Public Sector & Government, September 2026
September logged 49 verified events across Latin American public sector, with incidents, claimed leaks, and no critical CVEs in the material reviewed.
Key findings
- September 2026 closed with 49 verified events, 19 unclassified incidents, and a medium regional risk due to lower volume but persistent sensitive activity.
- CAPES confirmed a real incident in the Meus Dados Platform with unauthorized access to personal data and visible containment actions.
- Peru's MEF suffered compromise of its official X account, which was used to promote a crypto token, a clear case of institutional fraud.
- Paraguay produced the most sensitive signal due to internal leaks and criminal consequences at Senad, with direct impact on drug-trafficking investigations.
- Claims involving ANSES, Receita Federal, and Lex100 show the month was dominated by unverified assertions and technical debunks.
- The campaign attributed to FamousSparrow kept Latin America on the advanced cyberespionage radar, with focus on government targets in several countries.
- No critical CVEs were recorded in the analyzed material, which does not imply the absence of critical vulnerabilities in the region.
Monthly reference modules
These modules are completed automatically with the verified facts dated within the period. Each one states its basis and counting criterion, so the figures reconcile across modules. They are the recurring month-to-month readout; the analysis that follows develops the cases without repeating this summary.
Indicator window: 50 dated facts in September 2026. Facts from earlier months are used only as comparative context in the analysis, never as volume for this period.
Monthly executive summary
September 2026 closed with 49 verified incidents involving the public sector and government agencies in Latin America, with 19 unclassified incidents as the dominant category, 4 cases with ransomware or extortion as the primary focus, 4 fraud or phishing episodes, and only one documented regulatory move. The month was driven more by operational incidents and disputes over the authenticity of leaks than by confirmed encryption campaigns.
The most visible story was the mix of unauthorized access, compromised accounts, and alleged leaks claimed by third parties. There was an attack on the X account of Peru’s Ministry of Economy and Finance, a confirmed intrusion into CAPES’ Meus Dados platform in Brazil, and several cross-claims about alleged databases belonging to Argentine and Paraguayan agencies. In several cases, public confirmation was partial or nonexistent, which means the verified fact and the claims made by actors or leak sites must be carefully separated.
Pressure on agencies also came through less traditional channels. In Argentina, the judiciary denied a supposed hack of the Lex100 Case Management Portal after a technical review of the material attributed to the incident. At the same time, ANSES denied a hack tied to a dark web offer of 38 million SIPA records, with no independent confirmation of the data source. In Mexico, Yucatán was placed on alert over a supposed massive leak of government data, although the material provided no official confirmation.
In Paraguay, the signal was different and more sensitive from an institutional standpoint. There were indictments, preventive detentions, and removals of Senad officials in a case involving alleged leaks of information linked to narcotics investigations. That storyline, while not always describing a classic technical intrusion, still exposes a high risk for agencies with access to restricted information and direct ties to criminal investigations.
The regional reading is a medium level of risk. The number of incidents was lower than the previous month, and the number of ransomware or extortion cases also fell sharply. Even so, severity did not disappear, because incidents involving personal data, compromised official accounts, and espionage campaigns attributed to advanced actors persisted. The material also did not record critical CVEs, which reduces evidence of concrete vulnerability exploitation in this corpus, but does not allow a conclusion that technical risk is absent in the region.
Regional overview for the month
September’s regional picture was uneven. Volume was lower than in August, but several cases carried high institutional and reputational impact potential. Most of the noise came from incidents and data leak claims, while ransomware was concentrated in a few victims and was irregularly confirmed. Qualitatively, the risk level for the region stands at medium, because frequency fell but exposure of data, as well as intrusions into accounts and official systems, remained present.
The region did not show a single campaign that explains the entire month. Activity appeared in Argentina, Brazil, Paraguay, Peru, and Mexico, along with a cyberespionage campaign that, although observed since 2025, stood out in September for its impact on Latin American governments. That last case, attributed to FamousSparrow and its SparroWocky backdoor, added a persistent threat component that is not limited to visible exfiltration or public extortion.
The comparison with the previous month reinforces that reading. Verified incidents fell from 113 to 49, unclassified incidents dropped from 54 to 19, and ransomware or extortion cases declined from 26 to 4. At the same time, fraud or phishing incidents rose from 3 to 4, and regulatory moves fell from 4 to 1. The shift suggests less explosive activity, but not less exposure of sensitive assets.
