CiberLATAMbywhalemate
Intelligence reportAug 11, 202630 min read

Telecom and ISP Incidents, July 2026

July saw fiber outages, incidents at Copaco and Ecopetrol, telecom fraud, and strong ransomware pressure across the region.

Telecom and ISP Incidents, July 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are completed automatically with the verified, dated facts within the period. Each one states its basis and counting criteria so the figures reconcile across modules. They are the recurring month-to-month reading; the later analysis develops the cases without repeating this summary.

Indicator window: 73 dated facts in July 2026 · 1 without confirmed date (excluded from the indicators). Facts from earlier months are used only as a comparative frame in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Monthly verified signal dashboard July 2026 · Latin America Top threat: Unclassified (20 of 67 events). Coverage: 73 dated events in July 2026 · 1 undated e… VERIFIED EVENTS 67 period base: all counts measured from below is based on this total RANSOMWARE / EXTORTION 15 1 asset encryption confirmed · 14 classified not determinable with the UNCLASSIFIED INCIDENTS 17 breaches or outages without declared threat type FRAUD / PHISHING 2 documented fraud campaigns REGULATION 0 standards, resolutions, or penalties UNIQUE CVEs 6 CVE-2026-15409 / CVE-2026-15410
Monthly verified signal dashboard — Base: 67 verified, dated events for Latin America.
MONTHLY FIXED MODULE Threat Axis Distribution July 2026 · Latin America Each event is counted in only one axis, so the total is exactly 67. "Unclassified incidents" is the remainder. Unclassified 20 Incidents 17 Ransomware 15 Vulnerabilities 13 Fraud 2
Threat Axis Distribution — Each event is assigned to a single axis based on its classification; the total reconciles to the 67 events in the period.
MONTHLY FIXED MODULE Sector distribution of signals July 2026 · Latin America Base: 67 incidents in the period · total 76 because 7 incidents are classified in more than one sector. Other / no sector ident… 31 Technology 20 Public sector / OIV 12 Telecom 11 Finance 1 Retail / consumer 1
Sector distribution of signals — Heuristic sector classification based on the victim. One incident may affect more than one sector, so the total may exceed the base.
MONTHLY FIXED MODULE Geographic Distribution of Coverage July 2026 · Latin America Each event is assigned to a single country or to regional coverage, so the total is exactly 67 of 67 events… Regional 39 Colombia 13 Peru 8 Paraguay 3 Argentina 2 Chile 2
Geographic Distribution of Coverage — Verified events for the period grouped by country or regional coverage; each event is counted once.

Monthly executive summary

July 2026 delivered a fragmented but consistent signal for telecoms and connectivity providers across Latin America. There was no single dominant pattern, but instead a mix of physical service disruptions, security incidents on institutional platforms, third-party-linked leaks, and sustained ransomware pressure across the regional ecosystem. Operationally, the most visible connectivity case was the fiber optic cut in La Molina, Lima, which affected fixed internet users and was tied to cable tampering in underground telecom chambers. On the corporate side, Copaco proactively took down its website after detecting a security incident, while Ecopetrol faced an unlawful disclosure of sensitive information involving multiple companies in the group and triggering a coordinated response from several Colombian authorities.

The month’s risk reading for the vertical is medium-high. That assessment does not come from a single large-scale intrusion, but from the repetition of vectors that affect availability, trust and data exposure. The fiber infrastructure cut confirms that the physical attack surface remains a relevant point of failure for operators and wholesale services. The Copaco incident shows that an event limited to a web platform can force precautionary steps that affect visibility and user support. Ecopetrol, while not an ISP, serves as a reference case for managing large digital environments and privileged third parties, because the leak reached information from 15 linked companies and prompted a multiagency response. For telecoms and ISPs, that kind of incident matters because of the structural proximity between operator, provider, corporate customer and subcontractor chain.

There was also a telecom fraud component, although with an unconfirmed date in the material reviewed. Noticias RCN reported on a criminal network that impersonated a telecom company to offer illegal internet and television services and defraud a large sum of money. That incident is not included in the month’s tally, but it does illustrate a threat line that blends impersonation, fraudulent sales and reputational damage to the sector. At the same time, regional coverage of ransomware and vulnerability exploitation pointed to a hostile environment for connectivity providers, especially because of exposure in remote platforms, edge devices and administration tools that often fall within the reach of operators, integrators and MSPs.

