Chile Army Listed as Rhysida Victim
Invaders.ie lists the Chilean Army as a Rhysida victim, while Chile’s air force reported Escudo Minerva, a ransomware response drill.
Invaders.ie lists the Chilean Army as a ransomware victim attributed to Rhysida, with the incident discovery date set at Nov. 12, 2025. Chile’s air force also reported Escudo Minerva, an exercise on responding to ransomware attacks against critical infrastructure.
Update August 24, 2026: Invaders.ie added the Chilean Army as a ransomware victim attributed to Rhysida, with the incident discovery date set at Nov. 12, 2025. The Chilean Air Force also reported the Escudo Minerva exercise, focused on readiness for ransomware attacks against critical infrastructure.
Invaders.ie’s ransomware victim tracker lists the Chilean Army as a victim of an operation attributed to Rhysida, with the incident discovery date marked as Nov. 12, 2025 and classified under the Government category for Chile. The available material does not include additional technical details or an official confirmation from the Chilean institution.
What public records appear for Chile in the public maps?
In the public records reviewed, the Chilean Army appears as a ransomware victim, and the domain seit.cl is linked to an actor labeled Apt73. In both cases, the information is limited to what those portals display, with no supporting technical documentation in the material provided.
The ransomware.live map for Chile had already listed the Chilean Army as a victim of an operation the portal attributed to Rhysida, without additional technical details about the intrusion or an official confirmation from the Chilean institution. That view also linked seit.cl to Apt73.
What public context is there on Chilean ransomware preparedness?
The Chilean Air Force reported in November 2025 that it had carried out the national crisis management exercise Escudo Minerva at the Chilean Army War Academy. The drill focused on preparedness for possible ransomware attacks against critical infrastructure and was organized by the Cyber Defense Laboratory for the Protection of Critical Infrastructure, CIBERLAB, as a collaboration between the Chilean Army and the Pontifical Catholic University of Chile.
That context adds to what the National Cyber Security Index, NCSI, reports, which is that Chile carried out exercises such as Cyber Shield 2024, in civilian-military cooperation between Chile and Brazil. The index presents this as part of efforts to strengthen readiness for cyber incidents, although it does not detail a specific case involving the Army as a ransomware victim.
What is missing from the available evidence?
No recent, verifiable public reports were found in the provided material on APT campaigns or state actors aimed specifically at government, banking, or energy targets in Chile. The available reporting angle centers on the ransomware.live and Invaders.ie records, but without official validation for the Chilean Army case and without further technical context for seit.cl.
The second source available, a CronUp note on a large smishing campaign in Chile, points to impersonation of public agencies and companies, but does not attribute that activity to APTs or states. Based on the documentation provided, there is no basis to connect that campaign to the ransomware.live map records or to present a state attribution as verified.
Sources
- Campaña masiva de smishing continúa expandiéndose en Chile con suplantación de organismos públicos y empresascronup.com· CronUp
- Mapa de víctimas de ransomware en Chileransomware.live· ransomware.live
- Chile Ransomware & Cyber Attacks | Breach Housebreach.house· Breach House
- Ransomware Victims in Chile - 3 Attacksinvaders.ie· Invaders.ie
- Ransomware.live activity Government & Defense CLransomware.live· Ransomware.live
- 71 victims for Chile - Ransomware.liveransomware.live· ransomware.live
- Chile - National Cybersecurity Indexncsi.ega.ee· Estonian Information System Authority (NCSI)
- Fuerza Aérea en Ejercicio “Escudo Minerva”fach.mil.cl· Fuerza Aérea de Chile



