CiberLATAMbywhalemate
Intelligence report

Public Sector and Government Agencies, Aug 2026

August closed with 113 verified incidents in LATAM public sector, driven by incidents, ransomware, and leaks in Brazil

Sep 1, 202628 min read
Public Sector and Government Agencies, Aug 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are automatically filled with verified dated facts within the period. Each one states its basis and counting criterion, so the figures reconcile across modules. They are the recurring month-to-month reading; the later analysis develops the cases without repeating this summary.

Indicator window: 113 dated facts in August 2026. Facts from earlier months are used only as a comparative framework in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Verified Signal Monthly Dashboard August 2026 · Latin America Top threat: Incidents (54 of 113 events). Coverage: 113 dated events in August 2026 VERIFIED EVENTS 113 period base: all counts measured from below against this one total RANSOMWARE / EXTORTION 26 1 asset encrypted confirmed · 1 exfiltration no encryption (simple extortion) UNCLASSIFIED INCIDENTS 54 breaches or outages without declared threat type FRAUD / PHISHING 3 documented fraud campaigns REGULATION 4 standards, resolutions, or sanctions UNIQUE CVEs 0 none in the material reviewed (does not imply absence in the region)
Verified Signal Monthly Dashboard — Base: 113 verified dated events for Latin America.
MONTHLY FIXED MODULE Threat Axis Distribution August 2026 · Latin America Each event counts in only one axis, so the total is exactly 113. "Unclassified incidents" is the remainder. Incidents 54 Ransomware 26 Unclassified 23 Regulation 4 Fraud 3 Vulnerabilities 3
Threat Axis Distribution — Each event is assigned to a single axis based on its classification; the total reconciles with the 113 events in the period.
FIXED MONTHLY MODULE Sectoral Distribution of Signal August 2026 · Latin America Base: 113 incidents in the period · total 154 because 40 incidents are classified in more than one sector. Public sector / OES 78 Telecom 29 Other / unclassified… 22 Finance 8 Technology 8 Energy 4 Retail / Consumer 3 Health 2
Sectoral Distribution of Signal — Heuristic classification by victim sector. One incident may affect more than one sector, so totals may exceed the base.
MONTHLY FIXED MODULE Geographic Distribution of Signal August 2026 · Latin America Each fact is assigned to a single country or to regional coverage, so the total is exactly 113 out of 113 facts … Mexico 23 Regional 21 Chile 19 Brazil 17 Colombia 17 Argentina 8 Paraguay 4 Peru 4
Geographic Distribution of Signal — Verified facts from the period grouped by country or regional coverage; each fact is counted once.

Executive summary for the month

August 2026 produced 113 verified incidents across the public sector and government agencies in Latin America, led by operational disruptions and a sharp increase in ransomware and extortion compared with July. The month’s strongest signals came from Brazil, Colombia, and Chile, affecting ministries, municipalities, service platforms, and oversight bodies, while Mexico, Paraguay, and Argentina contributed lower-impact outages, attempted breaches, or identity impersonation cases.

The most serious incident in operational terms was the ransomware attack against Colombia’s Ministry of Justice and Law, which degraded digital public services, forced the use of alternative channels, and required technology recovery coordinated with COLCERT, the Attorney General’s Office, Microsoft, and BID partners. The ministry itself confirmed the case as ransomware, isolated systems, and restored services progressively, although the reviewed material showed no public evidence of data leakage. Across the region, the episode again highlighted the operational continuity of citizen service windows and platforms.

In Brazil, the signal combined leaks, alleged data exposures, and attacks claimed or tracked by third parties. There was an investigation into a possible leak of Caged numbers, another front involving alleged leaks of classified data linked to the STF and the Federal Police, an MP-BA investigation into the exposure of personal and health data belonging to more than 290 patients, and a case involving the alleged leak of investigative data inside the Federal Police. At the same time, the municipality of Arcos was linked to ransomware claims by the Emperador group, and multiple municipal bodies in Espírito Santo were taken offline by an attack that exploited Ágape Consultoria infrastructure.

Chile showed a different mix, with a hack of the National Migration Service, an investigation into a medical data leak within Carabineros, an internal disciplinary proceeding and criminal complaint in Curicó over the extraction of intimate material from official phones, and a preventive alert from ANCI after the hack of LiteLLM over a possible credential exposure. There was also a judicial investigation into the alleged leak of case information to a drug trafficking organization inside the judiciary. This was not a single campaign, but several events with different vectors and levels of severity.

