CiberLATAMbywhalemate
Intelligence report

Bolivia Cybersecurity Status, August 2026

Bolivia logged 59 verified events, including 1 ransomware case, 2 frauds, and 6 regulatory moves, with focus on insurance

Sep 1, 202618 min read
Bolivia Cybersecurity Status, August 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are filled automatically with verified dated facts within the period. Each one states its basis and counting criterion so the figures can be reconciled across modules. They are the recurring month-to-month readout; the later analysis expands on the cases without repeating this summary.

Indicator window: 59 dated facts in August 2026 · 2 after the period (excluded). Facts from earlier months are used only as comparative context in the analysis, never as part of this period’s volume.

CIBERLATAM / WHALEMATE Verified Signal Monthly Panel August 2026 · Bolivia Predominant threat: Unclassified (29 of 59 events). Coverage: 59 events dated in August 2026 · 2 later… VERIFIED EVENTS 59 period base: all counts measured from below over this total RANSOMWARE / EXTORTION 11 2 mentioned only on leak site · 9 cannot be determined with the material UNCLASSIFIED INCIDENTS 11 breaches or outages without declared threat type FRAUD / PHISHING 2 documented fraud campaigns REGULATION 6 rules, rulings, or penalties UNIQUE CVEs 0 none in the material reviewed (does not imply absence in the region)
Verified Signal Monthly Panel — Base: 59 verified events dated within the period for Bolivia.
MONTHLY FIXED MODULE Threat-axis distribution August 2026 · Bolivia Each event counts on only one axis, so the total is exactly 59. "Unclassified incidents" is the remainder. Unclassified 29 Ransomware 11 Incidents 11 Regulation 6 Fraud 2
Threat-axis distribution — Each event is assigned to a single axis based on its classification; the total reconciles to 59 events in the period.
FIXED MONTHLY MODULE Sector Breakdown of Signals August 2026 · Bolivia Base: 59 incidents in the period · total 70 because 10 incidents were classified in more than one sector. Public sector / OIV 31 Other / no sector ident… 16 Telecom 12 Finance 10 Retail / Consumer 1
Sector Breakdown of Signals — Heuristic sector classification by victim. One incident may affect more than one sector, so the total can exceed the base.
MONTHLY FIXED MODULE Critical Infrastructure in Bolivia August 2026 · Bolivia 12 of 59 facts in the period involve critical infrastructure. One fact may appear in more than one category. Public sector / government 31 Explicit critical infrastructure 2 Telecom / connectivity 12
Critical Infrastructure in Bolivia — Verified facts on public sector, utilities, and essential services

Monthly executive summary for Bolivia

August 2026 produced 59 verified cybersecurity and compliance incidents in Bolivia, with the month dominated by unclassified material, a ransomware case against an insurer, two documented frauds, and six regulatory moves. Activity was driven more by institutions than confirmed technical incidents, with attention centered on taxes, financial oversight, and the expansion of response capabilities.

The clearest offensive incident was the attribution to Qilin of the attack against Consultores de Seguros, a Bolivian insurance firm. Available material confirms the claim and the threat to publish data, but it does not allow a precise determination of whether there was asset encryption, prior exfiltration, or only a mention on a leak site. In parallel, the Central Bank of Bolivia reported a scam involving fake loans with QR codes and misuse of its institutional image.

On the defensive side, SIN moved ahead with mandatory two-factor authentication for the Tax Virtual Office and activated dedicated support channels for users. At the same time, ENTEL, AGETIC, and ATT pushed Bolivia Cibersegura 2026 and the strengthening of CSIRT Bolivia, with a promised national and sector-specific structure for prevention, detection, response, and recovery.

The month's risk reading is medium. There is no evidence of a wave of critical intrusions, but there is a diverse exposure surface, pressure on the financial sector, active regulatory debate, and signs of operational sophistication in fraud and extortion campaigns. The absence of any critical CVEs mentioned in the material does not mean there was no exploitation in the region, only that none appeared in this corpus.

