CiberLATAMbywhalemate
Intelligence reportAug 11, 202624 min read

Health, Clinics, Hospitals, Pharma, Jul 2026

Ransomware, disputed leaks, and sanctions shaped July in LATAM health, with Brazil and Sinaloa at the center.

Health, Clinics, Hospitals, Pharma, Jul 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are completed automatically with verified dated facts within the period. Each one states its basis and counting criterion, so the figures reconcile across modules. They are the recurring monthly reading; the later analysis develops the cases without repeating this summary.

Indicator window: 51 dated facts in July 2026 · 16 without confirmed date (excluded from the indicators). Facts from previous months are used only as comparative context in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Monthly verified signal dashboard July 2026 · Latin America Dominant threat: Ransomware (15 of 48 events). Coverage: 51 dated events in July 2026 · 16 undated confi… VERIFIED EVENTS 48 period baseline: all counts measured from below on this total RANSOMWARE / EXTORTION 15 2 encrypted assets confirmed · 1 exfiltration unencrypted (simple extortion) UNCLASSIFIED INCIDENTS 10 breaches or outages without declared threat type FRAUD / PHISHING 0 documented fraud campaigns REGULATION 2 standards, resolutions, or sanctions UNIQUE CVEs 9 CVE-2026-15409 / CVE-2026-15410
Monthly verified signal dashboard — Base: 48 verified dated events in Latin America.
MONTHLY FIXED MODULE Threat axis distribution July 2026 · Latin America Each event is counted in only one axis, so the total is exactly 48. "Unclassified incidents" is the remainder. Ransomware 15 Unclassified 11 Vulnerabilities 10 Incidents 10 Regulation 2
Threat axis distribution — Each event is assigned to one axis based on its classification; the total reconciles to the 48 events in the period.
FIXED MONTHLY MODULE Sectoral Distribution of Signals July 2026 · Latin America Base: 48 incidents in the period · total 59 because 10 incidents are classified in more than one sector. Public sector / OIV 15 Technology 14 Other / unspecified sector… 14 Health 12 Telecom 2 Energy 2
Sectoral Distribution of Signals — Heuristic sector classification by victim sector. One incident may affect more than one sector, so the total may exceed the base.
MONTHLY FIXED MODULE Geographic Signal Distribution July 2026 · Latin America Each event is assigned to a single country or to regional coverage, so the total is exactly 48 out of 48 events… Regional 28 Brazil 7 Mexico 6 Paraguay 4 U.S.A. 3
Geographic Signal Distribution — Verified period events grouped by country or regional coverage; each event is counted once.

Monthly executive summary

July 2026 sent a clear signal to health providers, clinics, hospitals, and pharmaceutical companies across Latin America: ransomware was once again the dominant theme, accounting for 15 of the 48 verified incidents in the period. The strongest and most legally sensitive case in that set was the Brazilian proceeding against Instituto Saúde e Cidadania, where ANPD opened a sanctions process over a failure to protect patient data from public health units. The authority said the episode involved ransomware and that the institution reported nearly 500,000 affected records, including tens of thousands of children, teenagers, and older adults. That mix of scale, sensitive data, and possible regulatory noncompliance places the case in a different category from a simple technical outage.

The rest of the month showed a fragmented regional picture, with coverage of a purported breach in Sinaloa, reports of cyberattacks on private hospitals and prepaid medical providers in Paraguay, and the hacking of the Hospital de Clínicas website in Uruguay. Not all of those incidents carry the same evidentiary weight. In several cases, the source did not confirm an intrusion, or described an automated defacement attack without access to patient data. That distinction matters, because the month’s material often mixed attacks with real operational impact, threat actor claims, still unverified leaks, and simple changes to public portals. From a CISO perspective, the takeaway is that the health sector remains broadly exposed, but the solid evidence of impact on clinical information or care continuity was far narrower than the month’s information noise suggested.

Brazil produced the strongest signal in regulatory and scale terms. The ANPD proceeding against Isac not only puts the focus on information security, but also on notification, prevention, and accountability obligations. The authority examined whether adequate measures had been taken and whether affected individuals were notified directly. That expands the scope of the incident beyond the technical perimeter. At the same time, July coverage of ransomware in the region continued to place Brazil as the most exposed country in several telemetry counts and vendor reports, although those figures reflect attempts, blocks, or victims published by third parties, not a single inventory of health incidents across the region.