The month also offered a clear signal about techniques that are becoming more operational than spectacular. TrendTIC described attacks in Colombia and [Mexico](/en/news/mexico-ranks-second-latam-ransomware) in which attackers printed ransom notes after encrypting systems with BitLocker. Kaseya and F5 Labs, meanwhile, documented exploitation of vulnerabilities in SonicWall SMA1000, FortiSandbox, SharePoint and other platforms that commonly appear in remote access, managed security and corporate administration environments. For an ISP or a telco, the issue is not only the specific vulnerability, but the combination of exposed devices, broad privileges and dependence on third parties for support or monitoring. That makes any weakness in authentication platforms, remote access or enterprise customer management more sensitive.

July did not bring a single major regional connectivity crisis, but it did leave several signs of operational erosion. There were local outages, web incidents, leaks involving third parties, extortion pressure and campaigns confirming that the telecom chain remains exposed both physically and logically. The month’s exposure was more dispersed than concentrated, but no less serious for that.

Regional overview for the month

TIMELINE Verified events from the period 1/7 TheRepublicreportedthat 1/7 The Republic added that,agregó que, 1/7 La Repúblicareported that 1/7 Movistarreported anoutage 1/7 The firstincidentreported 1/7 A reportfrom IBM
Verified events timeline, July 2026 — Confirmed milestones within July 2026. Events from earlier months are excluded from the timeline and used only as a comparison frame.

July’s regional signal combines two types of risk that often overlap in telecoms and ISPs. The first is outage risk, which appears when a fiber cut, tampering with underground vaults, or a platform incident forces service degradation, fallback measures, or restoration from contingency. The second is intrusion risk with data exfiltration, which does not always interrupt service, but can compromise trust, commercial integrity, and, in some cases, legal traceability. This month, both dimensions appeared in different countries and with varying levels of confirmation.

The qualitative reading is medium-high risk. It is medium because the material did not show a regionwide outage tied to a single actor, or an attack campaign aimed exclusively at ISPs with systemic effects. It is high because the verified cases point to surfaces that are, by definition, critical, urban fiber optics, institutional accounts, state operator web platforms, corporate cloud environments, and remote access systems. The material also shows that the pressure did not come only from direct attacks. The ransomware environment and active exploitation of vulnerabilities remained strong across the region, and that affects telcos and ISPs even when they are not always named as the final victim.

There is also an important note on the nature of the material. Several reports rely on journalists, company spokespeople, or police and judicial sources, with strong direct confirmation. Other pieces refer to vendor telemetry or regional ransomware trends, which are not the same as incidents with confirmed impact on telecoms. For that reason, July’s picture shows more pressure on the ecosystem than on a narrow subset of operators. In practical terms, that means reading the signal through a supply chain lens, access providers, administration platforms, third parties with privileges, edge infrastructure, and managed security layers.

The geographic dimension was also relevant. Peru accounted for a clear case of service interruption due to physical damage to the network. Paraguay contributed Copaco’s preventive measure on its institutional portal. Colombia brought the Ecopetrol incident and the mention of a fraud using a telecom company identity. Chile appeared in coverage of a suspected incident that authorities have not yet confirmed. The result is not a uniform geography, but a set of episodes with different levels of verification that, taken together, show a region where connectivity remains sensitive to sabotage, credential abuse, and extortion.

Country signal, qualitative readingBars sized in proportion to the density of verifiable incidents in the source material.ColombiaPeruParaguayChileMexico/BrazilEcopetrol leak, multi-agency response, and regional contextFiber cut and arrests for cable tamperingPreventive shutdown of the Copaco siteUnconfirmed incident and media alertRansomware context and regional telemetry
Countries with verifiable incidents — Country-by-country qualitative map based on confirmed incidents for the month.