Period indicators
The table summarizes September 2026 indicators as calculated from dated facts within the month, without adding aggregated telemetry or undated facts. The base is 49 verified facts, and the indicator window includes 50 facts dated in September 2026.
| Indicator | September 2026 | Previous month | Change |
|---|---|---|---|
| Verified facts in the period (base for all indicators) | 49 | 113 | -64 |
| Indicator time window | 50 facts dated in September 2026 | 50 facts dated in the previous month | no comparable data |
| Unclassified incidents (breaches or outages) | 19 | 54 | -35 |
| Cases with ransomware or extortion as the primary focus | 4 | 26 | -22 |
| Ransomware breakdown by impact type | Leak site mention only: 2, could not be determined from the material: 2 | not reported | no comparable data |
| Documented fraud or phishing cases | 4 | 3 | +1 |
| Documented regulatory moves | 1 | 4 | -3 |
| Critical CVEs mentioned | 0, none in the analyzed material, which does not imply absence in the region | no comparable data | no comparable data |
| Sectors with at least one documented fact | 7 | 8 | -1 |
| Main threat of the month | Incidents, 19 of 49 facts | Incidents, 54 of 113 facts | no comparable data |
| Facts with direct source confirmation | 45% | not reported | no comparable data |
| Aggregated telemetry figures excluded from the volume | 1, aggregated attempts or blocks, not incidents with confirmed impact | not reported | no comparable data |
The ransomware indicator requires separate reading. Of the 4 cases in the month, 2 were limited to a mention on a leak site and 2 did not allow a determination, from the material, of whether there was asset encryption or data exfiltration without encryption. That prevents grouping them into a single operational pattern without losing analytical precision.
Direct source confirmation for 45% of the facts means several of the month’s more striking claims should be treated cautiously. That does not mean they are false, but they do not have enough independent corroboration within this corpus to be treated at the same level as an official statement or a validated technical investigation.
Relevant incidents
CAPES and the Meus Dados platform
CAPES was the month’s strongest case in terms of official confirmation, after the agency acknowledged a security incident on the Meus Dados platform and described containment and response measures. The institution reported unauthorized access to personal data available in the system and said the possibly exposed information included CPF, email address, phone number, and banking data.
The analytical value of the episode lies not only in the potential exposure, but in the response itself. CAPES said it restricted the affected functionality, reviewed access and authorization mechanisms, preserved technical logs, and strengthened monitoring. That sequence is what allows the event to be classified as a confirmed incident rather than a leak rumor. It also suggests the impact was limited to the named platform, although the material does not allow for a count of affected people.
Operationally, the case points to two lessons. First, a platform holding sensitive data can be exposed even when final victim counts are unavailable. Second, early disclosure and technical containment are essential to avoid deepening reputational damage. CAPES’ response was one of the few this month that offered concrete, verifiable actions.
Peru’s Ministry of Economy and Finance, X account compromised
Peru’s Ministry of Economy and Finance confirmed that its official X account was compromised and activated security protocols to regain access. It also clarified that the content posted during the compromise did not belong to the agency. The sequence was linked to consecutive posts promoting the $HYLO token and to what appeared to be a crypto scam.
The case fits the category of documented fraud or phishing, not a network intrusion with confirmed exfiltration. The main problem was the takeover of an institutional identity to amplify a fraudulent message. Although the technical method of attack was not detailed, the impact was public, immediate, and visible to outside audiences, which makes the official account a trust vector that can be exploited.
The relevance for the public sector is clear. Social media accounts belonging to ministries and official agencies are not minor assets, because they are used to distribute notices, denials, and public policy updates. A compromise of that channel can be used for fraud, disinformation, or traffic diversion toward malicious assets. In this case, press coverage showed that the fake message was later removed, which reduces duration but not reputational risk.
Judiciary case management portal of Argentina’s federal courts
Argentina’s federal judiciary rejected claims of a mass extraction of users, passwords, and employee data from the Lex100 Case Management Portal. The technical review concluded that the material attributed to the alleged hack corresponded to public data from the historical site of the National Electoral Chamber, and found no signs of unauthorized access to the portal or compromise of credentials or personal information belonging to judicial staff.
This is a good example of why this month required separating attribution from verification. There was a hack claim, but the official technical review did not support it. For sector analysis, that means it should not be counted as a confirmed judiciary leak, although it does count as a relevant disinformation event or a case of questionable attribution involving a sensitive system.
