Brazil Tops Public-Sector Ransomware Attacks
Brazil accounts for 51% of public-sector ransomware attacks in Latin America as DragonForce scales extortion with RaaS and stolen data.
Brazil accounted for 51% of ransomware attacks against the public sector in Latin America, according to a study cited among the available sources. The figure places the country as the region’s main target at a time when ransomware cartels such as DragonForce are professionalizing every stage of extortion, from initial intrusion to public pressure on victims.
Brazil accounted for 51% of ransomware attacks against the public sector in Latin America, according to a study cited among the available sources. The figure places the country as the region’s main target at a time when ransomware cartels such as DragonForce are professionalizing every stage of extortion, from initial intrusion to public pressure on victims.
DragonForce is described by WeLiveSecurity as a ransomware cartel with full Ransomware-as-a-Service infrastructure. That setup includes admin panels, leak sites, negotiation systems and tools to manage victims. The same source says the group provides technical support to affiliates, allowing other actors to use its platform with specialized guidance.
The report also says DragonForce offers a stolen-data analysis service designed to maximize extortion, effectively auditing information taken from victims. On top of that, it includes an extortion kit that, according to WeLiveSecurity, gives affiliates lists of executives’ phone contacts and details on the regulatory impact an organization could face if it does not pay the ransom.
The group’s operating model does not rely on encryption alone. RecentBreaches says DragonForce runs a leak site and focuses on data theft and extortion against companies, confirming that publishing information on leak portals is a structural part of its model. RansomNews, for its part, places the actor as first observed in 2023 and later repositioned as a cartel with white-label ransomware and affiliate infrastructure.
Recent activity reinforces that scale. Between July 14 and July 16, 2026, DragonForce posted at least 18 victims on its leak site, spread across eight countries, including Mexico. Daily Security Review said the scope confirmed the transnational dimension of the operation and its focus on companies and critical services beyond Latin America. IntelFusions expanded on that same spike and reported more than 20 organizations affected in roughly 14 countries, across sectors including manufacturing, finance, telecommunications, energy and hospitality.
In the case of Ifage, CyberVeille said the public claim came about three months after the initial intrusion. That delay suggests DragonForce can maintain long-term access and process large volumes of data before moving to the public pressure phase, a pattern consistent with an operation designed to systematically exploit stolen information.
WeLiveSecurity warns that the main risk associated with the group is the consolidation of a scalable, decentralized criminal model, although it does not provide verifiable quantitative data on its current size in Latin America.
Sources
- DragonForce actor profilemallory.ai· Mallory.ai
- DragonForce malware profilemallory.ai· Mallory.ai
- DragonForce: Data Breaches, Victims & Methodsrecentbreaches.com· RecentBreaches.com
- DragonForce: the cartel that absorbed its rivalsransomnews.com· RansomNews
- Brasil concentra 51% dos ataques de ransomware ao setor público na América Latinabrasiliaeaqui.com.br· Brasilia é Aqui
- DragonForce: de banda a cartel ransomware en 2026welivesecurity.com· WeLiveSecurity (ESET)
- DragonForce Posts Eighteen Victims Across Eight Countries in 48 Hoursdailysecurityreview.com· Daily Security Review
- DragonForce ransomware posts more than 20 victims in three daysintelfusions.com· IntelFusions
- DragonForce revendique une cyberattaque contre l'Ifage et menace de publier 850 Go de donneescyberveille.ch· CyberVeille
- Government agencies falling victim to ransomware daily, warns studyiplogger.org· Iplogger



