CiberLATAMbywhalemate
Intelligence report

Health, Clinics, Hospitals and Pharma, Sep 2026

53 verified events, 20 incidents and 16 ransomware or extortion cases marked September in LATAM health, with Chile, Colombia and Paraguay in focus.

Oct 1, 202625 min read
Health, Clinics, Hospitals and Pharma, Sep 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are automatically completed with verified dated facts from the period. Each one states its basis and counting criterion, so the figures reconcile across modules. They are the recurring month-by-month readout, and the analysis that follows develops the cases without repeating this summary.

Indicator window: 54 dated facts in September 2026 · 1 without confirmed date (excluded from the indicators). Facts from earlier months are used only as comparative context in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Verified Signal Monthly Dashboard September 2026 · Latin America Dominant threat: Incidents (20 of 53 events). Coverage: 54 dated events in September 2026 · 1 undated e… VERIFIED EVENTS 53 period base: all counts measured from below using this total RANSOMWARE / EXTORTION 16 1 asset encrypted confirmed · 3 only mentioned in leak site · 12 not classified UNCLASSIFIED INCIDENTS 20 breaches or outages with no threat type declared FRAUD / PHISHING 0 documented fraud campaigns documented REGULATION 0 standards, resolutions, or sanctions UNIQUE CVEs 11 CVE-2026-78224 / CVE-2026-82329
Verified Signal Monthly Dashboard — Base: 53 verified dated events for Latin America.
MONTHLY FIXED MODULE Threat axis distribution September 2026 · Latin America Each event counts in only one axis, so the total is exactly 53. "Unclassified incidents" is the remainder. Incidents 20 Ransomware 16 Unclassified 10 Vulnerabilities 7
Threat axis distribution — Each event is assigned to a single axis based on its classification; the total reconciles to the 53 events in the period.
MONTHLY FIXED MODULE Sector Distribution of Alerts September 2026 · Latin America Base: 53 incidents in the period · total 99 because 34 incidents are classified in more than one sector. Health 36 Public sector / OIV 29 Education 12 Technology 8 Other / unidentified sector 7 Telecom 6 Retail / consumer 1
Sector Distribution of Alerts — Heuristic sector classification by victim. One incident may affect more than one sector, so the total may exceed the base.
MONTHLY FIXED MODULE Geographic Distribution of Signal September 2026 · Latin America Each incident is assigned to a single country or to regional coverage, so the total is exactly 53 of 53 incidents… Regional 25 Brazil 7 Argentina 6 Colombia 6 Chile 5 Paraguay 4
Geographic Distribution of Signal — Verified incidents from the period grouped by country or regional coverage; each incident is counted once.

Executive summary for the month

September brought 53 verified incidents across health providers, clinics, hospitals, and pharmaceuticals in Latin America, including 20 uncategorized incidents and 16 cases in which ransomware or extortion was the primary focus. The dominant signal was no longer confirmed encryption, but a mix of intrusions, leaks, and claims that data had been published online, with Chile, Colombia, and Paraguay accounting for much of the month’s operational and legal noise.

The clearest case in terms of direct confirmation was Hospital Clínico de la Universidad de Chile, which acknowledged a cyberattack on its Imaging Department and the exposure of information tied to medical exams. The institution said it disabled the compromised account and temporarily took down the external consultation platform. Media coverage also reported that the National Cybersecurity Agency notified the hospital on September 20 and that some of the information may have been published online.

In Brazil, the combination of a court ruling over the 2022 attack on Hospital Santa Marta and the incident reported at Farmanguinhos showed two different sides of the risk. In the first case, the courts upheld convictions for computer intrusion, extortion, and attacking a public utility service. In the second, a cyber incident was reported that affected production and shipment of supplies, with later operational recovery. The material does not support combining those events or treating them as part of a single campaign.