The quantitative profile also pointed clearly to the type of risk. With 54 unclassified incidents, 26 ransomware or extortion cases as the primary focus, and only 4 regulatory moves, the month was more operational than regulatory. The absence of critical CVEs mentioned in the analyzed material does not mean there was no exploitation in the region, but it does show that August’s public debate centered on intrusions, outages, internal leaks, and recovery, rather than on specific vulnerabilities identified by name.

Regional overview of the month

The regional reading for August points to high risk, not because of a single campaign, but because of the mix of scale, the range of affected entities, and the functional severity inside agencies that support essential public services. The month brought attacks against ministries, municipalities, judicial bodies, security forces, and government digital platforms, with direct effects on operational continuity, citizen services, and the handling of sensitive information.

Brazil accounted for the largest number of internal compromise cases and leaks. Reports there included ransomware claims against Intranet Gov Brasil and the Prefeitura Municipal de Arcos, attacks on city councils and municipalities in Espírito Santo through a shared provider, and several cases involving the exposure or suspected leakage of personal, health, and investigative data. These incidents do not point to a single pattern, but they do reflect an environment where data access and third-party intermediation increase the risk of spread and lateral exposure.

Colombia produced the highest-profile incident, after the Ministry of Justice confirmed ransomware that affected part of its infrastructure and degraded digital services for citizens. The event came with ColCERT alerts about rising ransomware activity against national targets, along with an institutional response that included containment, system isolation, and phased restoration. From a state continuity perspective, this is the kind of incident that requires a mature recovery plan and a clear prioritization of essential procedures.

Chile, by contrast, showed a more varied attack surface. The National Migration Service suffered an intrusion with a temporary lockout and mass institutional email sending, Curicó faced a leak of intimate material from municipal devices, Carabineros opened an investigation into sensitive medical data, and the Judiciary ended with pretrial detention over a leak of information to a drug trafficking group. Added to that was ANCI's warning about exposed credentials in the LiteLLM supply chain, which pointed to preventive risk and potential exposure, not a confirmed incident with mass impact.

Mexico, Paraguay, and Argentina completed a map dominated by outages, intrusion attempts, and impersonation rather than confirmed large-scale breaches. In Mexico there was a temporary outage of federal government sites and the gob.mx domain, plus the C5i of Tlaxcala case involving an attempt to compromise information. In Paraguay there were allegations of DDoS attacks against public agencies. In Argentina, the standout cases were the scam that impersonated the BCRA and the attack on Oldelval, which preserved operational continuity. The result is a high regional risk profile, with very concrete operational and leakage hotspots.

TIMELINE Verified events for the period 2/8 Pipelinesof theValley(Oldelval), 2/8 The Ministry ofJustice 2/8 Analysis ofspecializedmedia outlets 2/8 The responseteam 2/8 The public notice from 2/8 The Elattackofransomware
Verified events timeline, August 2026 — Confirmed milestones within August 2026. Events from earlier months are excluded from the timeline and used only as comparative context.

Period indicators

Indicator August 2026 Previous month Change
Verified facts in the period (basis for all indicators) 113 78 +35
Indicator time window 113 facts dated August 2026 78 facts dated July 2026 N/A
Unclassified incidents (breaches or disruptions) 54 41 +13
Cases with ransomware or extortion as the primary focus 26 1 +25
Ransomware breakdown by impact type, confirmed asset encryption 1 0 +1
Ransomware breakdown by impact type, exfiltration without encryption (simple extortion) 1 0 +1
Ransomware breakdown by impact type, mention only on a leak site 1 0 +1
Ransomware breakdown by impact type, type could not be determined from the material 23 1 +22
Documented fraud or phishing cases 3 2 +1
Documented regulatory moves 4 12 -8
Critical CVEs mentioned 0, none in the material analyzed, does not imply absence in the region N/D N/D
Sectors with at least one documented fact 8 7 +1
Dominant threat of the month Incidents (54 of 113 facts) Incidents (41 of 78 facts) N/A
Facts with direct source confirmation 76% N/D N/D

Relevant Incidents

Colombia, Ministry of Justice and Law

The month’s most sensitive case was the ransomware attack against Colombia’s Ministry of Justice and Law, confirmed by the agency itself starting on August 2 and accompanied by visible operational impacts for several days. The entity reported temporary system unavailability, disruption to part of its technology infrastructure, and the activation of alternate channels for citizen service while containment and recovery efforts moved forward.

