sale of databases tied to call centers, which included commercial references to retail and consumer ecosystem companies, but no conclusive attribution to a specific victim.

Indicators

Reading the indicators

The indicators above summarize the material reviewed and should not be read as a measurement of the entire region or as a total of homogeneous events. The critical CVE count is a reference to the material reviewed in this report and does not mean there are no other vulnerabilities being actively exploited in the market. In the case of ransomware or extortion, the five events include both operational confirmations and allegations on leak sites and third-party records; for that reason, the body taxonomy strictly separates what was confirmed from what was merely claimed.

Incidents

Adobe Commerce and Magento, active exploitation of CVE-2026-75650 and cross-platform risk

The most significant technical event of the month was CVE-2026-75650 in Adobe Commerce and Magento Open Source. Adobe said the flaw allowed unauthenticated remote arbitrary code execution and was being actively exploited. The official CVE record describes it as an incorrect neutralization of special elements in a template engine, exploitable without user interaction and capable of executing arbitrary code in the context of the current user. In parallel, the Australian Cyber Security Centre classified it as an unauthenticated remote code execution vulnerability and warned about active exploitation. CTIR Gov, in both alert 85/2026 and 90/2026, recommended identifying vulnerable versions and applying the developer’s fixes immediately, and specified the scope of affected branches in Adobe Commerce and Magento, including 2.4.9, 2.4.8, 2.4.7, 2.4.6, 2.4.5 and 2.4.4 with August 2026 updates.

Operationally, the significance of this flaw is not limited to site outages or visual page defacement. In e-commerce environments, an unauthenticated RCE can open the door to skimmer injection, credential theft, checkout persistence, payment method manipulation or pivoting into other connected systems. That is why the potential impact on confidentiality, integrity and availability, as noted by CTIR Gov, should be understood broadly. For midmarket retailers, the main risk is not just that an attacker gets in, but that they remain long enough to turn the sales platform into fraud infrastructure. That connects directly to the Pix campaign observed in Brazil: the same class of weakness, or of delayed patching, that enables intrusion can be used to manipulate the critical moment when the customer pays.

The timeline also matters. Adobe acknowledged active exploitation on September 7. SecurityWeek reported the same day that the company had fixed more than 170 vulnerabilities and that CVE-2026-75650 carried a CVSS score of 10/10. The Australian Cyber Security Centre issued its alert on September 9, and CTIR Gov published advisories at the end of the month. That cadence shows the risk moving first through the international technical layer and later through response agencies that helped set patching priorities. For a retail CISO, the practical reading is that exposure time is measured in hours or days, not quarterly platform change cycles. Stores running Magento as part of the front end or as a catalog layer, even if the payment engine is outsourced, should treat this kind of CVE as a potential business incident, not just an infrastructure issue.

A second nuance is that the material reviewed does not technically link this vulnerability to the Pix replacement campaign. In other words, both happened in the same month and both affect e-commerce, but the source material does not support a direct causal claim. The overlap does point to a broader trend, though: checkout has become one of the most profitable points for attackers, whether through direct platform exploitation, code injection, payment method tampering or abuse of third-party components. Defense therefore has to include hardening, DOM monitoring, script integrity validation, payment gateway change analysis and strict administrative privilege segregation.

Brazil, campaign that altered Pix QR and copy-and-paste code in online stores

The second major theme of the month was the fraud campaign that altered the QR Code and Pix copy-and-paste code on checkout pages for Brazilian online stores. Procon-SP warned consumers about the tactic and recommended checking the recipient’s name and CNPJ in the banking app, not just the amount, and requesting transaction challenge and reimbursement through the Special Refund Mechanism if the recipient did not match the purchase. According to the available coverage, Kaspersky identified the campaign as affecting 90 small and mid-sized online stores and redirecting payments to accounts controlled by criminals. The coverage also said the affected sites used Magento. Olhar Digital added that the firm recommended updating Magento, using unique and complex administrative credentials and monitoring sites continuously.

