Digital Services, Data Centers, and IT/SaaS Providers
August closed with 98 incidents across LATAM, driven by incidents, ransomware, service outages, and a critical cPanel/WHM vulnerability.
Key findings
- August closed with 98 verified incidents and a signal dominated by incidents, with a sharp jump from July in ransomware, outages, and affected sectors.
- The most serious case was ransomware against Colombia's Ministry of Justice, with real operational impact, confirmed encryption, and interagency recovery.
- Mexico showed two sensitive fronts, UASLP and the outage of gob.mx, both affecting availability and continuity of digital services.
- Stripe and LATAM Pass concentrated the risk of data exposure and fraud, with particular relevance for Brazil and regional payment integrations.
- The CVE-2026-65643 vulnerability in cPanel and WHM is the most delicate technical signal for hosting and data centers, due to its ability to escalate to root.
- The region depends increasingly on SaaS, connectivity, and third parties, so August's incidents hit continuity, identity, and secrecy especially hard.
- The drop in critical CVEs mentioned does not mean lower risk, but rather a month with more materialized incidents than purely technical alerts.
Monthly reference modules
These modules are filled automatically with verified dated facts from within the period. Each one states its source and counting criterion so the figures reconcile across modules. They are the recurring month-to-month reading; the analysis that follows develops the cases without repeating this summary.
Indicator window: 98 dated facts in August 2026 · 3 from previous months (comparative frame, not monthly volume). Facts from previous months are used only as a comparative frame in the analysis, never as volume for this period.
Executive summary for the month
August 2026 was a heavy month for digital services, data centers, and technology vendors in Latin America, with 98 verified incidents and a signal dominated by operational disruptions, service outages, ransomware, and exposed credentials. The most visible pressure combined direct impact on public agencies, strain on SaaS platforms, and a critical vulnerability in hosting software with systemic potential for data centers and infrastructure providers.
The month’s most severe case was the ransomware attack on Colombia’s Ministry of Justice, which began on August 2, reduced the availability of public services, and forced the activation of alternate channels, system isolation, evidence preservation, and a phased technology recovery. Coverage also showed the involvement of COLCERT, the participation of the Ministry of TIC, and support from Microsoft DART, making the episode a useful measure of the operational complexity faced by institutions with centralized infrastructure.
Mexico contributed two major signals in parallel. The Autonomous University of San Luis Potosí went through a cybersecurity incident that affected virtual classes, Caja Virtual, and other administrative services, with an impact on academic deadlines and the continuity of procedures. And the gob.mx domain suffered an outage officially attributed to a connectivity cut, although technical coverage exposed internal errors and component screens such as WildFly and Nginx, a combination that revealed weaknesses in design and operational hardening on one of the country’s most sensitive digital surfaces.
The third major axis was data and credential exposure on payments and loyalty platforms. Stripe was linked to a leak of merchant API keys, with 659 affected accounts and an estimated impact on 688,000 end customers, along with specific references to 30 Brazilian merchants and records that include charges, payment intents, invoices, refunds, and balance transactions. LATAM Pass, meanwhile, confirmed unauthorized access to personal data for a limited group of Brazilian members and notified the ANPD, while specialized media detailed the scope of the exposed data and the fraud risk tied to partial card information.
On vulnerabilities, the month closed with a high-value alert for the hosting and data center ecosystem, CVE-2026-65643 in cPanel and WHM, described by CSIRT Telconet and Threadlinqs Intelligence as a flaw that allows an authenticated user with low privileges to reach code execution as root on the underlying server. In a vertical where multi-tenancy and client separation are the backbone of the business, that kind of weakness is not an isolated finding, but a clear escalation path with cross-cutting risk.
Regional overview of the month
August’s regional reading is one of high risk, because the density of verifiable incidents was paired with real operational severity, exposure of sensitive data, and disruptions to critical everyday services. The signal was not uniform, but it was consistent across three fronts: business continuity, identity exposure, and weaknesses in the infrastructure layer that supports digital services, data centers, and SaaS.
Colombia saw the most serious episode, driven by the combination of ransomware, degraded public services, and an interagency response. Mexico showed a broad attack surface, from the public university to the federal government’s central domain, with failures that affected procedures, connectivity, and administrative management. Brazil, meanwhile, had its own weight on the privacy and payments front, especially because of LATAM Pass and the Brazilian portion of the Stripe case, reinforcing the pattern of impact on consumers and merchants that rely on platforms processed by third parties.