The sequence matters because it separates perception from evidence. The Ministry confirmed that COLCERT found preliminary indicators consistent with ransomware, and later said some public digital services were degraded. It also reported joint work with the Attorney General’s Office, COLCERT, Microsoft, and BID partners, which points to a coordinated technical and institutional response. No public evidence appears in the material of data theft from those systems, so the verifiable damage was primarily to availability.

The operational reading is clear. When a justice ministry loses partial availability, even without a confirmed public leak, the impact turns into delays in procedures, backlogs in case files, and greater pressure on in-person channels. The speed of isolation and recovery mattered, but the episode exposes a recurring issue in the region, dependence on single platforms to manage PQRDSF, case files, and query services.

Direct source from the ministry itself, dated August 2, 3, 8, 15, and 20, 2026, with support from external technical coverage in Infobae Colombia, DarkReading, DataEnforce, White Hunters, eSoft, and Nexsight.

Oldelval and Argentina’s energy front

Oleoductos del Valle reported to the CNV that it suffered a cyberattack on its administrative systems, but said crude transport continued without interruption. At the same time, specialized media described the incident as RaaS ransomware, and an actor attributed to Incransom said it had exfiltrated internal documents, including human resources, financial, and regulatory material.

The key point is the separation between operational impact and potential confidentiality impact. The company spoke of affected administrative systems, not a shutdown of the pipeline. The later claim in intelligence sources suggests exfiltration, but the material makes clear that the full scope was not independently confirmed and that there was no public validation of how many people were affected. In this case, the business risk is closer to document exposure than to the loss of physical continuity.

The combination of critical operations and administrative exposure is especially sensitive in energy infrastructure. This was not just a corporate incident, because the regulatory environment and market confidence are also in play. The case also showed how ransomware groups mix public pressure, victim listings on leak sites, and claims about data volume to maximize the visibility of the incident.

Espírito Santo and Ágape Consultoria’s supply chain

The facts around Ágape Consultoria point to a campaign with cascading municipal consequences. Local coverage said that websites and databases belonging to several municipalities and city councils in Espírito Santo went offline or were compromised after an attack that exploited vulnerabilities in the provider’s central servers. In parallel, analysis by PacificSec expanded the potential universe of affected clients.

The significance of the case is not only the number of public bodies reached, but the dependency pattern. If a provider serves dozens of city councils and municipalities, a central compromise can become a broad failure. The evidence collected in the material indicates that João Neiva, Ibatiba, Brejetuba, and Vitória were among the entities mentioned, along with other municipal institutions in the state.

There is no fully closed classification of the final impact here, because the sources mix access to databases, website outages, ransomware claims, and IT contingency needs. But the strategic message is consistent. The public sector attack surface does not end with each municipality’s own infrastructure, it extends to integrators, consultancies, and software vendors with privileged access.

Intranet Gov Brasil and The Gentlemen’s claim

Intranet Gov Brasil appeared in several tracking sources as a victim claimed by the group The Gentlemen. Breachsense logged it as a breach, Intel and Breaches included it among 83 new ransomware victims, and other monitoring platforms flagged the case as a leak-site post or an unconfirmed claim. The material, however, provides no public validation from Brazilian authorities or from the platform operators at the time of reporting.

For that reason, the case should be treated cautiously. The domain name and its description as a digital portal for public services and online access for citizens and companies suggest a wider infrastructure than a simple internal intranet. But the available material does not allow a determination of whether there was encryption, only a leak-site mention or exfiltration. That uncertainty does not erase the event, but it does mean it should not be overstated.

From a monitoring perspective, this kind of claim is useful as an early warning of reputational exposure and possible investigative follow-up. If the victim belongs to Brazil’s federal ecosystem, any reference to credentials, internal access, or shared services should be checked urgently. This month’s situation reinforces that ransomware victim lists are an early signal, not a closed proof of impact.

Chile’s National Migration Service

Chile’s National Migration Service suffered a hack on August 18 that temporarily blocked its platform and led to mass emails sent from institutional accounts with images and messages unrelated to the agency’s usual work. Sources agree that the site was unusable for several hours, roughly between 5 a.m. and 9 a.m., and that service was restored later that same day.