Colombia produced the strongest signal in terms of total sector exposure, although much of the material comes from analyses and coverage of detections or reported attacks, not from individually confirmed intrusions. Portafolio reported 410 ransomware attacks and claims in the first half of 2026 against health providers and companies, an average of 2.3 incidents per day, with 247 affecting hospitals, clinics, and other direct providers. That reference helps frame the month, but it is not included in the September count.

September also ended with a visible return of critical vulnerabilities to the center of the discussion. The material grouped 11 critical CVEs mentioned, several of them with active exploitation or advisories from CISA and Check Point. In a month when the region showed fewer confirmed ransomware cases than in August, the technical attack surface moved back to the center of the story and reinforced an uncomfortable reading for healthcare, there are more chained threats, but less public confirmation and more dependence on external monitoring or delayed statements.

Regional outlook for the month

September’s regional reading points to high risk, not because of a uniform surge in confirmed incidents across Latin America, but because of a mix of fragile operations, sensitive data exposure, and a significant number of unclassified or unconfirmed cases that still add pressure on response teams. Verified volume fell from August, but qualitative severity stayed high because of the type of asset affected, the sensitivity of the information, and the repeated targeting of clinics and hospitals.

This month’s picture also shows a shift in the makeup of the signal. In August, according to the comparative report, ransomware was the dominant theme. In September, unclassified incidents moved to the center. That does not mean less damage, only less public clarity about the exact nature of the impact. For a sector like healthcare, where an intrusion can lead to clinical disruption, medical record exfiltration, or extortion based on data, that operational ambiguity is part of the risk.

TIMELINE Verified events in the period 1/9 BreachSensereportedanalleged 6/9 A threat reportby threats 8/9 La Tercerareported that 9/9 A mainstreamnews outletreported 9/9 Monitoringsources 9/9 The logofRansomware.live
Verified timeline of events, September 2026 — Milestones with confirmed dates within September 2026. Events from earlier months are excluded from the timeline and used only as a comparative frame.

The regional picture was also shaped by a gap between confirmation and allegation. Several of the most discussed cases appeared as leak site records, threat intelligence monitoring, or preventive warnings, but without independent validation from the victim. That was the case with AmorSaúde, Hospifar, Clínica Universidad de los Andes, and the Ministry of Health of Paraguay, among others. The practical result is clear, the healthcare ecosystem was exposed to both real intrusions and reputational pressure tied to unverified claims.

Geographically, Chile and Colombia produced the most consistent readings. Chile contributed the confirmed case of Hospital Clínico de la Universidad de Chile and several preventive alerts about a supposed database from Clínica Universidad de los Andes. Colombia provided the densest contextual layer on intrusions against the sector, although part of that material comes from third-party analysis of IBM X-Force data. Brazil, meanwhile, combined the legal case involving Hospital Santa Marta with the operational exposure of Farmanguinhos. Paraguay appeared with allegations of defacement and exfiltration attributed to the Ministry of Health and the Superintendence of Health.

Period indicators

Indicator September 2026 Previous month comparison
Verified events in the period (basis for all indicators) 53 90, -37
Time window for the indicators 54 events dated September 2026 · 1 undated (excluded from the indicators) previous month not provided in this report base
Unclassified incidents (breaches or disruptions) 20 23, -3
Cases with ransomware or extortion as the primary focus 16 37, -21
Ransomware breakdown by impact type: confirmed asset encryption 1 not provided
Ransomware breakdown by impact type: leak site mention only 3 not provided
Ransomware breakdown by impact type: impact type could not be determined from the material 12 not provided
Documented fraud or phishing cases 0 10, -10
Documented regulatory moves 0 2, -2
Critical CVEs mentioned 11 2, +9
Sectors with at least one documented event 6 8, -2
Predominant threat of the month Incidents (20 of 53 events) previous month: Ransomware (37 of 90 events)
Events with direct source confirmation 49% not provided
Aggregated telemetry figures excluded from volume 1 (aggregated attempts or blocks: not confirmed-impact incidents) not provided

The statistical base matters because it avoids overstating monitoring noise. The 53 verified events for the month do not amount to 53 separate intrusions with the same level of impact. They include confirmed incidents, leak site references, court rulings, preventive alerts, and technical notices. In health care, that mix is common, but the indicators must be read as a signal from the ecosystem, not as a list of affected patients or encrypted systems.