At the same time, actively exploited vulnerabilities kept feeding ransomware and initial access campaigns. CISA, F5 Labs, and other intelligence chain actors cited critical flaws in Adobe ColdFusion, SonicWall SMA 1000, Fortinet FortiSandbox, and other platforms already listed in KEV. For the health sector, that is especially relevant because many institutions combine public portals, administrative systems, vendor integrations, and legacy software exposed to the internet. The month’s risk was not a single malware family, but the convergence of old attack surfaces, slow remediation, and actors already exploiting known flaws to move quickly toward extortion or encryption.

The final readout for the period is one of high risk. Not because all cases were confirmed with the same level of depth, but because the verifiable material did show three consistent traits: ransomware as the leading threat, strong pressure on sensitive health data, and a significant number of incidents where the absence of official confirmation prevented a firm technical diagnosis. In other words, the sector is facing not only attacks, but also a visibility gap that makes it harder to distinguish rumor, defacement, breach, and extortion with real impact.

Regional threat landscape

The region saw a mix of opportunistic attacks, public extortion, and regulatory developments tied to health and sensitive data. The dominant pattern was not the fraud or phishing documented in concrete incidents, which did not emerge as the main thread of verified events this month, but ransomware and its operational orbit, vulnerability exploitation, victim postings on leak sites, ransom notes, and demands for data access. In healthcare, that pattern is especially damaging because a single incident can affect confidentiality, integrity, and continuity of care at the same time.

Brazil recorded the highest density of verifiable events tied to that axis. There, a high-profile regulatory case, references to regional leadership in ransomware victims, and coverage of broader digital extortion campaigns converged. Mexico also accumulated signals, mainly through reports of rising cyberattacks and the public discussion around Sinaloa. Paraguay contributed a healthcare incident without much technical detail, but enough to show that private healthcare was not spared from regional pressure. Uruguay, for its part, was closer to digital vandalism against portals than to a confirmed exfiltration of medical records. That difference in form explains why the month’s narrative volume should not be confused with the severity of confirmed cases.

Verified severity was concentrated in a few events, but with significant data-protection and compliance implications. The Brazilian Isac case is the clearest example. The possible impact on about 500,000 patients, including minors and older adults, increases legal and reputational exposure. So does the possibility of sanctions under LGPD. At the same time, the website of Uruguay’s Hospital de Clínicas was taken offline on its informational side, but the institution itself said there was no access to personal data or medical records. The incident was described as a massive automated attack against vulnerable Joomla sites, not a targeted clinical intrusion. For a regional reading, this suggests that healthcare is dealing with two kinds of threat, one that compromises data or critical availability, and another that damages the digital presence without touching sensitive records.

The quality of the material varied widely. Some coverage relied on authorities or technical notices, other pieces on news reports repeating complaints from unidentified actors, and several remained in an intermediate zone without conclusive public forensic analysis. That makes it necessary to separate hard evidence from journalistic hypothesis. July’s report does not show a region out of control, but one where public evidence arrives late or incomplete. For healthcare and pharmaceutical companies, that visibility problem is as relevant as the incident itself, because it makes it harder to decide when to cut access, when to notify, when to restore, and when to activate legal response.

Distribución cualitativa de la señalMatriz narrativa de amenazas verificadas en julio 2026 para el vertical salud en América Latina.Monthly signalRansomwarepredominantLeakunclosedRegulationactiveCritical CVEsexploitedBrazilstrongest caseSinaloa, Uruguayand Paraguay
Qualitative distribution of the signal — Reading by type of verified event in the month, without mixing telemetry with incidents.

Period indicators

Indicator Value
Verified events in the period 48
Indicator time window 51 events dated in July 2026 · 16 with no confirmed date (excluded from the indicators)
Unclassified incidents (breaches or outages) 10
Cases with ransomware or extortion as the primary focus 15
Confirmed asset encryption 2
Exfiltration without encryption (simple extortion) 1
Classification could not be determined from the material 12
Documented fraud or phishing cases 0
Documented regulatory moves 2
Critical CVEs mentioned 9
Sectors with at least one documented event 5
Leading threat of the month Ransomware (15 of 48 events)
Events with direct source confirmation 88%
Aggregated telemetry figures excluded from the total 3 (aggregated attempts or blocks: these are not incidents with confirmed impact)

Relevant incidents

Brazil, ANPD sanction process against Isac

The clearest health-related case in Latin America this month was the sanction process opened by the ANPD against the Instituto Saúde e Cidadania. The authority said the social organization failed to protect patient data from public health units in Brazil and that the case involved a ransomware attack. The ANPD itself said the institution reported nearly 500,000 affected records, including approximately 78,772 belonging to children and adolescents and 47,921 to older adults. The combination of scale and sensitivity places the incident in a high-impact category, even before the legal fallout.

