Situación Nacional de Ciberseguridad - Junio 2026 - Chile
Chile ended June with new Law 21.663 requirements, zero-day alerts, and high patching pressure.
Key findings
- ANCI published the list of 915 Operators of Vital Importance and activated a compliance framework with incident reporting within three hours.
- June brought a high remediation burden, with up to 206 Microsoft vulnerabilities, three zero-days, and an active Chrome zero-day included in KEV.
- CVE-2026-11645 raised risk in Chromium browsers due to its low exploitation friction and the need to restart to load the patch.
- CVE-2026-41089 exposed Windows domain controllers with risk of full Active Directory compromise.
- The Cybersecurity Framework Law and the upcoming Personal Data Law are pushing Chile toward a stricter regime of evidence, sanctions, and traceability.
- Digital fraud continued to be dominated by vishing, phishing, smishing, and impersonation of financial and logistics brands.
- Ransomware.live records 74 victims linked to Chile, confirming persistent exposure and extortion potential.
Chile monthly executive brief
June 2026 brought Chile an uneasy mix for security, compliance, and operational continuity teams. On one side, the National Cybersecurity Agency published the list of 915 Operators of Vital Importance, with a clear sector breakdown: 147 power companies, 29 telecom firms, 413 digital services providers, 34 banking companies, and 114 health providers. On the other, the practical impact of the Cybersecurity Framework Law became more visible, with enforceable accreditation duties, incident reporting within three hours, and a sanctions regime that can reach 40,000 UTM.
The month’s technical picture was demanding as well. Microsoft’s June patch cycle forced a broad remediation push, with estimates ranging from 198 to 206 vulnerabilities fixed, including three actively exploited zero-days and high-impact flaws in BitLocker, HTTP.sys, Remote Desktop, and Hyper-V hosts. In parallel, Google released an emergency Chrome patch for CVE-2026-11645, a critical vulnerability in V8 with active exploitation and exposure across Chromium-based browsers, a particularly sensitive vector for companies managing distributed endpoints.
ANCI also reinforced its role as an official coordination channel by forwarding CSIRT de Gobierno de Chile alert AVC26 about Microsoft’s Patch Tuesday updates. That was not a minor step, because it makes visible the institutional path regulated organizations should follow when they face actively exploited vulnerabilities or threats that could affect essential services. The month’s practical guidance was consistent across sources: update immediately, verify actual deployment, restart systems, and centrally monitor versions.
On the regulatory front, June was more a month of operational transition than of abstract debate. The public consultation to define mandatory basic cybersecurity standards remained open until June 29, while compliance milestones for OIVs began to take effect in practice. At the same time, preparation accelerated for Ley N.º 21.719 de Protección de Datos Personales, whose full entry into force is set for December 1, 2026 and which local media has already linked to fines of up to 20,000 UTM for serious violations.
Threats and incidents in Chile
ANCI publishes list of 915 Critical Operators
On June 2, 2026, G5 Noticias reported that Chile’s National Cybersecurity Agency published the list of 915 Critical Operators in Chile. The breakdown is useful because it shows which risk surfaces the country concentrates in regulatory and continuity terms: 413 digital services organizations, 147 power companies, 114 healthcare providers, 34 banking-sector entities, and 29 telecom companies.
The operational impact goes beyond the list itself. The same coverage noted that these operators must report cybersecurity incidents within a maximum of three hours and can face fines of up to 40,000 UTM under the Cybersecurity Framework Law. That notification window is short even for mature teams, because it requires detection, validation, legal review, and response activation in a timeframe that rarely matches full work shifts or the availability of the right staff.
For Chile, this publication marks a shift from previous months, the issue is no longer just the future structure of the system, but the day-to-day management of concrete obligations tied to assets, third parties, crisis rooms, and incident traceability.
ANCI and the official channel after Microsoft’s Patch Tuesday
On June 9, 2026, ANCI posted on X about Microsoft’s Update Tuesday and pointed users to CSIRT de Gobierno de Chile alert AVC26. The message shared vulnerabilities compiled by the company affecting several of its products and reinforced the idea that the CSIRT remains the reference point for publishing critical alerts in the country.