Relative signal by countryChileBrazilColombiaParaguayArgentina/DR
Qualitative weight by country in the material — Narrative distribution of the documented signal, by confirmation and density of verified facts.

Relevant incidents

Hospital Clínico de la Universidad de Chile

The clearest case of the month in Chile was Hospital Clínico de la Universidad de Chile, which confirmed a cyberattack that affected its imaging service and involved unauthorized access to information tied to medical exams. The institution disabled the compromised account and temporarily suspended the external consultation platform, a response that points to early containment but also to a functional dependence on connected services.

T13 coverage added a key timeline detail, the Chilean National Cybersecurity Agency would have notified the hospital on September 20, 2026. That date helps explain why the issue resurfaced at the end of the month with a criminal complaint. This was not just a data exposure, but an incident that escalated into legal action and public confirmation by the institution itself.

The case matters for two reasons. First, it hit a highly sensitive hospital function, the flow of images and exams. Second, the compromised information was not a generic administrative database, but medical data tied to clinical studies. When the source says part of the material may have been published online, the case stops being only an intrusion and moves closer to a leak with potential for prolonged secondary harm.

Fresenius Medical Care

Fresenius Medical Care said it was investigating a cybersecurity incident involving unauthorized access to a limited number of internal systems. The company said its medical devices, patient care, manufacturing, and business continuity were not affected. It also said it brought in outside experts and notified law enforcement.

The most useful point in this case for regional analysis is not the attribution of a group, which was not publicly confirmed with confidence, but the separation between limited internal access and operational impact. The company said the investigation was still open and did not specify when the access occurred or whether any information was taken. That gap prevents the case from being classified as confirmed exfiltration or encryption, and keeps it in the category of an incident with still-unclear scope.

In cases like this, the corporate response is often as relevant as the attack itself. The absence of impact on medical devices or manufacturing suggests containment, but it does not eliminate exposure of internal processes. For the health sector, especially in networks with multiple vendors and connected systems, access to internal infrastructure can be enough to compromise credentials, move laterally, or support later extortion.

Grupo Hospifar S.R.L.

Grupo Hospifar S.R.L. appeared in several monitoring sources as a TITAN-attributed victim, with records alternating between a supposed data leak, a mention on a leak site, and an incident marked as pending. None of those pieces answered the central question, the available material does not confirm the real scale of the access or whether any data was actually published.

The analytical value of the case lies in the divergence between sources. RecentBreaches said Titan claimed to possess data on an undisclosed number of people, but that Hospifar had not confirmed the claim and no files were seen published. BreachSense reported a supposed 400 GB leak, although it noted that the indexed accounts and credentials were not necessarily related to the attack. ThreatCluster, meanwhile, treated it as unverified and lacking impact details.

DeXpose also described Hospifar as a health organization in the Dominican Republic, while other records placed it in Argentina. That contradiction is not minor, because it prevents the event from being pinned to a specific geography with confidence. For a regional report, the prudent approach is not to overread the attribution. What can be verified is that there was a ransomware claim with too little data to measure impact.

AmorSaúde

AmorSaúde appeared in multiple monitoring records that attributed the incident to LockBit 5.0, with a threat to publish data and a reference to 7,270 users compromised in the Ransomware.live record. BreachSense also listed credentials associated with the domain, but warned they could have come from customers or employees and were not necessarily linked to the ransomware claim.

The correct reading is that the case exists as an actor claim and as a signal in tracking systems, but not as an intrusion publicly confirmed by the organization. HookPhish and FalconFeeds.io said LockBit 5.0 claimed the attack and threatened to publish the information within a short period. None of those pieces, however, turns the allegation into proof of confirmed exfiltration.