The practical implication is twofold. On one hand, communications and security teams need to coordinate to quickly defuse unfounded claims. On the other, a false positive leak report can trigger questions about credential management, historical exposure, and custody of public data. The Lex100 case shows that an agency’s technical reputation also depends on rapid forensic validation.
ANSES and the alleged 38 million-record database
ANSES denied suffering a hack after dark web forum posts claimed to hold 38 million SIPA records. There was no independent public confirmation that those records came from the agency’s systems. Available material also showed specialized coverage that treated the alleged leak as unverified.
The significance of the case lies in the persistence of claims about massive databases tied to large public agencies. Even without confirmation, an offer of that size can fuel fraud, identity theft, or targeted phishing, especially if it is tied to pension or social security data. This case therefore cannot be counted as a confirmed breach, but it does signal pressure on Argentina’s public data ecosystem.
There is no evidence in the corpus of a validated technical intrusion at ANSES. What exists is an institutional denial and an uncorroborated third-party claim. In a report aimed at CISOs, that distinction matters because it avoids confusing rumor with incident, even if both still need to be monitored for their operational and reputational effects.
SENAD and the information leak case in Paraguay
Paraguay produced the most consistent set of facts on internal leaks with a criminal dimension. The Prosecutor’s Office charged current and former officials of the National Anti-Drug Secretariat over the alleged leak of information to people linked to the late lawmaker Eulalio "Lalo" Gomes. It was also reported that three senior officials were placed in preventive detention and that the agency’s general director was removed from office.
The key issue here is not malware or a stolen database, but the improper access to and transfer of sensitive information linked to narcotics investigations. That places the case at the intersection of cybersecurity, data governance, and organized crime. The impact can be high because it affects the integrity of ongoing investigations and trust in the chain of custody for restricted information.
The case also shows how an internal leak can be as damaging as an external intrusion. According to prosecutors, there was an attempt to enable leaks and stop arrests, and the judicial coverage cited confirmed preventive detentions. For agencies with intelligence, justice, or security functions, internal access controls and query traceability are as critical as the technology perimeter.
Yucatán state government and the alleged data leak
In Mexico, an attacker claimed to have obtained about 30 GB of information and roughly 50,000 documents from the Yucatán state government, including alleged CURP records, birth certificates, official documents, and Civil Registry data. At the time of publication, the state government had not confirmed the leak.
The case remained unverified, but that does not make it analytically irrelevant. The described data set points to highly sensitive information that is useful for document fraud and identity theft. When material lacks official confirmation, it should be recorded as a monitoring signal, not as a confirmed breach.
The takeaway for Mexico’s public sector is cautious. Civil registry, identity, and public service offices are often high-value targets because they concentrate data that later circulates in fraud markets. The absence of public confirmation does not rule out an internal review, but it does prevent the episode from being elevated to a verified incident in this report.
Threats and active campaigns
Ransomware and extortion
The month’s ransomware and extortion activity was smaller in volume than August’s, but it still offered useful clues about how groups targeting the public sector operate. Of the 4 cases in the period, 2 amounted to a single mention on a leak site, and 2 did not make it clear whether there was asset encryption or only exfiltration. That ambiguity is part of the risk, because the public sees the post and not necessarily the real scope.
The most visible case was N0n, which included Argentina’s Ministry of Education on a leak site. The post circulated by the group, and reproduced by several specialist outlets, said it had obtained network configurations, 1.08 million connection records and a supposed Monero miner. There was no public confirmation from the agency within the available material, so it should be read as an intrusion claim, not proof of compromise.
N0n and Argentina’s Ministry of Education
N0n came into public view starting on September 18 and appeared tied to a set of claimed victims within a 24-hour window. Among them, the Argentine Ministry of Education was the only target classified as government and defense in that batch, according to one analysis source. It was also noted that the group did not have, in public vendor reporting, a broad or consolidated attribution as a mature ransomware operation.
The actor’s alleged reach was broad and technical, but the analytical value of the case lies in the lack of institutional verification. The post included supposed connection logs linked to school platforms, scholarships and other systems, along with a threat to keep the ministry network in a total blackout until a deal was reached. That rhetoric is typical of public extortion and is designed to pressure victims even before independent confirmation.