The picture also shows an important difference from the previous month. In July, the material was more dispersed and less concentrated in incidents. In August, the dominant threat became materialized incidents, with greater weight on outages, unauthorized access, and extortion. That does not mean risk eased in other areas. It means that in August the visible signal was more concrete, more operational, and less abstract. The region was not only exposed, several events also left measurable impacts on availability, access, and reputation.
Period indicators
| Indicator | August 2026 | Previous month | Change | Basis and window |
|---|---|---|---|---|
| Verified events in the period | 98 | 39 | +59 | 98 events dated in August 2026, the indicator window uses the 3 previous months as a comparison frame, not the month's volume |
| Unclassified incidents (breaches or outages) | 30 | 11 | +19 | 98 events dated in August 2026, the indicator window uses the 3 previous months as a comparison frame, not the month's volume |
| Cases with ransomware or extortion as the primary focus | 29 | 6 | +23 | 98 events dated in August 2026, the indicator window uses the 3 previous months as a comparison frame, not the month's volume |
| Confirmed asset encryption | 3 | n/d | n/d | Ransomware breakdown by impact type within the period |
| Exfiltration without encryption (simple extortion) | 1 | n/d | n/d | Ransomware breakdown by impact type within the period |
| Leak site mention only | 2 | n/d | n/d | Ransomware breakdown by impact type within the period |
| Type could not be determined from the material | 23 | n/d | n/d | Ransomware breakdown by impact type within the period |
| Documented fraud or phishing cases | 4 | 2 | +2 | 98 events dated in August 2026, the indicator window uses the 3 previous months as a comparison frame, not the month's volume |
| Documented regulatory moves | 0 | 0 | no change | 98 events dated in August 2026, the indicator window uses the 3 previous months as a comparison frame, not the month's volume |
| Critical CVEs mentioned | 3 | 8 | -5 | 98 events dated in August 2026, the indicator window uses the 3 previous months as a comparison frame, not the month's volume |
| Sectors with at least one documented event | 8 | 5 | +3 | 98 events dated in August 2026, the indicator window uses the 3 previous months as a comparison frame, not the month's volume |
| Predominant threat of the month | Incidents (30 of 98 events) | Unclassified (18 of 39 events) | change in dominant category | 98 events dated in August 2026, the indicator window uses the 3 previous months as a comparison frame, not the month's volume |
| Events with direct source confirmation | 84% | n/d | n/d | Direct confirmation based on verified events in the period |
Relevant incidents
Colombia Ministry of Justice, ransomware and technology recovery
Colombia's Ministry of Justice and Law was the clearest case of operational disruption with a ransomware component during the period. Evidence dated in August places the incident on the 2nd, with part of the technology infrastructure affected, temporary unavailability of systems such as SGDEA, and contingency measures activated to serve the public. The ministry also said it had not received any prior alerts related to the attack.
The public response was phased. On August 3, alternate channels were enabled to maintain service while systems were restored, and that same day COLCERT carried out an inspection at the data center to preserve evidence and logs. Later, the ministry confirmed that preliminary evidence pointed to a ransomware-type virus, although with no clear public attribution to the actor. That lack of attribution does not lessen the seriousness of the event, but it does limit tactical analysis of specific tools or families.
Subsequent coverage added two important layers of context. First, the attack affected services tied to illicit drug monitoring and judicial processes, with compromised systems isolated to prevent spread. Second, DART teams from Microsoft intervened in the recovery alongside BIT and other authorities, indicating a highly complex technical response and a real operational dependence on external platforms to return to normal.
Sectorally, this episode cuts across government, internal technology infrastructure, digital public services and institutional continuity. On exposure, there was no confirmed data theft documented in the sources provided, but there was file encryption and service degradation. That places it among the month's highest operational-cost impacts, because the priority was not only containment, but restoring service capacity.
UASLP, academic disruption and complaint filed with the FGR
The Autonomous University of San Luis Potosí suffered an incident that affected several systems, including virtual classes and Caja Virtual, with direct impact on enrollment, re-enrollment and payments. The university's August 6 statement referred to a cybersecurity incident and extended payment deadlines. Then, on August 8, the university filed a formal complaint with the Fiscalía General de la República, elevating the case from internal management to a federal investigative matter.
