
Uruguay Cybersecurity Situation, September 2026
More ransomware, more fraud, and more regulation: September closed with 67 verified incidents, 14 extortion cases, and 9 regulatory measures.
Whalemate Labs is the research desk behind CiberLATAM news and analysis. It runs AI-assisted research agents that track CERTs, vendor advisories, regulators and specialist media across Latin America. Every story publishes automatically, but only after its cited URLs are checked over HTTP and the story is corroborated by at least two distinct outlets, or by one verifiable official source. Anything that fails those checks is not published. Corrections to published stories are always made by a human editor.
The BCP sanctions registry lists 11 concluded administrative cases against seven banks in Paraguay, tied to regulatory breaches, not cybersecurity.
Oct 9, 2026 · 2 min
OpenAI suspended accounts tied to a Russian influence campaign that used AI to target audiences in Latin America, especially Argentina.
Oct 9, 2026 · 3 min
OpenAI suspended Russia-linked accounts used for AI influence campaigns in Latin America, with Argentina in focus.
Oct 9, 2026 · 3 min
OpenAI suspended accounts used in covert influence campaigns in Argentina, Bolivia, Peru and Ecuador, with AI-assisted ransomware reported in Mexico.
Oct 9, 2026 · 3 min
Atlassian urged immediate patching for CVE-2026-21589, a critical flaw affecting multiple Data Center products.
Oct 9, 2026 · 3 min
ANPD signed an MoU with Portugal to develop joint guides and tools. The current inspection rule stays in force until a new resolution.
Oct 9, 2026 · 2 min
The OCC fined American Express National Bank $350 million for BSA and AML failures after delays in reporting suspicious activity.
Oct 9, 2026 · 2 min
Peru's BCRP and SBS set new rules for digital payments and open finance, with security, consent and transition deadlines.
Oct 9, 2026 · 2 min
CVE-2026-88771 and CVE-2026-88772 were used to plant web shells in NetScaler. CISA also added CVE-2026-88779 to KEV.
Oct 8, 2026 · 3 min
Federal Police launched Operation Insidioso after a July attack with sensitive data theft and possible intrusion and extortion charges.
Oct 8, 2026 · 2 min
Nueva EPS says its checks found no unauthorized access as it continues investigating claims of a data leak.
Oct 8, 2026 · 3 min
Peru’s lower house approved 90-day executive powers to legislate on cybercrime, with limits on due process and personal data.
Oct 8, 2026 · 3 min
Guatemala issued a favorable opinion on Initiative 6347, while Costa Rica seeks fines for storing personal data without encryption.
Oct 8, 2026 · 2 min
Reuters reported a power deficit above 1,500 MW in Venezuela, while protests spread across five states and a fake Corpoelec notice circulated.
Oct 7, 2026 · 2 min
Chile’s PDI and prosecutors warned of phishing using cloned bank and retail sites to steal credentials and verification codes.
Oct 7, 2026 · 2 min
Vicksburg, Mississippi, temporarily shut down municipal systems after a ransomware attack. Emergency services stayed online.
Oct 6, 2026 · 2 min
The SBS opened the draft open finance rule for public review. The proposal sets data, consent and participation rules.
Oct 6, 2026 · 2 min
Microsoft fixed an authorization flaw in on-prem Exchange Server that could let users read other mailboxes in the same organization.
Oct 6, 2026 · 2 min
ASEA said its @agencia_asea Instagram account was compromised and asked the public to ignore posts while it works to regain access.
Oct 6, 2026 · 2 min
CLOSEDQUORUM uses commercial AI models to steer malware, while OpenAI faces a lawsuit and Google launches Gemini 4 Argon.
Oct 5, 2026 · 3 min
Starting Oct. 1, 2026, the BCU will require stronger authentication and anti-fraud monitoring for electronic transactions.
Oct 5, 2026 · 2 min
The United States sanctioned 10 people and entities tied to a financial network linked to Tren de Aragua, accused of ATM hacks.
Oct 5, 2026 · 2 min
Mexico’s anti-corruption office found data protection failures at public agencies, including IMSS, SHF and SAT, and ordered fixes.
Oct 5, 2026 · 3 min
Wallstreet claimed an attack on Gibson Area Hospital in Illinois. FalconFeeds said 600 GB may have been exfiltrated.
Oct 4, 2026 · 3 min

More ransomware, more fraud, and more regulation: September closed with 67 verified incidents, 14 extortion cases, and 9 regulatory measures.

September in the USA was dominated by vulnerabilities and system exposure, with NetScaler, SonicWall, Microsoft, WSO2, and healthcare incidents in focus.

Ransomware led September in Mexico with 19 cases, 12 unclassified incidents, 8 regulatory moves, and 6 critical CVEs.

Brazil ended September with more incidents, ransomware, and AI-enabled fraud; the focus was judicial

September ended with rising incidents and regulation, an ICETEX case, pressure on finance and health, and 2 critical CVEs mentioned.

Fraud, ransomware, and a critical CVE shaped September in LATAM retail and e-commerce, with focus on Brazil, Argentina

Peru closed September with 48 verified incidents, focused on ransomware, insider fraud, and SBS rules on incidents and digital payments.

Puebla, APT campaigns, and 11 CVEs shaped September for LATAM mining and natural resources, with medium regional risk.

September recorded 56 verified events in the vertical, including 9 ransomware cases and 17 incidents, with a focus on transport

Bolivia saw entity attacks, banking fraud, and an intense regulatory agenda, with a focus on banking and personal data.

September logged 49 verified events across Latin American public sector, with incidents, claimed leaks, and no critical CVEs in the material reviewed.

Ransomware led September in Paraguay with 19 incidents and one Panzer case against Inovapy; there were also 13 unclassified incidents and 9 regulatory