CiberLATAMbywhalemate
Intelligence reportAug 11, 202628 min read

Digital Services, Data Centers, and IT/SaaS, Jul 2026

July ended with cloud and SaaS intrusions, critical Citrix and Ivanti alerts, and Ecopetrol as the region's most sensitive case.

Digital Services, Data Centers, and IT/SaaS, Jul 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are automatically filled with verified dated facts from the period. Each one states its source base and counting criterion, so the figures reconcile across modules. They are the recurring month-to-month readout; the later analysis expands on the cases without repeating this summary.

Indicator window: 41 dated facts in July 2026 · 1 from prior months (comparative frame, not monthly volume). Facts from prior months are used only as a comparative frame in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Monthly Verified Signal Dashboard July 2026 · Latin America Dominant threat: Unclassified (18 of 39 events). Coverage: 41 dated events in July 2026 · 1 of months ant… VERIFIED EVENTS 39 period baseline: all counts measured from below against this total RANSOMWARE / EXTORTION 6 1 asset encrypted confirmed · 5 not categorized undeterminable from the evidence UNCLASSIFIED INCIDENTS 11 breaches or outages without threat type stated FRAUD / PHISHING 2 documented fraud campaigns documented REGULATION 0 rules, rulings, or penalties UNIQUE CVEs 8 CVE-2023-46805 / CVE-2023-4966
Monthly Verified Signal Dashboard — Base: 39 verified dated events for Latin America.
MONTHLY FIXED MODULE Threat axis distribution July 2026 · Latin America Each event counts in only one axis, so the total is exactly 39. "Unclassified incidents" is the remainder. Unclassified 18 Incidents 11 Ransomware 6 Fraud 2 Vulnerabilities 2
Threat axis distribution — Each event is assigned to one axis based on its classification; the total reconciles with the 39 events in the period.
MONTHLY FIXED MODULE Sectoral Signal Distribution July 2026 · Latin America Base: 39 incidents in the period · total 42 because 3 incidents are classified in more than one sector. Other / no sector ident… 22 Public sector / OIV 10 Technology 4 Energy 3 Telecom 2 Health 1
Sectoral Signal Distribution — Heuristic classification by victim sector. One incident may affect more than one sector, so totals may exceed the base.
MONTHLY FIXED MODULE Geographic distribution of signals July 2026 · Latin America Each event is assigned to a single country or to regional coverage, so the total is exactly 39 of 39 events… Regional 19 Colombia 11 Paraguay 7 Chile 2
Geographic distribution of signals — Verified events from the period grouped by country or regional coverage; each event is counted once.

Executive monthly summary

July 2026 sent a clear signal for the digital services, data center, and technology provider vertical in Latin America. The most visible case was Ecopetrol, not only because of the scale of the unauthorized access and the associated data download involving thousands of accounts, but also because the incident reached cloud storage environments for about 15 subsidiaries and forced the company to revoke access, block mass-exfiltration mechanisms, and launch legal and forensic response work that was still open at month-end. The company stressed that there was no material disruption to critical operations and no confirmed encryption of original assets, but the reputational impact and the exposure of information were clear.

The other major theme for the month was preventive and structural. Chile's government CSIRT issued alerts on critical vulnerabilities in Citrix NetScaler ADC and Gateway, with CVE-2023-4966 identified as actively exploited, and on multiple critical flaws in Ivanti products. In this vertical, that combination matters more than the CVE list itself, because it points to remote access surfaces, gateways, and appliances that are often the first entry point into cloud, SaaS, and data center management environments. The material does not show any associated regulatory move, but it does show a clear operational warning: the logical perimeter of providers and digital services remained a priority target.

The regional picture also shifted along the espionage and persistent access axis. Paraguay reported infiltration by multiple actors linked to China in state systems, with the investigation still ongoing and references to an attempt to collect data quietly rather than to destructive sabotage. Although that episode does not belong strictly to the corporate cloud or SaaS subsegment, it reinforces a lesson that applies to the technology provider ecosystem: in Latin America, persistent, low-noise access remains a real risk for digital infrastructures with heavy operational dependence.