The available coverage shows a typical pattern for educational institutions with heavy dependence on centralized platforms. When the authentication layer, payments or access to virtual classrooms goes down, the damage is not only technical, but administrative and academic. In this case, recovery was also gradual, and the material itself refers to more than one affected system, though without public details on the entry vector.
The analytical value of the case lies in its functional scope. This was not a documented data breach, but an interruption that affected core education service processes. For SaaS providers and infrastructure teams, the lesson is clear: the availability of enrollment platforms, remote classes and digital collections cannot depend on a single operating path without tested contingencies.
gob.mx, outage attributed to connectivity and component exposure
The August 19 outage of gob.mx was presented by ATDT as a temporary inaccessibility caused by a connectivity cut, ruling out a cyberattack. That official explanation matters, but technical coverage added another signal: several portals showed internal server errors and screens associated with WildFly and Nginx, revealing unnecessary information about the infrastructure in use.
The incident lasted about two hours and affected the digital presence of the Presidency and numerous federal agencies. The reporting itself indicates that the initially estimated recovery time was shorter, suggesting a gap between continuity expectations and the architecture's actual tolerance for link interruptions. In this case, the visible problem was connectivity. The structural problem was the low resilience perceived by the end user.
There is also an incident governance detail. The only official account available was brief, without a full technical report or mention of a forensic investigation or federal CERT involvement in public communication. For a surface of this sensitivity, that lack of detail reduces institutional learning and leaves open questions about topology, redundancy and control of error exposure.
Stripe, exposed API keys and payment risk in the region
The Stripe case was one of the most relevant for the payments and digital services segment. Coverage agrees that the leaked material came from API keys used by merchants to make legitimate requests to their accounts, not from a breach in Stripe's internal systems. The technical corpus spans charges, payment intents, invoices, refunds and balance transactions between January 2022 and June 2026.
The scale of the incident is significant. Different sources speak of 659 merchant accounts, about 688,000 end customers and, in one specific cut, 30 businesses in Brazil. More than 50,000 additional API keys were also reported exposed in public repositories, GitHub Actions logs and misconfigured servers, turning a point incident into a broader sign of poor secret hygiene across development and operations ecosystems.
The technical reading matters more than the anecdote. The problem is not Stripe as a compromised core, but unsafe credential use in third-party environments. For Latin America, where much of digital commerce depends on integrations with global platforms, this case shows how exposure at the merchant perimeter can end in customer data leakage and fraud risk, even without intrusion into the main provider.
LATAM Pass, improper access and regulatory notice in Brazil
LATAM Pass confirmed a security situation involving personal data from a limited portion of Brazilian members, notified potentially affected customers and the ANPD, and said it took immediate containment and cybersecurity measures. The reporting also indicates that the incident was detected on July 29, although the development and coverage were consolidated in August.
The value of the case is not only in the confirmation of improper access, but in the category of data exposed. Specialized sources detail names, birth dates, emails, phone numbers, addresses, loyalty account data and partial card data. In a loyalty and frequent-consumption economy, that combination can be enough for targeted phishing, identity fraud or social engineering against account holders and service agents.
DPOExpert added a concrete regulatory detail. The ANPD's incident-handling coordination would preliminarily assess the case and could request additional clarification. Although August saw no other regulatory moves in the analyzed axis, this file shows how privacy and cybersecurity converge quickly when an incident touches personal data with high commercial value.
Microsoft 365, regional degradation and SaaS dependence
The Microsoft 365 degradation identified as MO1457636 affected users in South America and may have prevented access to multiple services in the suite. The available material does not provide a complete list of countries or workloads affected, but it is clear that organizations in Brazil, Argentina, Chile, Colombia and other regional markets had to treat the sudden inability to open Microsoft 365 as part of the incident until an official update was issued.
This was not a classic breach, but an operational reminder of the region's dependence on centralized SaaS. When a productivity suite degrades, the impact spreads to email, collaboration, documents and integrated authentication in many corporate environments. The signal for the month here is business continuity, not confidentiality.
What makes the coverage useful is that it connects availability and geographic dependence. Although the incident was not exclusive to Latin America, the region fell within the impact radius, and that is enough to include it in the vertical analysis. In organizations with hybrid deployments or heavy Microsoft 365 use, visibility into the health portal, contingency plans and internal communication alternatives is an essential control, not an extra.
