CiberLATAMbywhalemate
Intelligence reportAug 11, 202629 min read

Public Sector and Government Agencies, July 2026

July closed with more regulation, less fraud, and more availability incidents and leaks in public agencies across the region.

Public Sector and Government Agencies, July 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are filled automatically with verified dated events within the period. Each one states its source base and counting criterion, so the figures reconcile across modules. They are the recurring monthly readout; the follow-up analysis expands the cases without repeating this summary.

Indicator window: 79 dated events in July 2026 · 1 from prior months (comparative frame, not monthly volume) · 4 without confirmed date (excluded from indicators). Events from prior months are used only as a comparative frame in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Monthly verified signal dashboard July 2026 · Latin America Top threat: Incidents (41 of 78 events). Coverage: 79 time-stamped events in July 2026 · 1 from prior month… VERIFIED EVENTS 78 period baseline: all counts below are measured against this total RANSOMWARE / EXTORTION 1 1 undetermined classification with material UNCLASSIFIED INCIDENTS 41 breaches or outages with no declared threat type FRAUD / PHISHING 2 documented fraud campaigns documented REGULATION 12 standards, resolutions, or sanctions UNIQUE CVEs 1 CVE-2026-0257
Monthly verified signal dashboard — Base: 78 verified time-stamped incidents for Latin America.
MONTHLY FIXED MODULE Distribution by threat axis July 2026 · Latin America Each event counts toward only one axis, so the total is exactly 78. "Unclassified incidents" is the remainder. Incidents 41 Unclassified 21 Regulation 12 Fraud 2 Ransomware 1 Vulnerabilities 1
Distribution by threat axis — Each event is assigned to a single axis based on its classification; the total reconciles to the 78 events in the period.
MONTHLY FIXED MODULE Sectoral Distribution of Alerts July 2026 · Latin America Base: 78 incidents in the period · total 91 because 12 incidents are classified in more than one sector. Public sector / OIV 48 Other / unidentified sector… 23 Telecom 8 Technology 4 Finance 3 Health 3 Energy 1 Education 1
Sectoral Distribution of Alerts — Heuristic sector classification by victim sector. One incident may affect more than one sector, so the total may exceed the base.
FIXED MONTHLY MODULE Geographic distribution of signal July 2026 · Latin America Each incident is assigned to one country or regional coverage, so the total is exactly 78 out of 78 incidents of… Colombia 18 Mexico 13 Argentina 12 USA 10 Paraguay 9 Brazil 5 Regional 5 Chile 3 Uruguay 3
Geographic distribution of signal — Verified period incidents grouped by country or regional coverage; each incident is counted once.

Executive monthly summary

July 2026 painted a mixed picture for the public sector and government agencies in Latin America. The month was driven by availability incidents, data leaks and regulatory moves, with a clear drop in ransomware and phishing mentions compared with the previous month, but with much heavier rulemaking activity. The most consistent signal was not destructive encryption, but disrupted systems, exposed databases, unauthorized access and institutional responses aimed at putting tighter technical and legal limits on risk.

The verified volume for the period was lower than in June, but that does not amount to a straight improvement in risk. The public attack surface continued to show fragility in citizen service platforms, transparency portals, mobility systems and state support environments. In several cases, the main impact was operational and reputational, with some events lasting several days before partial restoration. Administrative and criminal investigations were added to that picture, confirming that cyber incidents in the public sector are no longer handled only as technical failures, but also as issues of institutional continuity, data stewardship and possible contractual or regulatory liability.

The highest concentration of events was seen in Colombia, Mexico, Paraguay, Brazil and Argentina, although the nature of those events differed. Colombia combined a high-profile case involving Ecopetrol with the ongoing debate over the data leak tied to mobility in Bogotá. Mexico produced a dense set of incidents in León and a series of reports about Sinaloa, still with substantial technical uncertainty in the available material. Paraguay moved between allegations of state-linked cyberespionage and the institutional response, while Brazil contributed two important signals, a data protection sanction tied to the public health system and an incident at the STM. In Mendoza, the signal was not an attack, but regulation under construction.

