CiberLATAMbywhalemate
Intelligence report

Health, Clinics, Hospitals, and Pharma, Aug 2026

August closed with 90 verified health-sector incidents in LATAM, driven by ransomware, data leaks, and banking fraud in Brazil, Peru

Sep 1, 202637 min read
Health, Clinics, Hospitals, and Pharma, Aug 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are populated automatically with verified dated events within the period. Each one states its source and counting criterion so the figures can be reconciled across modules. They are the recurring month-by-month readout, and the analysis that follows develops the cases without repeating this summary.

Indicator window: 90 dated events in August 2026. Events from earlier months are used only as comparative context in the analysis, never as part of this period's total.

CIBERLATAM / WHALEMATE Monthly Verified Signal Dashboard August 2026 · Latin America Dominant threat: Ransomware (37 of 90 events). Coverage: 90 dated events in August 2026 VERIFIED EVENTS 90 period baseline: all counts measured from the bottom on this total RANSOMWARE / EXTORTION 37 6 asset encryption confirmed · 3 exfiltration no encryption (simple extortion) UNTYPED INCIDENTS 23 breaches or outages without declared threat type FRAUD / PHISHING 10 documented fraud campaigns documented REGULATION 2 rules, resolutions, or sanctions UNIQUE CVEs 2 CVE-2024-1708 / CVE-2026-50751
Monthly Verified Signal Dashboard — Base: 90 verified dated events for Latin America.
MONTHLY FIXED MODULE Threat-axis distribution August 2026 · Latin America Each incident is counted in only one axis, so the total is exactly 90. "Unclassified incidents" is the remainder. Ransomware 37 Incidents 23 Unclassified 17 Fraud 10 Regulation 2 Vulnerabilities 1
Threat-axis distribution — Each incident is assigned to a single axis based on its classification; the total reconciles to the 90 incidents in the period.
MONTHLY FIXED MODULE Sector breakdown of signals August 2026 · Latin America Base: 90 incidents in the period · total 174 because 59 incidents are classified in more than one sector. Health 68 Public sector / OIV 53 Education 15 Finance 12 Technology 12 Telecom 7 Other / no sector id… 4 Retail / consumer 3
Sector breakdown of signals — Heuristic sector classification by victim sector. One incident may affect more than one sector, so the total may exceed the base.
MONTHLY FIXED MODULE Geographic Signal Distribution August 2026 · Latin America Each fact is assigned to a single country or to regional coverage, so the total is exactly 90 out of 90 facts… Regional 23 USA 21 Peru 14 Paraguay 13 Chile 10 Brazil 9
Geographic Signal Distribution — Verified facts from the period grouped by country or regional coverage; each fact is counted once.

Executive Summary

August 2026 painted a mixed picture for health systems, clinics, hospitals, and pharmaceutical companies across Latin America. On one side, a string of financial fraud incidents and data exposure cases involving healthcare providers and public surveillance systems became more established. On the other, new ransomware claims against hospitals and health platforms appeared in several countries, though with varying levels of public confirmation. The month was not defined by a single threat family. Instead, three patterns coexisted, ransomware extortion with leak site publications, banking fraud or online scams affecting health institutions, and disclosures of exposed databases without authentication that revealed regulatory and patient information.

The clearest and best documented signal of the period was the exposed SISVISA database in Brazil, which left 102,215 records and approximately 79 GB of related material accessible on health surveillance and licensing. Jeremiah Fowler's investigation showed that this was not an isolated file, but a set containing identifiers, tax data, regulatory documents, licensing requests, authorizations, inspection reports, compliance documentation, citizen complaints, and compressed backups. Although public access was disabled shortly after responsible disclosure, the actual exposure window could not be determined, and there is no public official confirmation on the full scope or any possible third-party access. For a healthcare CISO, the case is especially relevant because it shows how a poorly configured regulatory environment can become an exposure vector as sensitive as a clinical breach, with operational, reputational, and compliance consequences.

In parallel, EsSalud Lambayeque in Peru became one of the clearest examples of financial fraud enabled by remote access and technical impersonation. Media coverage converges on the finding that individuals posing as Scotiabank support gained remote access to the institution's devices through usernames and passwords provided by network staff, and from there carried out five unauthorized transfers totaling S/ 1.406.991. The case also led to a procedural turn, prosecutors ruled it was not only an external scam and opened an investigation into alleged embezzlement against four EsSalud officials, saying the money transfer appears to have involved direct participation from those responsible for the account. That distinction matters because it separates a simple technical deception from an internal controls failure, a combination that raises severity and requires reviews of not only cybersecurity, but also segregation of duties, out-of-band validation, and payment governance.