Bolivia’s national landscape in August

Bolivia closed August with a more concentrated agenda on digital government, oversight and prevention than on confirmed destructive incidents. The dominant signal was scattered but consistent across three fronts, regulatory modernization, tighter access to public systems, and episodes of fraud or extortion targeting visible entities. That leaves the month with moderate risk, more institutional than explosive.

Most of the activity centered on the state and financial sphere. The SIN defended 2FA as a global cybersecurity standard, the UIF advanced its narrative of leaving the FATF gray list, and the APS discussed supervisory modernization with the IDB. Taken together, those developments point to an ecosystem where compliance, transparency and protection of digital assets are starting to gain traction, although there is still no consolidated comprehensive personal data framework.

Bolivia, August 2026Most visible milestones of the monthSIN without2FA enabledCSIRTBoliviaBCB reports QRfraudQilinand InsuranceAug 05Aug 20Aug 19Aug 24
Bolivia, August 2026, cybersecurity milestones — A brief timeline of the month’s most visible events, focused on public defense, fraud, and ransomware.

There were also signs of operational pressure on the digital environment. The discovery of a mini bot farm tied to the Cerimedo case showed infrastructure for manipulation on social media and disinformation, while the BCB complaint about fake credit brokers using QR codes confirmed that digital fraud continues to adapt to mass usage habits. These are different events, but they point to the same weakness, user trust and the use of digital channels as a vector for deception.

In the regional context, Bolivia does not appear isolated. August across Latin America combined ransomware campaigns, payment fraud and regulatory debates on data and AI. Within that frame, Bolivia sat closer to the governance and response layer than to a documented spike in technical exploitation, although the Qilin case is a reminder that the insurance sector was exposed as well.

Indicators for the period in Bolivia

Indicator August 2026 Previous month Change
Verified events in the period (base for all indicators) 59 92 -33
Indicator time window 59 events dated August 2026 · 2 after the period (excluded) 92 events dated July 2026 · 0 after the period (per previous report) N/A
Unclassified incidents (breaches or disruptions) 11 17 -6
Cases with ransomware or extortion as the primary focus 11 20 -9
Ransomware breakdown by impact type, leak site mention only 2 N/A N/A
Ransomware breakdown by impact type, impact cannot be determined from the material 9 N/A N/A
Documented fraud or phishing cases 2 15 -13
Documented regulatory moves 6 13 -7
Critical CVEs mentioned 0 N/A N/A
Sectors with at least one documented event 4 7 -3
Predominant threat for the month Unclassified (29 of 59 events) Unclassified (25 of 92 events) N/A
Events with direct source confirmation 71% N/A N/A
Sectors with documented activityBolivia, August 2026, 4 sectors with at least one incidentFinance and insuranceGovernment and taxTelecom and CSIRTPolitical and mediaVisible risk, not a mutually exclusive totalThe same incident may affect more than one sector
Sector distribution visible in Bolivia — Sectors with at least one documented incident during August 2026, excluding overlaps such as mutually exclusive totals.

Relevant incidents in Bolivia

Insurance consultants and the Qilin attribution

The most significant offensive event of the month was the attribution of an attack against Consultores de Seguros, a Bolivian insurance firm, to Qilin. The material confirms that the case appeared on intelligence and leak tracking sites, but it does not clarify whether there was operational encryption, prior exfiltration, or only a claim on the extortion site.

Sources agree that the company’s name appeared in the group’s leak ecosystem and that Qilin threatened to release sensitive data. BreachSense, HookPhish, ransomware.live, HackerFeeds, GalaxyWarden, RecentBreaches and DeXpose provide traceability for the case, although not independent validation from the victim. That leaves the incident in the category of a leak site mention only, or an undetermined classification based on the available material.