Period indicators

Indicator Value
Verified facts for the period (basis for all indicators) 67
Time window for the indicators 73 facts dated in July 2026 · 1 without confirmed date (excluded from the indicators)
Untyped incidents (breaches or outages) 17
Cases with ransomware or extortion as the primary focus 15
Ransomware breakdown by impact type: confirmed asset encryption 1
Ransomware breakdown by impact type: unable to determine classification from the material 14
Documented fraud or phishing cases 2
Documented regulatory moves 0
Critical CVEs mentioned 6
Sectors with at least one documented fact 5
Predominant threat of the month Unclassified (20 of 67 facts)
Facts with direct source confirmation 96%
Aggregated telemetry figures excluded from volume 6 (attempts or aggregated blocks: not incidents with confirmed impact)

The period base is 67 verified facts. The time window includes 73 facts dated in July 2026 and 1 fact without a confirmed date, excluded from the indicators. That difference matters because it avoids mixing contextual material with the month’s operational volume. It also matters for reading the relative weight of the categories: the predominant threat label remained "unclassified," with 20 of 67 facts, which points to a high level of heterogeneity and incomplete classification in the material, not a lack of activity.

Aggregated telemetry figures are excluded from the volume. In this report, they are not counted as incidents or as evidence of a completed intrusion. They only serve as context if mentioned, and always with the clarification that they are attempts, blocks, or automated detections reported by vendors in specific measurement windows. In July, the coverage included, for example, ESET telemetry from January to May 2026 and FortiGuard reports on hacking attempts during 2025. Those data help gauge exposure, but they do not replace confirmed incidents in telecommunications or ISPs.

Relevant incidents

Movistar and the fiber cut in La Molina

The clearest fixed-connectivity outage occurred in Peru. Movistar reported a fiber optic cut in the La Molina district that disrupted fixed internet service in several parts of the area. La República added that the outage extended to La Molina, Chaclacayo, Ate, Santa Clara and Chosica, and that service was restored the same day at 12:16 p.m. Coverage also noted that the company detected a group of people tampering with another underground chamber at the intersection of Aragón and Asturias avenues, and that the incident was added to two other acts of vandalism that occurred over the weekend.

The significance of the case goes beyond the outage itself. The scene described by the sources points to a classic risk pattern for last-mile operators, physical access to chambers, tampering with cabling and direct fiber cuts with immediate impact on the customer experience. In incidents like this, the logical layer comes after the physical one. Service continuity drops first, then restoration begins, and in parallel the search for those responsible and the assessment of scope. The in flagrante detention of three people in La Molina while they were handling fiber optic cabling from an underground chamber during the early hours of July 3 reinforces the hypothesis that this was not an accidental technical failure but a deliberate intervention.

Infobae Perú added that preliminary investigations linked the detainees to the July 1 cut, when fiber damage left different parts of La Molina without internet. That continuity between an initial cut, another manipulation and a subsequent arrest suggests that infrastructure defense cannot be limited to network monitoring. It also requires physical control of chambers, ducts and splice points, especially in urban areas where a concentration of customers can turn a limited damage event into a neighborhood-wide or metropolitan corridor outage.

For operators and connectivity providers, the case leaves several operational lessons. The first is that redundancy must exist at the route level, but also at the physical access level. The second is that coordination with security forces and local authorities is part of recovery time, not a later administrative step. The third is that vandalism against fiber should not be treated as an isolated copper theft or cabling incident, but as events that can affect reputation, SLA and corporate support if they hit enterprise customer links. The coverage itself shows that the disruption was not only residential, but also affected several districts and forced rapid repair and restoration.

Copaco and the preventive shutdown of its website

In Paraguay, Copaco took its corporate website offline as a preventive measure after detecting a security incident that affected access to the platform. ABC Color reported that, at that point, technical reviews confirmed the incident had not affected critical systems. That distinction matters: taking down the website does not mean a total operational outage or a compromise of core infrastructure, but it does show that the public-facing surface can force conservative responses when there is doubt about integrity or availability.

What matters for the sector is not just the event itself, but the decision sequence. A state-owned telecom cannot afford to keep an exposed portal online if there is any suspicion of a security incident. The preventive measure reduces the risk of spread or further exploitation, but it introduces friction for users, sales teams and self-service channels. In other words, the response also has a cost. That is why this type of incident should not be read as simple web maintenance. It is a containment decision in response to an anomalous signal that, even without compromising critical systems, already affected access to the platform.

