CiberLATAMbywhalemate

Mexico Ranks Second in Latin America Ransomware

SCILabs logged 290 ransomware attacks in Latin America from January to June 2026. Mexico accounted for 17.93% of cases.

Whalemate Labs · AI-assisted researchPublished:Updated 4 min read

SCILabs recorded 290 ransomware-related attacks in Latin America between January and June 2026, up from 231 cases in the second half of 2025. Mexico accounted for 17.93% of regional incidents, Brazil for 25.17%, and Colombia for 11.03%.

Update September 14, 2026: SCILabs expanded its first-half 2026 summary with sector breakdowns, initial access vectors, and a ranking of the most active ransomware variants in the region. The full report will also be released after an official webinar on September 30, 2026.

SCILabs reported 290 ransomware-related attacks in Latin America between January and June 2026, up from 231 cases in the second half of 2025. That comparison represents a 25.5% increase, according to coverage based on the report. During that period, Mexico accounted for 17.93% of regional incidents, Brazil for 25.17%, and Colombia for 11.03%.

What did the SCILabs report show?

The report showed ransomware activity in the region rose during the first half of 2026. Coverage citing SCILabs puts the total at 290 attacks in Latin America, versus 231 in the second half of 2025, an increase of 25.5%, or 25.54%, according to the reference note.

Beyond the jump in total volume, the research identified 50 different ransomware variants active in the region during that half-year. That broadens the picture, because it points not only to more incidents, but also to a wider mix of families and strains in circulation.

Which countries had the most incidents?

Brazil, Mexico, and Colombia accounted for most of the cases SCILabs tracked in Latin America. Based on the coverage tied to the report, Brazil represented 25.17% of incidents, Mexico 17.93%, and Colombia 11.03%.

The same coverage places Mexico as the region's second most affected country. The figure also appears in El Destape Web's reporting, which drew on the same SCILabs report and said attacks in Latin America rose 25.5%, with Mexico accounting for a significant share of that activity.

Country Share of incidents Source
Brazil 25.17% Coverage based on SCILabs, Unotv
Mexico 17.93% Coverage based on SCILabs, Unotv
Colombia 11.03% Coverage based on SCILabs, Unotv

Which sectors were hit hardest?

The hardest-hit sectors in the region were services, government, and manufacturing, according to available coverage of the SCILabs report. Services accounted for 19.66% of attacks, government for 11.72%, and manufacturing for 8.28%.

That sector breakdown adds another layer to the geographic picture. It shows not only which countries saw the most activity, but also where ransomware groups concentrated a meaningful share of their operational pressure during the semester.

Sector Share of incidents Source
Services 19.66% El Destape Web
Government 11.72% El Destape Web
Manufacturing 8.28% El Destape Web

Which variants led the activity?

The Gentlemen was the most active variant in Latin America with at least 49 attacks, followed by Qilin with 46 and LockBit 5.0 with 43, according to the coverage citing SCILabs. The ranking places those three families at the top of the activity observed during the semester.

The mention of these variants also fits other recent industry reports. ZeroFox and Arete placed them among the most active operators worldwide during the same period, although without Colombia-specific breakdowns. ZeroFox also recorded Qilin with at least 1,480 global incidents between September 2025 and August 2026, ahead of the 767 attributed to The Gentlemen.

Variant Attacks Source
The Gentlemen 49 El Destape Web
Qilin 46 El Destape Web
LockBit 5.0 43 El Destape Web

How did the attackers get in?

The most commonly used entry vectors included vulnerabilities in internet-exposed infrastructure, credential theft, phishing campaigns, and the purchase of access in underground markets, according to available coverage of SCILabs. That pattern matches the standard intrusion techniques used before encryption or extortion.

The reference to those initial access methods helps explain why the report did more than measure incident volume. It also describes how operators gained the foothold needed to launch their campaigns across the region during the semester.

When will the full report be released?

Scitum and SCILabs said the full ransomware report for Latin America covering the first half of 2026 will be released after an official webinar scheduled for September 30, 2026. Until then, the published notes rely on an executive summary for the media.

The official communication says the event is titled "Ransomware Report in LATAM, First Half of 2026." Once the webinar ends, attendees will be able to download the full report, confirming that the information available so far does not yet come from the complete document.

Sources

View all