News coverage also added that the ANPD is examining whether Isac adopted adequate security measures and whether it notified affected individuals separately. That point is central. In health care, an incident does not end when an attacker encrypts or exfiltrates information. It continues into the compliance layer, where prevention, accountability, and communication are evaluated. O Globo and Poder360 agreed that the authority examined the lack of individual notice, while Defender360 highlighted the possible range of penalties under LGPD. That reading suggests the case may end up mattering as much for the administrative record as for the cyberattack itself.

The case also has structural value for the region. Public health systems often operate across multiple units, heterogeneous systems, and long third-party chains. When a social organization runs health infrastructure, the risk does not stop at the institution. It can extend to hospitals, clinics, databases, and care processes across several jurisdictions. The Isac case leaves a clear operational lesson: resilience is not measured only by backups, but by the ability to prove protection, traceability, and timely notification when an intrusion exposes patients.

Sinaloa, cross-claims and a breach still unresolved

Sinaloa drew several reports during July, but the available material did not allow for a single technical conclusion. El Sol de Sinaloa reported seven possible cyberattack complaints against public systems during the month, with references to medical records among the possible impacts, though without public findings. El Independiente said no authority had confirmed a cyberattack or the authenticity of the files circulated. Noroeste carried the acting mayor of Culiacán's denial of an attack on the city hall's official websites. Proceso, for its part, broadened the hypothesis and said the alleged cyberattack on Sinaloa governments may have exposed data on nearly one million people.

The most specific health-related report was the one mentioning the Culiacán Health Portal. Ransomware.mx published coverage from Intel MX in which a threat actor claimed to have compromised the portal and posted alleged medical records for free, including data on minors. Diario Bitcoin also reported a supposed leak of 4,045 medical records. However, the material itself says there was still no official public verification. That requires a cautious classification, there is a claim and there is data in circulation, but no independent technical closure on the origin, scope, or validity of the information.

From a defense perspective, Sinaloa shows a familiar problem. When several news sources describe the same environment, but there is no unified forensic review or clear attribution, time works against the data holder. Health teams are often forced to respond before they have full certainty. That timing gap is costly. If the circulating material is real, exposure is serious. If it is not, reputational damage can still be high. For that reason, the first task is not only to contain the system, but to preserve evidence, validate hashes or samples, and separate rumor from authentic material.

Paraguay, attacks on private clinics and low technical specificity

Diario Paraguayo published a report on a cyberattack that affected private clinics and prepaid medical companies in Paraguay. The coverage did not identify institutions or provide technical details on malware, vectors, or scope. In another piece, the outlet quoted an expert who described the episode as a sign of low cybersecurity maturity in the health sector. That reading is plausible as an opinion, but it cannot be treated as an official warning or as evidence of a specific campaign.

The value of the case lies precisely in its ambiguity. When information arrives without names, without a technical date, and without indicators of compromise, the sector ends up operating blind. Private clinics and prepaid providers often rely on administrative platforms, member portals, appointment systems, and billing tools. It does not take mass encryption to cause disruption. Unauthorized access to an appointment system or a credentials module can affect care and patient service even before any public leak exists. For that reason, even with limited confirmation, it deserves attention in the monthly picture.

Uruguay, hack of the Hospital de Clínicas website

The Hospital de Clínicas in Uruguay was another name that appeared repeatedly in July. Subrayado reported that its website had been hacked and was still down at the time of the report. El País said Agesic and the University of the Republic's IT services were investigating the case, but that no patient information had been accessed. The hospital itself clarified that the incident did not compromise medical records or affect care. Telenoche added that the site had been in maintenance for at least a week.

El Observador added a useful detail for classifying the incident: the attack apparently was not aimed specifically at the Hospital de Clínicas, but was part of an automated campaign that searched for vulnerable sites and exploited a Joomla flaw. In other words, the hospital was one of several targets reached by a broad internet scan, and recovery would consist of restoring a backup, reinstalling Joomla, and updating the environment.

That framing lowers the clinical severity of the event, but not its operational relevance. A portal that is down for days can disrupt public information, schedules, departmental communications, and contact channels. In large health institutions, even a defacement or a digital presence outage carries costs. The key point here is that the available material denied any impact on patient data. For that reason, this case should be read as web unavailability and not as a confirmed clinical breach.