From an operational standpoint, this case deserves more attention than a conventional phishing incident because the fraud is embedded in the legitimate transaction experience. The customer believes they are paying the right store, the merchant may not detect the modification immediately, and the bank processes a transfer to a recipient the consumer did not choose. It is a broken chain of trust inside the commercial flow itself. By intervening at checkout, the attacker captures a moment when the user is highly motivated to complete payment and less likely to hesitate. Procon-SP’s recommendation to verify the name and CNPJ in the banking app is important because it shifts part of the detection to the consumer side, but it should not be read as a substitute for merchant controls. Protection of checkout cannot be delegated to the customer.

The information attributed to Kaspersky and repeated by several outlets points to a scale pattern that combines technical precision with operational breadth. On one side, the universe of 90 small and mid-sized stores suggests an actor interested in volume and automation, not necessarily a single high-value target. On the other, the use of Magento as a common platform points to a shared technology dependency that makes replication easier. That is typical of campaigns where code is inserted into the payment page to alter the QR destination or the copy-and-paste data without necessarily showing a classic database intrusion. For security teams, that means detections must look at front-end integrity, not just transaction logs or ERP health.

There is also a legal and business continuity implication. A retailer affected by this kind of alteration may face consumer claims, chargebacks, disputes with payment gateways and a erosion of trust that is hard to measure. Unlike ransomware, where the problem usually shows up as downtime or exfiltration, here the damage can be silent and cumulative. Even a short-lived campaign can generate disproportionate losses if it goes unnoticed. That is why defense should include script integrity analysis, checkout change audits, validation of third parties that inject code and real-time alerts on payment method modifications. It is also worth running periodic end-to-end payment tests from multiple geographic points and with different devices, because some skimmers activate only under certain conditions.

Chile, Forus and the cybersecurity incident with partial system impact

Forus informed Chile’s Financial Market Commission that it had become aware of a cybersecurity incident caused by an external actor and that some of its IT systems were affected. Days later, Diario Financiero reported that the company said it had activated prevention, detection and response protocols with support from cybersecurity experts and digital forensic analysis. It said the incident was contained, its physical stores were operating normally and the other sales channels were still recovering intermittently. The company also said there was no evidence that personal data from customers, employees or others had been affected, and that it still did not have enough information to project financial effects on assets, liabilities or results.

The case is useful for separating operational impact from reputational impact. In public narrative, an incident that "affects some systems" can sound vague, but for an omnichannel retailer it can mean interruptions in digital sales, inventory issues, reconciliation delays, degraded integrations or a temporary inability to process certain logistics flows. The fact that physical stores kept operating normally suggests partial containment and possibly appropriate compartmentalization between channels. Still, the intermittent recovery of other channels shows that even without evidence of personal data exfiltration, the business can face meaningful friction. For the CISO, the lesson is that continuity should be designed around functional capability, not just network architecture.

The material also included third-party allegations trying to place the case inside a ransomware frame. DarkField reported that forus.cl had allegedly been included on a leak site associated with LockBit5. Ransomware.live recorded forus.cl as a victim attributed to LockBit5, and Kalir Brief reported that the LockBit leak site listed Forus as a victim. None of those sources, by themselves, prove the attribution or the existence of an effective leak. That is why this report keeps the correct classification: a ransomware/extortion allegation without independent public confirmation of encryption or exfiltration. That caution is not a minor editorial detail. It is the difference between a verifiable fact and an opportunistic narrative that may not hold up to forensic review.

For the retail sector, the Forus case also shows the tension between corporate statements and outside expectations. When a company says the incident is contained and there is no evidence of compromise of personal data, the market often asks for more detail, but the company may need time to complete forensic analysis. In that interval, the right approach is honest, limited and evolving communication, with messages that distinguish what is known, what is unconfirmed and what remains under investigation. In regulated environments, that discipline can be decisive in avoiding overstatements or misunderstandings that complicate the response.

