
Chile and Guatemala hospitals hit by ransomware
Direwolf posted Chile’s Hospital Clínico Universidad de Chile and Guatemala’s Incán. The Guatemala case disrupted radiotherapy for 194 patients.
Sep 5, 2026 · 2 min
Up-to-date cyber intelligence coverage. Filter by category or browse the full archive.

Direwolf posted Chile’s Hospital Clínico Universidad de Chile and Guatemala’s Incán. The Guatemala case disrupted radiotherapy for 194 patients.
Sep 5, 2026 · 2 min

Unit 42 found active campaigns against transport, government, water and finance in Mexico, Ecuador
Sep 5, 2026 · 3 min

KRYBIT, EMPERADOR, THEGENTLEMEN and INCRANSOM added victims in Mexico and the United States, with signs of regional expansion.
Sep 4, 2026 · 3 min

Security Arsenal logged 16 THEGENTLEMEN victims in 24 hours, with cases in Mexico, Brazil and Argentina and 31% in Latin America.
Sep 4, 2026 · 2 min

Greenberg Traurig appeared in multiple leak posts, but there is no official verification of a breach or of who was behind it.
Sep 4, 2026 · 2 min

In Colombia, 71% faced at least one fraud attempt in the past year, and 82% say these cases are increasing.
Sep 3, 2026 · 3 min

Experian found 73.5% of Peruvians faced at least one digital fraud attempt and 88% say these attacks have increased.
Sep 3, 2026 · 4 min

MITIC warned about a fake Portal Paraguay site targeting Tekoporã users for personal data. The Banco Atlas case also remains active.
Sep 3, 2026 · 3 min

Criminals are using Chilean RUT numbers to block bank accounts, impersonate bank staff and steal verification codes.
Sep 3, 2026 · 2 min

BREEZE COMET is hitting financial and payments firms in Brazil and running hundreds of fraudulent transactions in 24 to 48 hour bursts.
Sep 3, 2026 · 5 min

The Justice Department said several named agencies were targets, not confirmed victims, in a campaign attributed to QTFY.
Sep 3, 2026 · 3 min

KRYBIT, LOCKBIT5, and INC Ransom added new victims, with most activity centered on the United States and fresh listings in 48 and 24 hours.
Sep 2, 2026 · 3 min

KRYBIT named 13 victims in 48 hours, including cases in Brazil and Guatemala. Health, agriculture, retail and finance were among the targets.
Sep 2, 2026 · 3 min

Brazil's Oportunidados was listed on Direwolf's leak site, according to ransomware trackers and a threat intelligence alert.
Sep 2, 2026 · 2 min

CronUp Ciberseguridad added Sanatorio Modelo de Caseros to a list of Qilin victims, with an attack date of 08-26-2026.
Sep 1, 2026 · 3 min

Security Arsenal linked new victims to CHAOS, DragonForce, KRYBIT, STORM and GLOBAL SECRET GROUP, including cases in the U.S.
Aug 31, 2026 · 3 min

Darkfield, RecentBreaches and Hackmanac added more records on the Hospital Clínico Universidad de Chile case, still unconfirmed.
Aug 31, 2026 · 4 min

Local coverage says Paraguayan cooperatives are emerging from a ransomware attack, with more than 9 million records exposed online.
Aug 30, 2026 · 2 min

Gaspar said complaints of impersonation, phishing and account theft are rising in Paraguay, with more than 9 million data records exposed.
Aug 30, 2026 · 2 min

Banks and users in Latin America face impersonation, deepfakes and caller ID spoofing, with fraud attempts and official alerts.
Aug 30, 2026 · 3 min

San Luis Potosí City Hall reported 2.9 GB of data theft and an extortion attempt to get it back. The mayor said no deal was made.
Aug 29, 2026 · 3 min

Frato, neooftalmo.com.br and sysconth.com appear among new DragonForce and KRYBIT victims, with outside checks refining the claims.
Aug 29, 2026 · 3 min

A joint FBI, CISA and HHS notice says Medusa has hit more than 500 victims since 2021, with healthcare a frequent target.
Aug 28, 2026 · 3 min

Qilin claimed Chilean tech firm Difor. Incident trackers list it as a victim with an estimated attack date of Aug. 23, 2026.
Aug 28, 2026 · 2 min