This incident is different from classic ransomware. The material does not describe encryption or financial extortion, but rather platform blocking, misuse of institutional accounts, and an action with a strong sabotage or defacement component. Coverage also notes that, so far, it has not been reported whether personal data or sensitive records were compromised, so the impact on stored information remains unconfirmed publicly.

The operational reading is uncomfortable for public administration. Even though restoration was quick, citizens could not complete online procedures for several hours. The case also showed that the integrity of institutional email channels is part of public trust, not just technical continuity. A restored portal with compromised accounts remains a sensitive attack surface.

Curicó and the leak from institutional devices

Curicó’s municipality opened an internal disciplinary process and referred the matter to prosecutors after the leak and viral spread of intimate videos extracted from institutional phones. Sources describe a modus operandi in which a municipal IT employee allegedly accessed private photos and videos while repairing municipal or personal phones, raising the case from an administrative violation to a possible criminal matter.

Here the focus is not ransomware or an external intrusion, but abuse of legitimate access and irregular extraction of sensitive content. That detail matters, because in the public sector the boundary between technical support and improper access can be thin when there is no strong separation of duties, no activity logging, and no controls over managed devices. The municipality responded by removing the employees involved while the investigation continued.

The case also left a deep reputational risk. When a leak involves intimate material, the harm to those affected is immediate and the institutional exposure goes beyond classic cybersecurity. The criminal investigation and internal disciplinary process show that the problem was technological, disciplinary, and about internal trust.

Argentina, the BCRA, and impersonation fraud

The Central Bank of the Argentine Republic issued a public warning about a virtual scam that impersonates its identity and that of its officials. According to the notice, attackers used manipulated videos and channels such as email, WhatsApp, or SMS to simulate official communications and obtain data or payments. The BCRA clarified that it does not request payments or banking information through those means.

This is fraud and phishing, not a break-in against the bank’s internal systems. The value of the alert is that it shows a sufficiently convincing institutional impersonation to require direct public communication. The notice also includes a response path, if someone installed an app or shared data, they should contact their bank immediately and file a report with UFECI.

At the same time, the Oldelval case in Argentina increased attention on energy infrastructure and regulated services. There is no causal link between the BCRA scam and the Oldelval attack, but both incidents show that in Argentina’s public and para-public sector, social engineering threats coexist with more technically complex attacks. That coexistence means no single risk class should be prioritized to the exclusion of the others.

Mexico, Tlaxcala, and the collapse of government portals

Mexico produced several availability incidents. The federal government and the gob.mx domain experienced temporary outages and connectivity cuts, while Tlaxcala’s C5i registered a hack with an attempted breach of information. The material describes the episode as site disruption and widespread outage, but not as a breach with confirmed data theft.

The importance of the Mexican block is that the connectivity failure was not treated by the media only as a technical problem, but as an indicator of deeper vulnerability in public digital infrastructure. That does not amount to a confirmed exfiltration incident, but it does show dependence on links, configuration, and operational resilience. The Tlaxcala case adds the variable of an attempted access to public safety information.

In both episodes, the correct reading is that public visibility of the outage is itself a trust problem. When government portals go offline or become unstable, citizens perceive fragility even if the cause is not a data compromise. For public teams, those minutes of unavailability often open pressure windows for support, the media, and political authorities.

Chile, the judiciary, and sensitive leaks

On August 28, a Chilean judiciary employee was placed in pretrial detention after being accused of leaking information from judicial investigations to a drug trafficking organization. Sources refer to case files, rulings, and precautionary measures shared without authorization, with the Public Ministry involved and a decision from the San Bernardo Guarantee Court.

This is not a technical attack, but it is institutional cybersecurity in the strict sense, because it shows abuse of access to protected information inside the state. Unlike malware or a ransomware campaign, the problem here lies in malicious use of privilege. That kind of incident is harder to detect with traditional perimeter tools and usually depends on traceability, query controls, and internal auditing.

In the same month, Carabineros opened a disciplinary inquiry over the leak of sensitive medical data, which reinforces the pattern. There is a common signal, exposure of restricted information inside agencies that handle large volumes of personal and judicial data. The response needs to go beyond the specific incident and review access profiles, segregation of duties, and alerts for abnormal behavior.