The relationship between incident and response also changed in tone. The previous month had been marked by more ransomware and more documented phishing, while July was dominated by the block of incidents that were not classified, with a single reference to ransomware as a contained attempt and without sufficient confirmation to classify the impact precisely. At the same time, regulatory activity expanded sharply, from a comprehensive bill in Mendoza to ANPD decisions in Brazil and actions by Colombia’s Procuraduría on cybersecurity contracting. The region is therefore showing a partial shift from purely operational reaction toward more explicit governance frameworks, although they remain highly uneven across jurisdictions.

One relevant fact from the month is that the events directly confirmed by the source reached 81 percent of the material. That improves the quality of the reading compared with publications based on weak attribution or journalistic reconstructions without full technical support. Even so, gray areas remain that require caution, especially in campaigns with complex attribution, reports with figures not verified by the authority and cases where the material does not allow a determination of whether there was encryption, exfiltration or only a claim of responsibility.

TIMELINE Verified events for the period 7/1 Localmediareportedthat 7/1 The Department of TechnologiesTecnologías 2/7 The bill law 2/7 Thecybersecurityinitiative 2/7 The Governmentof Mendoza 2/7 Theinitiativesearchset up
Verified timeline of events, July 2026 — Confirmed milestones dated within July 2026. Events from earlier months are excluded from the timeline and used only as context.

Regional overview for the month

July’s regional readout points to medium-high risk, driven less by a wave of mass destruction than by the persistence of intrusions, leaks, and service outages in essential public systems. The risk assessment rests on 41 uncategorized incidents out of 78 verified events, a set of cases with direct impact on citizen portals and sensitive data, and high-impact institutional cases involving Ecopetrol, the STM, León, Bogotá, and Paraguay. It is not a month defined by sheer volume, but by events with operational and compliance consequences that dominated the agenda.

Geographic dispersion was also notable. No single geography dominated by threat type. Mexico concentrated availability failures and leaks in local governments, Colombia combined exfiltration, regulatory pressure, and criminal investigation, Paraguay brought the hypothesis of cyberespionage against state systems to the forefront, Brazil showed its data protection authority’s response and an incident at the top military court, and Argentina began turning state cybersecurity into a formal legislative issue. That mix suggests the region is not facing one problem, but several overlapping fronts, weak vendors, exposed public platforms, disputes over attribution, and uneven maturity in governance frameworks.

The balance between offense and defense also shifted. In June, extortion, fraud, and ransomware drew more attention. In July, the signal moved toward service unavailability, exfiltration, and a review of state capabilities. The inclusion of a critical alert for CVE-2026-0257 in Palo Alto GlobalProtect reinforces the idea that exposure does not depend only on the public sector as a direct victim, but also on its reliance on widely deployed infrastructure and software. The state risk surface remains tied to third parties, operating contracts, and controls that are often activated after the incident.

A maturity reading rounds out the picture. When a month brings this many regulatory mentions, it usually points to two things at once, the issue already has political weight, and the formal response is trying to catch up with a threat that appears before the solutions do. The Mendoza bill, ANPD’s sanction, the Attorney General’s warning in Colombia, and MITIC’s actions in Paraguay show that Latin American governments are moving toward more regulation, but this month’s evidence says they still arrive in the second phase, after the leak, outage, or intrusion. Prevention is still playing catch-up.

July 2026 Signal12Regulation41IncidentsSource: verified events from the period
Balance Between Regulation and Incidents — Visual comparison of regulatory moves and unclassified incidents reported in July 2026.