Kazu listed OSI and Brazil’s Mobilemed as victims, but public confirmation of the attacks remains limited.
Aug 28, 2026 · 3 min

ATF said an isolated system was affected and reported no signs of impact to eForms, its corporate network or other systems.
Aug 28, 2026 · 3 min

AA26-237A details two red team tests against U.S. critical infrastructure and finds gaps in phishing and Active Directory defenses.
Aug 27, 2026 · 3 min

CoinbaseCartel, Storm, Qilin, DragonForce and SilentRansomGroup posted new victims in the US and Canada across health, finance
Aug 27, 2026 · 4 min

DragonForce added Criba and Frato, KRYBIT added cases in Brazil and Guatemala, and CoinbaseCartel also posted Flecha Bus.
Aug 27, 2026 · 4 min

EsSalud reported five unauthorized transfers totaling S/1,406,991 in Lambayeque and asked banks to freeze the recipient accounts.
Aug 26, 2026 · 2 min

Zimperium found ToxicPanda 2.0, an Android variant expanding to more than 140 banking and crypto apps across 16 countries.
Aug 26, 2026 · 2 min

INCRANSOM, THEGENTLEMEN, METAENCRYPTOR and EVEREST added victims in the U.S. across health, finance, technology
Aug 25, 2026 · 3 min

CISA expanded its alert on Siemens S7 PLCs and said more than 100 water systems were hit in July, with limited but real impacts.
Aug 24, 2026 · 4 min

Prosecutors asked Tolima authorities, police and the army to report measures to protect the power grid after alleged attacks on transmission assets.
Aug 24, 2026 · 2 min

LATAM confirmed a LATAM Pass incident in Brazil that exposed member data. The company said it contained the event and notified Brazil’s ANPD.
Aug 24, 2026 · 2 min

Emperador claims an attack on Arcos city hall in Brazil. The case remains unverified, with no public confirmation from the municipality.
Aug 23, 2026 · 2 min

Breachsense flagged amca.org.ar as a BLACKWATER victim on Aug. 17, 2026. Security Arsenal also cited it among two new leak-site victims.
Aug 23, 2026 · 3 min

FBI, CISA and HHS updated their Medusa alert, saying the group has hit more than 500 victims and kept targeting US health care.
Aug 22, 2026 · 2 min

Ransomware hit Colombia’s Justice Ministry, while Grandoreiro resurfaced in Mexico, with detections also reported in Peru
Aug 22, 2026 · 2 min

Quaker State Mexico appeared in a Qilin-attributed listing, with no independent public confirmation of a breach or data theft.
Aug 22, 2026 · 2 min

Threat reports place Colombia among recent ransomware victims, while F5 and Security Arsenal also flagged related activity.
Aug 21, 2026 · 3 min

ransomware.live lists 83 Peru-linked victims, without attribution to any group. VECERT also reported unconfirmed activity.
Aug 21, 2026 · 2 min

Kaspersky attributed attacks on manufacturing, health, tech, finance, construction and logistics to The Gentlemen, with activity confirmed in Argentina.
Aug 21, 2026 · 3 min

Ransomware.live and Breachsense list mecasem.org as a 3AM victim. GalaxyWarden says there is no public confirmation from the company.
Aug 21, 2026 · 2 min

Security Arsenal tracked new U.S. victims from DIREWOLF, COINBASECARTEL and XPL0ITRS across health, tech and professional services.
Aug 19, 2026 · 2 min

Brazil’s Arcos city hall appears on a leak site tied to Emperador, but the claim has not been independently verified.
Aug 19, 2026 · 2 min

Bitdefender’s August 2026 threat debrief placed Argentina among The Gentlemen’s victims as the ransomware group pushed deeper into manufacturing.
Aug 17, 2026 · 3 min

Bitdefender logged 21 claimed ransomware victims in Argentina in July, with The Gentlemen, Qilin and DragonForce among active groups.
Aug 17, 2026 · 3 min

US agencies warned on Gunra, while Unlimited Technology Systems raised its breach tally to 3.8 million patients.
Aug 16, 2026 · 3 min

Colombia’s Justice Ministry confirmed ransomware hit part of its infrastructure. No data theft was detected, and recovery is ongoing.
Aug 16, 2026 · 3 min