Fake loans using QR codes and the BCB brand

The Central Bank of Bolivia filed criminal charges against alleged scammers who used its name and visual identity to offer fake loans through social media and messaging apps. The scheme included WhatsApp and Telegram messages, deposit requests through QR codes, and the use of forged documents to make the operation seem credible.

The significance of the case lies not only in the fraud itself, but also in the abuse of institutional legitimacy. The BCB said it does not grant loans to private individuals or manage individual accounts, and warned the public about investment or financing offers made in its name. It also said there are signs of similar cases in other parts of the country, although the criminal case cited by the press was filed in Cochabamba.

Mini bot farm in the Cerimedo case

Bolivia’s Public Prosecutor’s Office reported the discovery of a mini bot farm during searches in La Paz linked to Argentine political consultant Fernando Cerimedo. The operation description included equipment, automated infrastructure, and significant amounts of cash, dollars and euros.

This episode does not fit a classic breach or ransomware case, but it does point to manipulation of the digital ecosystem. The coverage cited describes the case as part of a criminal investigation for illicit enrichment and, at the same time, as a possible coordinated social media operation structure. The material does not link this finding to a corporate cybersecurity incident, but it does connect it to disinformation and the abusive use of digital infrastructure.

Strengthening CSIRT Bolivia

ENTEL, AGETIC and ATT promoted Bolivia Cibersegura 2026 with the goal of strengthening CSIRT Bolivia and coordinating national capabilities for prevention, detection, response and recovery. The event brought together public institutions, critical infrastructure operators and international specialists.

Although it is not an incident, the signal is relevant because it shows operational prioritization. AGETIC later said the program ended successfully and that the Computer Incident Management Center continues to operate as the national CSIRT. In terms of defensive posture, it is one of the few facts of the month with clear institutional continuity.

Threats and active campaigns in Bolivia

Ransomware and extortion, Consultores de Seguros

The only ransomware or extortion case clearly attributed in August was Consultores de Seguros, linked to Qilin. The material does not allow a determination of whether there was confirmed encryption, exfiltration without encryption, or only a mention on a leak site, so the operational classification remains open.

The strongest signal is the victim’s appearance in trackers and sites in the extortion ecosystem. That includes BreachSense, ransomware.live, HookPhish, RecentBreaches, GalaxyWarden, and HackerFeeds. In all cases, the company’s level of public confirmation does not appear in the material, and the claim still depends on the group’s post or intelligence aggregators.

Fraud and phishing, fake BCB managers

The documented fraud this month centered on impersonating the Central Bank of Bolivia to offer fake loans. The case combined social engineering, QR codes, and instant messaging, with an institutional authority narrative designed to speed up deposits and capture personal data.

There was no second phishing case with the same level of detail in the material. The operational relevance lies in the pattern, because this type of fraud relies on preexisting trust and everyday channels. The BCB responded with a criminal complaint and a public warning, which makes the incident a useful signal for the financial system and for anti-fraud teams.

APT, hacktivism, and disinformation operations, mini bot farm

The Cerimedo case was not presented as a classic APT, but as a structured digital operation that merits monitoring in the disinformation and automation abuse category. Public evidence points to a mini bot farm, seized devices for forensic review, and resources tied to political campaigns on social media.

For Bolivia, this matters because it shifts attention away from technical intrusion and toward manipulation of public conversation. There is no attribution to a state actor or a confirmed intrusion chain, so the incident should be read as hacktivism or organized disinformation only in the broad sense, not as proven cyberespionage.

Critical vulnerabilities with impact in Bolivia

No critical CVEs were reported in the material reviewed for August 2026. Their absence in this table means that no critically exploited or verifiably referenced vulnerabilities appeared in the month’s corpus, not that none exist in the region.

CVE Software Exploitation Source
N/A N/A No critical CVEs were identified in the material reviewed N/A

Regulation and compliance in Bolivia

August was more active on regulation than on signs of technical exploitation. The central development was the Senate’s approval of Bill No. 066/2025-2026 on Access to Information, which moved to the Chamber of Deputies. That came alongside progress by the UIF with the FATF, debates on AI and investments, and targeted measures from the SIN on digital security.