The day’s information flow matched the global environment. Specialized and local sources reported between 198 and 206 vulnerabilities fixed by Microsoft, with three zero-days and critical flaws in widely deployed components. For Chilean organizations with significant Windows infrastructure, that meant treating Patch Tuesday not as a desktop routine, but as an operational containment priority across workstations, servers, and virtualized environments.
CVE-2026-11645 in Chrome puts pressure on Chromium browsers
On June 10, HDTI published an analysis of CVE-2026-11645, a zero-day vulnerability in Chrome’s V8 engine with a CVSS score of 8.8. The key point for Chile is that it affects Chromium-based browsers, including Chrome, Edge, Brave, Vivaldi, Opera, and Electron applications. The exploitation trigger is simple and concerning, visiting a malicious webpage is enough to enable arbitrary code execution inside the browser sandbox.
Google had already issued an emergency patch on June 9, fixing 74 vulnerabilities in Chrome, but residual exposure remained high for any organization that did not update centrally and did not force browser restarts. That last point matters more than it may seem, because in enterprise environments a downloaded patch does not always mean the code has actually been loaded into memory.
The available evidence trail confirms that. CISA added CVE-2026-11645 to its KEV catalog on June 9, with a remediation deadline of June 23. NVD describes it as affecting Chrome versions earlier than 149.0.7827.103, and multiple analyses note that the required interaction is minimal. In operational risk terms, this pushes endpoint security, DEX, browser administration, and web filtering to function as a single control layer.
CVE-2026-41089 and exposure of Windows domain controllers
HelpNetSecurity reported on June 1 that CVE-2026-41089, a critical Netlogon vulnerability, was already being actively exploited in the wild. An Instagram post from June 3 repeated the reference to the flaw as a remote code execution issue in Netlogon, although the available excerpt does not allow confirmation of Microsoft’s original technical bulletin in that specific item.
Beyond that limitation, the technical substance is clear. Orca Security said there is public proof-of-concept code and that multiple threat actors are actively exploiting the flaw. If exploitation succeeds, attackers can gain SYSTEM-level execution on domain controllers, take control of the Active Directory domain, deploy malware, exfiltrate credentials, create backup accounts, and pivot to other domain-joined systems. The direct consequence for Chile is clear in sectors heavily dependent on AD, from banking and healthcare to digital services and critical providers.
Signs of sector readiness and institutional events
Public and private agendas followed that technical pressure. On June 8, an Instagram post announced that Santiago, Chile would host the Industrial Cyber Summit Chile 2026, focusing on ICS/OT security and regulation, organized by Fundación País Digital and ANCI. The same post said Patagonia Ciber 2026 would take place on June 11 and 12 in Concepción, with an emphasis on cybersecurity institutions, already enforceable standards, and the risk that a failure at one supplier could disrupt an entire production chain.
Although these announcements do not constitute incidents, they do show the type of conversation that dominated the month. Industrial security, supplier continuity, and regulatory enforceability were no longer on the margins. In Chile, June closed with growing tension between the pace of regulatory change and the technical reality of patch deployment.
Ransomware and extortion in Chile
The available evidence for June does not allow a single ransomware campaign tied to the country to be reconstructed, but it does point to several signals that should be read together. Ransomware.live shows 74 victims associated with Chile on its platform, and within that set there is at least one victim with a discovery date of 2026-06-02. That does not amount to a national total, but it does offer a measure of the problem’s persistence and the public visibility that leaks and extortion still have.
At the same time, an Instagram post from June 3 claimed that 56% of Chilean companies hit by ransomware in 2026 would have paid ransom. That figure appears without visible methodology in the available excerpt, so it cannot be treated as a consolidated datum in this report, but it does signal public discussion about economic pressure and weak responses to extortion.
The case of Renta Nacional Seguros, reported by Security-Chu on June 28, adds a different layer. The post said that policies, invoices, and insured customers’ RUT were exposed in a hacker forum. It is not presented as ransomware in the source provided, but rather as a data leak with potential reuse for fraud, extortion, or follow-on campaigns. In the insurance market, this kind of exposure hits both confidentiality and commercial trust.