Argentina, Diarco and Librería Santa Fe in leak lists without public confirmation

The Argentine case moved mainly in the realm of allegations. IntelFusions reported that INC Ransom included Diarco on a leak site during the week ending September 20, 2026. Ransomware.live recorded a claim against diarco.com.ar attributed to INC Ransom, with discovery on September 17 and an estimated attack date the same day. Galaxy Warden documented that INC Ransom included diarco.com.ar on its leak site, explicitly noting that Diarco had not publicly confirmed the claim and that there was no independent verification of intrusion or exfiltration. In parallel, Breach House recorded a ransomware claim against Librería Santa Fe on September 15, Galaxy Warden said The Gentlemen published santafelibros.com.ar on September 14, and HackerFeeds also recorded it as a target the same day. Ransomware.live also recorded a separate claim against LIBRERIA SANTA FE A P SRL attributed to Vexy Ransomware, with an estimated attack date of September 7 and a stated volume of 24.2 GB.

The accurate reading here is twofold. First, multiple third-party references placed Argentine retail and e-commerce brands on the radar of extortionists or leak sites. Second, none of those references on their own amount to a public confirmation that the company suffered an attack with proven impact. In taxonomic terms, this belongs in the category of leak-site claim or allegation, not a confirmed encryption or exfiltration incident. For risk management, however, a leak-site posting should not be ignored. It can trigger information requests, customer concern and commercial pressure, especially if the brand operates with high online sales volume or sensitive logistics chains.

The heterogeneity among the allegations is also worth noting. In the Diarco case, the overlap between several sources and the absence of public independent confirmation do not allow the matter to be elevated to a verified incident. For Librería Santa Fe, the multiple references to The Gentlemen and Vexy suggest extortion or reporting activity on more than one platform, but the material still does not show the real scope or whether assets were encrypted. For an intelligence team, that difference matters because it affects the threat hypothesis. A group posting across several sources may be maximizing reputational pressure, or simply duplicating records for the same claim. Without forensic evidence, it is best not to infer more than the material supports.

Mexico, investigation into databases linked to call centers and commercial references in retail

Mexico contributed a different case, centered on the alleged sale of databases on Telegram linked to call centers. The Ministry of Anti-Corruption and Good Governance said it detected a post found on September 22 that was allegedly offering more than 12.9 million records with personal data. The authority obtained a sample of 13,000 records from 13 databases and opened an investigation to determine the origin and any possible responsibility. N+ said the ministry obtained that sample and launched ex officio investigations. El País said the offer was associated with at least 13 databases. Xataka México noted that among the commercial references identified were Amazon, BBVA and Santander, stressing that the investigation was still focused on determining where the data came from. El Financiero, in turn, mentioned commercial references to companies with retail, e-commerce and mass-consumption operations, including Amazon, Liverpool, Sam’s Club, Sears, Suburbia, Banco Walmart, Sanborns, C&A and Soriana, while clarifying that the investigation had not established that those companies were victims of an attack or that the data came from their systems.

This episode matters because it shows a different type of exposure from ransomware and also different from skimming. Here there is no confirmation of intrusion into a specific retail organization, but rather an investigation into a set of records whose origin remains disputed. The risk for retail and mass consumption is that, even if the referenced brands are not necessarily the source of the leak, their names can appear in third-party databases, call centers, marketing campaigns, outsourced CRMs or commercial integrations. That complicates attribution and calls for analytical caution. A commercial reference in a sample does not automatically equal a compromised victim.

The coverage also shows that the investigation was not limited to the private sector. The Mexican authority opened proceedings to clarify who would be responsible for the exposure and possible sale, suggesting a regulatory dimension that may affect service providers, data processors and contact operators. For CISOs in the sector, the operational lesson is that third-party data governance should include contractual traceability, database inventories, data minimization and controls on mass exports. If a company’s commercial ecosystem depends on call centers, lead brokers or integrators with access to customer information, exposure will not always come from the store core, but from less monitored peripheral flows.