In ransomware, the month showed an unsettling mix of active campaigns, extortion tactics, and attribution noise. Ecopetrol confirmed a blocked attempt under its controls, while SCILabs reported shifts in the regional mix, with newer or more visible variants such as SafePay and The Gentlemen. TrendTIC described attacks in Colombia and Mexico where ransom notes were printed on corporate printers after BitLocker encryption, a sign of operational pressure that combines disruption, humiliation, and faster negotiation. The available evidence does not allow all of those cases to be grouped under a single label; the month included confirmed encryption, exfiltration without encryption, and, in several incidents, no precise mechanism was identified by the source.

The underlying reading is that July was not a month of a single major wave, but of risk stacking across layers, critical vulnerabilities in exposed components, intrusions focused on cloud and storage, ransomware campaigns with more aggressive tactics, and a persistent threat environment that continues to affect the region, whether in the public sector or in companies with strong digital dependence. The overall signal for this axis is high in severity, although fragmented across threat types. There is no single dominant pattern that is easy to summarize, because most of the events were left unclassified in the source material, but the combination of exposure, exfiltration, and active exploitation of appliances leaves little room for complacent reading.

Regional monthly outlook

The regional picture for July in digital services, data centers and technology providers is one of high risk, driven mainly by the convergence of three threat layers. The first is technical exposure: Citrix and Ivanti surfaced critical vulnerabilities, one of them already being actively exploited, affecting precisely the points where remote access, virtualization, administration and service publishing converge. The second is intrusion with exfiltration, visible at Ecopetrol, where unauthorized access spread into cloud archive environments and about 3,300 user accounts. The third is extortion pressure, with ransomware confirmed in one case, a blocked attempt in another, and several references to active campaigns whose exact classification could not always be determined from the material.

That overlap is especially sensitive for the vertical because the region depends on a broad chain of digital intermediaries. Third-party cloud environments, perimeter appliances, access gateways and managed services function as concentration points for risk. When a critical flaw appears in Citrix NetScaler or Ivanti, the issue is not just the vulnerability itself, but how easily it can become initial access, persistence or lateral movement into data hosted on customer systems. If the target is also a company with subsidiaries and distributed services, such as Ecopetrol, the exposure surface multiplies.

The geographic read is also clear. Colombia accounted for the month’s most sensitive corporate case, while Chile contributed high-value operational alerts from its CSIRT. Paraguay, meanwhile, stood out as a sign of cyberespionage with implications for infrastructure and digital sovereignty. The material does not show a broad set of incidents involving pure data centers or major SaaS providers with confirmed public impact, but it does show a chain of events that directly touches the digital business those providers support. In other words, July brought fewer mass outages and more incidents that compromise control, access and trust.

The month’s dominant threat remained unclassified in 18 of 39 cases, which is no minor gap. It points to reporting that captures consequences, official statements or alerts without a closed taxonomy for the attack. For a risk reader, that matters because a lack of classification does not reduce severity, but it does limit the ability to correlate techniques. Defensive operators should not read that figure as benign, but as a reminder that the observed surface is more distributed than in other months and that public evidence rarely arrives with every technical detail at once.

TIMELINE Verified events in the period 1/7 ISHTechnologyheld in 1/7 ESET noted thatthe 7/7 TrendTICreported thatAmerica 9/7 SCILabs noted asignificant 9/7 SCILabs reportedthat it 9/7 SCILabssaid thefive
Timeline of verified events, July 2026 — Milestones with confirmed dates within July 2026. Events from earlier months are left out of the timeline and used only as context.

Period indicators

Indicator Value
Verified facts in the period (basis for all indicators) 39
Indicator time window 41 facts dated in July 2026 · 1 from prior months (comparative frame, not monthly volume)
Unclassified incidents (breaches or outages) 11
Cases with ransomware or extortion as the primary focus 6
Ransomware breakdown by impact type: Confirmed asset encryption 1
Ransomware breakdown by impact type: Impact could not be determined from the available material 5
Documented fraud or phishing cases 2
Documented regulatory moves 0
Critical CVEs mentioned 8
Sectors with at least one documented fact 5
Dominant threat of the month Unclassified (18 of 39 facts)
Facts with direct source confirmation 97%
Aggregate telemetry figures excluded from volume 2 (aggregated attempts or blocks: not incidents with confirmed impact)

Methodological reading of the indicators

The base of 39 verified facts for the period is the starting point for all analytical interpretation. The time window of 41 facts dated in July 2026 and one fact from prior months is retained as context, but it is not included in the monthly volume. That distinction matters because it prevents July’s signal from being inflated by coverage published during the month but referring to an earlier period.