Also circulating in June was a broader narrative about fraud and identity theft as a monetization vector. While not all of that falls under ransomware, in practice Chilean organizations often face the same pressure chain, initial compromise, lateral movement, exfiltration, and then direct or indirect extortion. The analytical distinction matters, but from a defensive standpoint the requirement is the same, isolate quickly, preserve evidence, and cut off the ability to spread.
Critical vulnerabilities with impact in Chile
| CVE | Software | Exploitation | Source |
|---|---|---|---|
| CVE-2026-11645 | Google Chrome, Chromium-based browsers, Electron applications | Active, on CISA KEV, emergency patch on June 9, 2026 | NVD, CVEfeed, HDTI, Threat-Modeling.com |
| CVE-2026-41089 | Microsoft Netlogon in Windows, domain controllers | Active, with public PoC and observed exploitation | HelpNetSecurity, Orca Security, GitHub |
| CVE-2026-50507 | Windows BitLocker | Security bypass vulnerability, included in the June Patch Tuesday | Zero Day Initiative, Qualys, SentinelOne |
| CVE-2026-45585 | Windows BitLocker | Security bypass vulnerability, included in the June Patch Tuesday | Zero Day Initiative, Qualys, SentinelOne |
| Multiple June 2026 flaws | Microsoft Windows and related ecosystem | 198 to 206 vulnerabilities, with three zero-days and several critical components | csirt.telconet.net, Infosertecla, Qualys, CrowdStrike |
| Multiple June 2026 flaws | Various Adobe products | More than 120 vulnerabilities patched in parallel with Microsoft’s cycle | Infosertecla |
| Multiple June 2026 flaws | Android | Monthly vulnerabilities published on June 1, 2026 |
The table condenses the set of risks with the highest operational impact for Chile during the month. Not all of them belong to the same attack family, but they converge on the same control points, browsing, workstations, Windows domains, exposed servers and mobile platforms in corporate use.
For Chrome, the risk is direct because the exploit is triggered by simply visiting a malicious page. That makes the end-user surface a critical front. In Windows, the problem is more structural, since Netlogon and BitLocker affect services with high privileges or direct value for data protection. The combination of both fronts requires priorities to be set by exposure, not by the order in which the bulletin arrived.
Regulation and compliance in Chile
June was a month of regulatory implementation for Chile. ANCI opened a public consultation to define mandatory baseline cybersecurity standards for organizations subject to the Framework Cybersecurity Law, based on Exempt Resolution No. 140 and with comments due by June 29, 2026. That window shows the regulatory framework is still being adjusted, but it is already having concrete effects on what each organization will have to demonstrate to the authority.
In parallel, one of the first milestones of Law 21.663 took effect in June, requiring Critical Infrastructure Operators to show ANCI that they meet new digital security requirements. ADN Radio noted that the penalty regime can reach 40,000 UTM, a figure it estimated at more than 2,800 million Chilean pesos. The practical meaning is immediate: maturity is no longer measured only by controls in place, but by evidence of compliance and documented response capability.
The same logic extends to the Council for Transparency, which published its 2026 Manual of Transparency, Integrity, and Access to Public Information for Authorities. Although the document is not part of the core of operational cybersecurity, it does affect the handling of public information and the documentation discipline of government bodies. For teams working in government, municipalities, public companies, or regulated institutions, the line between security and transparency is increasingly narrow.
SERNAC also appears, which during CyberDay 2026 carried out a special digital inspection, monitoring advertising, consumer information, costs, and shipping times, while also warning about digital fraud and deceptive practices. This places online fraud in a space where security, consumer protection, and compliance converge. The impact is no longer only technical, because reputational and regulatory damage can stem from a poorly executed purchase or a phishing campaign tied to major commercial events.
Added to that is Law No. 21.719 on Personal Data Protection, which several Chilean media outlets reported in June as fully in force from December 1, 2026, with administrative fines of up to 20,000 UTM for serious violations and the creation of a Data Protection Agency with oversight, investigative, and sanctioning powers. The month made clear that the second half of the year would not be read as a waiting period, but as the final stretch to prepare inventories, contracts, legal bases, incident notices, and response processes.
Financial sector and digital fraud in Chile
This month’s material does support a discussion of the financial sector and digital fraud with enough evidence. First, because ANCI identified 34 banking-sector operators within the OIV roster, placing banking under a regime with explicit expectations for notification, continuity, and proof of control. Second, because public debate this month was packed with references to fraud via phone calls, WhatsApp, SMS, and e-commerce channels.
