Chile investigates telecom cyberespionage
The U.S. alerted Chile to alleged malware in Entel, Movistar and Telmex. Chile’s PDI is probing the so-called Chinese cable case.
The PDI is carrying out procedures at the Metropolitan North Central Prosecutor’s Office to verify a complaint based on information provided by the United States about possible cyberattacks on devices located in Chile, in the context of the case known as the "Chinese cable."
Chile’s PDI is carrying out work at the Metropolitan North Central Prosecutor’s Office to verify a complaint supported by information provided by the United States about possible cyberattacks on devices located in Chile, as part of the case known as the "Chinese cable" affair. The investigation points to alleged cyberespionage operations using malware in the networks of Entel, Movistar and Telmex, with a scope that, according to the coverage cited, may have affected nearly all Chileans who use mobile phones.
What is the PDI investigating in Chile?
The PDI is investigating possible cyberattacks attributed to an Asian cyberespionage group after receiving a complaint that included information provided by the United States.
Cooperativa reported that the case was tied to the "Chinese cable" affair and that the work aims to substantiate possible cyberespionage by "Lilac Typhoon" against companies such as Entel, Movistar and Telmex.
What alert came from the United States about telecommunications?
According to reporting by Revista Seguridad, U.S. intelligence agencies would have alerted the Chilean government to cyberespionage operations using malware in the networks of Entel, Movistar and Telmex.
In the same line, 24 Horas reported that the attacks would have begun to be detected in Chilean territory in September 2024, and that Microsoft attributes the malicious code to an actor whose origins point to China.
Emol said the investigation seeks to determine whether there was espionage targeting multiple private telecom companies, in a case linked to the so-called "Chinese cable."
In that coverage, U.S. Ambassador to Chile Brandon Judd said the activity put at risk the privacy and personal data of nearly all Chileans who use mobile phones.
What happened in Guatemala and Costa Rica?
Available coverage from Central America indicates that a cybersecurity review detected the presence of the APT-15 group, also known as Vixen Panda, Nickel and Nylon Typhoon, in several Guatemalan government systems.
The same review included Costa Rica, where the Costa Rican Electricity Institute announced in March 2026 an incident identified as cyberespionage, and a technical analysis by Mandiant found similarities with a group originating in China.
What does the regional diagnosis show about ransomware and trojans?
At the same time, Scitum’s assessment cited by Convergencia identified 78 ransomware variants targeting Latin America during 2025, with Qilin as the most active.
It also recorded banking trojan campaigns and said Argentina accounted for 13% of those campaigns, in a regional map that also includes obsolete equipment and other exposure surfaces mentioned in the coverage.
The mix of alerts about telecommunications in Chile, findings in Guatemalan government systems and the incident reported by ICE in Costa Rica leaves the region facing open fronts in both cyberespionage and malware campaigns aimed at stealing credentials and locking up data.
Sources
- Reportes de inteligencia de Estados Unidos alertan sobre actividad maliciosa y uso de malware en los sistemas de las empresas de telecomunicaciones en Chilerevistaseguridad.cl· Revista Seguridad
- PDI investiga posible espionaje a Entel, Movistar y Telmex tras advertencia de Estados Unidos24horas.cl· 24 Horas
- Centroamérica se enfrenta a un mayor riesgo de ciberataquesvietnam.vn· vietnam.vn
- Ciberseguridad: Ransomware, troyanos bancarios y equipos obsoletos en el diagnóstico de Scitum sobre Argentinaconvergencia.com· Convergencia
- "Lilac Typhoon": PDI indaga "posibles ataques informáticos" de un grupo de ciberespionaje asiáticocooperativa.cl· Cooperativa
- "Cable chino": Indagan a grupo de ciberespionaje asiático y eventuales accesos a empresas chilenasemol.com· Emol