The 11 unclassified incidents highlight a common problem in this vertical, the difficulty of closing the taxonomy from early public coverage. In digital services and technology providers, the first to speak is often the victim’s communications team or a wire report, and the technical details arrive late, if at all. That requires careful reading of the month. A case may be an intrusion with exfiltration, a blocked ransomware attempt, a breach without encryption, or a simple attribution on a leak site. Grouping all of that as "ransomware" erases operational differences that are central for a CISO.

The 8 critical CVEs mentioned were not a decorative data point. In this area, CVEs affecting appliances and gateways can immediately degrade control over access, sessions and traffic to internal or exposed services. The material does not add those CVEs to an intrusion count, and it should not be read that way. They are exposure and attack-surface signals, not confirmed incidents by themselves.

Relevant incidents

Ecopetrol and the cloud intrusion

Ecopetrol was the month’s most significant corporate case in this vertical because it combined several risk dimensions at once. The company reported unauthorized access to digital resources belonging to the company and its subsidiaries, along with a ransomware attempt that was blocked by its cybersecurity controls. Reuters added that the access affected cloud file storage environments for about 15 subsidiaries and led to the unauthorized download of data linked to about 3,300 user accounts. That makes the case especially relevant for digital services, because the incident was not limited to workstations or a single isolated system, but extended to cloud-hosted files and a broad group ecosystem.

The company’s public response was relatively clear on one key point, it had not identified a material disruption to critical operations, production capacity or essential services at the time of the statement. Noticias RCN also said no impact had been identified on transactional systems or the company’s and its subsidiaries’ digital solutions ecosystem, and that there was no evidence the original information had been destroyed or encrypted. That distinction matters because it separates availability impact from confidentiality impact. For a report on this axis, the intrusion with exfiltration and the blocked attempt weigh more than a simplified narrative of a successful ransomware attack.

The case’s evolution also showed a classic pattern of containment and a widening response perimeter. Ecopetrol said it revoked unauthorized access, blocked mechanisms associated with bulk data downloads, identified external infrastructure used to store or download data, and strengthened monitoring of its technology infrastructure. It also filed a criminal complaint with the Fiscalía General de la Nación. El País América Colombia added that in a third follow-up statement, the company was still acknowledging uncertainty over the full scope, impact and costs of the incident. That uncertainty is itself a risk variable in environments with multiple subsidiaries and distributed storage.

Public attribution also increased the case’s sensitivity. A group calling itself The Gentlemen claimed to have up to one terabyte of information from Ecopetrol and subsidiaries such as Hocol, Cenit, Eust and Econova. That claim was not independently verified by the available coverage, but it does reinforce a hypothesis that had already been emerging in the region, attackers combining theft, reputational pressure and later negotiation. For a technology provider or digital services company, the problem is not only the leak, but the attacker’s ability to turn data into operational and legal pressure.

Citrix NetScaler ADC and Gateway

Chile’s Government CSIRT issued an alert on July 17 about critical vulnerabilities in Citrix NetScaler ADC and Gateway, including CVE-2023-4966, which the alert says has been actively exploited in attacks against those appliances. In this vertical, that line matters more than the flaw listing. NetScaler and similar products often sit at the edge of access to internal resources, virtual desktops, published applications and authentication services. When a vulnerability is actively exploited there, the risk does not stop at the appliance, it extends to everything connected behind it.

The regional importance of the alert is twofold. First, it comes from a government CSIRT, not a commercial advisory. Second, it does not describe a single isolated historical vulnerability, but a set of critical flaws in a component that remains sensitive for organizations with distributed operations, private cloud providers, data centers and hybrid environments. Mitigation is neither immediate nor trivial when the exposed equipment supports active sessions, tunnels or remote access for internal and external users.

Ivanti and exposed access appliances

Chile’s Government CSIRT published another alert on July 23 about multiple critical vulnerabilities in Ivanti products, including CVE-2023-46805, CVE-2024-21887, CVE-2024-22024, CVE-2024-22026, CVE-2024-22028, CVE-2024-22029 and CVE-2024-22030. The analytical value of the case is not in the list, but in the combination of severity and context. Ivanti appears in management and access surfaces where exploitation can open a path into sensitive environments without passing through traditional network controls.

