CiberLATAMbywhalemate
Intelligence report

Brazil: cybersecurity landscape, June 2026

Brazil closed June with a massive false alert, 15 ransomware cases, and 6 regulatory moves amid high public pressure.

Jul 28, 202616 min read
Brazil: cybersecurity landscape, June 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are automatically filled with verified dated facts within the period. Each one states its basis and counting criterion, so the figures reconcile across modules. This is the recurring month-by-month reading; the analysis that follows develops the cases without repeating this summary.

Indicator window: 67 dated facts in June 2026 · 1 without confirmed date (excluded from the indicators). Facts from previous months are used only as comparative context in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Verified Signal Monthly Dashboard June 2026 · Brazil Top threat: Incidents (25 of 67 events). Coverage: 67 dated events in June 2026 · 1 undated confir… VERIFIED EVENTS 67 period baseline: all counts measured from below on this total RANSOMWARE / EXTORTION 15 1 asset encryption confirmed · 4 exfiltration unencrypted (simple extortion) UNCLASSIFIED INCIDENTS 25 breaches or outages without declared threat type FRAUD / PHISHING 5 documented fraud campaigns REGULATION 6 standards, rulings, or penalties UNIQUE CVEs 2 CVE-2026-35273 / CVE-2026-48907
Verified Signal Monthly Dashboard — Base: 67 verified dated events for Brazil.
MONTHLY FIXED MODULE Threat-axis distribution June 2026 · Brazil Each incident counts in only one axis, so the total is exactly 67. "Unclassified incidents" is the remainder. Incidents 25 Ransomware 15 Unclassified 12 Regulation 6 Fraud 5 Vulnerabilities 4
Threat-axis distribution — Each incident is assigned to one axis based on its classification; the total reconciles with the 67 incidents in the period.
MONTHLY FIXED MODULE Sectoral Distribution of Signals June 2026 · Brazil Base: 67 incidents in the period · total 87 because 19 incidents are classified in more than one sector. Public sector / OIV 41 Telecom 19 Other / unidentified sector 9 Technology 6 Health 5 Finance 3 Retail / Consumer 3 Education 1
Sectoral Distribution of Signals — Heuristic sector classification by victim. One incident may affect more than one sector, so the total can exceed the base.
MONTHLY FIXED MODULE Critical infrastructure in Brazil June 2026 · Brazil 9 of 67 incidents during the period affect critical infrastructure. One incident may appear in more than one category. Public sector / government 41 Telecom / connectivity 9
Critical infrastructure in Brazil — Verified incidents in the public sector, energy, telecom, and essential services

Monthly Executive Summary for Brazil

June 2026 was marked by a nationwide incident in the Defesa Civil Alerta system. A false alert sent remotely and classified as "Extreme Alert" woke millions of people, forced the platform offline around 1:30 a.m. on June 20, and triggered a Federal Police investigation. The episode was more than an operational failure. It exposed weaknesses in access control, decentralized panel management, and the resilience of the public notification channel.

The official response was swift. MIDR and the National Civil Defense temporarily centralized operations, restricted state access, and then announced a new framework with forms, Gov.br accounts, additional verification, and VPN use for state and municipal agents. At the same time, Anatel sought to calm public concern, but the reputational damage was already done: the system designed for emergencies had become a vector of distrust.

On the ransomware front, Brazil maintained a steady presence on leak sites and extortion panels. Monthly indicators show 15 cases with ransomware or extortion as the primary focus, although the source does not always make it possible to determine whether there was encryption, exfiltration only, or a simple mention on a leak site. Within that set, there were signals involving public health, logistics, education, manufacturing, the public sector, and services, with at least one confirmed double-extortion case and another in which the source only supports inclusion on the leak site.

The regulatory front also moved forcefully. ANPD advanced on Claro, closed monitoring of 56 data processing agents, and referred 21 organizations for sanction review. The Senate, meanwhile, pushed two core debates, one on data protection and security incidents, and another on a Cybersecurity Legal Framework. The month left the image of a country still under technical, regulatory, and political pressure at the same time.

Brazil, June 2026Jun 8 ANPDClaro/SerasaJun 15CTIR 50/2026FortiBleedJun 20 Alertfake DefesaCivilJun 23GSI 6.774incidentsJune 26 Newalert protocolalertsJune 30Legal Frameworkunder debate
Timeline of the most relevant events in Brazil — Brief chronology of June 2026, focused on the alerts incident, ransomware, and regulatory moves.

