Mexico accounted for 52 ransomware attacks
SCILabs recorded 290 ransomware attacks in Latin America in the first half of 2026. Mexico accounted for 17.93%, with finance in focus.
SCILabs recorded 290 ransomware attacks in Latin America in the first half of 2026, up 25.5% from the previous six months. Mexico accounted for 17.93% of those cases, about 52, and the report placed finance and telecoms among the strongest industries in the country.
Update October 8, 2026: New data were added on the The Gentlemen campaign, which reached Mexico and more than two dozen organizations in six countries. Quarterly figures from Comparitech for Argentina and expanded technical detail on the SharePoint vulnerabilities exploited by Warlock were also added.
SCILabs recorded 290 ransomware attacks in Latin America during the first half of 2026, a 25.5% increase from the previous six months. Mexico accounted for 17.93% of those cases, about 52, and the report identified financial services and telecommunications as the strongest industries in the country. It also said many small and midsize businesses were still running legacy technology without updates or a strong cybersecurity program.
What do the reports say about SMBs in the region?
Kaspersky found that among the Latin American SMBs surveyed, the most damaging incidents included ransomware, cited by 8% of respondents. Stealing sensitive information was the main objective named by 29% of respondents.
In the same survey, IT security teams were the most affected at 40%, followed by accounting and finance at 36% and IT at 35%. That suggests the impact was not limited to a technical team.
How did ransomware move globally in August?
Cyble reported that August 2026 marked the year’s peak in ransomware activity, with 1,034 public victims attributed to 88 gangs. In another summary from the same report, Qilin and The Gentlemen ranked among the most active groups worldwide, with 145 and 110 victims, respectively.
What cases did Symantec link to Warlock?
Symantec said Warlock, also tracked as Longlegs by Symantec and Storm-2603 by Microsoft, was exploiting Microsoft SharePoint vulnerabilities to compromise organizations in Spanish- and Portuguese-speaking countries, including Latin America. Among the victims observed by Symantec were a water utility, a telecom provider, a regional government entity and a university.
The coverage also said Warlock was targeting organizations in Spanish- and Portuguese-speaking countries across Latin America, Europe and Africa. BleepingComputer added that Storm-2603, according to Microsoft's tracking, was among the actors exploiting the ToolShell SharePoint vulnerability chain, and noted that those flaws remained viable initial-access vectors more than a year after Warlock first appeared.
The Hacker News said Longlegs combined SharePoint access with web shells and forged __VIEWSTATE payloads, and used the signed vulnerable K7RKScan driver to disable security tools before deploying ransomware. CyberPress, meanwhile, recommended patching SharePoint, rotating ASP.NET machine keys after a possible intrusion, blocking vulnerable drivers, checking SYSVOL and watching for tunnels, unusual downloads and queries to oastify.com.
Security Affairs said the persistence of the attacks is partly explained by the fact that some organizations still had not applied patches or mitigations for the SharePoint vulnerabilities tied to ToolShell. An independent analysis said the match between Storm-2603 and Longlegs, and the broader link to China, should be treated as moderately confident, so that attribution should not be presented as fully confirmed.
What new victims and figures did the latest coverage add?
The latest coverage added that The Gentlemen brought its campaign to Mexico and to more than two dozen organizations in six countries, including the United States, France, the United Kingdom, India and the United Arab Emirates, according to El Economista. Comparitech also reported that Argentina went from 18 attacks in the second quarter to 45 in the third quarter of 2026, a 150% increase, and placed Qilin and The Gentlemen as the groups with the most claims in the period, with 357 and 342, respectively.
In that same quarterly snapshot, Comparitech said Qilin kept claiming victims outside North America, including South America, while Bitdefender said the group continued registering victims in regions outside North America, including South America. SecPod added that Warlock's recent victims included critical infrastructure organizations in Europe, Africa and Latin America, and said the exploited flaws affect on-premises SharePoint deployments, not SharePoint Online in Microsoft 365.
What technical changes were made to the SharePoint flaws?
PCRisk explained that Microsoft first patched CVE-2025-49704 and CVE-2025-49706 in July 2025, then later assigned CVE-2025-53770 and CVE-2025-53771 to bypasses exploited as zero-days since at least July 18, 2025. The coverage added that Microsoft released emergency updates for SharePoint Server 2016, 2019 and Subscription Edition.
BleepingComputer also said Warlock emerged in June 2025 and gained notoriety for exploiting that ToolShell SharePoint zero-day chain. TechJuice, in an analysis based on Symantec, added that the group is also associated with Gold Salem and gains access through unpatched SharePoint servers, with the ability to collect ASP.NET machine keys from the SharePoint farm.
Sources
- El dato de la ciberseguridad en la era de la IA que enciende alarmas sector empresarialeldestapeweb.com· El Destape
- Cyble Threat Report: August 2026 Hits Record High with 1,034 Global Ransomware Victimscxotoday.com· CxO Today
- Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomwarethehackernews.com· The Hacker News
- Warlock Attackers Abuse Vulnerable Driver to Disable Security Toolscyberpress.org· CyberPress
- Warlock ransomware breach SharePoint in water, telecom operator attacksbleepingcomputer.com· BleepingComputer
- Cyble: Ransomware attacks reach 2026 high in Augustbackendnews.net· Back End News
- Expert Roundtable — October 3, 2026 morninghalilozturkci.com· Halil Öztürkci
- Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructuresecurityaffairs.com· Security Affairs
- Por ciberataques, 31% de las Pymes en Latinoamérica registra pérdidas económicas; Finanzas y TI, las áreas más afectadaseluniversal.com.mx· El Universal
- Warlock Ransomware Hits Large Spanish, Portuguese Orgsdarkreading.com· Dark ReadingUnverified URL
- Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructuresecpod.com· SecPod
- China-Linked Warlock Group Targets SharePoint Serverstechjuice.pk· TechJuice
- 'Warlock' ransomware used in attacks on critical infrastructure organizations in Portuguese- and Spanish-speaking countriestherecord.media· The Record
- Ciberdelincuentes usan IA para atacar con ransomware a una organización mexicanaeleconomista.com.mx· El Economista
- Bitdefender Threat Debrief | October 2026businessinsights.bitdefender.com· Bitdefender
- Warlock Ransomware Hits Water And Telecom Firms Via SharePointpcrisk.com· PCRisk
- Ransomware roundup: Q3 2026 stats on attacks, ransoms, and active gangscomparitech.com· Comparitech