Access to Information law and state openness

The Chamber of Senators approved the Access to Information bill and sent the initiative to the Chamber of Deputies. The proposal establishes that information held by the state will be public as a general rule and that anyone may request it without having to justify their reasons.

The debate was not only procedural. Soledad Chapetón explained that the law would cover state institutions, public companies, public universities, and other entities that manage public resources. Civil society organizations and the press pushed the discussion so the process would be simple and accessible, and asked for Articles 8 and 9 to be reviewed because of possible bureaucratic barriers.

Two-factor authentication at the SIN and taxpayer support

The SIN rolled out two-factor authentication for the Virtual Tax Office and for the Linked Third Parties function. The agency said the mechanism follows global cybersecurity standards and is designed to protect taxpayers’ information and assets.

The institutional response included support channels, a toll-free line, and operational recommendations such as checking the registered email account, the spam folder, and inbox availability. ABI reported that only 1% of users experienced difficulties. Beyond that friction point, the month’s message was clear, Bolivia’s tax system moved toward stronger authentication.

UIF, FATF, and financial oversight

The UIF said Bolivia is close to leaving the FATF gray list after making progress in fixing deficiencies related to money laundering and terrorist financing. The material places that progress within reinforced monitoring since June 2025.

That context was tempered by an El Día report citing Fundación Milenio and recalling structural problems tied to organized crime and institutional capture. The contrast is useful, regulatory improvement is real, but it is taking place on still-fragile ground. In parallel, the APS and the BID promoted practices to strengthen financial consumer protection and modernize supervision with a preventive approach.

AI, investment, and the technology agenda

The regulatory ecosystem also moved around artificial intelligence. There were references to AI-related bills in the Chamber of Deputies and to an official investment proposal that places it among priority sectors. This is not yet a comprehensive personal data law or a closed regulatory framework, but rather a work in progress.

A specialized analysis also noted that Bolivia lacks a comprehensive personal data protection law and that privacy is handled mainly through constitutional action. That fits the rest of the month, there is an intention to bring order to the digital space, but there is still no integrated legislative piece that closes the gap.

Most affected sectors in Bolivia

The financial and insurance sector drew the most attention, though not necessarily the most serious technical impact. It included the Consultores de Seguros case, the BCB complaint over fake loans, the debate over digital payments, and regulatory signals from the APS, the UIF and the BID. It is the sector where extortion, fraud, compliance and user trust intersect.

The second major front was the state and tax sphere. The SIN was central, with the rollout of 2FA, support channels and the logic behind protecting access to the Virtual Office. At the same time, the debate over access to information and draft regulations on AI reinforced the idea of a public administration that is more digital and more exposed at the same time.

The third axis was telecommunications and digital infrastructure, with ENTEL, AGETIC and ATT pushing CSIRT Bolivia and Bolivia Cibersegura 2026. That does not imply massive incidents in that sector, but it does signal a structural role. The fourth visible area was the political and media environment, marked by the mini bot farm linked to the Cerimedo case, which opened a debate about automation, manipulation and influence operations.

Compared with July, August showed fewer verified incidents, fewer unclassified incidents, less ransomware, and less documented fraud or phishing. Regulatory activity also slowed, as did the number of sectors touched by the signal, but the dominant threat remained the same: unclassified. That points to lower volume, not necessarily less complexity.

The drop in documented fraud, from 15 in the previous month to 2 in August, should not be read as evidence the problem is over. In this corpus, there is only one particularly well-documented case, the fake BCB loans, while most of the monthly signal was concentrated in regulation and defensive posture. The deception surface is still active, it just appears less often in the captured material.