The press coverage also referred to an "incident" without publicly specifying the technical cause. That requires a cautious reading. There is no evidence in the material of ransomware, exfiltration or credential compromise. What does exist is confirmation of an access issue and a preventive measure to contain it. For a telecom operator, this type of event usually activates hypotheses ranging from portal defacement or manipulation to abuse of web components, authentication failures or exploitation of a dependency. Without more technical detail, it would not be appropriate to say more than the sources do.

Ecopetrol and the leak tied to privileged third parties

The Ecopetrol case was the largest in terms of affected information and the broadest institutional response of the month. Infobae reported that the Prosecutor's Office opened an investigation into the cyberattack against Ecopetrol and that, at that point, there was no evidence of essential or especially serious harm to the company's operations. The same coverage said the attackers may have taken more than a terabyte of information, including data on employees and material linked to the board of directors. In addition, the Attorney General's Office opened an investigation into the illegal disclosure of sensitive information from 15 companies linked to the state-owned oil company.

Caracol Radio provided a technical detail that is especially relevant for connectivity operators and ecosystems with distributed access. According to Prosecutor's Office sources, access to Ecopetrol's environment may have come through a third party with administrator privileges, and then the attackers used Kali Linux to move through IT systems and extract data. If that reconstruction holds, the incident does not start with a classic remote exploit, but with a poorly managed trust point. For telecommunications companies and ISPs, that is a clear warning sign: the risk is not only at the perimeter, but in delegated administration, vendor access and credentials with broad privileges.

Ecopetrol confirmed that outside actors published information illegally copied from 15 companies in the Ecopetrol Group and that it was working with the Prosecutor's Office and MinTIC to remove the content from public access and limit its spread. The company also said the impact of the incident was limited to file downloads and that no compromise of data integrity was identified. Yahoo Finance, citing a PR Newswire statement, added that no identities were compromised for users associated with the 3,300 affected accounts and no access credentials were captured, and that no impact was detected in the transactional technology solutions of its digital ecosystem, or those of subsidiaries, commercial partners, suppliers and customers.

The response chain itself showed formal coordination with ColCERT, the Prosecutor's Office, the Joint Cyber Command, the National Police and DIJIN. ColCERT said it received the incident report, activated coordination with the relevant entities and maintained direct channels with the Prosecutor's Office, the Police and CTI for the investigation. In governance terms, that makes the case an example of multi-agency response to data exposure and public leaks. In sector risk terms, it leaves a direct lesson for telcos and ISPs with self-service portals, distributed NOCs or third-party integration: administrator privilege in the hands of a third party is not a contractual detail, it is an attack surface.

The compromised account linked to AFA Medios

July also included an event that, while not strictly telecom-related, is useful for understanding the logic of compromised accounts and unauthorized email sending. WeLiveSecurity reported that an account linked to AFA Medios was compromised and emails were sent to journalists without the entity's authorization. The Argentine Football Association reported unauthorized access to one of its institutional accounts and said it was working to clarify what happened.

The analytical value of this case lies in the mechanics. A compromised institutional account can be used as a channel for malicious communications, message leaks or social engineering. For connectivity providers and telecom companies that manage corporate mailboxes, email services or federated identity, the problem does not end with a password change. The question is how access was detected, what MFA controls were active, whether forwarding rules were present, whether persistent sessions existed and whether indicators of lateral abuse were reviewed. As reported, the account became a vehicle for unauthorized emails, not necessarily an infrastructure incident, but one with reputational and operational impact.

Chile and the still-unconfirmed incident at MTT

ADN Radio's coverage of Chile deserves separate reading because of its level of certainty. The outlet reported an alleged cybersecurity incident against the infrastructure of the Ministry of Transport and Telecommunications, but the note itself presented it as unconfirmed by authorities. It also said the event would have involved an alleged database with information from more than 100,000 users and officials, attributed by the site consulted to an unverified group. This material should not be read as a confirmed intrusion or as a verifiable impact volume, but as a journalistic alert with limited certainty.

