CiberLATAMbywhalemate

#Ransomware

This archive brings together reporting on digital extortion, data leaks, and operational disruption across Latin America. It covers attacker tactics, initial access methods, forensic response, and the business decisions that shape incident handling throughout the region.

Brazil: Arcos in Emperador’s claim

Emperador claims an attack on Arcos city hall in Brazil. The case remains unverified, with no public confirmation from the municipality.

Aug 23, 2026 · 2 min

Argentina's AMCA listed by BLACKWATER

Breachsense flagged amca.org.ar as a BLACKWATER victim on Aug. 17, 2026. Security Arsenal also cited it among two new leak-site victims.

Aug 23, 2026 · 3 min

Medusa tops 500 victims in health sector

FBI, CISA and HHS updated their Medusa alert, saying the group has hit more than 500 victims and kept targeting US health care.

Aug 22, 2026 · 2 min

Colombia and Mexico Hit by New Campaigns

Ransomware hit Colombia’s Justice Ministry, while Grandoreiro resurfaced in Mexico, with detections also reported in Peru

Aug 22, 2026 · 2 min

Quaker State Mexico listed by Qilin

Quaker State Mexico appeared in a Qilin-attributed listing, with no independent public confirmation of a breach or data theft.

Aug 22, 2026 · 2 min

Colombia Faces Ransomware, Justice Ministry Hit

Threat reports place Colombia among recent ransomware victims, while F5 and Security Arsenal also flagged related activity.

Aug 21, 2026 · 3 min

Peru logs 83 victims on ransomware.live

ransomware.live lists 83 Peru-linked victims, without attribution to any group. VECERT also reported unconfirmed activity.

Aug 21, 2026 · 2 min

Argentina: The Gentlemen hit critical sectors

Kaspersky attributed The Gentlemen attacks to manufacturing, healthcare, technology, finance, construction

Aug 21, 2026 · 2 min

MECASEM appears in 3AM leak listings

Ransomware.live and Breachsense list mecasem.org as a 3AM victim. GalaxyWarden says there is no public confirmation from the company.

Aug 21, 2026 · 2 min

US ransomware victims pile up in 48 hours

Security Arsenal tracked new U.S. victims from DIREWOLF, COINBASECARTEL and XPL0ITRS across health, tech and professional services.

Aug 19, 2026 · 2 min

Arcos appears in Emperador leak

Brazil’s Arcos city hall appears on a leak site tied to Emperador, but the claim has not been independently verified.

Aug 19, 2026 · 2 min

The Gentlemen ransomware hits LATAM

The Gentlemen grew into a double-extortion RaaS in 2026, targeting LATAM with Fortinet, RDP, and attacks in Colombia, Peru

Aug 17, 2026 · 39 min

Argentina Among The Gentlemen’s Victims

Bitdefender’s August 2026 threat debrief placed Argentina among The Gentlemen’s victims as the ransomware group pushed deeper into manufacturing.

Aug 17, 2026 · 3 min

Argentina Led Ransomware Victims in July

Bitdefender logged 21 claimed ransomware victims in Argentina in July, with The Gentlemen, Qilin and DragonForce among active groups.

Aug 17, 2026 · 3 min

US Alerts on Gunra, Unlimited Breach Hits 3.8M

US agencies warned on Gunra, while Unlimited Technology Systems raised its breach tally to 3.8 million patients.

Aug 16, 2026 · 3 min

Colombia Justice Ministry Confirms Ransomware

Colombia’s Justice Ministry confirmed ransomware hit part of its infrastructure. No data theft was detected, and recovery is ongoing.

Aug 16, 2026 · 3 min

Sears Mexico Appears on Space Bears List

Sears (Grupo Sanborns) was listed as a suspected Space Bears victim on a leak site and in aggregators, with no official confirmation.

Aug 16, 2026 · 2 min

THEGENTLEMEN, Gunra, INC Ransom hit Latin America

THEGENTLEMEN, Gunra and INC Ransom added victims and alerts across the region, with a focus on VPNs, firewalls

Aug 15, 2026 · 3 min

Colombia Confirms Ransomware at Justice Ministry

Colombia’s Justice Ministry confirmed a ransomware incident that disrupted part of its infrastructure and some digital services.

Aug 14, 2026 · 2 min

Chile investigates telecom cyberespionage

The U.S. alerted Chile to alleged malware in Entel, Movistar and Telmex. Chile’s PDI is probing the so-called Chinese cable case.

Aug 14, 2026 · 3 min