Brazil, BREEZE COMET and the pressure on payments, banking and e-commerce systems

At the actor level, September also kept attention on BREEZE COMET, formerly identified as UNC5669. Google Threat Intelligence Group and Mandiant described the actor as one that has targeted financial, retail and e-commerce organizations in Brazil since 2024 to manipulate payment systems and carry out fraudulent transfers. The official analysis also says the actor targets organizations authorized to operate through banking software, APIs and Pix, STR and Boleto systems, a category that includes payment processors, exchanges and financial software providers in addition to banks, retailers and e-commerce companies. Google also said BREEZE COMET uses four custom backdoors to keep access in compromised environments, even after defenders remove one entry point. Expert Insights, commenting on Mandiant’s research, said the group may have executed at least one fraudulent transfer worth tens of thousands of dollars.

The significance of this material for retail and e-commerce is strategic. BREEZE COMET does not appear to be looking only for a one-off intrusion, but for functional control of payment and authorization routes. That makes it especially dangerous for retailers that depend on integrations with banks, gateways, reconciliation APIs and financial software. In other words, the layer of the business that "talks" to the money becomes the primary target. That orientation is consistent with the Pix campaign observed by other reports in the same country, although the material does not say it is the same set of operators. What it does show is a criminal ecosystem focused on diverting payments, maintaining access and exploiting the complexity of Brazil’s digital commerce infrastructure.

From a defensive standpoint, Mandiant’s recommendations on deep packet inspection and TLS decryption are particularly relevant in a context where attackers can abuse compromised municipal websites to host payloads or hide their communications. The warning not to rely solely on domain reputation or government-domain allowlists has practical value across industries that use rigid allowlists. In e-commerce environments, an overly trusting policy toward "reputable" origins can let malicious payloads through if they are hosted on hijacked legitimate infrastructure. The lesson is clear: control should focus on behavior, integrity and communication authenticity, not just the domain name.

AI campaign and web skimming, 105 projects, 27 compromised companies and a card focus

In mid-September, Gambit Security reported that between September 10 and September 15, 105 attack projects were launched and that at least 27 companies were compromised to varying degrees in a campaign against online retailers. The investigation said the activity was ongoing and had begun in July 2026. The same source said more than 600,000 credit card records that were not expired had been stolen from two companies and that skimming scripts had been installed on websites belonging to five e-commerce businesses. According to the report, 488,372 cards were from the United States. Later coverage attributed the use of tools such as Strix, Cairn and Hermes to AI agents and said the activity was continuing, though those pieces are more interpretive than primary.

This case should be read with methodological caution. The material confirms the existence of a campaign against online retailers and the compromise of at least 27 companies to varying degrees, but the exact attribution of the card figures and the full interpretation of how they were obtained remains disputed in secondary coverage. For this report, the value is not in consolidating an additional total, but in recognizing the evolution of web skimming toward more automated operations, potentially AI-assisted, that aim to scale target selection and malware persistence. The fact that the campaign started in July and was still active in September also shows that this was not an instant burst, but a prolonged operation with the ability to adapt.

For Latin American retail, the implication is that skimming attacks should no longer be thought of as rudimentary scripts inserted into small sites. Modern campaigns can combine automation, multiple projects, infrastructure reuse and flexible code deployment depending on the technology detected. If a security team depends on manual reviews or static alerts, it may be late. Checkout integrity validation, third-party controls, continuous template-change review, payment-event monitoring and anomaly analysis in form output are all needed. The fact that the campaign affected online sites and not necessarily major brands also suggests that attackers gladly exploit the least mature link in the chain, not only the most visible targets.

Countries

Brazil

Brazil was, by far, the country with the highest density of verifiable retail and e-commerce incidents this month. Four threads overlapped there: a critical vulnerability exploited in Adobe Commerce and Magento, a Pix tampering campaign on checkout pages, BREEZE COMET activity against financial institutions, retailers and e-commerce companies, and secondary references to skimming campaigns and the use of AI tools. The mix was no accident. Brazil has high Pix adoption, strong e-commerce penetration and a payments ecosystem that is highly attractive to criminals seeking quick monetization.

The country-level lesson is that payment fraud does not happen at one layer. It can start with the exploitation of a platform vulnerability, continue with the injection of a script that alters a QR code, and end with funds diverted to a mule account. That chain forces defenders to harden multiple points at once: accelerated patching, front-end integrity controls, payment gateway monitoring, destination-account validation and administrative access reviews. In maturity terms, a Brazilian retailer cannot stop at server protection, it has to protect the transaction.