Brazil and Chile also saw notable incidents in the form of ransomware claims. In Brazil, Mobilemed appeared in monitoring lists as a presumed victim of the Kazu group, with an alleged exfiltration of 23.5 TB and a ransom estimated at US$ 1.5 million, although the company did not publicly confirm the scope. The analytical value of the case lies less in the figure, which comes from aggregators and the leak site, and more in the recurring pattern. Kazu continued to aim its posts at healthcare and at providers in the health supply chain, not only clinics or hospitals, but PACS platforms, telemedicine, practice management services, and other software critical to care delivery. In that same vein, Centro Médico Especializado OSI: Healthcare Solutions in Peru was listed by Kazu as a presumed victim, also without public confirmation from the clinic by the end of the period analyzed.

Chile accounted for another of the month's most sensitive pieces with the appearance of Hospital Clínico Universidad de Chile on the extortion portal attributed to Direwolf. Precision matters here, the available sources describe a leak site claim and automated tracking, not an independent validation by the hospital, a CERT, or a regulator. Even so, the case deserves attention for two reasons. First, there was the reported detection speed from the monitoring infrastructure, which identified the case in a window of less than 20 minutes according to the timestamp shared by HookPhish. Second, there was the campaign context, third-party analysis linked Direwolf to other victims published within a 24-hour span, including organizations in healthcare and a technology company, which suggests a multivictim and multiregional offensive pattern. For a response team, the value of this kind of observation is not to determine definitive culpability, but to refine prioritization, leak site monitoring, and crisis communications planning.

August's regional picture also included signs of regulatory and operational pressure in other countries. In Paraguay, the public narrative around cyberattacks on healthcare appeared in both parliamentary statements and interviews with specialists, although with limited verifiable technical detail. The most concrete case was Sanatorio San José in Ciudad del Este, where the investigation documented two unauthorized transfers of 250 million and 100 million guaraníes, carried out as manually entered operations using the username of an employee who was not authorized to approve payments, and later returned by the bank after intervention from the Prosecutor's Office and the Cybercrime Department. Although the bank denied any breach of its systems and attributed the events to attacks aimed at deceiving users, broad coverage cemented the idea of a "hacked" account, reinforcing public concern about private healthcare providers.

From a regional standpoint, August showed a chain of dependencies that amplifies risk. Clinics depend on cloud PACS platforms, sanatoriums depend on banks and tokens, hospitals depend on health surveillance portals, and provider networks depend on remote access or legitimate support tools that can later be abused. The common denominator was not a single technical family, but the exposure of critical information and payment flows in environments where clinical users, administrative staff, and outside vendors overlap. The recommendation for CISOs is clear, segment access, strengthen out-of-band approvals, remove unmanaged remote access software, audit privileged accounts, and prepare procedures to respond to ransomware, financial fraud, and regulatory exposure alike.

Panorama

August shows that Latin American healthcare remains an attractive target, not only because of the value of clinical data, but also because of its complex attack surface: fragmented internal networks, multiple vendors, integrations with banks, licensing portals, imaging systems, and telemedicine tools. That mix means a single organization can face, at different times, exposure of sensitive data, administrative fraud, and extortion through information leaks, without all of those events sharing the same vector or the same level of impact.

From a defensive standpoint, August 2026 leaves two especially important lessons. The first is that the sector still shows weakness in basic configuration controls and public exposure. The SISVISA case did not require advanced exploitation, only an unprotected database tied to the Brazilian government’s health surveillance and licensing portal. In other words, the issue was not a zero-day vulnerability, but a failure in operational hygiene and asset management. The second lesson is that fraud schemes reaching clinics and hospitals do not always involve ransomware or direct intrusion into the organization’s core systems. The EsSalud Lambayeque case, as well as the one involving Sanatorio San José in Paraguay, relied on social engineering, remote access, and manipulation of authorization flows. That forces the cybersecurity discussion to expand into fraud, financial continuity, and accounting controls.

There is also evidence of a more mature extortion model aimed at healthcare as an ecosystem, not just as a collection of isolated hospitals. Kazu, for example, appears to be an actor that does not limit itself to care providers, but also targets cloud PACS platforms, rehabilitation software, telemedicine, clinics, and clinical management services. The criminal logic is clear, by compromising a supply-chain provider, the attacker can reach multiple customers or force higher-value negotiations, even if the direct victim is not a large hospital network. Direwolf, meanwhile, was observed posting several victims within the same time window, including hospitals and tech companies, which suggests pressure for volume and visibility on its leak site. For defenders, the message is that the risk surface extends beyond the institutional perimeter and must include third parties, SaaS, cloud storage, and support vendors.