For this month's report, the value of the piece lies in the context: transport and telecommunications infrastructure is often an attractive target because of its role in sensitive information and interconnection among agencies. But until there is official confirmation, it should not be treated as a completed incident. Its inclusion here responds to the logic of the source material, which presents it as an unconfirmed event and therefore useful only as a qualitative watch signal.

Threats and active campaigns

Ransomware and extortion, with and without encryption

The month confirmed 15 cases with ransomware or extortion as the main focus, but the material only made it possible to determine one case with confirmed asset encryption and 14 in which the exact classification could not be established. That distinction matters. An intrusion with exfiltration and payment pressure is not the same as effective encryption of assets, and a mention on a leak site is not the same as a real operational outage. In July, the material does not allow all of this to be grouped into a single homogeneous block. The source does not always specify whether encryption took place.

TrendTIC reported attacks in Colombia and Mexico in which attackers printed ransom notes from corporate printers after encrypting systems with BitLocker. That detail does constitute confirmed encryption and, in addition, shows a psychological pressure technique meant to maximize visibility inside the organization. Instead of staying on the screen of the affected machine, the printed note appears in shared spaces and moves the extortion message into the physical environment. For operators, integrators, and managed service providers, this suggests the goal is not only to block processes, but to speed up negotiations through internal exposure.

The rest of the ransomware signal in the month was more diffuse. Kaseya reported that the Inc group had been exploiting SonicWall SMA1000 zero-days to gain remote code execution with root privileges, a finding that reinforces the value of remote access platforms as a springboard for ransomware deployment. CronUp, meanwhile, reported a week with 147 new victims on leak sites and described an operational pattern based on vulnerability exploitation and compromised credentials. Although these are not telecommunications incidents in the strict sense, they do help explain the pressure environment facing telcos and ISPs, which often run exposed services and depend heavily on remote access.

Regional coverage also confirmed that attackers continue to mix financial targets with infrastructure and services. ESET reported 4.699 ransomware attacks in the first half of 2026, with Brazil, Mexico, Argentina and Colombia among the most exposed countries according to the cited note. Nteve said business services, manufacturing and technology were among the most affected sectors, while EM and Lucas Alcaraz highlighted ransomware growth in Brazil and the country’s weight within the regional volume. None of those figures amount to a telecommunications incident, but they do point to a threat environment that sustains risk for connectivity providers and their enterprise customers.

Fraud and impersonation in telecommunications

The month’s material included two events with a documented fraud or phishing component. The clearest one, although without a confirmed date, was the Noticias RCN report about a criminal organization that impersonated a telecommunications company to steal 6.500 million pesos and illegally offer 1.500 internet and television services that affected 930 people. Although the case does not enter the period’s indicators because the date could not be confirmed, it remains relevant because it illustrates a highly sensitive vector for the sector: the use of a brand, a commercial identity, or a seemingly official sales channel to monetize someone else’s trust.

Operationally, this type of impersonation usually relies on fake profiles, improvised support channels, improper charges, and promises of services that do not exist. The damage goes beyond financial fraud. It also undermines the legitimacy of the affected company’s brand, can trigger user complaints, and forces customer service, legal, and security teams to coordinate consistent messaging. For telcos and ISPs, the risk increases when consumers cannot clearly tell the official channel from the fake one, or when the brand itself operates alongside multiple sales and support intermediaries.

The second documented event involved the compromise of an account linked to AFA Medios and the unauthorized sending of emails to journalists. Although it is not commercial fraud in the strict sense, it does follow the same logic as phishing and abuse of trust. A compromised legitimate account has high reuse value because it lowers recipient alerts and makes it easier to circulate messages that appear authentic. For the telecom sector, where email and support messaging are part of the daily relationship with users, this kind of abuse has direct implications for ticket validation, campaigns, and security communications.

APT and opportunistic intrusion

The material did not include a classic, clearly attributable APT campaign with a direct focus on telecommunications and ISPs, but it did contain several signs of opportunistic intrusion with a high level of operational maturity. Access to Ecopetrol through a third party with administrator privileges, the use of Kali Linux to move inside IT, credential abuse, and the active exploitation of vulnerabilities in exposed platforms outline a scenario in which attackers combine reconnaissance, initial access, and lateral movement with available tools and fairly conventional attack paths.