Period indicators

Indicator July 2026 Previous month Change Base / clarification
Verified events in the period 78 120 -42 Base for all indicators, calculated only from events dated within the period
Time window for the indicators 79 events dated in July 2026 1 from previous months 4 without confirmed date excluded Time frame for reading, not monthly volume
Unclassified incidents (breaches or outages) 41 56 -15 Main signal of the month
Cases with ransomware or extortion as the primary focus 1 11 -10 Ransomware breakdown by impact type: undetermined classification from the material, 1
Documented fraud or phishing cases 2 16 -14 Cases identified in verified material from the period
Documented regulatory moves 12 3 +9 Includes bills, sanctions, warnings and institutional actions
Critical CVEs mentioned 1 No comparable data N/A Only the material analyzed for the month
Sectors with at least one documented event 7 8 -1 One event can affect more than one sector
Predominant threat of the month Incidents (41 of 78 events) Incidents (56 of 120 events) Change in intensity Description of the dominant signal
Events with direct source confirmation 81% N/D N/D Share of direct confirmation in the material
Aggregated telemetry figures excluded from volume 1 N/D N/D Aggregate attempts or blocks, not incidents with confirmed impact

Relevant Incidents

Ecopetrol, data exfiltration, and corporate and state response

The month’s most visible case was the cyberattack against Ecopetrol, which combined exfiltration, attribution by a threat group, and regulatory fallout in Colombia. Reuters reported that the company detected the theft of information tied to about 3,300 user accounts and that the incident affected cloud storage environments across 15 subsidiaries. The same coverage said Ecopetrol managed to stop a ransomware attempt, but that did not make the event a simple intrusion with no consequences, because the exfiltration was confirmed and the company did not rule out possible adverse financial impact.

The response was also multi-channel. According to the corporate statement circulated by Yahoo Finance, Ecopetrol activated its response protocols, revoked unauthorized access, and deployed measures to prevent public release of the exfiltrated information. On July 28, according to El País, the company filed Form 6-K with the SEC reporting the cyberattack, and two days later the same outlet cited The Gentlemen group saying it possessed up to 1 terabyte of Ecopetrol and subsidiary data, including drilling records, payroll, banking data, medical histories, biometrics, and active VPN credentials. That chain of events matters not because of the attacker’s claimed volume, which has not been fully verified, but because it shows how a corporate incident at a strategic company can escalate into the public, regulatory, and market agenda.

Infobae added that the Fiscalía General de la Nación opened an investigation on July 31. In parallel, El Colombiano reported that ColCERT issued a high-risk alert for the business sector and that the Ministry of ICT received the report on July 17, triggering coordination with relevant agencies. The combination of a criminal investigation, a technical alert, and a filing with the financial regulator suggests the event is no longer being read as an isolated incident. For the public sector and for organizations that rely on critical contractors, the Ecopetrol case is an operational reminder about cloud exposure, access revocation, provider segmentation, and traceability of privileged accounts.

Bogotá and the mobility data leak

The incident tied to Bogotá’s District Mobility Secretariat remains relevant because it shows a classic third-party exposure pattern. According to Noticias RCN and El Tiempo, the February 2026 leak involved a historical database managed by an external technology provider, used as an internal reference source for specific operational processes. The outlets also specified that the intrusion hit the provider managing the database, rather than the Secretariat’s main infrastructure, and that at the time of reporting there was no final consolidated count of the data affected.

That did not reduce the reputational impact. Infobae reported that a group of attackers claimed access to information on nearly 4.5 million drivers in Bogotá, including personal data, licenses, SOAT, vehicles, and traffic violations, although the Secretariat did not confirm that figure. In the same information ecosystem, growing risk was flagged for phishing campaigns and scams aimed at drivers, built on exfiltrated data and personalized messages about citations and vehicles. The operational issue here is not only the leak itself, but the reuse of those data in secondary fraud, which can extend the harm long after the original incident.

Noticias RCN also reported that the technical investigations included preservation of digital evidence, traceability analysis, review of compromised systems, and formal requests to the provider to strengthen controls and deliver detailed technical reports. In addition, the District denied reports about citation tampering and impact on speed cameras. That kind of public clarification matters because it shows another feature of public sector risk: when forensic findings are incomplete, speculation, unverified claims, and political readings of the incident fill the gap. Bogotá therefore appears as a case of an exposure still being clarified, with operational, contractual, and public trust impacts.

