CiberLATAMbywhalemate
Intelligence report

Chile: Cybersecurity Situation, August 2026

Ransomware led August in Chile, with 24 cases, 16 regulatory moves, and two notable incidents in telecom

Sep 1, 202618 min read
Chile: Cybersecurity Situation, August 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are automatically completed with the verified facts dated within the period. Each one states its basis and counting criteria, so the figures reconcile across modules. They are the recurring month-to-month reading, and the analysis that follows develops the cases without repeating this summary.

Indicator window: 76 dated facts in August 2026. Facts from earlier months are used only as comparative context in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Verified Signal Monthly Dashboard August 2026 · Chile Top threat: Ransomware (24 of 76 incidents). Coverage: 76 dated incidents in August 2026 VERIFIED INCIDENTS 76 period base: total count measured from the bottom on this total RANSOMWARE / EXTORTION 24 3 encrypted assets confirmed · 1 exfiltration no encryption (simple extortion) UNCLASSIFIED INCIDENTS 16 breaches or outages with no declared threat type FRAUD / PHISHING 2 documented fraud campaigns REGULATION 16 rules, resolutions, or sanctions UNIQUE CVEs 6 CVE-2026-62832 / CVE-2026-68820
Verified Signal Monthly Dashboard — Base: 76 verified dated incidents for Chile.
MONTHLY FIXED MODULE Threat axis distribution August 2026 · Chile Each event is counted on just one axis, so the total is exactly 76. "Unclassified incidents" is the remainder. Ransomware 24 Regulation 16 Incidents 16 Vulnerabilities 9 Unclassified 9 Fraud 2
Threat axis distribution — Each event is assigned to a single axis based on its classification; the total reconciles to the 76 events in the period.
FIXED MONTHLY MODULE Sectoral Distribution of the Signal August 2026 · Chile Base: 76 incidents in the period · total 107 because 29 incidents are classified in more than one sector. Public sector / OIV 38 Other / no sector ident… 17 Telecom 12 Health 12 Technology 10 Education 9 Energy 7 Finance 2
Sectoral Distribution of the Signal — Heuristic classification by victim sector. One incident may affect more than one sector, so the total may exceed the base.
MONTHLY FIXED MODULE Distribution of OIVs in Chile August 2026 · Chile 15 of 76 incidents in the period involve critical infrastructure. One incident may appear in more than one category. Public sector / government 38 OIVs mentioned 1 Energy / utilities 8 Telecom / connectivity 10
Distribution of OIVs in Chile — Verified incidents linked to critical infrastructure operators or the public sector

Executive summary for the month in Chile

August ended in Chile with ransomware as the dominant threat and a clear increase in extortion pressure on local organizations. The month produced 76 verified incidents, 24 cases with ransomware or extortion as the primary focus, 16 regulatory moves, and two documented fraud or phishing cases. It also mentioned 6 critical CVEs and 16 unclassified incidents, in a context where 71% of the incidents were directly confirmed by the source.

The most visible case was the attack on Hospital Clínico Universidad de Chile, attributed to the Direwolf group and recorded on August 30. That was joined by claims or listings on leak sites linked to Difor, Layher, Incolur, Espinos, and Verbux, plus BlackNevas’s investigation into a French multinational with operations in Quilicura. The material does not always make it possible to distinguish between encryption, exfiltration, or only a mention on a leak site, so much of the month’s extortion activity falls into a middle zone of certainty.

Meanwhile, the regulatory front kept moving, though at a somewhat slower pace than in July. There were advances in the Ley Marco de Ciberseguridad, adjustments to the electrical standard, debate over the data protection law, and concrete signals from the CMF on stronger authentication, the end of the coordinate card, and the open finance system. The legislative agenda on deepfakes and digital integrity also advanced, adding a new layer of pressure on privacy, identity, and proof of authenticity.

The operational reading for the month is high risk. Not because of a single crisis, but because of the combination of active extortion, public incidents in sensitive sectors, a regulatory surface that already demands concrete changes, and growing exposure to AI-assisted fraud. August shows Chile under more attack pressure, more compliance obligations, and more friction in separating noise, potential exposure, and a confirmed incident.

National snapshot for the month in Chile

Chile saw a mix of concrete incidents, extortion campaigns, and regulatory adjustments in August, pushing organizations to raise their standards for monitoring and response. Ransomware was the dominant signal, but it appeared alongside defacements, a cyberespionage investigation in telecoms, pressure on the financial ecosystem, and an intense legislative debate over personal data and digital identity.