Brazil and regional pressure from ransomware in health care

Beyond the Isac case, July brought several references to ransomware pressure across the region and on health care in particular. SCILabs said Qilin was the most active variant in Latin America in 2025, followed by Akira and LockBit, and mentioned new families such as SafePay and The Gentlemen. Breachsense said the health sector was the most attacked in July 2026, with 71 victims, and that there were 811 victims published on leak sites during the month, attributed to 66 different groups in 78 countries. Both readings help explain pressure in the ecosystem, though they do not replace the month's health incident record.

The region also showed tactical diversity. TrendTIC reported ransomware attacks targeting organizations in Colombia and Mexico in which attackers printed ransom notes on corporate printers after encrypting systems with BitLocker. Kaseya reported on the Everest group and a demand for approximately 10 million Swiss francs from Stadler Rail after accessing a data-sharing platform shared with a vendor. In health care, that suggests attackers are still prioritizing visible disruption and psychological pressure, even when data theft is not immediately exposed.

Active Threats and Campaigns

Ransomware, confirmed encryption

Only two events in the period allow confirmed encryption of assets in the analyzed material. The first is the Brazilian case of Isac, described by ANPD and by media outlets as a ransomware attack. The second is the regional coverage of attacks in Colombia and Mexico, where systems were reported encrypted with BitLocker and ransom notes were printed. In both cases, the analytical value is that unavailability was an explicit part of the tactic, not a later inference.

For the rest of the ransomware-related events, the source did not always specify whether there was encryption, exfiltration, or only a mention of the victim on a leak site. That is especially important in health care, where coverage tends to use "vazamento", "attack" and "ransomware" as close terms, even when they do not technically describe the same thing. For a security team, that distinction changes the response. If there is encryption, the priority is restoration and continuity. If there is exfiltration, the priority is containment, forensics, and notification. If there is only a claim on a leak site, the priority is to verify evidence before assuming real impact.

Ransomware, exfiltration without encryption

The material this month only clearly supports identifying one case of exfiltration without encryption as the primary focus, although it is not unequivocally linked to a specific Latin American health institution. For that reason, it would not be advisable to force a broader regional reading than the sources support. What is clear is that simple extortion remains part of the playbook and that, in health care, the exposure of medical records alone can carry regulatory and reputational costs even without system downtime.

Ransomware, leak site mention only

Several July reports fell into this category. In Sinaloa, for example, there were references to posts of alleged medical records and claims by a threat actor, but no official confirmation of authenticity, scope, or intrusion. That nuance matters because a leak site mention does not, by itself, equal a validated leak. The material may be authentic, manipulated, or partly mixed with older data.

Fraud and phishing

No fraud or phishing cases were documented as concrete health-sector incidents for July 2026 in the material provided. That does not mean the risk is absent. It means that, in this corpus, the month was dominated by ransomware, portal outages, leak claims, and regulatory actions. Phishing does appear in general regional context material, but not as a fact attributable to a health institution during the period.

APT and hacktivism

There were no clearly identified health-sector APT or hacktivist events for the month within the verifiable materials. There was a general context of intrusion into Paraguayan state systems and an attack surface of automated attacks against Uruguayan websites, but that is not enough to classify an APT campaign against the health vertical. That distinction should be preserved to avoid mixing geopolitical noise with clinical operations incidents.

Critical vulnerabilities

The material does mention critical vulnerabilities being actively exploited, although not all are tied exclusively to the health sector. For healthcare and pharmaceutical institutions, the relevance lies in the shared attack surface: exposed appliances, public portals, remote access software, and third-party collaboration platforms.

CVE Software Exploitation Source
CVE-2026-48282 Adobe ColdFusion Active exploitation, path traversal with potential for arbitrary code execution, CVSS 10.0 The Hacker News
CVE-2026-15409 SonicWall SMA 1000 Active exploitation by the Inc group, used for remote code access F5 Labs / Quasa
CVE-2026-15410 SonicWall SMA 1000 Active exploitation by the Inc group, used for remote code access F5 Labs / Quasa
CVE-2026-25089 Fortinet FortiSandbox Unauthenticated command execution through manipulated HTTP requests F5 Labs
CVE-2026-56164 Not detailed in the material Added to the KEV as actively exploited Quasa
CVE-2026-56155 Not detailed in the material Added to the KEV as actively exploited Quasa
CVE-2026-48908 Not detailed in the material Added to the KEV as actively exploited Threat Modeling
CVE-2026-56290 Not detailed in the material Added to the KEV as actively exploited Threat Modeling
CVE-2026-55255 Not detailed in the material Added to the KEV as actively exploited Threat Modeling

The material analyzed does not show a direct link between these flaws and a specific healthcare breach in the region, but it does show an exposure pattern consistent with health environments that rely on perimeter software or legacy integrations. The presence of KEV in July is a tactical warning for hospitals, clinics, labs, and pharmaceutical companies, remediation windows are short and attackers are already using public flaws.