A second recurring pattern is weak credential and session management. In EsSalud Lambayeque, the attackers reportedly used remote access and usernames and passwords provided by internal staff, in addition to impersonating legitimate support. In Paraguay, the bank involved insisted that the fraud was based on user deception and fake websites, not on a compromise of its core systems. In both scenarios, technical defense alone is not enough if authentication processes, identity validation, and payment confirmation still rely too heavily on operational trust. In healthcare, where time is short and clinical urgency can pressure staff, this kind of manipulation is especially effective.

The regulatory picture is also uneven. Brazil showed investigative detection and a quick response to remove public access, but without a strong official communication that would fully clarify how long the exposure lasted. Peru, by contrast, combined a formal complaint, legal action, and public pressure on the bank to recover the funds, but the debate ended up shifting toward the possible involvement of internal employees. Chile and Argentina moved more in the realm of leak-site monitoring and threat intelligence analysis, with less visible institutional confirmation. That disparity means regional analysts have to read each case carefully: what appears in one country as an "incident" in a ransomware feed may be, in another, only an unverified claim, and what in one country is labeled bank fraud may conceal identity, process, or internal control problems.

Indicators

Incidents

Brazil: massive SISVISA exposure and pressure on health surveillance

The SISVISA case is one of the strongest this month in evidentiary terms, because it does not rely on an extortion narrative or a leak on a darknet portal, but on a technical finding involving an exposed database. Jeremiah Fowler, from ExpressVPN, found a database linked to the Brazilian government’s health surveillance and licensing portal that left 102.215 documents and about 79 GB of information accessible. Security Affairs said the database contained identifiers, tax data and regulatory documents without authentication, while Computer Weekly Brasil added a broader inventory: licensing requests, authorizations, inspection reports, compliance documentation, citizen complaints and two compressed backup files.

The significance of the case goes beyond volume. In public health and health regulation, inspection documents, licensing files and citizen complaints can reveal relationships among companies, facilities, inspectors and compliance processes. In other words, this is not just isolated personal data, but an operational map of the health ecosystem. For an attacker, that can support reconnaissance, reputational extortion, document fraud or the preparation of later campaigns against providers and authorities. For the public sector, the exposure also creates an institutional trust risk: a system meant to certify and oversee ends up exposed because of configuration failures, weakening the regulatory message.

One key point in the timeline is the response after responsible disclosure. Security Affairs said public access was disabled shortly after alerts were sent to several agencies, but there was no official public response and it is not known how long the database was exposed or whether third parties accessed the files. That lack of precision matters because it prevents a full assessment of the damage. In defensive cybersecurity, exposure time matters almost as much as the type of information. A database visible for minutes, hours or days changes the risk substantially. The case should therefore be read as a warning about exposed asset governance, permission review, segregation between operational environments and verifiable remediation.

Bahia Notícias added another dimension by noting that the SISVISA discovery also contained health information from a municipality in the interior of Bahia, including care records, patients and professionals. That detail broadens the potential impact because it suggests the exposed set was not limited to generic regulatory documentation, but could include clinical or care-related information from a municipal setting. Although the source does not allow quantifying how many such records existed, it does reinforce the need to treat the exposure as a high-sensitivity incident. Operationally, the lesson is straightforward: any system connected to health surveillance, licensing or inspection should be treated as a critical asset and subject to controls equivalent to those used for an electronic health record or laboratory platform.

Brazil: Mobilemed and Kazu’s pattern against the healthcare chain

Mobilemed appeared in several threat intelligence monitors as a Kazu victim. Ransomware.live listed it with a claimed exfiltration of 23,5 TB and a ransom estimate of US$ 1,5 million, while Dexpose.io reported that Kazu had allegedly attacked the company without any public statement at the time of coverage confirming or detailing the scope of the incident. The case remains an independently unverified claim, but the pattern is consistent with the group’s behavior during August: posting multiple healthcare targets in a single day and focusing on services that support clinical operations.

Mobilemed is described as a Brazilian cloud PACS provider for medical imaging. That detail matters because a PACS is not just a technical repository, it is part of the diagnostic workflow. If a platform of this kind is compromised, the potential impact reaches care continuity, physician access to images and the integrity of radiology data. Even if the incident has not been publicly confirmed, the mere inclusion of the provider on the leak site forces customers to review contractual relationships, notification clauses, backups and failover capacity. For a hospital network, depending on an external PACS means that extortion against the provider can translate into diagnostic delays or the need to activate manual procedures.

The analytical value of the case increases when it is viewed alongside other victims listed by Kazu on the same day. Security Arsenal said that on 23 August the group published nine victims in total, seven of them healthcare organizations or health-related SaaS platforms. Medrisk.io added that among them were entities from different countries and service types: Instituto Ferrero de Neurología y Sueño, Brazil Mobilemed, Meducar, ConsultorioMovil, Centro Médico Especializado OSI and other health management services. That suggests a broad campaign focused on the ecosystem, not just large providers. From a defense standpoint, the challenge is not only securing the hospital, but also mapping the appointment provider, telemedicine provider, imaging provider and remote support provider.

