CiberLATAMbywhalemate

Chile cyber resilience focus shifts to energy

Chile is weighing controlled degradation in energy as Rutify, Direwolf and Kaspersky data point to pressure on critical systems.

Whalemate Labs · AI-assisted researchPublished:2 min read

Chile’s critical infrastructure debate is now centered on operational resilience in energy, public sector exposure and attacks on health systems. At Industrial Cyber Summit 2026, speakers discussed controlled degradation to keep services running during incidents, while recent cases such as Rutify, a ransomware case at a university hospital and a Kaspersky survey highlighted growing pressure on agencies and companies.

Chile’s critical infrastructure debate has been shaped by operational resilience in energy, exposure in public systems and attacks against the health sector. At Industrial Cyber Summit 2026, the discussion turned to controlled degradation as a way to keep services running during incidents. In recent weeks, warning signs have also piled up with Operation Rutify, a ransomware case at a university hospital and a survey that attributes a meaningful share of attacks against Chilean organizations to artificial intelligence.

What did Industrial Cyber Summit 2026 put on the agenda?

In energy, the focus was on how to keep operating even if part of the infrastructure fails, so service outages do not become total interruptions. TECNAUTAS said that was one of the main themes in Chile, along with supply chain security as a central challenge for critical industries because vendors and third parties can access sensitive processes.

The same report recalled the blackout that affected much of Chile on February 25, 2025, as a lesson in the vulnerability and interdependence of essential services, including energy and telecommunications. That reading fits with Colbún’s account of the Canutillar hydroelectric plant, which showed its strategic role by returning to autonomous operation without power from the grid and helped make Puerto Montt one of the first cities to regain supply.

What do the recent cases show about exposure and ransomware?

In Chile, Operation Rutify ended with the arrest of one alleged participant in a network that is said to have breached systems tied to Fonasa, Servel, the Treasury and Sernac, according to CronUp. Prosecutors accuse an 18-year-old student of leading the group linked to the mass leak, which reportedly reached websites belonging to public and private institutions, including Fonasa, Sernac, the Treasury, IPS, the Digital Government Secretariat and the Municipality of Las Condes.

Lunmas also reported that the case describes a technical method based on automated web scraping, using flaws in institutional site code to extract large volumes of data. In that file, the attack vector appears more tied to design weaknesses and information exposure than to a classic CVE-type vulnerability.

CronUp added another health sector case, with the Hospital Clínico Universidad de Chile listed as a Direwolf victim amid a historic rise in ransomware victims observed in Chile during August 2026. Tech-Insider.org said that on August 30, 2026, the group posted three new victims in 24 hours, including that hospital and another health center in Turkey, reinforcing its pattern of coordinated campaigns against healthcare infrastructure.

What do the data say about AI use in attacks?

A Kaspersky survey cited by Infobae said 76% of organizations believe artificial intelligence was present in about half or more of the cyberattacks they received in the last 12 months, including Chilean companies. The figure adds to concerns about the attack surface facing agencies and critical service providers in a setting where law enforcement operations, data exposure and health sector attacks are connected by the same problem, essential services under growing pressure.

Sources

View all