Active Threats and Campaigns
Ransomware and extortion
The month was dominated by ransomware and extortion as the main theme, but the material does not always allow a precise split between encryption, exfiltration, and a simple claim of victimization. In the clearest cases, such as Colombia's Ministry of Justice, confirmed asset encryption and service degradation did occur. In other cases, the source does not specify whether encryption took place, or the victim appears only in a leak site mention.
That distinction matters because it changes both the response priority and the business risk. Confirmed encryption requires restoration, isolation, and continuity planning. Exfiltration without encryption calls for legal response, notification, and containment of misuse. A mention in a forum or leak site, by contrast, may point to reputational pressure or a claim of victimization without enough evidence of material impact. August showed all three variants, but not at the same level in each case.
Colombia's Ministry of Justice, ransomware with operational impact
Colombia's Ministry of Justice fits the category of confirmed asset encryption. The official source acknowledged a ransomware attack, the availability of several systems was affected, and contingency measures were activated. The material provided does not indicate any confirmed exfiltration, so the case centers on availability and integrity, with tangible operational damage.
Stripe, key exposure and potential extortion
The Stripe case is not presented as classic ransomware, but as a large-scale credential exposure that could enable fraud, transactional abuse, or extortion pressure on merchants. The source points to valid API keys used in legitimate requests, with a broad historical corpus and associated payment data. From a security standpoint, the attacked surface is secret management, not the provider's core infrastructure.
Fraud and phishing
August recorded 4 documented fraud or phishing cases, with a concentrated pattern of reused personal data and credentials. In this vertical, fraud appears more as a downstream consequence of a breach or leak than as a standalone campaign. LATAM Pass and Stripe are the clearest examples of how exposure at a third party or a merchant can feed impersonation attempts, fake verification, or account abuse.
In LATAM Pass, the presence of names, addresses, emails, and partial card data raises the risk of social engineering. In Stripe, simply having access to exposed API keys can turn into transactional fraud or account manipulation if rotation and scope controls are not in place. The region should read these cases as evidence that the identity and secrets layer is functioning as an indirect entry point to financial fraud.
APT and hacktivism
The month's material did not include any clearly attributable APT campaign within the scope analyzed. There were monitoring and research elements tied to complex incidents, such as the OpenAI and Hugging Face case disclosed in technical material that fell within the publication window, but that episode belongs to earlier months and should not be counted in August's volume. For the month in question, the strongest signal in this section remains operational rather than tied to an identified persistent actor.
Critical vulnerabilities
August did deliver useful vulnerability material, especially around the cPanel/WHM case and the alerts tied to Microsoft SharePoint. The fact that the monthly tally shows 3 critical CVEs mentioned does not mean the region was free of problems. It means only those three were spelled out in the material reviewed for this period.
| CVE | Software | Exploitation | Source |
|---|---|---|---|
| CVE-2026-65643 | cPanel and WHM | Privilege escalation from an authenticated user, arbitrary file creation via domain parking, and root-level code execution on shared hosting Linux servers | Threadlinqs Intelligence, CSIRT Telconet |
| CVE-2026-70355 | Microsoft SharePoint Server | Privilege escalation vulnerability included in August 2026 Patch Tuesday, with regional coverage linking it to failures in enterprise and cloud/SaaS deployments | CSIRT Telconet |
| CVE-2026-72898 | Metabase | SQL injection in an unauthenticated endpoint, tied in technical material to active exploitation and exposure of thousands of self-managed instances | Reference technical material cited in the Trezor file and associated analysis |
The practical reading of the table differs by segment. In cPanel and WHM, the impact is direct for hosting and data centers, because a failure to separate accounts can become a compromise of multiple customers on the same infrastructure. In SharePoint, the risk is tied to enterprise and hybrid cloud environments, especially where patching discipline is weak. In Metabase, the impact points to exposed analytics and BI systems, an environment many companies treat as secondary even though it often stores highly sensitive data.
Regulation and compliance
August did not record documented regulatory moves as a separate category in the month’s indicator, but it did produce concrete compliance responses in specific cases. The most visible was LATAM’s notice to Brazil’s ANPD, along with the regulator’s initial response, which said it would carry out a preliminary analysis of the incident and could ask for additional clarification.