Chile

In Chile, the Forus case showed a cybersecurity incident with partial impact on IT systems and uneven recovery across channels. The company said its physical stores were operating normally and that no personal data had been affected, which points to relatively effective containment. Even so, the simple interruption of some systems is enough to create friction in sales, logistics and customer service, especially in omnichannel models where the checkout, inventory and digital platform are connected.

The takeaway for the country is that resilience has to be tested under partial degradation scenarios, not only total outages. Chilean retailers, especially those operating multiple channels, should rehearse how they keep selling, shipping and reconciling if the digital front end or certain integrations go down. The case also shows that early attribution on leak sites can be misleading, a mention of Forus in LockBit5 is not the same as a confirmed leak.

Argentina

Argentina surfaced mainly through ransomware allegations against Diarco and Librería Santa Fe. In both cases, the available material included leak site posts, aggregator records and third-party reporting, but it did not publicly confirm the intrusion or data exfiltration. That does not reduce the risk relevance, but it does keep the matter from being elevated to a confirmed incident. For CISOs, that distinction matters. A leak site post may require investigation and response planning, but it should not be treated as a technically verified event.

The concentration of these claims in retailers and bookstores also suggests attackers still see value in sectors with direct consumer relationships and reputational leverage. Even when there is no evidence of encryption, the mere exposure of a brand in extortion forums can affect trust, third-party negotiations and market perception. In Argentina, the operational priority is therefore to strengthen leak-site monitoring, communications plans and internal forensic capability to separate noise from real incidents.

Mexico

Mexico did not record a confirmed retail victim during the period, but it did see a large-scale investigation into the alleged sale of databases linked to call centers on Telegram. Commercial references to retail, e-commerce and mass consumer companies made the case materially relevant for the sector, although the authority had not established that those companies were victims or that the data came from their systems. That caution matters because it avoids over-attribution and keeps the focus on data traceability.

The implication for retailers and consumer brands is that data exposure does not always originate in the store core. Call centers, collections campaigns, loyalty programs, marketing agencies and customer service providers can accumulate enough information to produce a large-scale leak. Mexico underscores the importance of governing the extended sales and service ecosystem. If an organization does not know what data is circulating outside its perimeter, it will have a hard time responding when it appears in an informal offer or an official investigation.

The month’s first trend is the rise of checkout as a priority attack surface. It is no longer enough to think only about endpoint malware or server ransomware. A critical vulnerability in Adobe Commerce/Magento, paired with a Pix tampering campaign in online stores, shows that attackers see payment as the most profitable moment. That means reviewing not just infrastructure, but also the integrity of the shopping experience. In practical terms, the customer’s browser has become a security environment that deserves as much attention as the backend.

The second trend is fragmented impact. In the same month, there were confirmed active exploitation, corporate incidents with partial impact, leak site allegations without confirmation, and an investigation into data supposedly offered for sale. That is challenging for defenders because the signals arrive mixed together. A CISO who treats all of those sources as equivalent risks overwhelming the team with noise or, worse, underestimating a real threat by confusing it with an unverified claim. Taxonomic discipline is therefore a security capability, not just an editorial one.

The third trend is the regionalization of fraud methods. In Brazil, Pix and Magento create fertile ground for payment manipulation; in Chile, omnichannel continuity shapes the impact; in Mexico, the problem shifts toward control of data spread across third parties; in Argentina, the reputational risk from leak sites keeps pressure on consumer brands. The regional map is not uniform, but it does share one constant, retail exposure depends increasingly on third parties, integrations, and data flows outside the main store.

The fourth trend is the persistence of actors focused on fast monetization in payment infrastructure. BREEZE COMET illustrates a threat class that targets banking, APIs, and financial software to carry out fraudulent transfers; the web skimming campaign and Pix tampering show money being diverted in transit; and the ransomware allegations work as a complementary pressure mechanism. That suggests the criminal business model is adapting to extract value at multiple points in the commercial chain. Defenders should assume the adversary does not necessarily want to destroy, many times, it wants to get paid without being seen.