Brazil’s national intelligence in June

June was defined by incidents, not quiet campaigns or background telemetry. Of 67 verified events, 25 fell into the unclassified incident category, which accounted for most of the material and was led by the Defesa Civil Alerta case. The event carried high public severity because it affected a national service, reached multiple states, triggered public panic, and led to immediate operational changes. At the same time, the ransomware ecosystem remained active, but in a fragmented pattern, closer to persistent leak sites and opportunistic extortion than to a single dominant campaign in the country.

The risk reading for Brazil in June is high. Not because the data show a uniform rise across all metrics, but because of three factors combined: a mass incident that compromised a critical state alert channel, a persistent ransomware base across diverse sectors, and a regulatory front that had to respond to concrete problems involving data sharing, security incidents, and oversight findings. When a public alert system has to be shut down and reconfigured in the middle of a crisis, the impact goes beyond the technical layer and becomes institutional.

The false-alert case also offers a regional signal. In Latin America, digitized public services and mass-notification platforms remain high-value targets, both symbolically and operationally. It does not take a sophisticated intruder to cause damage politically and socially, weak credentials, delayed centralization, or poorly distributed access controls are enough. Brazil showed that clearly in June, and the month ended with changes to the alert channel design, not just an open investigation.

Verified signal by type, BrazilJune 2026, qualitative reading of consolidated facts for the periodIncidents25 factsRansomware15 casesRegulation6 developmentsCVE2 criticalOperational takeawaysThis month’s signal is centered on high-public-impact incidents, with widespread ransomware and growing regulatory pressure.
Narrative breakdown of the verified signal in Brazil — Qualitative matrix based on the period’s verified facts, excluding aggregated telemetry.

Brazil period indicators

Indicator Value
Verified facts in the period 67
Indicator time window 67 facts dated June 2026 · 1 with unconfirmed date (excluded from indicators)
Unclassified incidents (breaches or outages) 25
Cases with ransomware or extortion as the primary focus 15
Confirmed encryption of assets 1
Exfiltration without encryption (pure extortion) 4
Leak site mention only 1
Unclassifiable with available material 9
Documented fraud or phishing cases 5
Documented regulatory moves 6
Critical CVEs mentioned 2
Sectors with at least one documented fact 7
Predominant threat for the month Incidents (25 of 67 facts)
Facts with direct source confirmation 61%
Comparative baseline No comparative baseline: this is the first archived period with this indicator format for this country.

Relevant Incidents in Brazil

Defesa Civil Alerta and the fake extreme alert

The month’s most significant incident was the intrusion into the Defesa Civil Alerta system. The official MIDR source said the platform was taken offline around 01:30 on June 20, 2026, after an unauthorized remote push of extreme alerts. Reuters, Agência Brasil, O Globo, Teletime, and other outlets agreed on the core facts: there was a fake message, the platform was proactively disabled, and the Federal Police opened an investigation. The differences among sources are in the level of detail, not in the substance.

What matters for a security team is not only that there was an intrusion. The incident showed that the risk was not confined to a single jurisdiction or a marginal channel. Messages were reported in several states, at least eight capital cities, and thousands or millions of phones, depending on the source consulted. In addition, the use of the word "misantropia" and distribution through Cell Broadcast and SMS point to a compromise in the system administration chain, not a simple notification delivery issue. The later centralization of the service in Brasília confirms that the previous architecture was too exposed.

Operational changes to the public alert system

The MIDR responded with a new governance and access setup. First it limited direct use by the states, then implemented a semi-automated workflow with forms and a single authority enabled to trigger alerts during containment. Later it announced an automatic scheme with VPN, Gov.br accounts, and an additional code verification step. That sequence matters because it shows how a real incident ends up rewriting the operating process of a critical platform.

From a security standpoint, the problem no longer stops at the initial entry vector. Credential traceability, decentralized panel control, the role of regional users, and the separation between testing and production also come under scrutiny. The fact that the system had to be taken down and then reactivated after new tests confirms that the attack reached a sensitive asset, not a secondary surface.

Security incidents tied to personal data and payments

Outside the alert case, the month also produced other specific signals. The Central Bank confirmed a security incident linked to unauthorized access to a system managed by the Polícia Civil do Maranhão, with exposure of Pix key data, including name, CPF, institution, branch, account, and creation date. The available information makes clear that passwords, balances, and financial transactions were not compromised, which limits the impact, but does not make it trivial.

A report dated but not confirmed also mentioned a ThreeAM ransomware campaign against WS Group Brasil involving double extortion and deletion of shadow copies. Because the date is not confirmed, it is not included in the monthly tally, although it does help frame criminal groups’ interest in Brazilian corporate infrastructure.