For government teams, the episode points to two lines of work. One is preparing responses to leak-site claims, which should be handled as crisis communications as well as technical events. The other is segmenting critical services and protecting credentials, because in campaigns like this the actor combines public visibility with pressure on dependent services.
Emperador and Brazil’s Receita Federal
Brazil’s Receita Federal appeared on Emperador’s leak site with a claimed exfiltration of 6.3 GB of data. Different reports said the attributed material included personnel and customer documents, plus gov.br user data, including passwords according to the group’s claim. None of the sources in the corpus presented the episode as confirmed by the agency.
This case sits in an intermediate zone between extortion and a leak-site claim. There was no public evidence of system encryption or of official validation of the files’ origin. For that reason, the most accurate classification is a single mention on a leak site with undetermined typology in the available material.
The fact that an actor named Brazil’s federal tax authority is enough to trigger fraud and impersonation monitoring. Tax-agency data often has a long commercial life in attackers’ hands, even when the publication goes no further than an unverified claim. The operational recommendation is to treat any such claim as a trigger to review access, tokens and exposure of citizen-facing services.
SIPA’s database and the risk of secondary extortion
The alleged offer of 38 million SIPA records on a dark web forum was not presented as a confirmed intrusion, but it did appear as material with potential for secondary extortion. The fact that the post was treated as unverified does not reduce the risk that such samples can fuel phishing, pension fraud or social engineering campaigns against citizens and public employees.
This is where a precise distinction matters. There is no evidence in the corpus of ANSES system encryption or proven extraction of those 38 million records. What does exist is an offer attributed to a third party and an official denial. That combination makes it necessary to monitor data circulation, password reuse and identity theft, rather than conclude that a breach has been closed.
Fraud and phishing
The month logged 4 documented fraud or phishing cases, a low number in absolute terms but relevant because of the type of asset compromised. The Peruvian case was the clearest, because the MEF account on X was used to push a crypto promotion that did not come from the agency. In this kind of incident, the vector is institutional trust, not necessarily data loss.
The claim about ANSES also belongs here, because although there is no breach confirmation, the circulation of a supposed database of 38 million records triggers a chain of potential fraud. The usual victims are not only government systems, but also citizens exposed to personalized messages. The operational risk appears when the material is reused to open accounts, verify identities or push fraudulent calls and emails.
APT and cyberespionage
The most serious campaign from a strategic standpoint was attributed to FamousSparrow, with the deployment of SparroWocky against government entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico and Venezuela. ESET said the campaign was first observed in August 2025, but September coverage again highlighted its regional impact and the concentration of targets in Latin America.
The cited sources described system information collection, command execution, screenshot capture, file exfiltration and TCP proxy capabilities, along with anti-analysis techniques. They also said initial access may have come through publicly exposed Microsoft Exchange servers, without the corpus identifying a specific CVE. That places the issue at the intersection of exposed infrastructure and persistent espionage operations.
For the public sector, the important finding is not only the sophistication of the tool, but the range of agencies reached. The region appears to be a preferred focus of observation, and not necessarily because of a single country. That means reviewing exposed email, segmentation, server hardening and monitoring for anomalous activity on high-value platforms.
Critical vulnerabilities
No critical CVEs were recorded in the September 2026 material reviewed. That does not mean critical vulnerabilities were not exploited in the region, only that this corpus did not document them in a verifiable way. In particular, the campaign tied to FamousSparrow mentioned initial access to publicly exposed Microsoft Exchange servers, but did not identify a specific CVE.
| CVE | Software | Exploitation | Source |
|---|---|---|---|
| No critical CVEs were recorded in the material reviewed | Not applicable | Not applicable | Period indicator |
The absence of CVEs in the material does not reduce the need to prioritize patching. It only shows that, in this corpus, public evidence leaned more toward compromised accounts, claimed leaks, and espionage operations than toward technical exploitation tied to a specific vulnerability identifier.
Regulation and compliance
The only regulatory move documented in the month came from Argentina. The National Cybersecurity Center said it held two sessions aimed at supporting National Public Sector agencies in complying with Provision No. 1/2026. The publication describes a regulatory support activity, not a security incident.
That kind of action often stays out of incident headlines, but in a sector report it matters for its practical effect. It shows that compliance is not detached from day-to-day operations, especially when controls cover access, technical logs, and monitoring. In a month with many breach claims and few solid confirmations, an active regulatory framework helps organize responses and responsibilities.