Regulation and Compliance

Brazil gave regulation a larger role than in previous months by turning a health incident into a high-profile administrative case. The ANPD opened a sanctioning proceeding against Isac on the basis of a failure to protect patient data. The agency also examined whether prevention measures were insufficient, whether notice to affected individuals was incomplete, and whether the organization could support its claim that there was no risk or harm. That approach reinforces a reading that has been gaining weight in the region, in health care, information security is inseparable from the obligation to demonstrate diligence.

The case also strained the relationship between outsourced operations and accountability. When a social organization or a vendor manages data from public units, the regulator can review both the technical architecture and data governance. That includes notification, control documentation, impact assessment, and response capacity. For clinics, hospitals, and pharmaceutical companies, the message is direct, a lack of evidence of controls can be as problematic as the intrusion itself.

Beyond Brazil, the source material did not show other major regulatory moves with the same weight. There was coverage of investigative authorities in Uruguay and references to prosecutors or CERT in Paraguay, but they do not amount to an administrative sanction in the health sector on a comparable scale. For that reason, the month’s regulatory balance is concentrated in a single event, even if that event is enough to reshape compliance priorities in the sector.

Countries and most affected subsegments

Brazil

Brazil was the clearest signal in the region this month. The Isac case involves patient data from public health units, an active regulatory investigation, and a possible penalty under LGPD. Other regional context also placed the country among the most affected by ransomware and among victims named in vendor reports. That combination makes Brazil not only a large market, but also a jurisdiction where the cost of a healthcare incident can quickly reach the regulatory agenda.

At the subsegment level, the material points mainly to public health and to organizations that manage services for third parties. There was no concrete pharmaceutical case this month with the same level of documentation. That does not rule out exposure in the segment, but it does mark a difference in the volume of verifiable facts. Operationally, most of the visible pressure fell on data managers and public care services, not on labs or manufacturers.

Mexico

Mexico surfaced through two angles. One is the regional reading on the rise in cyberattacks, with a 38% spike in the country and a link to the StrikeShark wave. The other is coverage of Sinaloa, where reporting mixed possible cyberattacks on public systems, leaks under discussion, and versions about the Culiacán Health Portal. The country did not have in July a healthcare case as tightly closed as Brazil's, but it did show a higher density of exposure signals and narrative dispute.

In subsegment terms, the most visible area was public health and medical information portals. The lack of official confirmation in Sinaloa calls for caution, but it does not reduce the need for monitoring. When a leak moves across several newsrooms without forensic analysis, the potential harm to patient data already exists on the reputational level, even if technical validation remains open.

Paraguay

Paraguay showed the angle of private clinics and prepaid health companies. The material does not identify institutions, but it does reflect a concrete sector concern. The value of the case is not in the technical detail, but in the overlap between a private healthcare ecosystem and a perception of insufficient readiness. That is often a recipe for incidents with low public visibility and high internal operational friction.

Uruguay

Uruguay contributed a more limited, and at the same time highly illustrative, case. The Hospital de Clínicas suffered a hack of its website, affecting the informational side of the portal, but without compromise of patient data or medical records, according to the institution itself. The attack was described as automated and opportunistic, relying on a Joomla vulnerability. At the subsegment level, this points to universities, public hospitals, and outreach portals that still depend on exposed software and uneven maintenance.

Sinaloa and the public health ecosystem

Sinaloa cannot be read as a single institution, but rather as an ecosystem of public systems under narrative pressure. There were reports of possible cyberattacks, mentions of medical records, and conflicting versions about a leak. Without a conclusive finding, the most affected subsegment is that of public care platforms and health portals. The problem is not only the intrusion, but also the lack of a technical account that would make it possible to narrow the scope.

There is no comparative baseline in this format, so it would be inaccurate to invent a month-over-month trend versus the prior period. What can be said is that July reinforced three signals worth tracking closely in August and through the rest of the second half.

