Uruguay appears in Section9 ransomware case
Breach House lists a .com.uy domain as a claimed Section9 attack, but there is no public confirmation from the victim
Breach House logged a ransomware attack attributed to Section9 against the domain ********.com.uy, with Uruguay linked to the victim, but there is no public confirmation from the affected organization or Uruguayan authorities.
A Section9 case without official confirmation
Breach House logged a ransomware attack attributed to the Section9 group against the domain ********.com.uy. In that post, the case is tied to Uruguay and labeled a "ransomware attack claimed," meaning it is an attack claimed by the leak site operator, not publicly confirmed by the affected organization or by Uruguayan authorities.
The reference also appears on Recentbreaches, which says ********.com.uy was listed by Section9 on July 26, 2026. That portal describes the alleged theft of internal files and presents the episode as a "data breach" linked to Uruguay, although it still does not specify whether the target was a municipality or a local government entity, and it does not provide official validation of the incident.
What the public records show
In the public view on ransomware.live, the entry "Victim: ********.com.uy, Section9" and the "Country statistics" for Uruguay show that the country has 19 victims associated with its ransomware map. That metric, however, does not break down how much of that total corresponds to national government entities, municipalities, or other local public bodies.
Based on the available information, the case remains more a publication on leak sites than a corroborated incident involving the parties named. The material provided also does not include statements from CERTuy, AGESIC, or the alleged victim that would confirm who was affected or the scope of the intrusion.
CERTuy's documentation on information security incident statistics for the first half of the year, along with AGESIC's institutional access, provides a framework for placing the episode within the country's cyber response and digital governance ecosystem, but the material received does not include data linking those records to a confirmed attack on a municipality or a local government agency.
What does Recentbreaches indicate?
Recentbreaches also lists the domain ********.com.uy as a case attributed by Section9. That mention reinforces that this is a leak site publication, not an official confirmation of the incident.
In the available material, the portal places the alleged intrusion in Uruguay and says internal files were exfiltrated, but it does not identify the victim by name or provide validation from authorities. For that reason, the report remains in the realm of public attribution, not a corroborated incident.
Sources
- ********.com.uy — Section9 Ransomware Attackbreach.house· Breach House
- Estadísticas de incidentes de seguridad de la información – Primer semestregub.uy· Centro Nacional de Respuesta a Incidentes de Seguridad Informática (CERTuy)
- Agencia de Gobierno Electrónico y Sociedad de la Información y del Conocimientogub.uy· Agencia de Gobierno Electrónico y Sociedad de la Información y del Conocimiento (AGESIC)
- ********.com.uy Data Breach (2026) — What Leaked & Am I Affected?recentbreaches.com· Recentbreaches
- Country statistics – Uruguaymobile.ransomware.live· ransomware.live