The ransomware trend is even more clearly down. The previous month recorded 20 cases with ransomware or extortion as the primary focus, and August had 11. However, this month’s material is heavily concentrated in one strong case, Consultores de Seguros, with the rest spread across trackers and intelligence sources. The lower volume does not erase the value of the case, because it confirms that the insurance sector is also on the pressure list.

The regulatory line deserves close attention because Bolivia is trying to bring several fronts into order at once. If the access to information bill moves forward in the Chamber of Deputies, if the SIN’s 2FA continues to gain adoption, and if the UIF keeps making progress with the FATF, the country could enter a phase of greater procedural maturity. The risk is that regulatory speed does not always translate into equivalent technical capability.

Recommendations for security teams in Bolivia

Review authentication and access policies immediately, especially in taxpayer portals, financial systems, and any service that relies on email as a second factor. The SIN case shows that 2FA is no longer optional in the public agenda, and that it also needs operational support so legitimate users do not see a worse experience.

Strengthen anti-fraud controls on messaging channels and social media. The BCB incident confirms that institutional brand impersonation remains effective when it combines QR codes, time pressure, and loan promises. Mentions, fake accounts, and suspicious payment flows should be monitored with the same priority as a technical alert.

For insurers and financial players, review exposure to reused credentials and exposed access across breach ecosystems. The Consultores de Seguros case shows that a presence on extortion sites can be preceded by credential accumulation or by public visibility of domains and accounts. Identity hygiene and privilege segmentation are the first line of defense.

For public institutions and critical operators, consolidate procedures with CSIRT and clear escalation paths. Bolivia Cibersegura 2026 and the role of AGETIC suggest the country is trying to formalize that layer. If teams do not have tested playbooks, national coordination takes too long once the incident has already become a crisis.

Frequently Asked Questions

What mix of events drove the most visible risk in Bolivia this month?

In August, a ransomware case against Consultores de Seguros, a fake credit scam using QR codes tied to misuse of the BCB brand, and the strengthening of CSIRT Bolivia all unfolded at the same time. Taken together, they point to pressure on finance, user fraud, and institutional response.

Did the Consultores de Seguros case involve encryption, data theft, or only exposure on a leak site?

The available material does not allow that to be determined precisely. The sources confirm attribution to Qilin and the threat to disclose data, but they do not clarify whether there was encryption, exfiltration without encryption, or only a mention on leak sites. The threats section draws that distinction.

What regulatory signals this month affect sectors beyond finance?

Along with progress on the Access to Information Law, SIN strengthened digital authentication, and ENTEL, AGETIC and ATT promoted Bolivia Cibersegura 2026 with a focus on CSIRT. That reaches the state, telecoms and critical infrastructure, not just banks or insurers.

Why does the absence of critical CVEs not mean there is no technical risk?

Because the 0 indicator only reflects that no critical CVEs appeared in the August material analyzed. It does not mean there were no exploited vulnerabilities in the region. The vulnerabilities section and the limitations section explain that distinction so coverage is not confused with operational reality.

Which sectors should prioritize measures over the next month?

Finance and insurance, because of the Qilin case and the BCB fraud, and the public sector as well, because of the rollout of 2FA at SIN and the access to information agenda. Telecoms and digital infrastructure should maintain coordination with CSIRT and response testing.

Material limitations

This report was built exclusively from the material provided for Bolivia, August 2026, and uses only facts dated within that window to calculate indicators. Two facts dated after the period were excluded, and aggregated telemetry was not included because this is not an incident count.

A value of 0 for any indicator, especially the critical CVEs mentioned, means it did not appear in this month’s analyzed material, not that no critical vulnerabilities were exploited in the region. The same applies to categories that could not be recorded with operational precision, such as some ransomware or extortion cases.

Consumer social media posts and sponsored or promotional pieces were also left out as primary evidence, even if some were referenced in the research material. When blog or aggregator content was cited, it was used only to describe what those sources claimed and not as independent confirmation. Facts without a confirmed date were excluded from the counts, although in this corpus it was not necessary to rely on them for the month’s indicators.

Sources