CiberLATAMbywhalemate

Brazil Leads Health Sector Ransomware

Brazil logged 99 confirmed ransomware attacks in H1 2026, keeping healthcare among the country’s top targets.

Whalemate Labs · AI-assisted researchPublished:Updated 4 min read

Updated August 20, 2026: a new Vision Cybersecurity analysis cited by CrowderTech confirmed 99 ransomware attacks in Brazil in the first half of 2026, 36.3% of the 273 incidents detected in Latin America. The report also found that healthcare accounts for 10.4% of victims in the country and that the local ecosystem has fragmented with emerging groups.

The ransomware.live project listed Global Secret Group as a victim in Brazil, identifying it as an Hospitals & Clinics organization and detecting the incident on July 26, 2026. The record confirms another ransomware attack against a Brazilian healthcare provider and adds to a pattern of sustained pressure on hospitals, clinics and other parts of the health system.

How exposed was Brazil in 2026?

Brazil accounted for 99 confirmed ransomware attacks in the first half of 2026, according to a sector analysis by Vision Cybersecurity cited by CrowderTech. That volume represents 36.3% of the 273 incidents identified in Latin America and keeps the country as the region’s main focus during the period.

The same report says that while LockBit 5 continues to lead activity, the local ecosystem has fragmented with emerging groups such as TheGentlemen, Incransom and CoinbaseCartel. It also mentions campaigns such as Vect 2.0, which show a high level of technical sophistication.

What place does healthcare hold in the attack map?

Healthcare represented 10.4% of ransomware victims in Brazil in 2026, according to Vision Cybersecurity. At the same time, the corporate services sector accounted for 27.3% of attacks, leaving the health system among the hardest-hit targets even if it was not the most targeted in absolute terms.

Portal Information Management had already said Brazil became Latin America’s ransomware epicenter in healthcare in 2026, with 51% of sector incidents in the region. The same review placed the country among the three largest global targets in the segment, based on data from PwC studies and other reports cited by the outlet.

That analysis linked the expansion of the problem to the spread of generative AI and chatbots without governance, the movement of medical data through unencrypted platforms and basic configuration errors in cloud services. The report suggests that a large share of current risk in the sector comes from operational and management failures rather than highly sophisticated attack techniques.

What tactics are the groups using?

Vision Cybersecurity describes predominant technical TTPs such as partial encryption of large files, including VMDK, MDF and .vbk backups, to maximize encryption speed in corporate environments. That approach aims to cause rapid impact without needing to lock down all assets at once.

Cafe com Bytes reinforced that reading by saying Brazil accounts for 51% of ransomware incidents in Latin America’s healthcare sector. The same outlet added that healthcare makes up 10.4% of ransomware victims in Brazil and that, in 2026, LockBit 5 and TheGentlemen lead activity in the country, with thirteen victims each. The article also noted that the criminal market appears fragmented, with other groups such as Incransom and CoinbaseCartel gaining ground.

On the financial side, Cafe com Bytes cited the Brazilian healthcare sector as having the highest average data breach cost among the sectors analyzed, at R$ 11.43 million per incident according to IBM’s Cost of a Data Breach report. In the same piece, Brazil’s average data breach cost was put at R$ 7.19 million, up 6.5% year over year.

What other indicators show the pressure on the system?

The SINDPD union provided broader context by saying Brazilian healthcare institutions suffered an average of 3,167 attacks per week in 2025, about 37% above the global sector average. It also said healthcare leads the global ranking of cyberattacks ahead of finance and consumer sectors.

According to that same review, in the first half of 2025 Brazil’s healthcare sector logged more than 11,000 security breaches, most of them considered successful and a significant share classified as high severity. The picture drawn by those figures is one of a broad attack surface, where ransomware exists alongside a high volume of intrusions and breaches.

G1 added another indicator of the size of the threat ecosystem in Brazil, reporting, with Fortinet data, 753.8 billion digital attack attempts in 2025 and more than 187 million malware occurrences. In that environment, attacks against hospitals, clinics and providers in the health system are landing in a space already under pressure from multiple vectors.

What regulatory changes are accompanying this scenario?

Portal Information Management also added a regulatory angle, noting that Lei nº 15.352/2026 turned the ANPD into a special-purpose autarchy with expanded oversight powers over sensitive data, including health data. In addition, Resolução CFM nº 2.454/2026 established Brazil’s first framework for the use of artificial intelligence in medicine, in force since August, in response to the rise in incidents and the risk of ungoverned AI use in the sector.

At the same time, Flare.io identified TheGentlemen among the groups attacking healthcare organizations and providers in the health ecosystem. That analysis, focused on EMEA, described a dynamic that targets the full healthcare supply chain, including software vendors, clinics, laboratories and hospitals, and monetizes leaked data through leak sites and secondary fraud. The pattern matches the pressure seen in Brazil on providers such as MedicSolution and private clinics.

ransomware.live had also recorded Global Secret Group in Brazil as a victim, an organization in the Hospitals & Clinics sector, with the incident discovered on July 26, 2026, confirming that the offensive continues to reach Brazilian healthcare providers.

Sources

View all