Brazil: CTIR Gov warning on SQL Server and the need for immediate patching

CTIR Gov published ALERTA 76/2026 on a critical SQL Server vulnerability, recommending that vulnerable versions be identified and the vendor’s patches applied immediately. The notice also says the flaw appears in CISA’s KEV catalog and has an EPSS of 44,66%. For the healthcare sector, this is especially relevant because SQL Server often underpins electronic health record systems, laboratories, billing, ERP and auxiliary repositories. In other words, this is not a distant infrastructure component, it can be a core one.

The appearance of an official alert like this in the same month as reported exposures and ransomware claims means the risk should be read as cumulative. The issue is not only that a critical CVE exists, but that healthcare environments often combine heterogeneous versions, difficult maintenance windows and third-party dependencies. When an official notice points to KEV and a high EPSS, defensive priority should be immediate. This does not mean every SQL Server in the region is compromised, it means teams must inventory, verify exposure, review segmentation and confirm that patches were actually applied, not just approved on paper.

Peru: EsSalud Lambayeque, financial fraud and the collision between cybersecurity and internal controls

The EsSalud Lambayeque case is one of the most complex in the period because it does not fit the usual ransomware or data breach narrative, but rather a financial fraud mediated by remote access and support impersonation. The formal complaint filed by EsSalud with the National Police of Peru and the Public Prosecutor’s Office said five unauthorized bank transfers diverted S/ 1.406.991 from an account belonging to the Lambayeque healthcare network. The incident took place on 14 August, after people posing as Scotiabank support gained remote access to the entity’s devices using usernames and passwords provided by network staff.

Infobae Perú added that the modus operandi included remote access tools such as AnyDesk and UltraViewer, along with Scotiabank support impersonation to capture passwords and banking tokens. El Machete and La República reported that five unrecognized bank orders were detected, executed through different transfer mechanisms, and that ten individuals and legal entities were reported to the Divincri de Chiclayo. From an operational perspective, the case shows a mix of vectors: telephone or digital social engineering, abuse of legitimate remote administration tools and weakened approval controls in the payment flow.

The reporting became even more serious when the Second Corporate Provincial Criminal Prosecutor’s Office of Chiclayo decided to investigate four EsSalud officials for alleged embezzlement, concluding that the money outflow may have involved direct participation by those responsible for the account. That decision is key because it shifts the focus from a purely external incident to possible internal collusion or, at minimum, a serious failure of segregation of duties. For CISOs and auditors, the lesson is that technical security cannot be separated from permission management, dual-control principles and traceability in approvals. If an attacker convinces an operator to allow remote access and then executes financial transactions, the organization does not only need antivirus or EDR. It needs out-of-band human verification, strict control or prohibition of remote access software, and alerts for anomalous payment behavior.

There is a second important nuance. The case unfolded amid a public dispute with the bank. Itaú Paraguay clarified in another related incident that its systems were not breached and that the frauds were the result of attacks aimed at deceiving users. In EsSalud’s case, the affected institution demanded explanations from Scotiabank for failures in security mechanisms and asked for the recipient accounts to be frozen. In other words, responsibility is spread across the bank, the user, internal staff and control processes. That kind of friction is common in financial fraud, but it also reveals a governance weakness: when there is no prior clarity about who validates what, the incident response becomes a later negotiation instead of a preventive mechanism.

Peru: Centro Médico Especializado OSI and Kazu’s campaign against clinical services

Centro Médico Especializado OSI: Healthcare Solutions, based in Lima and focused on physical medicine, rehabilitation, physiotherapy, chiropractic care and alternative medicine, appeared on the leak site attributed to Kazu. Medrisk.io placed the case within a day in which the group published eight healthcare targets, while Security Arsenal later expanded the map to nine total victims, seven of them healthcare or health-related SaaS. Dexpose.io said the group allegedly threatened to publish sensitive medical data unless negotiations moved forward, while ransomware.live recorded a US$ 250.000 ransom for the case.

Although the institution had not issued a public statement at the time of coverage, the case matters because of the actor and the victim profile. OSI is not just an isolated clinic, the ransomware.mx bulletin described it as a healthcare provider with multiple clinics in the Lima metro area, specializing in rehabilitation and physical medicine. If an extortion actor claims access to that environment, the potential impact is not limited to administrative data. It can affect patient schedules, diagnoses, long-term treatments and relationships with insurers or referrals. And because it is a multi-site provider, an interruption can cascade across several clinics and affect patient flow in the capital.