Kaspersky, according to Infosertecla, reported a campaign called StrikeShark that uses new malware, SharkLoader, and included organizations in Colombia among its targets. Even though the material does not link it directly to a telecommunications operator, the signal deserves attention because it points to an active campaign in the region and because the access, email, authentication, or software distribution infrastructure of a telco can be a natural target for this type of malware. The value of the data lies in the distribution logic, not in a specific victim within the vertical.

Critical Vulnerabilities

The monthly material cites six critical CVEs, but not every item can be linked to telecommunications and ISPs in the region with the same level of detail. The list below consolidates only what the available sources explicitly mentioned.

CVE Software Exploitation Source
CVE-2026-15409 SonicWall SMA1000 Zero-day actively exploited to achieve remote code execution with root privileges F5 Labs
CVE-2026-15410 SonicWall SMA1000 Zero-day actively exploited to achieve remote code execution with root privileges F5 Labs
CVE-2026-25089 FortiSandbox Flaw in multiple versions, including FortiSandbox Cloud and PaaS, with exposure relevant to managed security providers and large operators F5 Labs
CVE-2026-39808 FortiSandbox Flaw in multiple versions, including FortiSandbox Cloud and PaaS, with exposure relevant to managed security providers and large operators F5 Labs
CVE-2026-58644 SharePoint The source stated that it requires at least Site Owner privileges, narrowing the practical attack path F5 Labs
CVE-2026-48282 Adobe ColdFusion Path traversal, CVSS 10, linked by Senserva to CISA KEV and relevant for internet-facing applications Senserva

No additional critical CVEs were recorded in the material reviewed for this report, but that does not mean critical exploited vulnerabilities were absent in the region. This block also needs to be read carefully, because a vulnerability mention does not equal an incident in telecommunications. It does point to platforms that may fall within the exposure radius of telcos, ISPs, MSSPs and operators with remote management infrastructure, especially when they are used for access, administration or service publication.

In parallel, CISA published its weekly bulletin for July 20, 2026, with vulnerabilities actively exploited during that week, and Security Arsenal said that 10 vulnerabilities were added to KEV between July 13 and 16. Hacker Storm said CISA added eight new vulnerabilities to KEV, including Fortinet FortiOS and Arista VeloCloud Orchestrator. Telefónica Tech also published a weekly bulletin for July 25 to 31 that mentions the addition of one vulnerability to KEV on July 22. Those references do not by themselves prove impact on Latin American telecommunications, but they do place the month within a window of active exploitation targeting tools that telcos and ISPs often manage or integrate.

Regulation and compliance

No documented regulatory moves were recorded in the period materials. That does not mean regulatory activity was absent in the region, only that, for July 2026 and based on the material provided, there were no verifiable items on new rules, resolutions, or specific regulatory announcements for the telecom and ISP vertical.

Even without new rules, the month still carried clear compliance implications. The Ecopetrol case shows interaction with Fiscalía, MinTIC, ColCERT, CCOCI, Policía and DIJIN to handle information that was unlawfully disclosed and to remove content from public access. In Copaco, the decision to proactively take down the website fits a containment logic and a duty of care in the face of public exposure. In the Chilean MTT case, the lack of official confirmation underscores a communications compliance point, not every press report should become an attributed fact from the organization, especially if the authority has not confirmed it.

For telcos and ISPs, compliance in this context was driven less by a major reform than by response discipline. Timely internal notification, evidence preservation, third-party access control, coordination with CSIRT or CERT, and traceability of containment decisions were the elements that carried the most weight in the month’s material. No new regulation appears, but there is a clear demand for operational governance.

Countries and most affected subsegments

Peru

Peru was the country with the most direct impact on end-user connectivity. The fiber cut in La Molina affected fixed internet in several districts of East Lima and forced Movistar to report service restoration the same day. The episode showed a clear physical vector, with tampering involving cabling and underground telecom chambers. For an operator, that is a warning about urban access points and about the link between vandalism, theft, and service disruption. There was no data exfiltration or ransomware here, but there was an availability impact that was visible to users.