León, portal outages, transparency, and preventive blocking

León was one of the month’s most consistent focal points in Mexico. On July 1, local media reported that the official website of the León government had gone offline because of a cyberattack that mainly affected the Citizen Services System, freezing procedures and fine payments. La Silla Rota added that data belonging to citizens may have been stolen during the incident, although it did not specify volume or technical evidence. The next day, the municipal Information Technology Directorate said that through 2026 it had recorded about 1,637,000 hack attempts against the municipal digital infrastructure, a figure that should be read as attempt telemetry and not as confirmed incidents.

The later evolution showed prolonged unavailability. AM León said the Transparency portal was still operating with limited access to files eight days after the attack and that the municipality’s main site was restored on July 6, but the Transparency portal remained disabled at least through the 7th. Contacto Noticias said the digital portal had accumulated nine days offline. That extension matters because the impact was not limited to the initial website outage, but reached accountability functions and access to required information.

The official response focused on containment. The municipality said, according to AM León, that it applied a preventive block to the computer equipment to avoid greater damage and later ran security tests before restoring services. AM also reported database leaks and municipal purchases in the context of a hack against Seguritech linked to local government services. The overall picture reflects a highly recognizable operational pattern for municipalities in the region, where the boundary between in-house systems, outside vendors, and citizen services is blurred. When an actor compromises one layer of that ecosystem, the resulting outage or leak quickly affects procedures, transparency, and public trust.

Mendoza, bill proposal, and the state cybersecurity architecture

In Argentina, the strongest signal was not an incident, but a cybersecurity bill for Mendoza. The legislative text, published by El Sol, creates the Strategic Cybersecurity Steering Committee as the enforcement authority and highest political and strategic body, chaired by the Ministry of Security and Justice and made up of other strategic provincial agencies. It also establishes an Operational Cybersecurity Authority under the same ministry, with monitoring, detection, management, and incident response functions, including operation of a provincial SOC and a government CSIRT.

The value of this initiative is that it turns into regulation a set of decisions that in other jurisdictions are often scattered or remain only as best practices. The bill requires the creation of an Inventory of Critical Information Assets of the provincial government, the classification of information, and the development of a Cybersecurity Risk Management Program based on recognized standards and best practices, including ISO/IEC 27001. It also specifies that the mandatory scope covers the Central Administration, decentralized agencies, autonomous entities, state-owned companies and corporations, and other organizations with majority state participation. It is a regulatory piece aimed at closing the gap between operational informality and the need to respond with institutional capability.

Diario San Rafael added that the initiative is aimed at protecting the state’s technology infrastructure and the personal data of Mendoza residents, and that it also includes public awareness campaigns. Although it is not a response to a specific incident, its inclusion in the report is relevant because it shows how some provinces are beginning to treat cybersecurity as critical public infrastructure, not as an accessory expense. In public policy terms, that can affect procurement, audits, provider governance, and asset prioritization.

Paraguay, cyberespionage, criminal complaint, and state attribution

Paraguay was one of the month’s most sensitive cases because of the nature of the material published. Coverage from ABC Color, DW, Diario Paraguayo, and La Tribuna said that MITIC and U.S. authorities detected infiltration by multiple China-linked threat actors into Paraguayan state systems. The available material indicates that the government described malicious cyber operations aimed at state digital platforms and that a cyberespionage complaint was filed, with the prosecutor’s office opening a criminal case.

La Tribuna published statements from Pedro Martínez, MITIC’s director general of Cybersecurity and Information Protection, saying the goal of the incident was the covert collection of data and continuous monitoring, not destruction or sabotage of the infrastructure. That distinction is key, because it shifts the reading of the case away from visible damage and toward persistence and observation. For the public sector, the threat of cyberespionage is harder to detect and harder to quantify. If the purpose is to plant a state-data collector or maintain silent access, the problem is not an immediate outage, but the possibility that the adversary remained in the network for an extended period.