For the vertical, that means security teams should not stop at a simple urgent patching message. The deeper question is what services the appliance exposes, what credentials or sessions it can reach, what real segmentation exists behind it, and whether there is behavior monitoring for anomalies in authentication, tunnels and downloads. In a month when unauthorized access to cloud resources was a real problem in Colombia, an alert like this is not abstract. It is another piece of the same attack surface.

Paraguay and the cyberespionage hypothesis

Paraguay does not present a technology provider case in the strict sense, but it does provide a persistent access campaign that is worth reading for its implications for digital infrastructure. ABC Color reported that the Prosecutor’s Office opened an investigation after the MITIC complaint and had already taken testimony from the ministry’s head, Gustavo Villate, while steps continued to determine the scope of the reported attack. Regional coverage also said the complaint coincided with the expansion of the 5G network and mentioned operators such as Tigo and Personal in the context of restrictions on Chinese-origin equipment.

DW and La Tribuna added the technical and political hypothesis. Pedro Martínez, from MITIC, said the threats matched activity typical of groups operating for the Chinese government and that the goal was not to destroy or sabotage infrastructure, but to collect data stealthily and maintain continuous monitoring of state activity. EFE, carried by Infobae, added that MITIC and the US government reported the detection of multiple China-linked actors in Paraguayan state cyber systems. In this case, the value for this report is the confirmation that espionage-motivated actors continue to target complex networks and quiet data collection, a logic that can also affect service providers and data center operators when they host critical services or privileged identities.

StrikeShark campaign and new malware

Kaspersky reported a cyberattack campaign called StrikeShark, with activity against organizations in Colombia and other countries, using a new malware called SharkLoader. The available coverage does not place the campaign solely within the IT/SaaS vertical, but it does connect it to Latin America and to an intrusion pattern that matters for this segment because of loaders and the potential to chain infection, persistence and later deployment of more damaging payloads.

The point to watch is not just the campaign name, but the dynamics. When a new loader appears, the operational value for attackers is usually in delivering other malware families or opening the door to later intrusion phases. In technology providers and digital services, that matters because administration and support environments concentrate high-value credentials and permissions. If a campaign appears first in Colombia, but has regional reach, the signal for the rest of the region is early vigilance, not waiting.

Threats and Active Campaigns

Ransomware with confirmed encryption

The only case this month in which the material supports confirmed encryption in this vertical is the one TrendTIC reported in attacks in Colombia and Mexico, where attackers printed ransom notes on victims' corporate printers after encrypting systems with BitLocker. That tactic matters because it confirms not only an impact on availability, but also adds a physical and visible layer of pressure on the organization. Printing the ransom note turns a digital incident into a tangible reminder for users and support teams.

From a technical standpoint, the use of BitLocker as part of the encryption chain confirms that the attacker is trying to immobilize the system and force a fast response. For the digital services vertical, that means reviewing scenarios where encryption is not limited to business servers, but extends to admin components, remote desktops, support systems, and machines used to operate platform services. The visibility of the ransom note on printers also points to a level of preparation in post-exploitation that should not be underestimated.

Ransomware or extortion without determinable encryption

Ecopetrol reported a ransomware attempt blocked by cybersecurity controls, but the material does not specify whether the attacker managed to encrypt assets or whether execution was only attempted before being stopped. That requires classifying the episode as a contained extortion attempt, not confirmed encryption. The distinction is essential. A blocked attempt may leave evidence of compromise and require forensic response, but it is not the same as an availability incident caused by encryption.

SCILabs also observed a shift in the regional mix of active variants, with SafePay and The Gentlemen gaining visibility in Latin America. That reading should be treated cautiously because the material refers to telemetry and changes in prominence, not necessarily incidents with confirmed impact in each country. Even so, for security teams this suggests that the extortion surface is not limited to the better-known legacy families. When an actor changes tools or renames an operation, detection and response patterns need to revisit assumptions.

Single mention on leak site or public attribution

The Ecopetrol case also came under public attribution pressure. The group The Gentlemen claimed to possess up to one terabyte of information and listed data categories that would include drilling records, payroll, banking data, medical and biometric employee information, as well as active VPN credentials. Because the coverage makes clear that this is the group’s claim and not an independent verification, the correct reading is as an extortion and exposure threat, not full confirmation of the exact volume or nature of the data.