G5 Noticias’ report on 3,123 attacks per week in Chile did more than cite a headline figure. It places the country in a high-exposure category, which for banks and financial services means more pressure on authentication, transaction monitoring, identity protection, and fraud response. The line between a technical attack and financial fraud gets thin when the most valuable asset is not the server, but the credential or the session.
June also brought several news pieces on vishing and digital fraud. Mundo en Línea reported that Chile closed 2025 with a historic record of 41,703 fraud cases before the Judiciary, although that figure is attributed to the source and cannot be treated here as consolidated. The same publication said vishing would account for 71% of phishing-type fraud, according to a joint study by the University of Chile and SERNAC. TrendTIC, for its part, said nearly 1 in 3 digital fraud cases in Chile is linked to vishing and that the average amount stolen would reach $1.3 million. Both pieces point to the same phenomenon, social engineering remains the dominant vector for end-user fraud.
Publimetro added another layer, reporting that 60.1% of Chileans would have been victims of some kind of financial fraud through digital platforms and that between 122,000 and 135,000 phishing emails are detected each month. Those figures were published as recent, but the available excerpt does not provide methodology, so they should be read as journalistic references, not official statistics.
At the same time, HackingChile described the most common impersonations in local phishing as targeting BancoEstado, Banco de Chile, Falabella, Ripley, Correos de Chile, and the SII, while also noting the widespread use of smishing. That overlap across brands, logistics, and tax administration helps explain why digital fraud in Chile tends to be opportunistic and mass-market, not necessarily sophisticated, but persistent.
CyberDay week added more noise. Radio Cooperativa posted a Facebook alert about an increase in QR code fraud involving home-delivery parcels during the event. There is no need for a complex technical chain when the attacker exploits user urgency, the expectation of a purchase, and a brief interaction with a malicious QR code. In banking and payments, effective response depends on transaction controls, anti-fraud education, and verification filters, not on a single layer.
Regional overview: Chile in the LATAM context
Chile emerges in June as one of the Latin American countries where cybersecurity regulation is starting to turn into measurable operational obligations, not just policy debate. The OIV roster, the three-hour reporting deadline, the public consultation on standards and the explicit reference to steep penalties place the country at a more advanced stage of institutionalization than is usually seen in broad regional assessments.
The technical noise, moreover, was global, not local. Microsoft, Google, Adobe and Android accounted for the bulk of patching activity, while CISA, NVD and several international response teams classified multiple vulnerabilities as actively exploited. Chile sits within that same exposure cycle because its technology stack depends heavily on international software and because its critical sectors, from energy to healthcare, run on IT supply chains that do not recognize borders.
June, then, pointed to a clear picture: the country is not facing an isolated threat, but the combined pressure of three fronts, regulatory compliance, urgent remediation and large-scale user fraud. The region shares the same campaigns and the same affected products, but Chile enters that conversation with greater regulatory density and with a universe of critical operators already named by the authority.
Period indicators
| Indicator | Value | Scope | Source |
|---|---|---|---|
| Critical Operators published by ANCI | 915 | Chile | G5 Noticias |
| Electric utilities within OIV | 147 | Chile | G5 Noticias |
| Telecommunications companies within OIV | 29 | Chile | G5 Noticias |
| Digital services companies within OIV | 413 | Chile | G5 Noticias |
| Banking entities within OIV | 34 | Chile | G5 Noticias |
| Health providers within OIV | 114 | Chile | G5 Noticias |
| Incident reporting for OIV | 3 hours | Chile | G5 Noticias, Gerencia.cl |
| Maximum fine under the Cybersecurity Framework Law | 40.000 UTM | Chile | G5 Noticias, ADN Radio |
| Microsoft vulnerabilities patched in June 2026 | 198 a 206 | Global, impact in Chile | csirt.telconet.net, Qualys, CrowdStrike, Infosertecla |
| Microsoft zero-days in the month | 3 | Global, impact in Chile | csirt.telconet.net, CrowdStrike |
| Adobe vulnerabilities patched in June 2026 | More than 120 | Global, impact in Chile | Infosertecla |
| Emergency Chrome vulnerabilities patched | 74 | Global, impact in Chile | HDTI |
| CVE-2026-11645 severity | 8.8 | Global, impact in Chile | Tenable |
| Victims linked to Chile on Ransomware.live | 74 | Chile | Ransomware.live |
| Discovery date of at least one victim in Chile | 2026-06-02 | Chile | Ransomware.live |
Reading for security teams in Chile
The first priority is still operational, not theoretical: inventory, classification, and response times. If an organization falls under OIV, June makes clear that the regulatory clock is already running. Three hours to report incidents leaves no room for improvisation, so the crisis room, legal workflow, and technical classification capability should be practiced before an event, not after.