In Colombia, the Ministry of Justice worked with COLCERT, the Attorney General’s Office, and other authorities, and also preserved evidence in its datacenter for forensic analysis. That sequence does not amount to a sanction or a formal regulatory action, but it does show the institutional process expected when an incident affects critical public infrastructure. The value for the private sector is clear, documentation, evidence preservation, and decision traceability need to be ready from the first hour.
The absence of aggregated regulatory moves in the month should not be confused with a lack of compliance activity. In payments, loyalty, SaaS, and digital government environments, notifications, investigations, and information requests can move outside public view without meaning inaction. What can be said, based on the material, is that August did not show a regulatory wave comparable to the operational pressure created by the incidents.
Countries and most affected subsegments
Colombia
Colombia had the highest qualitative weight because of the incident at the Ministry of Justice and Law. The case affected institutional continuity, public services, document management, and interagency response. It also triggered forensic work and coordination with COLCERT, making it the month’s most sensitive event in the government digital services segment.
The country also saw the alert on SharePoint Server issued by cyber authorities, which adds another signal. Exposure is not limited to a single incident, since the public technology ecosystem is also watching for vulnerabilities in widely deployed enterprise software. That increases the monitoring burden for on-premises environments that are still common in public administration and among local vendors.
Mexico
Mexico concentrated signals in higher education and digital government. UASLP showed a clear impact on classes, payments, and enrollments, while gob.mx exposed operational weakness and technical details during a connectivity outage. The combination is relevant because it links dependence on academic platforms with the central digital presence of the state.
In digital services, Mexico also sits within the broader cloud and AI discussion, according to technical coverage of the exfiltration at Hugging Face and the structural risk for hosted services. Although the technical case involving OpenAI and Hugging Face was not an August incident in the region, it does help explain why dependence on external platforms and API-based operating models requires stronger controls.
Brazil
Brazil stood out for the volume of impact on privacy and payments. LATAM Pass affected Brazilian members and prompted a response from the ANPD. Stripe, meanwhile, had an explicit Brazilian component, with 30 merchants affected within the reported set. In both cases, the common denominator is the handling of data and credentials in third-party environments.
The most sensitive subsegment here is digital payments and loyalty programs. These are environments where personal, transactional, and identity data have high reuse value for fraud. For teams operating in Brazil or serving a Brazilian customer base, the lesson is that partial exposure of a single data point can be enough for follow-on attacks, even if there is no evidence that the provider’s core was compromised.
Argentina, Chile, and Colombia in regional SaaS
The degradation of Microsoft 365 potentially affected organizations in Brazil, Argentina, Chile, and Colombia, as well as other South American markets. This was not a country-specific incident, but a signal of shared dependence on productivity and collaboration services. That matters because, in many companies, business continuity depends on the availability of email, documents, chat, and meetings in a single suite.
Financial services, education, and government
The most affected subsegments of the month were government, higher education, payments, and loyalty programs. Government appears in Colombia and Mexico, with the two most visible cases of availability and infrastructure. Higher education appears in UASLP, with direct operational impact. Payments and loyalty programs appear in Stripe and LATAM Pass, with a clear focus on personal data and fraud risk. That distribution explains why the month was so intense, since the signal was not confined to one type of organization, but crossed several public-facing touchpoints.
Trends and signals to watch
The comparison with the previous month shows a sharp acceleration. Verified incidents in the period rose from 39 in July to 98 in August, an increase of 59 cases. Unclassified incidents climbed from 11 to 30, and cases with ransomware or extortion as the primary focus increased from 6 to 29. The trend is clear, August was much denser in terms of materialized events.
At the same time, the count of critical CVEs mentioned fell from 8 to 3. That does not mean lower technical risk, but rather a shift in the signal. In July, the focus leaned more heavily on vulnerabilities. In August, it centered on concrete incidents, outages, and data exposure. For security teams, that means looking beyond patching and also focusing on continuity, response, and recovery.
Another relevant signal is the change in the dominant threat. The previous month was led by the unclassified group, while in August the main category became incidents. That shift points to greater clarity around visible damage and coverage that no longer describes only potential risk, but real impact. Operationally, that usually translates into more pressure on help desks, identity teams, infrastructure teams, and legal teams.