Paraguay

Paraguay appeared because of Copaco, the state-owned telecom company. The incident involved the preventive deactivation of its institutional website after a security issue was detected. Coverage did not detail the technical cause, and there is no evidence of any impact on critical systems. Even so, the move is significant because it reflects a containment posture in response to an anomaly on the public surface. In a state-owned telco, the website is not an accessory component. It is part of the user-facing channel, the access point for information and, in many cases, the place where procedures or payments are handled.

Colombia

Colombia concentrated several signals. The most important was the leak linked to Ecopetrol, which involved information from 15 companies in the group and triggered a coordinated response with multiple entities. Although Ecopetrol is not a telco, the type of intrusion, with a privileged third party and lateral movement, is highly relevant for connectivity operators and managed service providers. In addition, regional coverage of ransomware and Kaspersky's reference to the StrikeShark campaign included Colombian organizations among its targets. The country also appears in the material with the telecom fraud case reported by Noticias RCN, although no confirmed date was provided.

Chile

Chile was tied to two layers of signal. On one side, ADN Radio's coverage of a supposed incident against MTT infrastructure, not confirmed by authorities. On the other, telemetry cited by Nteve placed Qilin as the family with the most detections in Chile, with a peak in January within ESET's aggregated window. That last figure is telemetry and should not be treated as an incident, but it does help explain why Chile appears to be a market sensitive to active ransomware families. For the vertical, the right reading is that the country combines exposure of public infrastructure with a high detection environment at the regional level.

Brazil, Mexico, and Argentina as regional context

Brazil, Mexico, and Argentina did not contribute specific telecom incidents in the month's material, but they do dominate the regional ransomware context. ESET, Nteve, Agencia NVM, EM, and Lucas Alcaraz placed Brazil as the most affected country, followed by Mexico, with Argentina and Colombia also among the most exposed. That distribution does not automatically translate into telecom incidents, but it does create structural pressure on operators that support corporate services, remote access, intermediary cloud, and enterprise customer support. For an ISP, the cost of that environment is not always visible in its own monthly statistics, but in the load of monitoring, hardening, and preventive response.

Subsegments of the vertical

The clearest affected subsegment was last-mile fixed connectivity, visible in Movistar's fiber cut. The second is the operation of institutional portals and channels, reflected in Copaco. The third, although outside the core of the vertical, is the administration of environments with third-party access, which Ecopetrol exposes very clearly and which is especially relevant for telcos with OSS, BSS, NOC, hybrid cloud, or managed services. There are also signs of commercial identity risk and fraudulent sales, closer to the user relationship and distribution channel than to the network core, but still relevant for mass-market ISPs.

There is no comparable baseline because this is the first archived period with this indicator format for Latin America. For that reason, it would not be accurate to claim an increase or decrease from the previous month within this series. What can be done is to identify signals that, because of their frequency and type, should remain under close watch through August and the rest of the third quarter.

The first signal is the persistence of physical risk to fiber and urban ducts. The La Molina case shows that service availability can deteriorate through very concrete deliberate actions, carried out in underground infrastructure and with immediate impact. For connectivity operators, that means reinforcing inspections of critical points, sensors, cameras, chamber sealing and territorial coordination. This is not only a technical issue. It is also a matter of physical security and local response.

The second signal is the significance of third-party privileged access. Ecopetrol made it clear that an administrator third party can become the entry point to a broad ecosystem. That dynamic is not limited to energy or industry. In telecommunications, where providers, integrators, outsourcers, field teams and third-party platforms coexist, the trust surface is large. The month suggests a tighter review of onboarding, revocation, sessions, MFA and shared administration logs.

The third signal is the maturity of operational extortion. TrendTIC showed ransom note printouts after BitLocker encryption, and several items this month pointed to ransomware with active exploitation of vulnerabilities. That reinforces a mixed pattern, where the attacker does not limit itself to encrypting data but also seeks to leave a mark, accelerate pressure and exploit any exposed edge. Telcos and ISPs should read this together with KEV activity and the use of remote access platforms, because these are elements that often coexist in the same technical environment.