ABC Color said prosecutor Irma Llano confirmed initial steps and the taking of testimony from the head of MITIC. Another report said the ministry had presented actions before the Senate to strengthen state cybersecurity, linking the complaint to an institutional response agenda. In parallel, DW reported that the United States and Paraguay detected the infiltration during a joint review. Even with the necessary caution around attribution, the case leaves an important regional signal: governments are no longer discussing only service protection, but intrusion into state networks with possible intelligence objectives.

Mato Grosso do Sul’s Detran and unavailability due to intrusion attempts

Mato Grosso do Sul’s Detran reported instability in its systems after intrusion attempts against its technology environments and clarified that there was no data breach of institutional or citizen information. Coverage from Campo Grande News added that the attempts triggered security protocols and caused intermittent failures in the connection with Sefaz. Although the material does not support describing a confirmed intrusion with exfiltration, the case fits the category of an operational incident with containment response.

The importance of the episode is not its spectacle, but its normality. Traffic agencies are recurring targets because they combine high citizen demand, dependence on integrations with other agencies, and strong sensitivity to service continuity. When the failure reaches links with the finance department or undermines system stability, the problem stops being technical and becomes direct friction for procedures, revenue collection, and public service. For the region, this kind of case is as representative as a major leak, because it reflects the everyday resilience of the state apparatus.

Brazil’s STM, portal outage, and limited scope

The Superior Military Court reported a cyber incident on its website around July 2 and temporarily took the site offline while it analyzed and restored systems. G1 said the incident affected only the institutional website and did not cause damage to internal systems or to the court’s case processing. That distinction, though it may seem small, matters greatly from an operational perspective, because it shows effective containment of scope and avoids overstating the event.

The case remains relevant for that reason. An outage of a public portal in a judicial or defense institution can affect legitimacy, access to information, and the perception of institutional security, even when internal systems remain intact. From a regional standpoint, the STM confirms that front-end unavailability remains an important signal in the public sector, especially in a month when several agencies had to block or take platforms offline to contain greater damage.

Active threats and campaigns

Unencrypted exfiltration

The month’s most visible pattern in the public and quasi-public sector was confirmed exfiltration without encryption. Ecopetrol showed the clearest version of that pattern, with data theft, access revocation, and containment of a ransomware attempt that, based on the material available, never became an incident with confirmed encryption. The key point is that the exfiltration was verifiable and the extortion threat remained in play, even if the material does not allow the case to be classified as ransomware with proven operational impact.

Bogotá also fits this category, although in a different form. The leak from a historical database managed by an outside vendor was treated as data exfiltration, while the later use of that information to tailor fraud or possible phishing campaigns magnifies the damage. In León, references to stolen citizen data and leaked databases in an ecosystem linked to Seguritech suggest a similar logic, an access or leak that can later be reused for other purposes, from social engineering to reputational pressure. In both cases, the absence of encryption does not mean lower severity. Sometimes the opposite is true, because service continuity is preserved while data exposure turns into a persistent risk that is harder to eliminate.

Fraud and phishing

The month recorded only two documented fraud or phishing cases, a sharp drop from June. Even so, one of those cases deserves follow-up, Bogotá, because the data leak involving drivers is fueling scam campaigns built around specific information on traffic fines, licenses, and vehicles. The value of that signal is not in the volume, but in the quality of the fraud. When messages are customized with real data, credibility rises and the victim’s threshold for responding falls.

Operationally, the reading is that the public sector continues to be an indirect source of fraud for third parties. Not always because the agency is the final target, but because an administrative or vendor breach creates a reservoir of information that opportunistic attackers can exploit. In an environment where citizens already expect notices and fines through digital channels, the risk of contextual phishing is especially high. For security teams and citizen service units, that means strengthening communication validation, official message design, and monitoring of abusive campaigns that use agency names and administrative terminology.