Additional material on iFood and Nissan

Two additional items served as context, although they do not drive the monthly assessment. On one hand, a WCYB Digital Radio report said iFood had allegedly disclosed data exposure affecting about 1.2 million users tied to a prior incident. On the other, SecurityWeek reported a breach at Nissan Americas linked to exploitation of CVE-2026-35273 in Oracle PeopleSoft, with possible impact on employees in Brazil among other countries. In both cases, the material is useful for trend analysis, but the direct connection to the country carries less weight than the confirmed local incidents.

Threats and active campaigns in Brazil

Ransomware with confirmed encryption

The only case in the month’s material with confirmed asset encryption was the Mato Grosso State Health Secretariat, linked to LockBit5. The combined sources support the conclusion that there was both exfiltration and system encryption, fitting a classic double-extortion pattern. No verifiable IOCs or technical details were published that would allow anything beyond attribution and the general attack pattern.

Ransomware with exfiltration, no confirmed encryption

The exfiltration-only category includes cases where the source describes data theft or data leaving the environment, but not operational blocking of systems. Coemi Imóveis falls into this group because Krybit claimed to have stolen data and threatened publication if negotiations did not begin. Meta, a Brazilian occupational health provider, was listed by BravoX with an assertion that sensitive information had been exfiltrated. Editora Irmãos Vitale also fits this category more closely, since the material points to data leakage without clear documentation of encryption. The common thread is extortion focused on disclosure of information, rather than technical unavailability.

Cases that cannot be classified from the available material

There are nine cases in which the source does not specify whether there was encryption, exfiltration, or only inclusion on a leak site. This includes several mentions in weekly radars and leak aggregators, such as ws.com.br, MHE9 Logística, Clínica Vida, Silmquinas e Equipamentos, sweetome.com and the reference to gov.br attributed to APT73/Bashe. In those cases, strict interpretation is needed: appearing on an extortion site does not, by itself, prove verified operational impact.

Leak site mention only

In June, at least one case remained, for now, as a leak site mention only. The Gentlemen included Mackay Sugar on its site, but had not yet released data at the time of the cited report. That distinction matters because it separates the publication of a target from evidence of an actual data leak.

Documented fraud and phishing

The month also included five documented fraud or phishing incidents. They are not the main theme, but they do fit the broader pressure on users and credentials. In a period that included discussion of fake alerts, cloned credentials and unauthorized access to panels, social engineering was not a side issue. The material provided does not support building a single phishing campaign, but it does point to an environment favorable to impersonation and abuse of trust.

APT and hacktivism

The only claim that comes close to an APT or hybrid-actor line is the mention of APT73, also identified as Bashe, against gov.br. The claim appeared on extortion sites and in tracking reports, but without official confirmation or public IOCs. From an editorial standpoint, that means it should be treated as an actor claim, not as a settled fact of effective intrusion.

Critical vulnerabilities affecting Brazil

CVE Software Exploitation Source
CVE-2026-35273 Oracle PeopleSoft Zero-day exploitation in a campaign attributed to employee data theft in several countries, including Brazil; the source describes possible access to payroll, banking, tax, and ID records. SecurityWeek, The Register
CVE-2026-48907 JCE Pro for Joomla Pre-auth remote code execution, with a recommendation to update to 2.9.99.6 or later, or uninstall the component if that is not possible. CISC, Portal Gov.br

The material reviewed did not record any other critical CVEs with documented impact in Brazil during June. That does not mean other vulnerabilities were not exploited in the region, only that they did not appear in the corpus used for this report.

Regulation and Compliance in Brazil

ANPD and the enforcement front

The ANPD had an active month. It closed monitoring of 56 processing agents, including public agencies and private companies, over the role of the encarregado de dados, and sent 21 organizations for review after they failed to respond. It also opened an administrative proceeding against Claro over alleged irregularities in the sharing of personal data with Serasa. That case matters not only for the specific dispute, but because it confirms the authority is willing to turn governance obligations into potential sanctions.

Federal Senate and data protection

The CCT approved a bill that clarifies the ANPD's authority to oversee security measures and apply penalties when an incident leads to vazamento de information pessoal. The CDH, meanwhile, moved forward with an amendment to the Marco Civil da Internet to require notification when content is removed without a court order. While the issue is not identical to operational cybersecurity, it does affect abuse management, moderation, and traceability in decisions on digital platforms.