The figure also shows a decline from the previous month, when 4 regulatory moves were recorded. That does not automatically signal any easing, only less visible normative activity in the material reviewed. For compliance teams, it does not change the need to review controls and traceability, especially in agencies handling large volumes of personal information.
Countries and Most Affected Subsegments
The month’s geographic spread was concentrated in Argentina, Paraguay, Brazil, Peru, and Mexico, with different readings depending on the type of event. Argentina saw false positives tied to data leaks, a claimed ransomware campaign, and references to regional espionage. Paraguay concentrated the most sensitive criminal case. Brazil and Peru produced confirmed cases of account and platform exposure or compromise. Mexico appeared in an alert over an alleged state-level leak.
Argentina
Argentina had the broadest range of signals this month. The alleged hack of Lex100 was later disproven by technical review, ANSES claimed 38 million unverified records, the Ministry of Education appeared on N0n’s leak site, and several entities were named in data compilations attributed to third parties. That variety does not mean every case was a confirmed breach, but it does show Argentina’s state ecosystem was under pressure from public and private attribution claims.
From a subsegment perspective, the judiciary, education, and social security were the most frequently mentioned. These are three areas with high data value and significant reputational exposure. For offensive and defensive security teams, that means reviewing access lists, verification mechanisms for outside claims, and response capacity for leak sites.
Paraguay
Paraguay concentrated the most sensitive block of internal leaks and judicial consequences. Senad was at the center of an investigation into the alleged leak of information linked to drug trafficking, with charges, preventive detention, and the removal of officials. There was also a preventive alert about a possible exfiltration attributed to the Ministry of Health, although it was not confirmed.
The security and intelligence subsegment stands out here as the most exposed, not because of a classic technical intrusion, but because of internal integrity failures. When systems and case files are used by personnel with privileged access, oversight has to be stricter than in other areas. Traceability and insider-abuse controls become a core part of institutional cybersecurity.
Brazil
Brazil had a narrower signal set, but with clear impact. CAPES acknowledged a security incident in Meus Dados, and Receita Federal appeared as a claimed victim on a leak site. The first is an institutional confirmation; the second is an unverified claim that should not be treated as a confirmed breach.
The higher-education and administrative services subsegment appears to be especially exposed to personal and banking data. This also highlights the value of digital government portals as both an attack surface and a target for reputational extortion. The mix of citizen services and sensitive data requires stronger monitoring and segmentation.
Peru
Peru was marked by the compromise of the X account of the Ministry of Economy and Finance. It is a different signal, but an important one, because it shows institutional identity on social media remains an exploitable asset for fraud. The episode did not show evidence of technical exfiltration, but it did show misuse of the official channel.
For the economic administration subsegment, the priority is not only regaining access. It is also designing contingency procedures for publishing, rebutting, and removing malicious content. Response speed matters as much as account control strength.
Mexico
Mexico appeared in an alert over an alleged leak from the Government of Yucatán involving supposed Civil Registry data and official documentation. Without institutional confirmation, the case should be treated as a third-party claim. Even so, it points to a set of data with high value for document fraud and impersonation.
The civil registry and identity services subsegment deserves special attention. When these systems are leaked, or claimed to be leaked, the effects often go far beyond the agency itself. Fraudulent reuse of documents can extend the impact well beyond the administrative perimeter.
Trends and signals to monitor
Month-over-month comparisons show a steep drop in overall volume, but not a linear reduction in risk. There were 64 fewer verified incidents, 35 fewer unclassified incidents, and 22 fewer ransomware or extortion cases. At first glance, that points to a quieter month. In practice, confirmed incidents, questionable leaks, fraud involving official accounts, and attributed espionage keep the need for monitoring high.
The first signal to watch is the shift from ransomware to public leaks and institutional fraud. In September, there were fewer extortion campaigns than in August, but more cases where the goal was to gain visibility or monetize access through indirect channels. That means monitoring leak sites and official social media accounts has to be strengthened, not just endpoint surveillance.
The second signal is the persistence of cases with partial confirmation. The corpus includes a significant number of events in which the threat actor claims the intrusion and the organization denies it, or the reverse. That pattern is especially visible in ANSES, Receita Federal and Yucatán. For security teams, the priority is to speed up forensic validation and denial procedures.
The third signal comes from the FamousSparrow campaign. Although the operation did not begin in September, the reviewed evidence again places Latin American governments among the targets of espionage activity with modular, persistent capabilities. The focus is no longer only on stealing visible data, but on sustained observation of networks and systems.