At this point, it is useful to distinguish between proof of access, proof of exfiltration, and proof of publication. The July material confirms unauthorized access and downloads associated with thousands of accounts, but it does not publicly prove the complete integrity of the leaked set. For a CISO, that distinction changes the response: a claim on a leak site requires crisis readiness and exposure monitoring, but it should not be confused with the full operational chain of a fully validated breach.

Fraud and phishing

The period left two documented references in this area. On one hand, ESET said phishing remains the most common attack vector in Latin America and affected 73% of the organizations surveyed. On the other hand, the regional industrial cyberthreat material reiterated that phishing and malicious documents remain a high-yield entry point for actors seeking initial access, malware delivery, or credentials. Neither of those items translates automatically into a specific incident in the vertical, but they do define the baseline risk.

For technology providers and digital services, that persistence matters because many serious intrusions start with what looks like a routine email, an attachment, or a fake login page. When the target is administrators, support staff, or personnel with console access, a single click can open the door to cloud environments, customer portals, or data center management systems. The issue is not phishing as a generic concept, but its ability to feed the month’s other threat categories.

APT and hacktivism

The Paraguay incident is the clearest signal in this area, even if its exact nature oscillates between espionage and geopolitical accusation. The key point for this report is not to settle attribution between states, but to record that there was multi-stage, persistent infiltration activity oriented toward data collection, with explicit reference to actors linked to China. In the digital services vertical, that kind of operation can overlap with perimeter infrastructure exploitation, credential gathering, and identity service monitoring.

The coverage on Colombia, with VECERTRadar pointing to a presumed hosting infrastructure compromise, also deserves mention even without confirmation from authorities, ColCERT or the provider named. Because it is a social media intelligence alert, it is not included as a confirmed incident or as part of the count. It does, however, leave an operational signal, the hosting segment and public procurement appear to be points to watch, but they should not be overstated without official verification.

Critical vulnerabilities

CVE Software Exploitation Source
CVE-2023-4966 Citrix NetScaler ADC and Gateway Actively exploited in attacks according to the Chile Government CSIRT alert Chile Government CSIRT
CVE-2023-46805 Ivanti Critical vulnerability mentioned in the Chile Government CSIRT alert Chile Government CSIRT
CVE-2024-21887 Ivanti Critical vulnerability mentioned in the Chile Government CSIRT alert Chile Government CSIRT
CVE-2024-22024 Ivanti Critical vulnerability mentioned in the Chile Government CSIRT alert Chile Government CSIRT
CVE-2024-22026 Ivanti Critical vulnerability mentioned in the Chile Government CSIRT alert Chile Government CSIRT
CVE-2024-22028 Ivanti Critical vulnerability mentioned in the Chile Government CSIRT alert Chile Government CSIRT
CVE-2024-22029 Ivanti Critical vulnerability mentioned in the Chile Government CSIRT alert Chile Government CSIRT
CVE-2024-22030 Ivanti Critical vulnerability mentioned in the Chile Government CSIRT alert Chile Government CSIRT

The table above summarizes the 8 critical CVEs mentioned in the analyzed material. No additional critical CVEs associated with other vendors in the axis are recorded in this corpus. That does not mean there are no critical vulnerabilities being exploited in the region, only that none appeared in the July material with a confirmed date and a usable source.

Regulation and compliance

There were no documented regulatory moves in the July material for this vertical. That 0 should be read literally and narrowly: no formal ruling, penalty, mandatory guidance, or compliance change appeared that could be recorded as a fact for the month in the corpus reviewed.

The absence of visible regulation does not reduce the compliance burden that emerges from the incidents. Ecopetrol had already said it would file a criminal complaint before the Fiscalía General de la Nación, and the handling of unauthorized access, evidence preservation, and blocking exfiltration implies practical obligations around traceability, response, and likely internal and external notification under the applicable framework. In Paraguay, the opening of a prosecutor-led investigation after MITIC’s complaint also shows how cyberespionage incidents and compromises of state systems quickly move into an evidentiary and authority-driven phase.

For the technology vendor subsegment, compliance depends less on a new law and more on the ability to demonstrate control over access, segmentation, logs, and incident response. The month offered enough examples to show that the regulatory conversation may not have been public, but the legal cost of a breach, an exfiltration, or an actively exploited vulnerability remains in play.

