Mexico Ranks Second in Latin America Ransomware
SCILabs logged 290 ransomware attacks in Latin America from January to June 2026. Mexico accounted for 17.93% of cases.
SCILabs recorded 290 ransomware-related attacks in Latin America between January and June 2026, up from 231 cases in the second half of 2025. Mexico accounted for 17.93% of regional incidents, Brazil for 25.17%, and Colombia for 11.03%.
Update September 14, 2026: SCILabs expanded its first-half 2026 summary with sector breakdowns, initial access vectors, and a ranking of the most active ransomware variants in the region. The full report will also be released after an official webinar on September 30, 2026.
SCILabs reported 290 ransomware-related attacks in Latin America between January and June 2026, up from 231 cases in the second half of 2025. That comparison represents a 25.5% increase, according to coverage based on the report. During that period, Mexico accounted for 17.93% of regional incidents, Brazil for 25.17%, and Colombia for 11.03%.
What did the SCILabs report show?
The report showed ransomware activity in the region rose during the first half of 2026. Coverage citing SCILabs puts the total at 290 attacks in Latin America, versus 231 in the second half of 2025, an increase of 25.5%, or 25.54%, according to the reference note.
Beyond the jump in total volume, the research identified 50 different ransomware variants active in the region during that half-year. That broadens the picture, because it points not only to more incidents, but also to a wider mix of families and strains in circulation.
Which countries had the most incidents?
Brazil, Mexico, and Colombia accounted for most of the cases SCILabs tracked in Latin America. Based on the coverage tied to the report, Brazil represented 25.17% of incidents, Mexico 17.93%, and Colombia 11.03%.
The same coverage places Mexico as the region's second most affected country. The figure also appears in El Destape Web's reporting, which drew on the same SCILabs report and said attacks in Latin America rose 25.5%, with Mexico accounting for a significant share of that activity.
| Country | Share of incidents | Source |
|---|---|---|
| Brazil | 25.17% | Coverage based on SCILabs, Unotv |
| Mexico | 17.93% | Coverage based on SCILabs, Unotv |
| Colombia | 11.03% | Coverage based on SCILabs, Unotv |
Which sectors were hit hardest?
The hardest-hit sectors in the region were services, government, and manufacturing, according to available coverage of the SCILabs report. Services accounted for 19.66% of attacks, government for 11.72%, and manufacturing for 8.28%.
That sector breakdown adds another layer to the geographic picture. It shows not only which countries saw the most activity, but also where ransomware groups concentrated a meaningful share of their operational pressure during the semester.
| Sector | Share of incidents | Source |
|---|---|---|
| Services | 19.66% | El Destape Web |
| Government | 11.72% | El Destape Web |
| Manufacturing | 8.28% | El Destape Web |
Which variants led the activity?
The Gentlemen was the most active variant in Latin America with at least 49 attacks, followed by Qilin with 46 and LockBit 5.0 with 43, according to the coverage citing SCILabs. The ranking places those three families at the top of the activity observed during the semester.
The mention of these variants also fits other recent industry reports. ZeroFox and Arete placed them among the most active operators worldwide during the same period, although without Colombia-specific breakdowns. ZeroFox also recorded Qilin with at least 1,480 global incidents between September 2025 and August 2026, ahead of the 767 attributed to The Gentlemen.
| Variant | Attacks | Source |
|---|---|---|
| The Gentlemen | 49 | El Destape Web |
| Qilin | 46 | El Destape Web |
| LockBit 5.0 | 43 | El Destape Web |
How did the attackers get in?
The most commonly used entry vectors included vulnerabilities in internet-exposed infrastructure, credential theft, phishing campaigns, and the purchase of access in underground markets, according to available coverage of SCILabs. That pattern matches the standard intrusion techniques used before encryption or extortion.
The reference to those initial access methods helps explain why the report did more than measure incident volume. It also describes how operators gained the foothold needed to launch their campaigns across the region during the semester.
When will the full report be released?
Scitum and SCILabs said the full ransomware report for Latin America covering the first half of 2026 will be released after an official webinar scheduled for September 30, 2026. Until then, the published notes rely on an executive summary for the media.
The official communication says the event is titled "Ransomware Report in LATAM, First Half of 2026." Once the webinar ends, attendees will be able to download the full report, confirming that the information available so far does not yet come from the complete document.
Sources
- México concentra el 18% de los ataques de ransomware en ...imagenradio.com.mx· Imagen Radio
- Flash Report: Qilin Claims Record Number of Monthly Attacks for 2026zerofox.com· ZeroFox
- Ransomware Trends & Data Insights: August 2026areteir.com· Arete
- México, segundo lugar en ataques de ransomware en Latinoaméricaunotv.com· Unotv
- Alerta por ciberseguridad: crecen un 25% los ataques con secuestro de información y revelan cuáles son los países más afectadoseldestapeweb.com· El Destape Web
- August 2026 Ransomware Wrap-Upzerofox.com· ZeroFox
- Participa en el webinar Reporte de Ransomware en LATAM – 1er semestre de 2026x.com· Scitum