Active Threats and Campaigns

Ransomware and Extortion

The month produced 26 cases with ransomware or extortion as the main focus, but their impact was not uniform. The material makes it possible to identify one confirmed case of asset encryption, one case of exfiltration without encryption, a single mention on a leak site, and 23 cases that could not be classified with the available material. That breakdown matters because it keeps disruption, extortion pressure, and a simple victim claim from being lumped together.

The only confirmed encryption case in the material reviewed was the one involving Colombia's Ministry of Justice, where the agency itself and several technical sources described ransomware affecting infrastructure and services. The Oldelval case is closer to exfiltration without encryption, because the attributed actor said it had extracted internal documents, while the company insisted crude oil transport continued uninterrupted. The rest of August's claims, especially those linked to Brazil, lacked enough precision to distinguish encryption, exfiltration, or a simple leak site posting.

In practice, that means a victim's public exposure does not always equal the same kind of damage. A leak site post may be used for reputational pressure without any verifiable evidence of full encryption. For public sector teams, the priority should be confirming actual system availability, backup integrity, and possible data exfiltration, not just the victim name on an extortion panel.

Fraud and Phishing

The 3 documented fraud or phishing cases in the month revolved around impersonation of institutions and visual or audiovisual manipulation. The clearest case was the BCRA, with manipulated videos, use of email, WhatsApp, and SMS, and an explicit warning not to hand over credentials or banking data through those channels. The value of the statement lies in how it targets the trust point, the appearance of official status.

Although the material only counts three cases, the broader signal is stronger. In a month with many operational incidents, impersonation fraud exists alongside users' anxiety over outage alerts, service shutdowns, or urgent communications. That gives campaigns built on urgency, authority, and fear a better chance of success. In the public sector, the visual identity of agencies and officials remains a lucrative attack vector.

APT and Targeted Intrusion

There was no confirmed APT campaign against a Latin American public entity in the incidents from the month, but investigations and alerts tied to cyberespionage and remote access did appear. In Chile, the PDI and the Prosecutor's Office investigated possible attacks attributed to Lilac Typhoon against telecommunications companies, with mention of ShadowPad and suspicions of computer sabotage. The material makes clear that no specific breach in state systems was confirmed.

The most useful signal in this block is not the attribution itself, but the spillover effect on the state. When foreign intelligence and local media link cyberespionage to telecommunications networks, the public agenda quickly shifts to national security, criminal investigation, and critical infrastructure oversight. That forces public sector agencies to review their indirect exposure, even if they are not the primary target.

Critical vulnerabilities

No critical CVEs were recorded in the August 2026 material analyzed. That does not mean critical vulnerabilities were absent from the region, only that none appeared by name and number in the incidents covered by this report. The month’s risk surface was driven more by intrusions, ransomware, data leaks, and service outages than by any publicly identified single vulnerability.

CVE Software Exploitation Source
No critical CVEs were recorded in the material analyzed N/A N/A Period material

Regulation and compliance

There were 4 regulatory moves in August, a sharp drop from 12 in the previous month. Even so, the month was not institutionally quiet. There were court decisions, internal investigations, complaints, and technology recovery efforts that, while not regulation in the strict sense, still show a formal state response to security incidents and leaks.

In Colombia, the Ministry of Justice coordinated its response with COLCERT, the Attorney General's Office, Microsoft, and IDB partners. It also adopted temporary measures to handle PQRDSF while its document management system remained affected. That sequence matters for compliance because it combines service continuity, protection of institutional information, and status updates to the public. The goal was not only to restore systems, but also to sustain administrative and service obligations.

In Chile, the opening of internal investigations in Curicó and Carabineros, along with the preventive detention of the judicial official, shows that the response to the incident no longer stays on the technical side. A disciplinary, criminal, and data protection dimension is activated when the source is internal. For compliance teams, this requires evidence preservation protocols, legal notification, and access traceability from minute one.

In Brazil, the MP-BA and the Federal Police opened investigations into alleged leaks, while the MTE moved to speed up a possible vazamento of Caged numbers. The common thread is that public authorities stopped treating the leak as press rumor and began handling it as a potentially investigable fact. That move toward formalization matters, because the regional response system still depends heavily on the initiative of each affected agency.

Countries and subsegments most affected

Brazil

Brazil had the highest density of public sector-related incidents in August. There were ransomware claims involving Intranet Gov Brasil and the Prefeitura Municipal de Arcos, attacks on municipal cameras and city governments in Espírito Santo, and multiple leaks or suspected leaks of sensitive data at the federal and state levels. The range of institutions hit suggests a mix of technical exposure, vendor dependence, and insider abuse.