The core point is that Kazu appears to favor targets that can support scalable extortion. By going after telemedicine, PACS, practice management and specialized centers, the group attacks links that concentrate information, credentials and operational continuity for multiple clients or sites. For a healthcare CISO, that means risk assessment must include not only the organization itself, but also its digital health partners. If the platform provider goes down, the clinic is exposed even if it was not directly breached. The defensive strategy must include an inventory of critical SaaS, MFA requirements, environment segregation, offline backups and early-notification contractual clauses.

Paraguay: Sanatorio San José, fund diversion and a dispute over the incident narrative

The Sanatorio San José case in Ciudad del Este shows how the same situation can be described differently depending on the source. Diario Vanguardia reported that Joaquín Andrés Duarte Ojeda was arrested in Areguá as part of the investigation into the diversion of 350 million guaraníes from the institution’s corporate accounts, under alleged computer fraud and unauthorized system access. The complaint filed on 31 July detailed two unauthorized transfers, one for 250 million and another for 100 million, using the username of a female employee who was not authorized to approve payments through a transaction token. The outlet added that the banking system recorded the transactions as manually entered and that authorized executives did not receive alerts or verification codes.

La Nación covered the arrest and said the sanatorium account had been "hacked," which pushed the case into public debate as an example of a breach at a private healthcare provider. However, Itaú Paraguay issued a statement clarifying that its security systems were not breached and that the events were the result of cyberattacks aimed at deceiving users into handing over access credentials. That statement does not eliminate the incident, it simply redefines the vector and shifts the focus to the user and the validation process.

Later coverage added that the case was part of a broader alleged scheme to empty bank accounts involving at least two companies defrauded for a total of about 356 million guaraníes. That suggests a reusable financial fraud operation rather than an isolated attack on a healthcare institution. For the sector, the implication is clear: administrative areas must be treated as first-tier risk surface. It is not enough to protect medical records. Corporate accounts, online banking access, supplier payment flows and account recovery procedures also need protection. A clinic or sanatorium can have strong perimeter security and still lose money if an employee authorizes remote sessions or if an attacker manages to induce manual transfer entries.

Paraguay: signs of healthcare cyber incidents and political pressure

Beyond the specific Sanatorio San José case, Paraguay saw a broader public conversation in August about cybersecurity in healthcare. In an interview on 24 August, a specialist said incidents over the past year had involved the Instituto de Previsión Social, medical data, pre-paid medicine information at several sanatoriums, imaging diagnostic services in Ingavi and private companies, insurers and cooperatives. The source did not provide technical details or specific dates, so it cannot be used to count incidents for the month, but it does reflect a growing perception of cross-cutting exposure in Paraguay’s healthcare ecosystem.

There was also Rocío Vallejo, who in a note dated 18 August mentioned recent cyberattacks on private healthcare institutions and state entities as an argument for promoting the cybersecurity law. The lawmaker also reported the theft of about US$ 5.800 from her bank account, with the National Police attributing the event to possible malware operated remotely. While that last case is not healthcare-related, it helps explain the threat climate around financial fraud in the country and why the legislative debate on digital security is gaining traction.

For a healthcare CISO in Paraguay, the lesson is twofold. First, exposure is not limited to visible ransomware. There is also account fraud, abusive remote access and possible banking malware. Second, the political conversation is moving toward a higher expectation of institutional diligence. If the public narrative starts linking healthcare with digital fragility, providers will face more pressure to demonstrate concrete controls, not just compliance statements.

Chile: Hospital Clínico Universidad de Chile on Direwolf’s leak site

Hospital Clínico Universidad de Chile was listed by Direwolf as a victim on its leak portal, according to multiple threat intelligence monitors. Ransomware.live places it as a Direwolf victim with an estimated attack date of 30 August 2026, 1.633 users compromised and 240 GB allegedly exfiltrated. HookPhish assigned it the domain redclinica.cl and dated the breach to 30 August, with discovery a few minutes later. Ransom-DB identified it as a public university hospital located in Independencia, Santiago, and noted the domain hospital.uchile.cl. Security Arsenal, meanwhile, analyzed Direwolf activity over 24 hours and found that Hospital Clínico Universidad de Chile was among three victims published in that span, two of them in the healthcare sector.

It is important to stress what is not known. None of these sources provide public confirmation from the hospital, and neither regulators nor cybersecurity firms nor the institution had officially validated the claim at the time of analysis. There is also no public technical evidence to determine whether there was encryption, only exfiltration or a mere leak-site claim. Even so, the case is operationally useful because it shows the monitoring dynamic response teams should follow. When a hospital appears on an extortion portal, even without confirmation, the minimum response includes log review, access analysis, integrity validation, communication with response partners and monitoring of later postings.