Recommendations for CISOs

  1. Prioritize accelerated patching of Adobe Commerce and Magento Open Source, especially the affected branches cited by CTIR Gov and Adobe. On critical platforms, patching should be followed by post-fix validation and a review of integrations, not just the application of the fix.

  2. Implement checkout integrity controls. That includes monitoring third-party scripts, comparing hashes or resource references, alerting on changes in QR elements or copy-and-paste components, and running automated tests that validate the payment flow across multiple browsers and devices.

  3. Review administrative privileges and unique credentials for e-commerce environments. The material on the Pix campaign and the recommendations attributed to Kaspersky point to the use of complex, unique credentials as a basic control, yet one that is still missing in many mid-sized operations.

  4. Segment operations by channel. The Forus case shows that physical stores can keep operating while other channels are degraded. That requires resilient architecture, inventory contingency plans, and continuity procedures specific to each channel.

  5. Prepare monitoring of leak sites and third-party sources with verification criteria. Not every mention amounts to an incident. The security team should have a playbook to classify allegations, request evidence, and decide when to activate a formal response.

  6. Increase scrutiny of third parties that handle customer data. Call centers, agencies, integrators, and support providers can become sources of exposure even when the main brand has not been directly compromised.

  7. Review protection for local payments. In Brazil, verifying the name and CNPJ in the banking app is a useful customer control, but merchants need additional layers of defense to prevent payment instrument tampering at the source.

  8. Avoid relying only on domain reputation. The investigation into BREEZE COMET and the observation of payloads hosted on compromised sites show that rigid allowlists can be insufficient against legitimate infrastructure that has been hijacked.

  9. Strengthen forensic and communications capabilities. When an incident is contained but not closed, the company needs to speak precisely, what is known, what is not known, and what remains under analysis.

  10. Drill silent fraud scenarios. Not every incident produces a black screen; some simply divert money or alter the transaction. That type of exercise should be built into executive simulations.

Material limitations

The material reviewed provides solid visibility into critical vulnerabilities, official alerts, and several extortion or ransomware claims, but coverage is uneven by country and by incident type. In several items, the information comes from aggregators or secondary notes that repeat what third parties said, so attribution should be treated with caution. The absence of facts in the material does not mean there were no incidents in the region, only that they did not appear in the database reviewed for this report.

It is also worth remembering that events from prior months serve only as comparison context and are not part of the period’s volume. Telemetry figures or vendor campaign data should not be confused with confirmed business incidents. In this edition, for example, alerts about BREEZE COMET activity or the skimming campaign describe real threat context, but they should not be mechanically added to confirmed corporate cases or leak-site claims.

Frequently Asked Questions

What type of risk dominated the month for retail and e-commerce?

A mix of critical vulnerabilities in commerce platforms, checkout fraud, and unconfirmed ransomware claims dominated the month. The main defense issue was not just intrusion, but payment-stage manipulation and data exposure across third-party ecosystems.

Were there confirmed ransomware incidents against retail brands?

There were several claims and third-party listings involving brands in Argentina and Chile, but in the cases reviewed there was not always public, independent confirmation of encryption or exfiltration. The report therefore carefully separates what was confirmed from what was only claimed.

What was the most urgent technical alert?

The CVE-2026-75650 vulnerability in Adobe Commerce and Magento Open Source, because the vendor itself reported active exploitation and official agencies recommended immediate remediation. For retailers using Magento, that means patching and integrity validation are top priorities.

What should a sector CISO review first?

First, the integrity of checkout and the exposure of their Magento/Adobe Commerce platforms. Next, the controls of third parties that handle data or payments, channel continuity, and the ability to distinguish a claim from a confirmed intrusion.

Does the lack of CVEs in the indicator mean there were no critical vulnerabilities?

No. It means that, in the material analyzed for this report, no additional CVE list was consolidated beyond the highlighted case. That does not mean there were no other critical vulnerabilities exploited in the region during the month.

Sources