The clinic and dental network has a particular risk because of its operational spread. Credential records may reflect exposure of users, providers, or patients, and they do not always mean there was an intrusion into clinical systems. That means the case should be treated as a pressure campaign and possible extortion, not as a validated leak.

Hospital Santa Marta

In September, Hospital Santa Marta was linked to a court decision that upheld convictions for the 2022 attack, with sentences of 8 years and 4 months and 9 years and 4 months in prison. The ruling upheld liability for computer intrusion, extortion, and an attack against the security of a public utility service.

This case does not describe a new campaign, but it does provide high-value context for understanding how the region is handling attacks on health infrastructure. The court coverage made it clear that the defendants accessed a secondary hospital database without authorization, obtained patient documents and information, and demanded 43 bitcoins not to disclose the material.

The importance is not only the criminal penalty, but the type of asset involved. A secondary database may seem less critical than the core clinical environment, but it can still hold enough data to drive extortion and reputational damage. The case also shows something that monthly tallies often miss, some health incidents end long after the attack, when the courts assign responsibility.

Farmanguinhos

Farmanguinhos, linked to Fiocruz, was mentioned as affected by a single cyber incident that hit the production and shipment of supplies. Available material indicates operations were resumed and delivery schedules continued to be monitored. In the undated source with no confirmed date, the same factual core is repeated, but it cannot be added to the monthly count.

The case matters operationally. This was not a medical data leak or a ransomware event with confirmed encryption, but an impact on a production and shipping chain for supplies. In the pharmaceutical sector, that kind of incident can be invisible at first and later show up as delays, logistics shifts, or pressure on inventory.

The prudent reading is that the incident illustrates how vulnerable health manufacturing is to digital disruption even when there is no evidence of extortion or data publication. That makes it a business continuity case rather than a classic confidentiality breach.

Active Threats and Campaigns

Ransomware and extortion with confirmed or likely impact

In September, 16 cases surfaced with ransomware or extortion as the primary focus, but only one had confirmed asset encryption according to the material provided. The rest were split between leak site mentions and cases that could not be classified, which means technical damage that was actually proven must be separated carefully from mere claims by threat actors or third-party monitoring.

That distinction matters for healthcare. A leak site can pressure a target's reputation without evidence of operational impact. A mention with no files published can support extortion or an attempt to monetize access. Confirmed encryption, as a category, changes the response profile entirely because it affects clinical availability and continuity of care.

Among the month's cases, AmorSaúde, Grupo Hospifar, and the Hospital Clínico de la Universidad de Chile fell into the gray area of attribution or partial confirmation, while the Hospital Santa Marta case belongs to a judicialized episode from 2022, not a new September campaign. By contrast, the attack on the Hospital Clínico de la Universidad de Chile does appear as a confirmed incident with unauthorized access and data leakage, although the material does not classify it as encryption.

Fraud and phishing

There were no documented fraud or phishing cases in the September material. The absence of cases in this category should not be read as the absence of regional risk, but as a lack of verified cases within the corpus analyzed for the month.

That gap has its own meaning. In healthcare, phishing often works as an initial access vector or as a complement to ransomware campaigns, but it does not always generate separate public coverage. If the monthly report does not show it, that does not necessarily mean it did not happen, only that there was not enough documentation or that it was absorbed into another type of incident.

APT and hacktivism

There were also no documented APT or hacktivism incidents as the main focus during the period. The closest examples were preventive alerts about forum posts, claims by threat actors, and a warning about a possible defacement against sites of Paraguay's Superintendencia de Salud, but with no independent confirmation of access or authorship.

For operational readers, that means the month did not show advanced persistence campaigns against healthcare in the material received, although it did leave a broad exposure surface attributed to extortion groups and opportunistic publishing actors. The line between hacktivism and criminal activity remains blurry in public reporting, but the September corpus does not provide solid evidence to classify those cases as APT.