The timeline reported by HookPhish is especially interesting, with a "date of breach" at 14:35:36 UTC and discovery at 14:53:50 UTC the same day. That proximity does not prove internal detection speed, but rather the ability of a tracking system to record the leak post almost immediately. For strategic defense, the point is that external ransomware monitoring has become a complementary early-warning signal. If a hospital has a threat intelligence agreement, it should use those feeds to trigger immediate review when the institution’s name appears on an extortion site.

Argentina: Sanatorio Modelo de Caseros and Qilin’s regional expansion

Although the mentions of Sanatorio Modelo de Caseros appear in the material as a ransomware claim attributed to Qilin and without public confirmation, the case adds regional context because it joins a sequence of healthcare targets in the Southern Cone. MedRisk said that on 26 August Qilin added the private sanatorium in Greater Buenos Aires to its leak site, claiming to have stolen internal data. Hendry Adrian described a ransomware incident involving encryption of critical files and an interruption of operations, although the sanatorium had not issued an official statement at the time of coverage. Since the primary source is threat intelligence rather than institutional validation, the case should be read as an unconfirmed claim.

Even so, the timing alongside other healthcare events in August is useful for trend analysis. When an actor like Qilin adds private sanatoriums to its list, it confirms that hospitals and care centers in Argentina remain on extortion groups’ radar, even if they do not dominate national headlines. For regional CISOs, the operational point is not to wait for public confirmation before reviewing exposure. A leak-site appearance alone already calls for credential monitoring, key rotation and backup verification.

McKesson: cloud incident and the cross-border reach of the pharma supply chain

McKesson said it detected a cybersecurity incident on 25 August 2026 that included unauthorized access and data extraction from cloud-hosted accounts, confirming the intrusion and exfiltration while it continued to investigate the scope of the affected information. Although the cited coverage does not come from a Latin American source, the case matters for this report because of the pharmaceutical supply chain and its potential impact on international markets. DiarioBitcoin also reported that a hacker group claimed to have stolen millions of patient records through intrusion into several corporate cloud accounts. That figure was not confirmed by the company and should be treated as an attacker claim.

The relevance for Latin America is that global distribution and pharmaceutical service providers can be interconnected with regional operations, logistics, procurement or data support. When a company of this size confirms exfiltration from cloud accounts, the lesson for local pharma firms is obvious: cloud is not inherently secure simply because a third party manages it. Identity controls, session monitoring, privilege segmentation and anomaly detection remain shared responsibilities.

Countries

Brazil

Brazil saw two distinct but complementary signals in August, a major regulatory exposure and multiple ransomware claims involving health services. The SISVISA case showed how a misconfiguration can expose a database with tens of thousands of records and sensitive documents, while Mobilemed and other entities linked to Kazu showed the pressure extortion gangs are putting on providers across the health care supply chain. CTIR Gov's alert on SQL Server added another preventive layer, there is exposure from configuration errors, there is risk from vulnerable software, and there is pressure from criminal actors exploiting both conditions.

For Brazilian providers, the immediate priority should be an audit of exposed assets, a review of databases and cloud repositories, and mapping of dependencies tied to PACS, telemedicine, and regulatory systems. At the same time, it is worth reviewing responsible disclosure policies and response times. If a researcher finds an open database, the organization should be able to verify, contain, and document remediation without relying on the case becoming public in the media. Brazil's health care ecosystem is large enough to attract both ransomware groups and researchers looking for accidental exposure, and in both cases access control quality is decisive.

Peru

Peru had one of the most serious financial cases of the month with EsSalud Lambayeque, where the combination of remote access, support impersonation, and internal control failures ended in the diversion of more than S/ 1,4 million. The fact that prosecutors are investigating four officials for alleged embezzlement shows that health sector security cannot be separated from administrative chains and payment validation. For any care network, this is a warning about the need to segment environments, ban unauthorized remote access tools, and document an approval process that cannot be manipulated by a single user.

On the extortion and possible ransomware claims front, Peru also saw Centro Médico Especializado OSI appear on Kazu's leak site. Although the institution did not publicly confirm the allegation, the repeated appearance of Peruvian clinical service names in intelligence feeds suggests that the country is on the radar of actors seeking to extort providers that depend heavily on digital systems. The defense strategy should therefore combine financial controls with clinical continuity controls, backup, recovery, MFA, and formal assessment of health software vendors.

Paraguay

Paraguay spent the month with health cyber issues mixed in with bank fraud, public complaints, and legislative debate. The Sanatorio San José case shows that a private provider can end up caught in an account-draining operation even without, according to the bank, any breach of its systems. That difference between user deception and a core attack is crucial for response planning. If the human factor was the vector, mitigation should focus on training, identity verification, and blocking remote tools or fake domains.