The sector breakdown is also worth watching. With 8 sectors affected, up from 5 in the previous month, August showed a broader spread of impact. That does not mean every sector was hit equally, but it does show the issue stopped being isolated and began affecting government, education, payments, loyalty programs, SaaS, and hosting with some simultaneity. The regional risk became more cross-sector.
The month’s other trend is in the infrastructure layer. The cPanel and WHM case, along with the degradation of Microsoft 365 and the exposure of Stripe secrets, points to a common pattern. The most sensitive surface is not always in the company core, but in operational tools, administration layers, and third-party providers. When those layers fail, the impact multiplies across customers, end users, and partners.
Recommendations for security teams
First, review secrets and credential controls across the entire development and operations chain. The Stripe case shows that API keys exposed in public repositories, logs, configuration files, or backups remain a real path to compromise. Teams should audit rotation, permission scope, code secret detection, and fast revocation, especially in payment integrations.
Second, strengthen continuity plans for SaaS platforms and critical productivity services. The Microsoft 365 degradation and the gob.mx outage show that relying on a single service or a single connectivity path can bring entire operations to a halt. Organizations should have alternate communication procedures, emergency access routes, and drills that account for full or partial unavailability of the main suite.
Third, treat shared hosting and admin panels as high-value attack surfaces. CVE-2026-65643 is not a minor flaw, because it allows an authenticated user to jump to root. Hosting providers, data centers, and MSPs should prioritize patching, strong tenant segmentation, panel hardening, and monitoring for anomalous administrative activity.
Fourth, prepare a ransomware response that does not depend on attribution. The Colombian case shows that, even without an identified actor, operational damage requires isolating systems, preserving evidence, coordinating with CERT, and keeping alternate channels running. Organizations should not wait for a public claim from the attacker to activate playbooks, because the useful window is in the first hours.
Fifth, connect privacy with fraud in every case involving personal data. LATAM Pass showed that seemingly partial information can support phishing, impersonation, and later abuse. When a leak includes name, email, phone number, address, or partial card data, the risk is no longer only regulatory. Fraud monitoring, customer warnings, and stronger validation in support channels are necessary.
Sixth, expand monitoring of third-party providers and critical dependencies. Many of August's incidents were not direct intrusions into the affected organization, but problems in its ecosystem of providers, panels, repositories, suites, or integrations. That requires a living inventory of third parties, early notification clauses, and recovery tests that include services outside the organization's own perimeter.
Frequently Asked Questions
What changed between July and August in the month’s signal?
August rose from 39 verified events in July to 98, with a sharp increase in incidents, ransomware, and affected sectors. The report’s comparison also shows that the dominant threat shifted from "unclassified" to "incidents," which points to a more operational and less ambiguous signal.
Which cases this month had the greatest real operational impact?
The clearest were the ransomware attack on Colombia’s Ministry of Justice, the disruption at UASLP, and the outage of gob.mx, because they affected service availability. Stripe and LATAM Pass carried greater weight in data exposure and fraud risk, so they should be read together with the threats section and the countries section.
Why is cPanel/WHM so sensitive for data centers and hosting?
Because CVE-2026-65643 allows an authenticated user to escalate to root on the underlying server. In a shared hosting environment, that can break isolation between customers and compromise multiple accounts on the same infrastructure. The vulnerabilities table and the recommendations section explain why the impact is systemic.
What is the relationship between the Stripe case and fraud risk in Brazil?
The leak affected 659 merchants and included a subset of 30 Brazilian companies, with customer data tied to purchases and payments. Since the material also describes exposure of valid API keys, the risk does not end with the leak, it can also lead to transactional abuse, phishing, or targeted fraud, according to the threats section and the countries section.
Was there any new regulation in August for this vertical?
No aggregated regulatory moves were documented for the month as a category. There was, however, notification to the ANPD in the LATAM Pass case and a preliminary review announced by the Brazilian regulator, along with institutional coordination in Colombia. The details are in the Regulation and Compliance section.
Material limitations
This report was built exclusively from the facts dated August 2026 included in the provided material, plus three facts from earlier months used only as comparative context when the text allows it and always with the month stated explicitly. No internet or sources outside the approved list were used, and no aggregated telemetry was included because the material does not provide it.
When an indicator appears as 0, especially the critical CVEs mentioned or regulatory moves, that means no such event was recorded in the material analyzed for this period, not that it did not exist in the region. The same caveat applies to any missing count, absence in the sample does not equal actual absence of the phenomenon.