The qualitative assessment for the month is high. Severity depends not only on the number of incidents, but on their concentration in sensitive sectors, healthcare, telecommunications, banking, energy, and public agencies. It also matters that several cases remained preliminary or only partially attributed, which complicates crisis management and external communications. In other words, the risk was not only technical, it was also a matter of governance and interpretation.

At the regional level, Chile tracked a broader Latin American trend, more AI use in fraud, more hyper-personalized phishing campaigns, more exploitation of vulnerabilities in corporate products, and a greater role for extortion groups that post victims on leak sites. The difference is that in Chile, that pressure came alongside an especially dense regulatory agenda, with direct impacts on banks, essential service providers, and operators of vital importance.

Cronología de hechos verificados en Chile, agosto 2026Timeline con hitos del mes sobre ransomware, regulación, fraude y vulnerabilidades.Aug 08Telecomunder investigationAug 11Ransomware inhealthcareAug 14LiteLLMANCI alertAug 18MigrationsdefacementAug 21Electrical standardwithout CSIRTAug 24Deepfakes inChamberAug 30DirewolfUCH hospital
Timeline of verified events in Chile, August 2026 — Monthly milestones ordered by date, focusing on incidents, regulation, and critical vulnerabilities.

Chile period indicators

Indicator Value
Verified facts in the period (base for all indicators) 76
Indicator time window 76 facts dated in August 2026
Unclassified incidents (breaches or outages) 16
Cases with ransomware or extortion as the primary focus 24
Ransomware breakdown by impact type: Confirmed asset encryption 3
Ransomware breakdown by impact type: Exfiltration without encryption (simple extortion) 1
Ransomware breakdown by impact type: Mentioned only on a leak site 3
Ransomware breakdown by impact type: Cannot be determined from the available material 17
Documented fraud or phishing cases 2
Documented regulatory moves 16
Critical CVEs mentioned 6
Sectors with at least one documented fact 8
Main threat of the month Ransomware (24 of 76 facts)
Facts with direct source confirmation 71%

Comparative table with the previous month

Indicator August 2026 Previous month Change
Verified facts in the period 76 68 +8
Unclassified incidents 16 18 -2
Cases with ransomware or extortion as the primary focus 24 9 +15
Documented fraud or phishing cases 2 7 -5
Documented regulatory moves 16 24 -8
Critical CVEs mentioned 6 no comparable data n/a
Sectors with at least one documented fact 8 7 +1
Main threat of the month Ransomware (24 of 76 facts) Regulation (24 of 68 facts) shift in focus

Relevant incidents in Chile

Hospital Clínico Universidad de Chile and the Direwolf campaign

On August 30, Hospital Clínico Universidad de Chile appeared as a ransomware victim attributed to the Direwolf group, with independent reporting in technical trackers and incident monitoring sites. The material matches on the victim name, the health sector, and the date, although it does not provide public confirmation from the hospital on the real scope of the intrusion.

The technical source classifies the case as a breach and a ransomware victimization, but it does not specify exactly what data was compromised or whether encryption was confirmed by the institution. That leaves the case in a relevant operational category, but still incomplete for forensic purposes. In terms of public exposure, it is the clearest health sector incident of the month.

National Migration Service and the defacement with mass email

On August 18, the National Migration Service suffered a website intervention that temporarily blocked the digital services platform and replaced its content with an image and messaging associated with Augusto Pinochet. At the same time, mass email was reported from accounts linked to the service, amplifying the incident beyond a simple visual takeover of the portal.

The institution said the attack began around 5:00 a.m. and that an internal investigation was opened. The reports reviewed indicate that services were restored during the morning, but they do not specify whether there was data exfiltration or compromise of case files. The episode falls squarely within the 16 unclassified incidents in the period.

Investigation into cyberespionage in telecommunications

Between August 8 and 10, several reports covered an investigation by the Metropolitan North Central Prosecutor's Office and the PDI into possible computer attacks against Entel, Movistar, and Telmex, with references to the Lilac Typhoon group and the offense of computer sabotage. The material insists that this was a preliminary complaint, based on information provided from the United States.

This case did not solidify as a confirmed breach during the month. Even so, it left important signals, including the mention of ShadowPad and the possible use of compromised infrastructure for obfuscation. It also opened a political discussion about privacy, national security, and parliamentary oversight. By the end of August, it was still an investigation, not a proven incident.