The parliamentary mention of recent cyberattacks on private health institutions and state entities indicates the issue is already part of the public agenda. That may be positive if it leads to better regulatory frameworks, but it also raises expectations for transparency across the sector. Paraguayan clinics, sanatoriums, and insurers should prepare for more detailed questions about controls, incident response, and access governance. August suggests that attacks do not necessarily look like spectacular hacks. They can be quiet frauds, remote sessions, stolen credentials, or fake websites that end in unauthorized transfers.

Chile

Chile had a significant exposure on the reputation and threat-monitoring front with the Hospital Clínico Universidad de Chile on Direwolf's leak site. Since the case was not publicly confirmed by the institution, it would be unwise to overstate the operational impact or assume definitive encryption or exfiltration. However, the fact that multiple intelligence sources recorded it on the same day indicates that monitoring of Chilean hospitals is active and that attackers use publication as pressure even without an immediate institutional statement.

For security leaders in Chile, the lesson is practical. There must be procedures to quickly validate whether a mention on a leak site reflects a real intrusion, a mere claim, or a false positive. That requires prior contact with threat intelligence providers, playbooks for access review, and crisis communications processes. In a university hospital, the complexity is even greater because clinical care, teaching, and research coexist, which expands the exposure surface and the number of critical accounts and systems.

Argentina

Argentina appeared mainly in Kazu's orbit, with the Instituto Ferrero de Neurología y Sueño listed as one of the targets cited in the eight-victim health care day and Sanatorio Modelo de Caseros as another case circulated by aggregators. Although these claims have no public institutional confirmation, they suggest the country remains an attractive target for extortion groups that are probing private sanatoriums and specialized services.

The takeaway for Argentina is not that there is a single dominant vector, but that attackers are exploiting fragmentation in the care ecosystem. Sanatoriums, sleep centers, rehabilitation services, and health software are valuable targets because they concentrate sensitive data and depend on constant availability. Organizations should review not only backups and MFA, but also exfiltration controls, SaaS inventory, and contractual policies with vendors. A leak site can be the first warning of a breach, but not the only one. Before that, there are often signs of anomalous authentication, suspicious cloud sessions, or off-hours access.

August 2026 makes it clear that the threat to healthcare in Latin America is no longer a single ransomware problem. The region is facing accidental data exposure, financial fraud with social engineering components, and extortion through data publication on clandestine portals at the same time. That variety matters because each incident type requires a different response. A leak site is not handled like an unauthorized transfer, an exposed database is not mitigated like a remote support attack, and an unverified claim is not treated the same as a confirmed exfiltration.

The first trend is the shift by attackers toward the full healthcare chain. Kazu is not targeting hospitals alone, it is also going after cloud PACS, telemedicine, clinical management platforms, and rehabilitation services. That confirms that the value lies in interdependence. If an imaging or scheduling provider goes down, multiple clients can be affected at once. For CISOs, this means rethinking third-party management, including an inventory of critical vendors, notification clauses, access control requirements, and coordinated recovery tests.

The second trend is the convergence between fraud and legitimate operations. EsSalud Lambayeque and Sanatorio San José show that abuse of remote tools, credentials, and support processes can generate significant financial losses without destroying systems or encrypting servers. In these cases, the attacker exploits the friction between operational urgency and verification. Healthcare institutions often have staff focused on clinical continuity, and criminals know it. They present themselves as technical support, a bank, or a service provider. The response should include recurring training, simulations, blocking unauthorized remote software, and independent checks for sensitive transactions.

The third trend is the persistence of basic configuration failures. The exposed SISVISA in Brazil confirms that even in state-run or regulated environments, a poorly exposed database can leave sensitive, high-value information exposed. Sophisticated exploitation is not required to damage trust in a healthcare system. Security programs in the sector should therefore include external exposure reviews, assessment of buckets, databases, APIs, and repositories, and continuous monitoring mechanisms. When the asset is tied to regulation or health surveillance, the priority is not only protecting patients, but also preserving the integrity of state oversight.

The fourth trend is the importance of threat intelligence monitoring as an operational function, not just an analytical one. Several cases this month were detected or corroborated by ransomware tracking services and dark web sources. That does not replace official confirmation, but it does help trigger early investigation. In hospitals and clinics, where response time is often limited, alerts about appearance on leak sites can make the difference between containing an incident in time and learning about the breach through the media. Even so, teams must avoid assuming that every mention automatically means confirmed encryption or exfiltration.

The fifth trend is the hardening regulatory and reputational environment. When a university hospital, a private clinic, or a health surveillance system appears in headlines, the impact is not only technical. Public trust, management capability, and the quality of internal controls also come under scrutiny. For healthcare organizations, this means cybersecurity can no longer sit apart in a technical silo. It must be integrated with legal, finance, operations, communications, and corporate governance. Financial fraud cases are especially important here, because security and administration now have to work together, and approval workflows and remote access tools are part of the risk perimeter.