The fourth signal is that the month continued to expose internal control failures. The Paraguay case is the clearest example, because the leak was not about malware but about people with privileged access and the alleged manipulation of sensitive information. That requires a review of privilege profiles, traceability, and separation of duties.
Recommendations for security teams
First, formally separate technical incident response from external complaints. A leak site, a dark web post, or a media complaint is not the same as a confirmed breach. Even so, each should trigger a validation process with defined deadlines, because an agency’s reputation can be damaged before anything is verified.
Second, tighten protection for official social media accounts and their recovery. The case of Peru’s MEF shows that an institutional account can become a fraud platform in minutes. Phishing-resistant MFA, token controls, session monitoring, and response procedures for fake posts should be standard across ministries and agencies.
Third, prioritize internal access control and traceability on systems that handle judicial, health, pension, or security information. Paraguay sent a very clear warning about insider risk. Broad privileges, unjustified queries, and weak correlation between access and role open the door to leaks with criminal or political impact.
Fourth, review the exposure of public services that use email or external platforms, especially where initial access may come through exposed infrastructure. The campaign attributed to FamousSparrow reinforces that the perimeter does not end at the internal network. Publicly reachable servers, authentication services, and collaboration components remain relevant entry points.
Fifth, strengthen crisis communications management so an official denial does not come too late or without enough evidence. The Lex100 case shows that a quick technical review can shut down a false positive, but that capability must exist before media attention builds. Technical and press teams need joint protocols.
Sixth, add monitoring for the reuse of leaked data in later fraud. It is not enough to detect the first publication; teams need to track how a dataset, real or not, turns into phishing, deceptive calls, or impersonation. That is where much of the real damage to the public sector and to citizens occurs.
Frequently Asked Questions
What was the difference this month between confirmed incidents and unverified leak claims?
The distinction was central to interpreting the period. CAPES in Brazil and Peru's MEF had official confirmation of incidents, while ANSES, Yucatán, the Receita Federal, and the Lex100 case remained unverified claims or were denied. That distinction cuts across the Relevant Incidents section and the Active Threats and Campaigns section.
Which country saw the most sensitive case from an institutional standpoint?
Paraguay carried the most sensitive signal because of the case against Senad officials, with charges, pretrial detention, and removals from office. This was not a malware case, but a leak of sensitive information tied to drug trafficking. That overlaps the Countries and Most Affected Subsegments section and the Relevant Incidents section.
Was ransomware confirmed against public-sector agencies in the region?
There were 4 cases with ransomware or extortion as the primary focus, but the material did not allow confirmation in all of them as to whether assets were encrypted. Two appeared only as mentions on a leak site, and two could not be classified precisely. The correct reading comes from combining the period indicators with the Active Threats and Campaigns section.
What practical risk did the campaign attributed to FamousSparrow leave behind?
It left the risk of persistent espionage against governments in several Latin American countries, with the ability to run commands, capture screenshots, and exfiltrate files. Although the campaign has been observed since 2025, September brought it back into focus because of its regional reach. That answer overlaps with Critical Vulnerabilities, even without CVEs, and APT and Cyberespionage.
What should a public-sector CISO monitor first after this month?
First, the integrity of official accounts and privileged access. Next, leak site claims, because they can lead to fraud or disinformation before technical confirmation. Finally, exposure of public services with external access. That prioritization crosses the Relevant Incidents, Trends, and Recommendations sections.
Material limitations
This report was prepared exclusively from the material provided for September 2026, with no access to the internet or sources outside the authorized list. Undated facts were excluded from the indicators and were not used to build monthly counts. Aggregated telemetry was also not added to the incident volume.
An indicator at 0, especially the critical CVE indicator, means none were recorded in the analyzed material, not that no critical vulnerabilities were exploited in the region. The indicator window covered 50 dated events in September 2026, and the calculations were based on 49 verified events from the period.
The scope of the material included attacks, breaches and regulation applied to government bodies and the public sector in Latin America. Sponsored content, consumer social networks, LinkedIn posts and other platforms not listed as valid sources were excluded. When a claim came from a leak site, a forum or an unverified third party, it was treated as an unverified claim, not a confirmed incident.