The second priority is patch management with exposure in mind. The Chrome and Netlogon cases show that having the patch is not enough. Organizations need to verify deployment, force restarts in Chromium browsers, review versions on managed endpoints, secure domain controllers, and confirm that mitigations are actually active. In environments with many remote assets, visibility into compliance matters as much as downloading the package.
Third, June confirms that attackers are still looking for the pieces that open the network, not necessarily the final asset. A browser with an exploitable flaw, an unremediated Windows domain, or a session stolen through vishing can have equivalent effects if they enable persistence and lateral access. Defensive focus should be on reducing entry opportunities, hardening identity and monitoring, and quickly closing escalation paths.
Fourth, the digital fraud front should be treated as part of the security program, not as a customer service add-on. The data on phishing, QR codes, vishing, and brand impersonation shows that an organization that does not coordinate anti-fraud efforts, communications, and identity protection ends up reacting too late. In regulated sectors, that lag can also lead to reputational exposure and compliance costs.
Fifth, the second half of the year demands documented readiness. The public consultation on standards, the progress of Law 21.719, and the actual implementation of the controls in Law 21.663 create an environment in which declaring controls is no longer enough. Evidence, traceability, updated policies, third-party contracts, continuity exercises, and criteria for classifying incidents are all needed before December.
Material limitations
This report was built exclusively from the material provided. No verifiable observations were accumulated during the period, and the month’s internal statistics are listed as zero. For that reason, several assertions rely on deep research confirmed by source, while other newsroom details, though useful for context, appear in the material as source-attributed and are not used as consolidated facts.
No unverified figures were added, and no trends were extrapolated beyond what the available sources allow. Nor were victims, campaigns, or impacts assigned if they were not explicitly documented in the corpus provided. In particular, the ransomware case associated with Chile could not be reconstructed as a single campaign during June, although there is evidence of activity recorded on specialized platforms.
The period showed a clear imbalance between regulation, global vulnerabilities, and digital fraud. That makes it possible to describe the pressure on Chilean organizations with precision, but not to assert, based on the available material, a direct correlation between a specific incident and a particular sector beyond the cases and categories mentioned.
Sources
- Enorme ciberamenaza: Chile recibió más de ocho billones de intentos de ataques cibernéticos el año pasadoLa Tercera
- Patch Tuesday de junio de 2026 - SplashtopSplashtop
- Ciberataques se incrementan en Chile y la regiónGerencia.cl
- Microsoft corrige 200 vulnerabilidades en el Patch Tuesday de junio 2026Infosertecla
- 3.123 Ataques Por Semana a Organizaciones: Chile Está en el Centro del Cibercrimen GlobalG5 Noticias
- Microsoft corrige 198 vulnerabilidades en su Patch Tuesday de junio 2026 con 3 zero-dayscsirt.telconet.net
- Chrome Zero-Day CVE-2026-11645: Tu navegador es la puerta de entradaHDTI
- Agencia Nacional de Ciberseguridad (ANCI) en X sobre UpdateTuesday junio 2026Agencia Nacional de Ciberseguridad (ANCI)
- Publicación sobre 56% de empresas chilenas que pagó rescate por ransomware en 2026Instagram
- Publicación sobre Industrial Cyber Summit Chile 2026 y Patagonia Ciber 2026Instagram