The time window for the indicators is the one stated in the assignment, with 98 facts dated August 2026 and 3 facts from earlier months used only as comparative reference. The sectors are not exclusive, and the same fact can affect more than one sector, so any sector total should be read as thematic coverage, not as a single overall total.
Materials not included in the list of available sources for citation were also excluded from the evidence, as were social media posts not authorized by the prompt. Where a source used uncertain language or attributed hypotheses without confirmation, the report treated it as such and did not turn it into a settled fact.
Technical appendix: indicators of compromise and TTPs
cPanel and WHM, CVE-2026-65643
The vulnerability described by CSIRT Telconet and Threadlinqs Intelligence points to abuse of the domain parking function from an authenticated account with low privileges. The central TTP is privilege escalation to root through arbitrary file creation and manipulation of the separation between domains and accounts in shared Linux hosting.
Stripe, credential exposure
Although no classic IoCs such as hashes or domains were published in the enabled material, the case leaves clear TTPs, exposure of API keys in public repositories, CI/CD logs, .env files, and poorly protected backups. The operational indicator for defensive teams is secret rotation and detection of credentials in development environments, not hunting for a specific IP.
Colombia Ministry of Justice, ransomware
The material confirms ransomware, system isolation, and forensic preservation, but it does not provide verifiable IoCs to include here. The operational pattern that is clear is the degradation of public services, containment through segmentation, and coordination with authorities and external support for gradual recovery.
Sources
- API Keys From 659 Stripe Merchants Leaked Alongside 688,000 Customer RecordsFinanceFeeds
- Over 50000 Stripe API Keys Exposed in Public Code RepositoriesGate.com
- Filtran claves API de 659 comercios de Stripe y exponen 688.000 registros de clientesDiarioBitcoin
- Latam Pass Data Breach: Exposed BIN Data Creates Fraud Risk Beyond Partial Card ClaimsTechTimes
- Notícias de privacidade e proteção de dados – agosto 2026DPOExpert
- Stripe Merchant API Keys Leak Exposes 688K Customer RecordsDarknetsearch
- Vazamento expõe 659 chaves Stripe e atinge 30 lojistas no BrasilBitnoticias
- LATAM Pass sofre invasão cibernética e expõe dados de clientesTecmundo
- Microsoft 365 Service Degradation Disrupts Users Across South AmericaCybersecurity News
- Dados de clientes do programa de fidelidade da Latam são vazadosFolha de S.Paulo
- Ransomnews: API Keys From 659 Stripe Merchants Leaked Alongside 688,000 Customer RecordsWuBlockchain / Ransomnews
- MinJusticia activa plan de recuperación tecnológica luego de vulneración cibernética garantizando servicios esencialesMinisterio de Justicia y del Derecho de Colombia
- CVE-2026-65643: Arbitrary File Creation in cPanel/WHM Domain Parking Leads to Root-Level Code ExecutionThreadlinqs Intelligence
- Boletines de seguridad agosto 2026CSIRT Telconet
- La semana en brechas de seguridad 26 de agosto de 2026Kaseya
- Así se recupera el Ministerio de Justicia tras ciberataque que redujo la disponibilidad de algunos serviciosInfobae
- DarkReading #Colombia #CyberCrime #Ransomware #White_Hunters
- ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, ...The Hacker News
- Ransomware Hits Justice Ministry as Colombia Gets New PresidentDark Reading
- Colombia Justice Ministry Hit With Ransomware — 0dayNews0dayNews
- Actualización de seguridad de Microsoft Patch Tuesday agosto 2026CSIRT Telconet
- Critical SharePoint RCE Exploited on Internet-Exposed On-Premises ServersMallory.ai
- Cyber Alert sobre ataque de ransomware al Ministerio de Justicia de ColombiaHackmanac
- Actualización del comunicado oficial sobre el incidente de ciberseguridadMinisterio de Justicia y del Derecho de Colombia