APT and hacktivism

July’s material does not include a classic APT campaign with solid attribution across the board, but it does show several signs of persistent intrusion and strategic interest. Paraguay is the clearest example, because the public discussion centered on cyberespionage, multiple actors linked to China, and a criminal investigation opened by MITIC. The hypothesis that a collector of state data was deployed points to persistence and observation rather than immediate sabotage.

STM, Detran of Mato Grosso do Sul, and León itself show a second layer of risk, less sophisticated but just as relevant, where the actor seeks to disrupt services, degrade availability, or test the resilience of the public perimeter. In these cases, the line between opportunistic intrusion and organized campaigning is not always visible in the material. What does stand out clearly is that government agencies remain targets of multiple motives, from sabotage to quiet data extraction.

Critical vulnerabilities

No additional critical CVEs were recorded in the month’s analyzed material, except for the alert from Chile’s National Cybersecurity Agency on CVE-2026-0257 in Palo Alto GlobalProtect. This does not mean there were no critical vulnerabilities exploited in the region, only that this was the sole one explicitly identified in the verified July corpus.

CVE Software Exploitation Source
CVE-2026-0257 Palo Alto GlobalProtect Chile’s ANCI published an alert about a critical vulnerability affecting GlobalProtect portals and gateways Agencia Nacional de Ciberseguridad de Chile, 2026-07-04

Regulation and Compliance

July was the most active month in the period for regulatory action. The dominant signal did not come from a single rule, but from a buildup of moves spanning institutional design, enforcement, administrative investigations, and legal responses to incidents. For the public sector, that matters as much as a technical campaign, because it redraws the perimeter of obligations and changes how agencies and vendors are assessed.

Jurisdiction Development Scope Operational read
Mendoza, Argentina Cybersecurity bill Creates CCEC, an operational authority, SOC and government CSIRT Formalizes governance, asset inventory and risk management
Brazil ANPD sanction process Social organization tied to 500,000 patients in public health units Reinforces responsibility for processing and safeguarding sensitive data
Colombia Prosecutor's Office request Contract for cybersecurity tools in public entities Introduces scrutiny over procurement and possible irregularities
Paraguay Complaint and criminal investigation Cyberespionage against state systems Elevates the incident to the criminal and international level
Chile ANCI critical alert CVE-2026-0257 in GlobalProtect Pushes review of perimeter exposure and patch prioritization
Brazil STM institutional response Temporary portal takedown after incident Signals containment response and forensic analysis

The Mendoza bill deserves a more technical reading. It does not just create command structures, it also defines mandatory scope for different types of state entities and requires an asset inventory, information classification and a risk management program. That makes it an implementation rule, not just a statement of principles. If it advances, it could serve as a model for other provinces that still rely on fragmented policies or reactive incident response.

ANPD's action in Brazil also carries regional weight. The case involving the social organization linked to the processing of data from 500,000 patients in public health units underscores that personal data protection in public health does not end at the hospital or the ministry. Third parties that run databases, services or platforms can become the weakest link. The sanction also comes at a time when Brazil has already been consolidating a more demanding regulatory ecosystem, so the message to the public sector and its contractors is clear: custody of sensitive data requires verifiable controls.

In Colombia, the Prosecutor's Office's position on a contract worth close to 300,000 million for cybersecurity tools in public entities adds another layer. The issue is no longer just securing a system, but justifying the quality, transparency and relevance of cybersecurity spending. In compliance terms, that requires reviewing bid documents, implementation metrics, technical deliverables and the provider's real capacity to sustain a security solution in complex government environments.

Countries and Most Affected Subsegments

Colombia

Colombia concentrated high-impact incidents in two different lines. On one hand, Ecopetrol, a strategic company with state ownership and systemic weight, suffered a cyberattack with confirmed exfiltration, a contained ransomware attempt, and referral to the Fiscalía, ColCERT, and the Ministry of ICT. On the other, Bogotá kept dealing with the fallout from a mobility data leak, with impact on drivers, an external vendor, and possible secondary fraud campaigns.