The first is ransomware’s persistence as the dominant threat. Not only because of the number of incidents, but also because of the range of tactics observed: confirmed encryption, leak site claims, ransom note printing, and exploitation of exposed software. In healthcare, that usually comes before mixed incidents, where attackers combine service disruption with pressure over sensitive data.

The second signal is regulatory. The ANPD case could set a stricter standard for evidence of controls, notification, and accountability for operators handling public health. If the case ends in sanctions, the region will have a meaningful precedent for similar organizations in other countries.

The third signal is technical. July’s critical vulnerabilities showed that attackers are still prioritizing actively exploited flaws and common hospital and vendor attack surfaces, especially portals, remote access appliances, and collaboration platforms. As long as remediation remains slow, the window for intrusion will stay open.

Security team recommendations

First, operationally separate three scenarios that are often confused in many meetings: confirmed encryption, exfiltration without encryption, and unverified claims. Each scenario requires a different response sequence, and mixing them up delays decisions on isolating the network, cutting access, restoring systems, or notifying stakeholders.

Second, immediately review exposure of public portals and perimeter systems. This month’s material mentions software and appliances that often appear in hospitals, clinics, and health care third parties. If a team has ColdFusion, SonicWall, Fortinet, Joomla, or similar tools exposed, remediation cannot wait for the normal patch cycle.

Third, tighten third-party management. The Brazilian case suggests responsibility does not end with the institution that operates the service. Contracts, control audits, owner inventories, and notification paths need to be in place before an incident, not after.

Fourth, review the ability to preserve evidence. In several July incidents, the public debate moved forward without technical forensics. That is a problem because, without logs, forensic images, and traceability for privileged accounts, the organization gets trapped between denying too early or confirming too late.

Fifth, test real restoration, not just the existence of a backup. In health care, recovery has to include shifts, portals, electronic medical records, printing, lab integrations, and patient communications. A backup that does not restore full clinical operations is of little use.

Sixth, strengthen communications and compliance management. If the incident involves sensitive data, individual notice, legal language, and coordination with regulators must be prepared in parallel with technical containment. The Isac case shows that this layer can become the main front of the episode.

Material limitations

This report was built exclusively from the material provided for July 2026 and from the thematic scope of health, clinics, hospitals, and pharmaceuticals in Latin America. No external sources or internet data were used. Facts without a confirmed date were excluded from the period indicators and were used only, when appropriate, as qualitative context with that explicit caveat.

The indicator window is the one stated in the material, 51 dated facts in July 2026 and 16 without a confirmed date, with the latter excluded from the counts. The indicators reproduced above should be read exactly as provided, without recalculating bases or redistributing categories.

An indicator at zero does not mean the phenomenon did not exist in the region. In particular, the 0 documented fraud or phishing cases mean only that no facts of that type appeared in the material analyzed for this period. The same applies to CVEs if the material had not recorded any, although in this case 9 critical CVEs were mentioned. Absence from the corpus does not equal the real absence of vulnerabilities or incidents in Latin America.

Aggregate telemetry figures were also left out of the volume, because they correspond to attempts, blocks, scans, or vendor detections, not to intrusions with confirmed impact. When they were mentioned, it was only as context and always distinguished from incidents. Finally, the material excluded consumer social media and sponsored content, so they were not used as evidence.

Material limitations

This report was built exclusively from the material provided for July 2026 and from the thematic scope of health care, clinics, hospitals, and pharmaceuticals in Latin America. No external sources or internet data were used. Facts without a confirmed date were excluded from the period indicators and were used, when appropriate, only as qualitative context with that explicit caveat.

The indicator window is the one stated in the material, 51 dated facts in July 2026 and 16 without a confirmed date, the latter excluded from the counts. The indicators reproduced above should be read exactly as provided, without recalculating baselines or redistributing categories.

A zero indicator does not mean the phenomenon did not occur in the region. In particular, the 0 documented fraud or phishing cases mean only that no facts of that type appeared in the material analyzed for this period. The same applies to CVEs if the material had not recorded any, although in this case 9 critical CVEs were mentioned. The absence in the corpus does not equal the absence of vulnerabilities or incidents in Latin America.

Aggregate telemetry figures were also left out of the total volume, because they refer to attempts, blocks, scans, or vendor detections, not to intrusions with confirmed impact. When they were mentioned, it was only as context and always distinguished from incidents. Finally, the material excluded consumer social networks and sponsored content, so they were not used as evidence.

Sources