The fourth signal is the blurring line between incident and brand abuse. The case of the alleged telecommunications company in Colombia, although without a confirmed date, is a reminder that impersonation fraud can affect customer relationships and trust in sales channels. At the same time, the compromised account tied to AFA Medios shows how a legitimate identity can be reused for unauthorized communication. In both cases, the trusted channel matters as much as the infrastructure.

The fifth signal is that the region continues to face steady pressure from critical vulnerability exploitation. F5 Labs, CISA, Security Arsenal and Telefónica Tech place July as a month marked by activity against SonicWall, Fortinet, SharePoint, ColdFusion and other sensitive components. A telco does not need to be the named victim for that to matter. If a connectivity provider manages any of those components, its exposure is immediate. If it does not manage them, it still depends on them in its service chain.

Recommendations for security teams

  1. Review third-party access maps with elevated privileges immediately. The Ecopetrol case suggests a third-party administrator may have been the initial access vector. In telecoms and ISPs, active accounts, persistent sessions, effective MFA, access expiration, and segregation between support, operations, and administration should be revalidated.

  2. Strengthen physical protection for cameras, ducts, and splice points. The La Molina incident shows that physically cutting fiber remains a simple, effective way to degrade service. That calls for perimeter controls, video surveillance, patrols, opening sensors, and rapid-response procedures with crews and authorities.

  3. Tighten monitoring of institutional portals and public-facing surfaces. Copaco proactively took its website offline. That should remind teams that an exposed portal may require immediate containment. Dedicated playbooks for corporate web, self-service, and public authentication are advisable.

  4. Audit exposure of remote access and administration platforms. SonicWall SMA1000, FortiSandbox, SharePoint and ColdFusion appeared in the sources as active exploitation points or critical vulnerabilities. If any of those technologies are present in the operator’s environment or supplier chain, the review should be prioritized and documented.

  5. Treat ransomware as a chain, not a single event. The month showed encryption, extortion, printed notes, data leakage and credential abuse. Defense should include restorable backups, backup segregation, recovery testing and exfiltration monitoring, not just malware blocking.

  6. Harden the communication channel with users and journalists. The compromised account linked to AFA Medios shows that a legitimate identity can be used for unauthorized messages. For an operator, that means reviewing email, distribution lists, templates, MFA, forwarding rules and sender validation for sensitive communications.

  7. Establish a clear coordination path with CSIRT, regulators and law enforcement. The Ecopetrol case involved ColCERT, Fiscalía, Policía and other entities. For telecoms and ISPs, advance coordination reduces response time and avoids improvisation when an incident affects critical infrastructure or customer data.

Material limitations

This report was built exclusively from the material provided for July 2026. No internet access or additional external sources were available. As a result, any reading of trend, impact, or attribution is limited to what the available sources could verify. Items excluded for lack of a confirmed date do not count toward the indicators, even if they may provide qualitative context. That is the case with the Noticias RCN report on the impersonation of a telecommunications company, which was not counted as part of the period's volume.

The declared time window for the indicators includes 73 dated events in July 2026 and 1 without a confirmed date, but the period indicators are calculated on 67 verified events. That base must be respected exactly as provided. Likewise, a zero value does not mean the phenomenon was absent in the region. In particular, the regulatory movements indicator at 0 means it did not appear in the analyzed material, not that there was no regulatory activity in Latin America.

The same applies to critical CVEs. Here, 6 CVEs were mentioned, so the corresponding table develops them. If in another month the indicator were 0, the correct reading would be that no critical CVEs were recorded in the analyzed material, not that the region was free of exploited vulnerabilities. That distinction is essential to avoid confusing the limits of the input with the real absence of risk.

Aggregated telemetry figures were also excluded from the volume. These are attempts, blocks, detections, or weekly vendor averages, not incidents with confirmed impact. They can be used as context if cited with the proper clarification, but they should not be added to the period's events or confused with verified intrusions. This report maintained that separation.

Finally, the material did not include detailed IoCs such as hashes, domains, or IPs, nor a consistent set of TTPs with MITRE taxonomy for the vertical. For that reason, no technical appendix of indicators of compromise was included. The absence of that section does not mean the absence of malicious activity, only the lack of verifiable input within the available corpus.

Sources