This month’s Colombian pattern is one of layered exposure. The attack surface includes large corporations with cloud storage, vendors managing legacy databases, and oversight bodies that step in once an incident reaches a certain level of severity. That makes Colombia one of the countries with the highest density of signal in July, not because it had the most uniform volume of events, but because of the mix of impact, visibility, and institutional response.

Mexico

Mexico saw a heavy load of municipal incidents. León was the main point of attention because of the official site outage, disruption to the Citizen Service System, the preventive block, the continued unavailability of the Transparency portal, and references to database leaks and procurement. Sinaloa, by contrast, appears as an area of uncertainty, with several reports of possible cyberattacks against public systems, but without a conclusive public technical finding in the material reviewed.

The dominant subsegment here is local government and citizen service platforms. This is especially relevant for mid-sized and large municipalities, where portal continuity, transparency, and service management coexist with vendors, integrations, and political pressure. It is no coincidence that the impact concentrated on citizen services and transparency, because those are two areas where downtime is felt quickly and becomes visible.

Paraguay

Paraguay stood out for the scale of state-sponsored cyberespionage. The available material describes infiltration of government networks, a complaint filed by MITIC, intervention by the Fiscalía, and a joint review with the United States. This is not a municipal-style service disruption case, but a threat focused on persistence, data collection, and possible geopolitical attribution.

The subsegment here is the central administration and its state systems. If anything distinguishes the Paraguayan case from the rest of the month, it is the attention on the silent nature of the intrusion. According to the statements cited, the goal was not destruction but to install or maintain collection capabilities. For the state, that means thinking about early detection controls, segmentation, and behavioral monitoring, not only post-incident recovery.

Brazil

Brazil contributed two different signals. The STM showed a limited unavailability event with the portal taken down, while the ANPD opened a sanction process against a social organization linked to 500 mil patients from public health units. That combination brings together the judicial or military system on one side, and public health and data protection on the other.

The most sensitive subsegment is public health, because the link to personal data is more direct there and the reputational cost of a failure is usually higher. The STM case, meanwhile, shows that institutional portals remain a vulnerable surface even when the intrusion does not reach internal systems. The country-level reading is one of tighter governance, but with incidents that still find operational gaps.

Argentina

Argentina appears in this month through Mendoza and its bill. This is not about incident volume, but institutional depth. The subsegment is clearly provincial administration and state entities under a single mandatory framework. If the bill moves forward, it could organize the relationship between political leadership, the operations team, the asset inventory, and incident response.

Mendoza's regional relevance is that it introduces an architecture that other subnational governments could replicate. In a context where many responses remain ad hoc, the bill proposes strategic leadership, an operational authority, a SOC, and a government CSIRT, raising the minimum expected standard of maturity.

Chile

Chile had a specific but important signal, the critical alert on CVE-2026-0257 in GlobalProtect. In subsegment terms, that affects any organization that depends on that remote access perimeter or secure gateway. Although the event is not an incident in itself, it does shape patching and exposure priorities.

The relevance of the Chilean case lies in its early warning function. In a month dominated by incidents and regulations, a critical alert of this kind is a reminder that much of the state risk is decided at the basic edge, especially when remote access is part of administrative continuity.

The comparison with the previous month shows three clear shifts. First, ransomware or extortion as the primary focus fell sharply, from 11 to 1. That should not be read as the problem disappearing, but rather as that pattern becoming less visible in the material analyzed. In the case of Ecopetrol, there was in fact a contained ransomware attempt, confirming that the threat remains present even if it does not dominate the count.

Second, documented fraud or phishing cases also fell, from 16 to 2. That decline may reflect either less relevant material or a real shift in focus toward availability incidents and exfiltration. The operational signal to monitor is whether the July leaks begin to trigger secondary campaigns in August and September, something that often appears with a delay.