Sources
- Hackeo fantasma al Lex100Diario Judicial
- Supuesto hackeo a la ANSES: qué se sabe sobre la filtración de 38 millones de datos y la desmentida oficialÁmbito
- Qué se sabe sobre el supuesto hackeo a la ANSES y cómo cuidar tus datosLa Brújula 24
- N0N Ransomware: 10 Victims Posted in Single-Day Surge — Cross-Sector Campaign Hits Telecom, Finance, Government and EducationSecurity Arsenal
- n0n ransomware group: victims, TTPs, profileZeroHour
- Victim: Ministry of Education — ArgentinaRansomware.live
- Argentina had its busiest week yet on ransomware leak sitesIntelFusions
- Ministry of Education — Argentina ransomware attack — n0n leakPulse by Kali
- Massive leak of Argentine government data: AFIP, BCRA and policeKali Linux Intelligence Reports
- Noticias de ciberseguridadArgentina.gob.ar
- Argentina SIPA database with 38 million records for salePulse by Kali
- Comunicado sobre incidente de segurança na Plataforma Meus DadosCAPES — Coordenação de Aperfeiçoamento de Pessoal de Nível Superior
- Brazil's tax agency appears on a young crew's leak siteIntelFusions
- Receita Federal aparece em portal de ransomware grupo Emperador com suposto vazamentoTechstart
- Cyber Alert: Brazil — Receita Federal do BrasilHackmanac
- Emperador claims Brazil’s federal tax authority — alleged 6.3GB of government dataDaily Dark Web Intelligence
- #LaMafiaManda: Cámara confirma prisión preventiva de exdirectores de la SenadABC Color
- Tribunal confirma prisión para imputados por filtración de datos a Eulalio GomesLa Nación Paraguay
- Se entrega el exdirector de ente antidrogas de Paraguay imputado por filtrar informaciónAgencia EFE / Infobae
- Fiscalía: Agentes de Senad filtraron dato para ayudar a un narco a huirÚltima Hora
- #LaMafiaManda: envían a Viñas Cue a tres altos mandos de la SenadABC Color
- Rachid dice que fiscales quisieron hacer “un circo” de la causa por supuesta filtración en SenadABC Color
- WEBSITE DEFACEMENT CAMPAIGN AGAINST ...VECERT Analyzer
- Imputan a 4 funcionarios antidrogas de Paraguay por filtrar datos a narcotraficantesAgencia EFE / Swissinfo
- Hackean cuenta de X del Ministerio de Economía y FinanzasLa República
- Ministerio de Economía y Finanzas: ciberdelincuentes hackean cuenta de X y la institución se pronunciaEl Popular
- Peru Economy Ministry's X Account Hacked in Likely Crypto ScamBloomberg
- Hackean cuenta del Ministerio de Economía de Perú para promocionar una criptomonedaBloomberg Línea
- MEF alerta que su cuenta oficial de X fue vulnerada y advierte que publicaciones no son oficialesCaretas
- MEF advierte que su cuenta en la red social X ha sido vulneradaAgencia Andina
- New SparroWocky backdoor deployed in attacks on governmentsCyber Insider
- China's FamousSparrow hackers target Latin America with new backdoorThe Record
- 21st September – Threat Intelligence ReportESET Research / Check Point Research
- China's Salt Typhoon backdoors Latin American orgs with new snooping malwareThe Register
- Chinese hackers use SparroWocky malware in govt espionage attacksBleepingComputer
- China-Linked FamousSparrow Deploys SparroWocky Backdoor in Latin AmericaHackread
- China-Aligned FamousSparrow Deploys SparroWocky Backdoor in Latin AmericaThe Hacker News
- Alertan por presunta filtración de datos del Gobierno de YucatánEl Diario de Yucatán
- FBI hunting the hackers who stole its employees' sensitive informationNPR
- FBI reportedly declares 'cyber security incident' after hackers steal agents' personal dataTechCrunch
- Agentes no autorizados de OpenAI atacaron tres sitios web distintos del Gobierno de EE.UU.CNN en Español
- OpenAI Discloses Unauthorized AI Agent Activity Across U.S. Government WebsitesSecurity Boulevard
- Rogue OpenAI agents accessed US government websitesPolitico
- FBI probes cyberattack tied to third-party jobs portalCybersecurity Dive
- FBI investigates breach of jobs website as hackers claim sensitive data stolenThe Guardian
- El FBI investiga un presunto ciberrobo de datos personales de sus agentesEFE