Countries and most affected subsegments

Colombia

Colombia saw the vertical's most serious incident in July, the Ecopetrol case, which affected cloud file storage environments at about 15 subsidiaries and led to the unauthorized download of data tied to approximately 3,300 user accounts. The company also faced public pressure after an attribution by The Gentlemen and had to clarify that it saw no material disruption to critical operations or confirmed encryption. The corporate scope of the incident is very high because it touches both the cloud and the company’s multi-tier structure.

Colombia also appears in campaign and telemetry signals. Kaspersky reported StrikeShark activity against organizations in the country, and TrendTIC placed it, along with Mexico, among attacks where the ransom note was printed on corporate printers after BitLocker encryption. While some of that data comes from third-party coverage and not from a single public incident, the accumulation of references points to a broad risk surface, ranging from intrusion and exfiltration to ransomware pressure.

Chile

Chile appeared less for incidents and more for alerting capacity. Chile’s government CSIRT published two high-value advisories, one on Citrix NetScaler ADC and Gateway and another on multiple critical Ivanti vulnerabilities. That makes the country a technical reference point for the region this month, because the signal was not a publicly reported, completed attack, but an early warning about surfaces that are often at the center of digital infrastructure.

For regional teams, these alerts should not be read as closed national events, but as defensive inputs with cross-cutting reach. A vulnerable appliance in Santiago or any other Latin American capital can become the entry point to remote services, data centers or SaaS platforms with users distributed across the region.

Paraguay

Paraguay stood out because of the cyberespionage case reported by MITIC and followed by the Prosecutor’s Office. Press coverage linked it to 5G expansion and restrictions on Chinese-origin equipment, while sources cited in the material pointed to multiple threat actors tied to the Chinese government. The takeaway here is that the country was pulled into a discussion about persistence, access and data collection rather than destruction or encryption.

Even if this is not a commercial technology provider case, it matters for regional digital infrastructure because it shows sustained pressure on complex state networks. The same vectors, or their variants, can appear in organizations with centralized identity administration, access services and hybrid platforms.

Mexico

Mexico appears in ransomware coverage and the broader escalation of cyberattacks. Infobae cited a 38% increase in cyberattack cases in the country and linked it to a regional wave associated by Kaspersky with StrikeShark. TrendTIC also included Mexico in the ransomware pattern in which corporate printers were used as a pressure channel. In the context of this vertical, that points to persistent exposure among organizations that depend heavily on digital services and distributed administration.

ESET’s data on regional victims and its mention of Mexico as one of the countries most affected by ransomware in the first half of the year reinforces the baseline reading: Mexico appears here not just as a number in telemetry, but as a country where the combination of corporate scale, digital services and extortion pressure remains visible.

Brazil

Brazil did not lead a specific corporate incident in the July material, but it did serve as a regional benchmark in telemetry and threat volume. ESET and SCILabs placed it among the Latin American countries with the most victims or notable activity, and EM coverage said it leads Latin America in ransomware incidents and ranks ninth globally. That last reference comes from the source and should be treated cautiously, but it helps frame Brazil’s weight in the regional discussion.

For an analysis of digital services and data centers, Brazil remains a market with concentrated infrastructure and broad exposure, so any shift in ransomware families, phishing techniques or appliance exploitation there tends to have a demonstrative effect on the region.

Cloud and online storage subsegment

This subsegment was clearly pressured by Ecopetrol. The unauthorized access reached cloud file storage environments and affected multiple subsidiaries. In risk terms, that puts cloud storage and identity administration at the center of the story. This was not a classic service outage, but a loss of control over data that, by definition, depends on strong authentication, permissions, monitoring and traceability.

Perimeter appliances and remote access subsegment

Citrix NetScaler and Ivanti represent the other side of the month. These are components that sit on the boundary between users, applications and internal services. When active exploitation shows up there, the threat is not theoretical. The subsegment is exposed to initial intrusion, session theft, lateral movement and access to platforms that later support broader digital operations.

There is no archived comparative baseline for this indicator format, so it would be wrong to invent a month-over-month change based on a historical series that is not available in the material. What can be said is that July combines different kinds of signals that, together, raise attention on the vertical.

The first signal is the persistence of critical vulnerabilities in access appliances. When Citrix and Ivanti appear in the same monthly window with high-impact alerts, the problem is not just the CVE, but the repeated exposure of the same class of surface. For digital service operators, that points to inventory review, external exposure, active sessions, authentication, and the real ability to patch without downtime.