Critical vulnerabilities

September again put critical vulnerabilities on the regional healthcare sector’s agenda. The material compiled 11 critical CVEs, several with active exploitation, official advisories, or inclusion in exploited vulnerability catalogs. These are not pure healthcare flaws, but software and devices that can affect clinical services, management systems, or connected infrastructure.

CVE Software Exploitation Source
CVE-2026-94127 F5 BIG-IP Access Policy Manager Active exploitation, remote code execution under certain conditions without authentication Check Point Research
CVE-2026-85102 Check Point Security Gateway Active exploitation, possible remote code execution Check Point Research
CVE-2026-93616 Check Point Security Management Active exploitation, possible remote code execution Check Point Research
CVE-2026-87121 lwIP TCP/IP Stack, MQTT Client Application CISA advisory, possible code execution on the device, no public exploitation reported CISA
CVE-2026-91018 lwIP, Lightweight IP CISA advisory, possible system crash, denial of service, memory corruption, or code execution, no public exploitation reported CISA
CVE-2026-82583 NextGen Mirth Connect Vulnerability addressed in an update, no public exploitation known Clinical Cyber
CVE-2026-78224 NextGen Mirth Connect Vulnerability addressed in an update, no public exploitation known Clinical Cyber
CVE-2026-82578 NextGen Mirth Connect Vulnerability addressed in an update, no public exploitation known Clinical Cyber
CVE-2026-82329 JFrog Artifactory Added to CISA’s KEV catalog, evidence of active exploitation in the wild The Hacker Wire
CVE-2026-9586 Sangoma Switchvox Added to CISA’s KEV catalog, evidence of active exploitation in the wild The Hacker Wire
CVE-2026-83548 SonicWall SMA1000 Added to CISA’s KEV catalog, evidence of active exploitation in the wild The Hacker Wire

The defensive reading is straightforward. Not all of these flaws belong to the healthcare sector, but several affect components commonly found in hospitals, clinics, and laboratories, such as load balancers, gateways, network stacks, and integration middleware. That means the priority is not only patching visible clinical systems, but also reviewing network layers and gateways that support day-to-day operations.

CISA’s material on lwIP is especially relevant for environments with connected devices or embedded equipment. The cited advisories did not report specific public exploitation, but the fact that Healthcare and Public Health appears as relevant critical infrastructure means these vulnerabilities should be treated as potentially applicable to healthcare ecosystems with telemetry, sensors, or connected medical devices.

Regulation and compliance

No documented regulatory moves were recorded in the September material. That does not mean the month lacked legal or institutional consequences, because there was a relevant ruling in Brazil and a criminal complaint in Chile. The difference is that those developments are counted here as incidents or judicial responses, not as regulatory changes.

The decision involving Hospital Santa Marta shows how litigation can close the loop on an attack years later. The criminal complaint filed by the Hospital Clínico de la Universidad de Chile marks a different path, the institution turns the incident into a criminal action while the cybersecurity agency reports the event. Both processes reinforce the expectation of traceability and evidence preservation in healthcare.

From a compliance standpoint, the month leaves a straightforward signal. Institutions must not only respond to the incident, but also document access, separate compromised accounts, preserve logs, and decide when to notify regulators, patients, or authorities. The September material shows that when that sequence fails, the discussion moves to courts or to external monitoring by third parties.

Countries and subsegments most affected

Chile

Chile stood out for two types of signal. On one hand, there was the confirmed case involving the Hospital Clínico de la Universidad de Chile, with unauthorized access to medical information and a subsequent lawsuit. On the other, there were preventive alerts and unconfirmed reports about Clínica Universidad de los Andes, which shifted the conversation toward possible exposure of structured clinical data.

The hardest-hit subsegment was hospitals, especially imaging and consultation systems. Chile matters less for the raw number of incidents than for the quality of the evidence: there is direct confirmation, an official filing, and a clear public narrative around access to medical data. That gives the country disproportionate weight compared with other, more ambiguous cases.