LiteLLM, ANCI preventive alert, and potential exposure

On August 14 and 15, ANCI activated a preventive protocol over a possible exposure tied to the LiteLLM hack and notified about 20 Chilean institutions. The reports stress that this was a possible exposure, not a confirmed incident, and that the agency had not identified significant impacts at the time it issued its alerts.

The significance of the episode lies less in a confirmed local intrusion and more in how it showed the exposure surface of Chilean organizations to supply chain compromise. The material mentions domains associated with public, financial, educational, and corporate entities. As context, it is useful for understanding defensive prioritization, but not for adding confirmed incidents.

Threats and active campaigns in Chile

Ransomware and extortion dominate in Chile

August was marked by a more visible extortion campaign than July. The month brought 24 cases with ransomware or extortion as the primary focus, including 3 confirmed encryption events, 1 case of exfiltration without encryption, 3 leak site-only mentions, and 17 situations in which the material did not allow for a precise impact assessment. Most of the activity therefore remained in a space of strong attribution but only partial operational effect.

The month’s pattern shows a mix of sectors and verification levels. Direwolf hit Hospital Clínico Universidad de Chile, BlackNevas appeared in an investigation involving a French multinational with a subsidiary in Quilicura, TheGentlemen listed Layher, Incolur, Espinos and Verbux, and Qilin claimed Difor. In several of those cases, the company did not confirm the intrusion, so the primary source is the leak site or a specialized tracker.

Confirmed encryption, exfiltration and leak sites

Only three cases in the period allow for confirmed asset encryption, according to the provided taxonomy. One of them corresponds to Hospital Clínico Universidad de Chile, while other incidents in the month remained at the level of extortion or publication on leak forums without enough technical detail. There was also one identified case of exfiltration without encryption in the material, but the rest could not be conclusively classified.

That calls for caution in reading the month. In practice, leak site noise often overstates the real scope if it is not backed by victim confirmation. In August, Chile saw a mix of criminal posts, incident trackers and very little formal corporate confirmation. The alert is real, but the effective impact is not always proven.

Fraud and phishing in Chile

Fraud had a smaller footprint than ransomware, but a more consistent day-to-day impact. The month recorded 2 documented cases, although the broader context was much larger. The Central Bank reported US$98 million in complaints over fraudulent banking transactions in the first half, and several reports warned about vishing, smishing and scams using RUT, voice cloning or highly personalized AI-generated messages.

The clearest case in August was the description of a bank phone scam that uses the RUT as an entry point and poses as the bank’s fraud department. That was joined by the Central Bank’s warning about AI-generated content impersonating authorities and at least two pieces on the rise of phishing and vishing in Chile. The trend points to more sophisticated social engineering, not just a higher volume of mass messages.

Cyberespionage and pressure on telecoms

The investigation into Lilac Typhoon did not go beyond a preliminary case, but its political and technical weight was high. The material places it as a cyberespionage operation linked to China, with possible effects on Entel, Movistar and Telmex networks, and with references to ShadowPad, network reconnaissance and metadata extraction. There was no public confirmation of an effective breach during August.

For the monthly report, the value of this campaign lies in the mix of media attention, criminal proceedings and parliamentary reaction. If the case advances in later months, it could become one of the year’s most relevant storylines for the telecom sector. For now, it remains a warning sign, not a proven intrusion.

Critical vulnerabilities with impact in Chile

The month's material did not directly link the exploitation of critical vulnerabilities to a confirmed local incident, but it did surface a significant set of alerts Chile should have on its radar. The most relevant exposure was Zimbra, followed by Spring Security, Haiwell IoT Cloud HMI Gateway, and Palo Alto PAN-OS, with potential impact on email, authentication, industrial infrastructure, and perimeter monitoring.

CVE Software Exploitation Source
CVE-2026-73570 Zimbra Collaboration Suite Confirmed active exploitation and added to KEV NVD, CISA, INCIBE-CERT
CVE-2026-59270 Spring Security Critical vulnerability published with an official warning; exploitation not confirmed in the Chilean material HeroDevs, INCIBE-CERT, HunCERT
CVE-2026-19188 Haiwell IoT Cloud HMI Gateway Critical advisory, with no record of specific public exploitation by the close of the material CISA, OpenCVE, INCIBE-CERT
CVE-2026-0301 Palo Alto PAN-OS, Prisma Access and Cloud NGFW Information disclosure, with patching recommended and regional advisories issued Palo Alto Networks, CSIRT Panama, Rapid7
CVE-2026-32560 MagicAI for WordPress LFI advisory, with no evidence of local impact in the material INCIBE-CERT
CVE-2026-12556 HP Easy Start for macOS Security advisory, with no direct link to local incidents INCIBE-CERT

The takeaway for Chile is preventive. The material did not draw an explicit line between these CVEs and confirmed breaches in the country, but it did signal a strong need for defensive readiness, especially around Zimbra and Microsoft's patch cycle. In a context where email, identity, and remote access are recurring attack vectors, this matters more for potential exposure than for the isolated number of alerts.