The second signal is the maturity of extortion. Ecopetrol showed exfiltration without visible material disruption, while TrendTIC documented a case with confirmed encryption and ransom notes printed. That contrast forces a move away from the mental model of "ransomware equals encryption." In July, extortion pressure took different forms, and the defensive response must account for blocking data theft, segmentation, secure backups, and monitoring of printers and output devices as much as servers.

The third signal is the normalization of persistent, quiet access. The Paraguayan case, even outside the pure corporate subsegment, is a reminder that the region remains a target for actors seeking persistence and data collection, not just disruption. For technology providers and data centers, that means watching not only visible security events, but also anomalous administration, authentication, and lateral movement behavior.

Security team recommendations

  1. Review the external exposure of remote access and edge appliances immediately, especially the Citrix and Ivanti families mentioned in CSIRT alerts. It is not enough to confirm that a patch exists. Version, exposed surface, multifactor authentication, persistent sessions, and signs of recent use need to be verified.

  2. Prioritize defense of cloud storage environments and the identities with privileged access to them. The Ecopetrol case shows that exfiltration can happen even when critical operations keep running. That calls for reviews of inherited permissions, inactive accounts, access between subsidiaries, application keys, and large download logs.

  3. Add controls focused on exfiltration, not just encryption. Blocking unusual outbound traffic, detecting external infrastructure used to store data, alerts for mass dumping, and log retention are more useful than assuming the incident will present itself as classic ransomware.

  4. Strengthen protection for printers, print queues, and shared devices. Printing ransom notes is not a minor detail. It signals that the attacker is seeking internal visibility and psychological pressure. These assets should be part of incident response and segmentation.

  5. Review VPN credentials, privileged access, and session tokens. The mention of active VPN credentials in the attribution by the group that claimed Ecopetrol, even without independent verification, points to a recurring vector. Every administrative or remote access account should be rotated and validated after an incident of this kind.

  6. Increase monitoring for phishing and malicious documents among users with access to consoles, cloud administration, and technical support. ESET and TrendTIC agree that this vector is still very active. In technology vendors, an administrator’s email is worth more than a regular user’s.

  7. Prepare response scenarios that distinguish exfiltration, encryption, and public attribution alone. Containing confirmed-encryption ransomware is not the same as managing a leak claimed on a leak site. The plan should cover communication, evidence, forensics, legal issues, and continuity in each case.

  8. For organizations with a regional footprint, standardize minimum monitoring across countries. Paraguay, Colombia, Chile, and Mexico showed different signals, but they share surface patterns. If each subsidiary responds under its own criteria, the attacker will take advantage of that disparity.

Material limitations

This report covers only the material provided for July 2026 and uses it as the sole source of truth. Facts from earlier months, included in the archive as a comparative frame, are mentioned only when they help contextualize the trend, but they are not part of the monthly volume. In particular, the May to June 2026 item recorded in the comparative block should not be read as July activity.

The absence of an indicator does not mean the phenomenon was absent in the region. If a value appears as zero, such as documented regulatory moves, it means none were recorded in the material analyzed for this period. The same applies to CVEs: if no critical number had appeared in the corpus, that would not prove that no vulnerabilities were exploited in Latin America, only that they were not documented in the material used for this report. Here, the 8 CVEs mentioned correspond exclusively to the Citrix and Ivanti alerts available in the source.

The time window for the indicators includes 41 dated facts in July 2026 and 1 fact from earlier months included only as a comparative reference. The 39 verified facts from the period are the basis for the indicators. Aggregated telemetry figures, such as attempts or blocks, were not added to the volume because they are not incidents with confirmed impact.

Sources not authorized by the provided list were excluded from the analytical build, as were consumer social networks, sponsored posts, commercial press releases, and any content not included in the list of available sources to cite. When the material included claims from a company or from an intelligence alert without independent confirmation, they were attributed as such and were not presented as settled facts.

Technical appendix: indicators of compromise and TTPs

The material provided does not include verifiable IoCs such as hashes, domains, or IPs, nor does it explicitly detail published TTPs or MITRE mappings in the authorized sources for this report. For that reason, this section does not include technical lists, and the analysis remains at the level of campaigns, surfaces, and observable controls.

Sources