In the municipal subsegment, the Ágape Consultoria case is the clearest example of a domino effect. Several public agencies were left with offline or compromised services from the same infrastructure base. At the federal level, concerns centered on the Gov.br ecosystem, the STF, the Federal Police, and the MTE, each with different forms of exposure or investigation. It is a sign that the risk is not limited to citizen-facing portals.

Colombia

Colombia recorded the most severe operational incident, the ransomware attack on the Ministry of Justice. The case affected digital public services, required alternate support, and triggered a recovery effort involving national and international organizations. Along with the ColCERT warning about growing interest from ransomware groups, the country showed a scenario in which the threat was no longer potential, but an actual service disruption.

By sector, the Ministry of Justice was the center of gravity, but the impact on PQRDSF services and the outage of SGDEA show that the disruption reached state records management. This was not just a system outage. It affected the layer of operations that connects records, public service, and internal processes.

Chile

Chile was the other major focus, although the incidents were more fragmented. The National Migration Service suffered a hack that led to a temporary lockout and misuse of institutional email. Curicó faced a leak of intimate content from municipal devices. Carabineros and the Judiciary added cases involving leaks of sensitive information, and the ANCI issued a preventive alert over possible exposure following the LiteLLM hack.

The municipal and judicial subsegments are the most sensitive in the material. Both involve personal data, case files, or restricted material that require tight access controls and traceability. The technical exposure surface coexisted with insider abuse, which brings privilege governance back to the forefront, not just perimeter defense.

Argentina

Argentina contributed two different readings. On one hand, the BCRA and its impersonation alert showed a fraud campaign aimed at users, with a strong social engineering component. On the other, Oldelval faced a cyberattack that affected administrative systems and led a ransomware actor to claim exfiltration. These are different threats, but they coexist within the same institutional and regulatory risk environment.

Mexico

Mexico was marked by government portal outages and an attempted compromise in Tlaxcala. The material does not confirm a data breach with exfiltration, but it does record service disruption and a public response that treated the episode as evidence of weak digital infrastructure. For the government digital subsegment, the focus is continuity and network resilience.

Paraguay and Peru

Paraguay appears in the material only with DDoS claims against public agencies, with no confirmation of lasting damage. Peru appears tangentially in monitoring alerts and in a leak that exposed police intelligence data and records of Venezuelan citizens, but the material does not present it as a government incident picture comparable to Brazil, Colombia, or Chile. The signal is one of monitoring, not monthly dominance.

July comparison shows three clear shifts. First, the total number of incidents rose from 78 to 113, signaling more verified activity across the axis. Second, ransomware or extortion cases jumped from 1 to 26, a change that reshapes the month’s reading and makes operational continuity and recovery a priority. Third, regulatory actions fell from 12 to 4, suggesting that formal response did not keep pace with the increase in incidents.

The concentration of incidents in Brazil, Colombia, and Chile is another signal to monitor. Brazil shows a pattern of exposure through vendors and internal leaks, Colombia points to a growing maturity in ransomware response, and Chile combines intrusions, defacement, and insider abuse. That mix points more to access governance, segmentation, and traceability issues than to a single malware family.

The drop in regulatory actions, combined with the rise in incidents, leaves a gap between exposure and formalization. In other words, there were more incidents and greater severity, but not necessarily more regulation, sanctions, or visible policy updates in the material. For a public-sector CISO, this means incident costs will continue to be absorbed locally, with pressure on internal, legal, and communications teams.

Verified signal comparison, July vs. AugustSource: verified facts for the period, July 2026 vs. August 2026Facts78113JulyAugustIncidents4154JulyAugustRegulation124JulyAugust
Verified signal comparison, July vs. August — The comparison uses only the indicators provided for the period and the previous month.

Recommendations for security teams

First, review continuity and recovery for critical public services, with a focus on administration and citizen services. The case of Colombia’s Ministry of Justice showed that ransomware does not need to take down every system to disrupt government operations. If PQRDSF, case files, queries, or procedures go down, the damage is already material. Recovery plans must test real restoration, not just the existence of backups.

Second, audit privileges, traceability, and insider abuse. Curicó, Carabineros, the Chilean judiciary, and Brazil’s Federal Police showed that part of the month’s risk came from legitimate access used improperly. This calls for immutable logs, anomaly-based access reviews, strict segregation of duties, and alerts for mass queries of sensitive data.

