CiberLATAMbywhalemate

#3AM

This tag collects reporting on malicious activity and defensive responses that surface outside normal business hours, when security teams still need continuous watch. It brings together analysis, alerts, and context on campaigns, tactics, and warning signs that can affect organizations across Latin America during periods of reduced oversight.

MECASEM appears in 3AM leak listings

Ransomware.live and Breachsense list mecasem.org as a 3AM victim. GalaxyWarden says there is no public confirmation from the company.

Aug 21, 2026 · 2 min