Third, regulatory moves rose from 3 to 12. That change is probably the most important of the month, because it points to a stricter institutional cybersecurity perimeter. Mendoza, ANPD, Colombia's Prosecutor General's Office, and MITIC in Paraguay are different pieces of the same process, the attempt to turn incidents and breaches into formal obligations, contractual controls, and greater state visibility.

The underlying trend remains third-party dependence. Bogotá, León, and Ecopetrol show that a substantial share of public-sector risk materializes outside the institutional core, in suppliers, integrations, cloud environments, or outsourced services. That requires closer attention to contracts, access revocation, account traceability, and service continuity in mixed environments. When the vendor goes down or leaks data, the agency is the one that answers to citizens, regulators, and the press.

There is another signal to watch, less frequent but increasingly sensitive, cyberespionage and persistence in state networks. Paraguay made that category visible, and it should not be treated as an isolated case. If the region starts detecting more silent collection operations, the risk vector will no longer be only disruption or data theft for resale, but also sustained exposure of government information of strategic interest.

Recommendations for security teams

First, immediately review the map of vendors with access to public or semi-public data. The cases of Bogotá and Ecopetrol make clear that external links can turn a single vulnerability into broad exposure. Organizations should require up-to-date third-party inventories, contracts with early notification clauses, access revocation tests, and evidence of environment segmentation.

Second, strengthen response capabilities for outages affecting portals and citizen systems. León and the STM show that a portal going offline is not just a reputational issue. It affects procedures, transparency, service delivery, and legitimacy. Teams should test prolonged outage scenarios, preventive blocking procedures, restoration from backups, and coordinated public communication with legal and press teams.

Third, prioritize detection of exfiltration, not just encryption. Julio showed that data loss and the later use of that information can be more damaging than a visible ransomware event. Alerts are needed for abnormal account behavior, large transfers, unusual cloud access, and extraction of historical databases. Where personal data is involved, assume the leak can end in secondary fraud.

Fourth, strengthen identity and privilege hygiene. Ecopetrol and Bogotá highlight the value of revoking unauthorized access, reviewing active VPN credentials, and auditing privileged accounts. In public agencies with contractor turnover and multiple departments, access control cannot rely only on administrative onboarding and offboarding. Technical verification of actual privileges is required.

Fifth, bring the regulatory dimension in from the start of the incident. The ANPD sanction, the Colombian Fiscalía investigation, and the Procuraduría action show that a case can begin with potential administrative and legal consequences. Security teams need to work with legal, procurement, and compliance to preserve evidence, document decisions, and maintain technical traceability from minute one.

Sixth, take critical vulnerability alerts in remote access products seriously. The notice on CVE-2026-0257 in GlobalProtect should trigger exposure reviews, segmentation checks, and patch prioritization. In the public sector, an outdated or poorly monitored gateway can become an entry point for silent intrusion or operational disruption.

Material limitations

This report was prepared exclusively from the material provided for July 2026 and the explicit month-over-month comparison included in the file itself. No internet access or external sources were used. Only the facts in the period block are part of the July volume; facts from prior months were used only as comparative context and always with their explicit month, without being counted in July.

The four facts without a confirmed date were excluded from the indicators and can only be used as qualitative context, with the caveat that their date is not confirmed. The same applies to any reference with uncertain attribution or insufficient support in the material. When the source does not allow a distinction between asset encryption, exfiltration without encryption, or a mere mention on a leak site, the report says so and does not force an artificial classification.

In particular, a critical CVE count of 1 does not mean there were no other critical vulnerabilities exploited in the region. It only means that, in the period material analyzed, a single critical CVE was mentioned in a verifiable way. Likewise, aggregated telemetry figures, such as the attempts or blocks reported by the municipality of León, were not counted as incidents with confirmed impact and are mentioned only as quantified background noise according to the source itself.

Consumer social media, sponsored posts, and other items that were not enabled as citeable sources in the file were also excluded from the analytical body. The regional reading therefore describes the documentary signal available for July 2026 on the public sector and government institutions axis in Latin America, not a complete reconstruction of the full universe of incidents in the region.

Sources