- Reel de ANCI sobre ESET Security Days Chile 2026Agencia Nacional de Ciberseguridad (ANCI) / Instagram
- Feed de Noticias de Ciberseguridad [03/06/2026]CronUp Ciberseguridad
- Actualización de seguridad de Microsoft - Junio 2026Cyberzaintza (Gobierno Vasco)
- Boletín de seguridad de Android: junio de 2026Google
- Microsoft and Adobe Patch Tuesday, June 2026 Security Update ReviewQualys
- CVE-2026-11645 - Google Chromium V8 Out-of-Bounds Read and ...CVEfeed
- Google Chromium V8 Out-of-Bounds Read/Write (CVE-2026-11645)Threat-Modeling.com
- CVE-2026-11645Tenable
- CVE-2026-11645 - CVE RecordCVE Program
- Windows Netlogon RCE exploited (CVE-2026-41089)HelpNetSecurity
- 0xBlackash/CVE-2026-41089GitHub / 0xBlackash
- Netlogon RCE CVE-2026-41089 Flaw | Orca SecurityOrca Security
- ANCI inicia consulta pública para definir los estándares básicos obligatorios de ciberseguridad en ChileTrendTIC
- El dolor de cabeza de las empresas chilenas: Dos nuevas leyes y sanciones que superan los $2.800 millonesADN Radio
- Manual de Transparencia, Probidad y Acceso a la Información Pública para Autoridades 2026Consejo para la Transparencia
- Sernac monitors CyberDay 2026 and warns about misleading advertising and potential digital fraudServicio Nacional del Consumidor (SERNAC)
- En seis meses entra en vigencia la Ley de protección de datos personales: un error humano puede costarle millones de pesos a una empresaPublimetro Chile
- Ley de Datos Personales: Multas millonarias y cambios en el tratamiento de la informaciónPaís Lobo
- Ley 21.719: qué es y cómo preparar tu empresaSilocyData
- Lo que viene desde la ingeniería de privacidad: la nueva Ley de Datos Personales de ChileComunidad IALatam
- 74 victims for Chile - Ransomware.liveRansomware.live
- Renta Nacional Seguros sufre filtración de datos: pólizas, facturas y RUT de asegurados expuestos en foro de hackersSecurity-Chu
- Día Mundial de las Redes Sociales: 6 de cada 10 chilenos han sido víctimas de fraude digitalPublimetro Chile
- Epidemia del Vishing en Chile: alertan por récord histórico de fraudes por teléfono y WhatsAppMundo en Línea
- Casi 1 de cada 3 fraudes digitales en Chile se asocian a vishing y el monto medio estafado a consumidores alcanza los $1,3 millonesTrendTIC
- Ciberataques más comunes en Chile: tipos y cómo evitarlosHackingChile
- Alerta de ciberseguridad en pleno CyberDay 2026: Reportan un aumento en fraudes ejecutados a través de códigos QR en encomiendas domiciliariasRadio Cooperativa
- Expertos en ciberseguridad detectan más de 92,000 ciberataques escondidos tras falsas herramientas de IATrendTIC
- Feed De Noticias De Ciberseguridad [15/06/2026]CronUp Ciberseguridad
- Panorama De Ciberseguridad: Semana Del 22 Al 26 De Junio De 2026CronUp Ciberseguridad
- EDR, XDR o SIEM para empresas en Chile 2026NBitek
- El robo de identidades es la mayor brecha de seguridad corporativaITware Latam
- Nueva Ley Marco de Ciberseguridad y su impacto en las empresasAguilaycia.cl
- Ley 21.719 Chile 2026: protección de datos personalesAnami
- Ciberseguridad en marcha: Desafíos y avances para un Chile resiliente. Patagonia Ciber 2026Instagram
- Chile ya tiene Ley Marco de Ciberseguridad (Ley 21.663) y exige reportar incidentes al CSIRT NacionalInstagram
- Observaciones Informe SSCC 2027 Versión junio 2026Coordinador Eléctrico Nacional
- Mes: junio 2026Guía Chile Energía
- Aviso de mantenimiento programado de NIC Chile para el 20 de junio de 2026NIC Chile (Instagram)
- Publicación sobre intentos de ciberataques durante CyberDay y cifras de ataques en ChileCoopeuch (Instagram)
- Cifran en seis millones clientes afectados por filtración de datos de CarnivalPortalPortuario.cl
- La semana en noticias sobre filtraciones: 17 de junio de 2026Kaseya