Brazil

Brazil contributed two different signals. The first was judicial, with the upholding of convictions in the Hospital Santa Marta case. The second was operational, with the incident at Farmanguinhos that affected the production and shipment of supplies. One touches the criminal side of ransomware and extortion. The other affects the industrial continuity of a pharmaceutical player.

The pharmaceutical subsegment deserves particular attention because the Farmanguinhos case shows that a cyber incident can hit the supply chain without a ransomware statement being issued. That kind of event often takes time to become visible to the public, but it can disrupt schedules, inventories, and deliveries.

Colombia

Colombia had the highest density of contextual reporting, even if it did not have the most individually confirmed cases during the month. Portafolio reported 410 ransomware attacks and claims against healthcare providers and companies in the first half of 2026, with 247 affecting hospitals, clinics, and other direct providers. Other coverage built around the same topic insisted that 60% of reported cyberattacks targeted health care.

That material should not be confused with pure telemetry or with verified September incidents, but it does explain why the country keeps appearing in regional conversations. For Colombian health care, the issue is not just frequency. It is the persistence of an attack model that combines reputational pressure, extortion, and exposure of patient records or care platforms.

Paraguay

Paraguay appeared in September with preventive alerts involving the Ministry of Public Health and Social Welfare and the Health Superintendence. The material refers to a supposed 10.5 GB publication, a possible defacement campaign, and a database of subdomains, but in all cases the source or monitoring notes that there is no independent confirmation.

The value of the case lies in the pattern. Actors or forums use the names of health agencies to create pressure, even when the evidence remains vague. For a security team at a health ministry or regulator, that means monitoring not only internal infrastructure but also the public exposure of subdomains, admin panels, and download repositories.

Argentina and Dominican Republic

These two countries appear tied to the Hospifar discussion, but with an important caveat: the material does not allow the incident to be placed in a single geography with confidence. One record classifies it as Argentina, while DeXpose describes it as a health organization in the Dominican Republic. That discrepancy rules out any definitive country-level reading.

Even so, the case is a reminder that geographic attribution is a critical stage of analysis. If it is not resolved correctly, a report can overstate or understate country risk. Here, the only solid conclusion is that there was a ransomware claim against a health care or pharma actor, with no public evidence strong enough to close the question of location or impact.

The first trend this month is a drop in volume compared with August, paired with a higher share of unclassified incidents. The previous period had been dominated by ransomware, while September was led by incidents. That points to less public clarity and a wider range of situations, not necessarily lower real risk.

The second signal is that fraud and phishing cases fell to zero in the material reviewed. That should not be celebrated as a structural improvement. It looks more like a gap in monthly documentation. In healthcare, these campaigns are often absorbed as initial access or supporting pieces of larger operations, and they are not always published as standalone events.

The third signal is the rebound in critical CVEs, from 2 to 11 versus the prior month. That jump should not be read as a wave of exploitation in Latin American hospitals, but it does serve as a reminder that the technical attack surface is active. Alerts from CISA and Check Point show that exposure windows can emerge in network software, gateways, and integration tools that support clinical services.

The fourth signal is the persistence of unconfirmed claims, especially in cases involving clinics, hospitals, and ministries. Hospifar, AmorSaúde, Clínica Universidad de los Andes, and Paraguay share a pattern, actors or trackers publish alerts before official validation exists. For security teams, that requires separating noise from real impact, without ignoring it. In many cases, the claim comes before a negotiation or a later disclosure.

The comparison with August also leaves one useful data point. There were more ransomware reports the previous month, but in September the most consistent signal was incidents and partial confirmations. In other words, the risk did not disappear, it shifted toward a less visible mix of unauthorized access, data leakage, and disrupted continuity.

Security team recommendations

This month’s priorities are practical and concrete. First, strengthen visibility into imaging systems, consultation portals, integration middleware, and gateways that connect clinical environments with external services. The Hospital Clínico de la Universidad de Chile case shows that a compromised imaging account can be enough to expose sensitive medical information and force service interruptions.