Recommendations for CISOs

  1. Inventory and classify critical health providers. Cloud PACS, telemedicine, labs, scheduling software, remote support, and regulatory services should be tracked in a single dependency map. If a third party goes down, there must be a continuity plan and an emergency contact.

  2. Strengthen controls over remote access. AnyDesk, UltraViewer, RDP, VPN, and any support tool must be explicitly approved, logged, and monitored. Improvised remote access is a recurring vector in fraud and compromise.

  3. Apply out-of-band verification for payments and sensitive changes. Transfers, account changes, beneficiary additions, and credential resets should require independent validation through an alternate channel. No single operator should be able to complete a critical payment workflow.

  4. Audit external exposure of databases and repositories. The SISVISA case shows that a misconfiguration is enough to expose sensitive documents. Reviewing ports, permissions, authentication, cloud services, and exposed storage should be a recurring exercise, not an annual one.

  5. Prioritize remediation of vulnerabilities with a high official signal. When a CERT or CSIRT advisory mentions KEV and the vendor already has a patch, the update must move to urgent status. The SQL Server case flagged by CTIR Gov is a reminder that prioritization cannot depend only on the normal change calendar.

  6. Create playbooks for "mention on leak site" without confirmation. Not every claim is a confirmed incident, but every mention requires a fast investigation. The playbook should include log review, integrity validation, communication with threat intelligence providers, and escalation criteria.

  7. Separate clinical and financial cybersecurity domains, but coordinate them. Protection for PACS, the medical record, and the financial ERP cannot be managed in silos. An attacker will exploit the weakest one.

  8. Review authentication and MFA in corporate clouds. The McKesson case underscores that cloud accounts remain a path for exfiltration. Policies should cover privileged sessions, geolocation alerts, phishing-resistant tokens, and review of anomalous access.

  9. Prepare crisis communications for patients and regulators. A breach or financial fraud creates immediate questions. Having preapproved messages, designated spokespeople, and legal routes reduces improvisation and reputational damage.

  10. Test recovery with hybrid scenarios. Not only ransomware, but also banking fraud, data exposure, and provider outages. The drill should include what happens if the PACS, the regulatory portal, or the payments platform all go offline at the same time.

Methodological limits and reading

This report is built only from the research material provided and does not assume unverified facts. Several references from the period come from leak sites, ransomware aggregators, or social media monitoring accounts. So, when there is no public confirmation from the affected party, they should be read as claims or tracking records, not as independently validated intrusions. Likewise, the fact that a sector indicator or official alert appears in the material does not mean it was exploited against a specific victim in the period. If it is a vulnerability advisory, it is interpreted as risk context, not automatic attribution.

In particular, the material does not allow a reliable reconstruction of how many ransomware events involved encryption, how many involved only exfiltration, and how many were limited to a mention on a leak site. When the source does not specify the technical impact, this report says so explicitly. Nor is any fact counted as part of the period if it belongs to earlier months, unless it is used for comparison and the corresponding month is always mentioned. That distinction is essential to avoid overstating trends with out-of-window data.

Finally, the absence of a category in the indicators should not be read as a real absence of risk in the region. If a type of incident does not appear in the material analyzed, that only means it was not documented in this reference base, not that it did not occur. For CISO readers, the methodological lesson is the same as the operational one: visibility is partial, and decisions must be made with that limitation in mind.

Frequently Asked Questions

Which country had the most verifiable case this month?

Brazil had the most technically verifiable case, based on public documentation, the exposed SISVISA database. In addition, CTIR Gov's notice about SQL Server added a relevant preventive element. At the same time, there were ransomware claims involving Mobilemed and other healthcare targets.

Was ransomware confirmed against hospitals in the region?

There were multiple ransomware claims against hospitals and clinics, but not all of them had independent public validation. In the case of the Hospital Clínico Universidad de Chile and other victims listed by Direwolf, the public evidence available comes from leak sites and threat monitoring, not an official hospital confirmation.

Was the EsSalud case ransomware?

No. The available reporting describes a financial fraud case involving remote access, support impersonation, and unauthorized transfers. EsSalud reported it as an alleged computer fraud, and prosecutors also opened a line of inquiry into possible embezzlement by officials. It was not a ransomware incident.

What should a healthcare CISO prioritize after this month?

Three things: remote access controls, review of critical third parties, and validation of exposed configurations. August showed that a breach can enter through a PACS, a regulatory portal, or a remote support session. The priority is to reduce the attack surface, harden authentication, and prepare for fraud and leak site activity.

Sources