- Actualización sobre el ataque cibernéticoMinisterio de Justicia y del Derecho de Colombia
- Ransomware Hits Colombia's Ministry of Justice - dataenforceDataEnforce
- Minjusticia adopta medida temporal de contingencia para la atención de PQRDSFMinisterio de Justicia y del Derecho de Colombia
- Mensaje en X sobre riesgo de ransomware en ColombiaCOLCERT
- Inside OpenAI's Hugging Face Report - Developers DigestDevelopers Digest
- Mexico Government Websites Down for Two HoursThe Rio Times
- Una aparente falla menor de conectividad expone profundas vulnerabilidades de ciberseguridad en la infraestructura digital del Gobierno de MéxicoInfobae México
- Caen páginas del Gobierno de México: ¿qué pasó con gob.mx y qué servicios fueron afectados?EjeCentral
- Reportan caída temporal de las páginas web del gobierno de México por un corte de conectividadLatinus
- Avanza recuperación digital en la UASLP tras ciberataquePlano Informativo
- UASLP retrasa inscripciones en una de sus facultades tras ataque cibernéticoEl Universal SLP
- The Hidden Cost of Growing Fast Cloud AI Cybersecurity in MexicoMexico Business News
- Cyberhebdo du 7 août 2026 : une semaine d'une violence exceptionnelleLeMagIT
- UASLP denuncia incidente ciberseguridad ante FGRPulso SLP
- Resumen de Amenazas — Agosto 2026: 10 vulnerabilidades críticas | Boletín de Seguridad CiberPlanetaCiberPlaneta
- Reportan ciberataques contra la Universidad Autónoma y el Poder Judicial de SLPProceso
- Aumentan ataques cibernéticos de robos de datos 38 por ciento, advierten especialistasLa Jornada
- Incidente de ciberseguridad afecta servicios de la UASLP y genera dudas entre estudiantesPotosí Noticias
- OpenAI–Hugging Face Autonomous AI Agent IntrusionTI Mindmap Hub
- OpenAI's Autonomous Agent Chained Nine Zero-Day CVEs to Breach Hugging FaceForkast
- Listado de víctimas Kazu en XIntel and Breaches (X)
- Kazu Ransomware Targets Centro Médico Especializado OSI in PeruDexpose
- Centro Médico Especializado OSI: Healthcare Solutionsransomware.live
- Centro Médico Especializado OSI: Healthcare Solutions — KAZU Ransomware AttackBreach House
- Kazu gang posts eight healthcare targets in one leak dayMedRisk.io
- [Intel MX] 2026-08-23 Kazu golpea la telemedicina: una plataforma de salud usada en México en la miraransomware.mx
- Redacted data breach — Kazu ransomware leak (2026)Orizon Darkfield
- Victim: Global Go - Ransomware.liveransomware.live
- Ransomware Group killsec Hits: Global GoHookPhish
- Global Go data breach — Killsec ransomware leak (2026)Orizon Darkfield
- Global Go — KILLSEC Ransomware AttackBreach House
- Qilin Ransomware Group Strikes Chilean Company Difor - DeXposeDeXpose
- DiforBreachSense
- Ransomware Group kazu Hits: Brazil Mobilemed: Cloud PACS PlatformHookphish
- Colombia's Ministry of Justice Hit by Ransomware AttackCyber.NetSecOps
- Centralized cyber intelligence monitoring report on alleged data exfiltration in Latin AmericaVECERT Analyzer
- Colombia's Ministry of Justice hit by ransomware attack | briefSC World
- Ransomware en el Ministerio de Justicia de ColombiaDataEnforce
- Trezor Data Breach Analysis: 14000 Customers Exposed in ShipMonk Metabase SQL Injection IncidentRescana
- Crypto breaches 2026: shipping leaks fuel wrench attackscrypto.news
- Trezor Data Breach 2026: ShipMonk and Metabase Vulnerabilities Expose Customer DataAviatrix Threat Research Center
- 14,000 Trezor Customers Impacted by Data Breach at ShipMonkSecurityWeek
- 2026 Trezor — ShipMonk fulfillment breach; 13,689 customers (addresses/phones; Metabase path)BreachHistory
- Trezor Data Breach Exposes 13689 Customers via ShipMonkOurCryptoTalk
- Cyber Intel Brief: CVE-2026-72898 in MetabaseDataminr
- CVE-2026-72898: Metabase SQL Injection Under Active Exploitation - Detection and Remediation GuideSecurityArsenal
- CVE-2026-72898 - Vulnerability DetailsOpenCVE
- 2026 ShipMonk — Metabase vulnerability path; unauthorized access to customer/order data (Trezor notices)BreachHistory
- SQL injection using an unauthenticated endpoint leading to ... (Security Advisory)Metabase