Second, review credentials and active sessions tied to public domains, vendors, and care platforms. The AmorSaúde and Hospifar cases show that third-party disclosures often mix accounts, credentials, and user data with incomplete evidence. The right response is not to assume the entire set belongs to ransomware, but to cut access, rotate secrets, and verify whether credentials were reused.

Third, prioritize patches and mitigations for the components named in September’s advisories. It is not enough to look at visible clinical software. Load balancers, gateways, embedded stacks, and integration solutions such as Mirth Connect also need review, because they concentrate flaws that can open the door to remote code execution or denial of service.

Fourth, prepare legal and forensic response before the incident escalates. The ruling on Hospital Santa Marta and the complaint filed by Hospital Clínico de la Universidad de Chile show that digital evidence ends up being central. If an institution does not preserve logs, freeze accounts, and document chain of custody properly, it weakens its defense and attribution options.

Fifth, train business continuity around partial impact scenarios, not only full encryption. Farmanguinhos is a good example of a production interruption that does not necessarily fit the classic ransomware model. Pharmaceutical and hospital organizations should rehearse what happens if a dispensing system, an imaging platform, or an e-prescribing component goes down.

Frequently Asked Questions

What type of events dominated September among incidents, ransomware, and leaks?

Unclassified incidents dominated, with 20 cases out of 53 verified. That is more than the 16 cases where ransomware or extortion was the main focus, and it shifted the month’s signal toward intrusions, disruptions, and partial exposure. See also the monthly executive summary and period indicators sections.

Which cases were best confirmed, and which remained in a gray area?

The best-confirmed case was Hospital Clínico de la Universidad de Chile, with unauthorized access and exposure of medical information. AmorSaúde, Hospifar, Clínica Universidad de los Andes, and several alerts involving Paraguay remained in a gray area, because the material only provides claims, monitoring, or unverified posts. See Relevant incidents and Active threats and campaigns.

What does the comparison with August reveal about regional risk?

It shows lower overall volume, less ransomware, and less documented phishing, but more critical CVEs mentioned and more unclassified incidents. In other words, the month was not calmer, just less readable. Risk remained high because of the sensitivity of the assets, even though the visible form of the threat changed. See the month’s regional overview and Trends and signals to monitor.

Which countries provided the most useful signal for defense this month?

Chile provided the clearest confirmation of clinical impact, Colombia provided the broadest context of pressure on healthcare, Brazil combined a legal case and an operational one, and Paraguay showed preventive alerts involving health agencies. Argentina and the Dominican Republic were left with unresolved geographic attribution in the Hospifar case. See Most affected countries and subsectors.

Which vulnerabilities should healthcare teams review first?

First, those with active exploitation or CISA and Check Point advisories, such as CVE-2026-94127, CVE-2026-85102 and CVE-2026-93616. Then, the lwIP issues and those affecting Mirth Connect and other integration platforms. The key criterion is not only technical severity, but exposure in hospital and pharmaceutical networks. See Critical vulnerabilities.

Material limitations

This report was built exclusively from the material provided for September 2026 and from the sources available for citation. No internet was used, and no telemetry outside the listed sources was incorporated. Facts without a confirmed date were used only as context and are not included in the period indicators.

An indicator at 0, especially in CVEs, means none were recorded in the material analyzed for this month, not that no critical vulnerabilities or exploitation existed in the region. The same applies to fraud, phishing, or regulation. Absence in the corpus does not equal actual absence of activity.

The declared time window for the indicators is 54 dated events in September 2026 and 1 without a confirmed date excluded from the indicators. The comparative data with the previous month are reproduced exactly as provided and were not recalculated. Where the material does not allow the exact type of impact to be determined, the classification was kept as undeterminable.

Also excluded from interpretation as incidents were aggregated telemetry figures, attempts or automated blocks, and detection measurements. Those references can help contextualize exposure, but they do not prove intrusion or confirmed impact. Sources outside the authorized list were also avoided, including disallowed social media and promotional material that does not serve as an independent basis for trend analysis.

Sources