On June 30, the CCT discussed PL 4.752/2025, which establishes the Marco Legal da Cibersegurança and creates the Programa Nacional de Segurança e Resiliência Digital. ABIN took part in the public hearing. The move does not solve the month's operational problems on its own, but it shows that Brazil's political system is trying to build a more coherent regulatory framework to respond to incidents with national reach.

Internal rules and public administration

Enap approved Resolução 96, which sets internal procedures for reporting security incidents, information access requests, and registro de compartilhamento de dados pessoais. Although it is an internal measure, it adds to a month in which the Brazilian state put its own reporting and custody flows under review.

Most affected sectors in Brazil

The public sector was the most visible, both in volume and intensity. That was not only because of the Defesa Civil Alerta incident, but also because of the buildup of cyber incidents affecting federal bodies and entities, the Pix case handled by a state civil police force, and regulatory debates tied to personal data and institutional security. The state appeared at once as victim, regulator, and the entity responsible for corrective action.

Health also stood out. Mato Grosso’s Health Secretariat appeared in the LockBit5 extortion ecosystem, and Clínica Vida was listed in another weekly radar. This reinforces a familiar pattern in Brazil and across the region: health combines high operational sensitivity with pressure to keep services running, which makes it especially attractive for extortion.

Logistics, business services, education, manufacturing, and consumer services round out the observed distribution. These are distinct sectors, but they share a common exposure, reliance on authentication systems, data exchange, and business continuity. The fact that the material shows seven sectors with at least one documented incident points to a dispersed month, with no concentration in a single vertical, although the public sector clearly ranked highest in strategic relevance.

There is no month-over-month baseline in this format, so it would be wrong to invent a trend for intermonthly variation. June did leave two signals worth watching. The first is the fragility of public notification systems that rely on multiple channels and decentralized administration. The second is the continued use of leak sites as a tool for reputational pressure, even when the operational impact is not clearly verified.

MIDR's announced hardening also deserves attention. The move to VPN, Gov.br accounts and additional verification may reduce risk, but its real effectiveness will depend on how regional credentials are managed and on whether centralization reduces the attack surface or only shifts the single point of failure. At the same time, the regulatory front could become more demanding if the Senate turns what was still debate in June into law.

In ransomware, the most useful signal is not a single group, but the range of sectors targeted and the frequency of mentions with incomplete classification. That points to an active ecosystem, more fragmented than spectacular, where public visibility comes from leak sites and aggregators as much as from victims confirming incidents.

Security guidance for teams in Brazil

First, review privilege administration and access traceability in systems that distribute alerts, notifications, or mass messages. If a panel can be triggered remotely by regional accounts, session control, credential rotation, and separation of duties must be measurable, auditable, and subject to periodic testing.

Second, tighten controls over personal data disclosure flows and third-party sharing operations. The ANPD, Claro and Serasa cases show that the problem is not only external data theft. There is also risk in how information is negotiated, shared, and documented within the commercial ecosystem.

Third, treat leak sites as an early signal, not as final proof. If an organization appears listed, it is advisable to validate the real scope, compromised access, exfiltration, and any published artifacts before communicating or denying it outright. The difference between "mention," "exfiltration," and "encryption" changes the response plan.

Fourth, prioritize patches for the two critical vectors mentioned in the material, CVE-2026-35273 and CVE-2026-48907. In both cases, the operational value of the fix clearly outweighs the cost of a short maintenance window. In public and corporate environments, exposure of collaboration services, ERP, and web components can open very different doors, but equally harmful ones.

Fifth, adjust crisis procedures so a false alert does not turn into prolonged operational confusion. The June incident showed that technical security and public communication must be aligned. If they are not, the attacker or intruder does not only compromise a channel, they also compromise trust in the entire infrastructure.

Material limitations

This report was prepared exclusively from the material provided for June 2026 and from facts dated within that time window. Facts without confirmed dates were excluded from the indicators and were used only, when appropriate, as qualitative context, with that caveat.

A zero indicator, especially for CVEs, means it was not recorded in the material analyzed for this period. It does not mean that critical vulnerabilities exploited in Brazil or the region did not exist during the month, only that they did not appear in the available corpus for this report.

The coverage also excluded aggregated telemetry, blocked attempts, and vendor averages that do not constitute incidents. Likewise, social media posts and promotional or commercial material outside the permitted sources were not used as evidence. When a source described a fact without sufficient confirmation, it was treated as attribution or context, not as a consolidated incident.

Finally, the indicator format has no prior comparative baseline for Brazil, so no artificial month-over-month trend was constructed. The result is a snapshot of June 2026, not a historical series.

Sources