CiberLATAMbywhalemate

Mexico accounted for 52 ransomware attacks

SCILabs recorded 290 ransomware attacks in Latin America in the first half of 2026. Mexico accounted for 17.93%, with finance in focus.

Whalemate Labs · AI-assisted researchPublished:Updated 4 min read

SCILabs recorded 290 ransomware attacks in Latin America in the first half of 2026, up 25.5% from the previous six months. Mexico accounted for 17.93% of those cases, about 52, and the report placed finance and telecoms among the strongest industries in the country.

Update October 8, 2026: New data were added on the The Gentlemen campaign, which reached Mexico and more than two dozen organizations in six countries. Quarterly figures from Comparitech for Argentina and expanded technical detail on the SharePoint vulnerabilities exploited by Warlock were also added.

SCILabs recorded 290 ransomware attacks in Latin America during the first half of 2026, a 25.5% increase from the previous six months. Mexico accounted for 17.93% of those cases, about 52, and the report identified financial services and telecommunications as the strongest industries in the country. It also said many small and midsize businesses were still running legacy technology without updates or a strong cybersecurity program.

What do the reports say about SMBs in the region?

Kaspersky found that among the Latin American SMBs surveyed, the most damaging incidents included ransomware, cited by 8% of respondents. Stealing sensitive information was the main objective named by 29% of respondents.

In the same survey, IT security teams were the most affected at 40%, followed by accounting and finance at 36% and IT at 35%. That suggests the impact was not limited to a technical team.

How did ransomware move globally in August?

Cyble reported that August 2026 marked the year’s peak in ransomware activity, with 1,034 public victims attributed to 88 gangs. In another summary from the same report, Qilin and The Gentlemen ranked among the most active groups worldwide, with 145 and 110 victims, respectively.

Symantec said Warlock, also tracked as Longlegs by Symantec and Storm-2603 by Microsoft, was exploiting Microsoft SharePoint vulnerabilities to compromise organizations in Spanish- and Portuguese-speaking countries, including Latin America. Among the victims observed by Symantec were a water utility, a telecom provider, a regional government entity and a university.

The coverage also said Warlock was targeting organizations in Spanish- and Portuguese-speaking countries across Latin America, Europe and Africa. BleepingComputer added that Storm-2603, according to Microsoft's tracking, was among the actors exploiting the ToolShell SharePoint vulnerability chain, and noted that those flaws remained viable initial-access vectors more than a year after Warlock first appeared.

The Hacker News said Longlegs combined SharePoint access with web shells and forged __VIEWSTATE payloads, and used the signed vulnerable K7RKScan driver to disable security tools before deploying ransomware. CyberPress, meanwhile, recommended patching SharePoint, rotating ASP.NET machine keys after a possible intrusion, blocking vulnerable drivers, checking SYSVOL and watching for tunnels, unusual downloads and queries to oastify.com.

Security Affairs said the persistence of the attacks is partly explained by the fact that some organizations still had not applied patches or mitigations for the SharePoint vulnerabilities tied to ToolShell. An independent analysis said the match between Storm-2603 and Longlegs, and the broader link to China, should be treated as moderately confident, so that attribution should not be presented as fully confirmed.

What new victims and figures did the latest coverage add?

The latest coverage added that The Gentlemen brought its campaign to Mexico and to more than two dozen organizations in six countries, including the United States, France, the United Kingdom, India and the United Arab Emirates, according to El Economista. Comparitech also reported that Argentina went from 18 attacks in the second quarter to 45 in the third quarter of 2026, a 150% increase, and placed Qilin and The Gentlemen as the groups with the most claims in the period, with 357 and 342, respectively.

In that same quarterly snapshot, Comparitech said Qilin kept claiming victims outside North America, including South America, while Bitdefender said the group continued registering victims in regions outside North America, including South America. SecPod added that Warlock's recent victims included critical infrastructure organizations in Europe, Africa and Latin America, and said the exploited flaws affect on-premises SharePoint deployments, not SharePoint Online in Microsoft 365.

What technical changes were made to the SharePoint flaws?

PCRisk explained that Microsoft first patched CVE-2025-49704 and CVE-2025-49706 in July 2025, then later assigned CVE-2025-53770 and CVE-2025-53771 to bypasses exploited as zero-days since at least July 18, 2025. The coverage added that Microsoft released emergency updates for SharePoint Server 2016, 2019 and Subscription Edition.

BleepingComputer also said Warlock emerged in June 2025 and gained notoriety for exploiting that ToolShell SharePoint zero-day chain. TechJuice, in an analysis based on Symantec, added that the group is also associated with Gold Salem and gains access through unpatched SharePoint servers, with the ability to collect ASP.NET machine keys from the SharePoint farm.

Sources

View all