Third, tighten vendor management for suppliers with access to multiple public agencies. The case of Ágape Consultoria in Espírito Santo is a direct example of supply-chain spread. Contracts with integrators, consulting firms, and management software vendors should include segmentation, named accounts, strong MFA, credential rotation, and recovery tests for each affected entity.

Fourth, response teams need to distinguish precisely between encryption, exfiltration, and publication on a leak site. In August, many claims lacked clear classification. It is not enough to know that there is ransomware. Teams must determine whether data was encrypted, whether it was exfiltrated, and whether the harm affects people, case files, or infrastructure. That classification changes the legal and operational response.

Fifth, antifraud communications need to reinforce institutional identity. The spoofing of the BCRA showed how phishing adapts to public alert messages. Internal campaigns should teach people to verify channels, distrust urgency, and avoid installing apps or handing over credentials outside official portals.

Sixth, email and institutional account protection deserves priority. The breach at Chile’s National Migration Service showed that a compromised mailbox can amplify the impact of an intrusion. MFA, rapid revocation, session review, and mass-mail policies must be tested before an incident, not after it.

Frequently Asked Questions

Which incidents this month had direct operational impact, and which ones were limited to leaks or internal abuse?

Colombia's Ministry of Justice and Chile's National Migration Service had direct operational impact, with service degradation or outages. Oldelval affected administrative systems without interrupting transportation. By contrast, Curicó, Carabineros, and Chile's Judiciary reflected internal abuse or leaks, not malware. See also the relevant incidents and active threats and campaigns sections.

Where was the heaviest pressure from ransomware and extortion?

The heaviest pressure was in Brazil and Colombia. Colombia had a confirmed ransomware case with functional impact at the Ministry of Justice. Brazil concentrated multiple complaints or investigations linked to ransomware, extortion, or leaks, including Intranet Gov Brasil, Oldelval does not apply to the same country, and Arcos, although several classifications remain unresolved. Review the relevant incidents and trends.

Which country showed the most signs of sensitive data leaks from inside public agencies?

Brazil and Chile. In Brazil, there were investigations into leaks of confidential, health, and police investigative data. In Chile, there were leaks of medical data at Carabineros, intimate material in Curicó, and judicial information to a drug trafficking organization. These are different cases, but they share internal access abuse. See the countries and most affected subsegments and regulation and compliance.

Were any critical CVEs identified in the month’s material?

No. The August 2026 material analyzed did not record any named critical CVEs. That does not mean critical vulnerabilities exploited in the region do not exist, only that they did not appear by name and number in this sample. The month was more focused on incidents, leaks, and ransomware. See critical vulnerabilities and material limitations.

What should a public-sector team prioritize to reduce the risk left by August?

It should prioritize restoring essential services, controlling internal privileges, protecting providers with cross-cutting access, and validating MFA and backups. The month showed that damage can come from ransomware, internal abuse, or a connectivity outage. It is also advisable to train staff on fraud prevention because the BCRA was impersonated with apparent success. See recommendations for security teams.

Material Limitations

This report was built exclusively from the dated facts in August 2026 included in the provided research block. No internet access or external material beyond the authorized list was used. Data from earlier months were used only for comparison, never to count activity in the period. By definition, the time window for the indicators is 113 facts dated in August 2026.

An indicator at 0, especially the one for critical CVEs, means it did not appear in this month’s analyzed material, not that it did not occur in the region. The same applies to any lack of specific evidence, such as an unconfirmed exfiltration or an attribution that remained unresolved. When a source did not allow the impact to be classified, the uncertainty was retained rather than forcing a label.

All facts without a confirmed date were also excluded from the count, although there were no such facts in this set. Aggregated telemetry, attack attempts, and automated blocks were not used as incidents unless a source described them as a verifiable fact with impact. Sponsored content, advertorials, and commercial pieces were also excluded as a basis for trend analysis.

Social consumer sources and publications that were not among those available for citation were also excluded. In particular, Facebook, Instagram, TikTok, Threads, Reddit, and LinkedIn posts were not used as evidence. When material came from leak site claims or monitoring sites, it was treated as a source attribution and not as full confirmation, unless there was additional corroboration in an official or journalistic source included in the authorized list.

Sources