Regulation and compliance in Chile

August was a heavy month for regulation. There were 16 documented moves, and the regulatory agenda touched at least four fronts: personal data, cybersecurity, open finance, and digital safety for minors and synthetic identity. The regulatory conversation is no longer just about future compliance, but about deadlines, penalties, reporting, and concrete operating criteria.

Law No. 21.719 remained at the center of the debate. Several media outlets and industry players reported that the government is weighing a delay to its effective date, set for December 1, 2026, because a fully operational enforcement agency is still lacking. Some voices called for a short extension of no more than six months, while others warned that pushing it back by a year would damage both reputation and operations.

At the same time, the CMF moved forward with the rollout of Reinforced Customer Authentication, ending the general use of coordinate cards as of August 1, and continued refining the Open Finance System. NCG 569 extended the SFA implementation timeline and established a pilot scheme, while other technical guidelines set out requirements for availability, reporting, and interoperability that are already forcing banks and other participants to review architecture, continuity, and incident response.

The agenda on deepfakes and digital integrity also moved. On August 24, the Chamber of Deputies approved in general a bill regulating AI-generated content and penalizing deepfakes, in a line that intersects privacy, digital evidence, and platform liability. Outside that bill, the debate over IMSI Catchers and surveillance powers remained active, confirming that digital security now overlaps with privacy, organized crime, and fundamental rights.

Regulation and compliance table

Date Milestone Operational impact
2026-08-01 Full ARC implementation begins and general use of coordinate cards ends Changes in banking authentication and transfers
2026-08-05 Guidelines and FAQs on Law 21.663 are released Greater clarity on incident reporting
2026-08-11 The Undersecretariat of Energy orders the electric standard to be adjusted and the sector CSIRT to be removed Reporting is unified under the National CSIRT
2026-08-12 Decree 295 and reporting obligations to ANCI Speeds up alert and response windows
2026-08-18 The National Anti-Transnational Financial Fraud Roundtable is signed More coordination between the public and private sectors
2026-08-21 The CNE confirms the elimination of the Electric CSIRT The energy sector is aligned to a single window
2026-08-24 The Chamber approves the anti-deepfake law in general New layer of obligations on digital identity
2026-08-25 to 2026-08-28 Debate continues on the Data Protection Law and the SFA Ongoing compliance and governance adjustments

Most affected sectors in Chile

The monthly signal reached eight sectors, with visible concentration in healthcare, telecommunications, finance, energy, government, technology, construction, and transportation or logistics. Not every sector is backed by the same quality of evidence, but the mix already shows where the real pressure sits and where the main issue is third-party exposure or claims on leak sites.

Healthcare was the clearest case, driven by the attack on Hospital Clínico Universidad de Chile and by its weight in the ransomware figures cited by Sophos. Telecommunications came under investigation without a confirmed breach, and that alone raises scrutiny because it is a highly privacy-sensitive infrastructure. In finance, the focus was more on fraud, authentication, and compliance than on a single public intrusion.

Energy appears on two fronts. First, as a strategic sector affected by the regulatory debate over the technical cybersecurity standard for the electric sector. Second, through the Espinos case listed on a ransomware leak site. Technology also had a clear presence, with Difor and Verbux in extortion claims, while construction and logistics appear in Layher, Incolur, and Servicios Marítimos MG.

The public sector was exposed on two different fronts, one incident-related and one regulatory. The defacement against Migraciones showed a visible operational and communications failure, while ANCI and other agencies continued pushing standards, reports, and preventive alerts. The sector-wide picture does not point to a single failure point, but to cross-cutting pressure that mixes availability, authentication, fraud, and data exposure.

Compared with July, August showed a sharp rise in ransomware and a drop in documented fraud or phishing. Cases involving ransomware or extortion rose from 9 to 24, while regulatory activity fell from 24 to 16 and documented fraud declined from 7 to 2. The shift in the dominant threat, from regulation to ransomware, is the clearest signal this month.

The trend was not only numerical. In August, extortion pressure increased because several victims appeared on leak sites without public confirmation, and because the cases with solid evidence were concentrated in healthcare and in at least one company with local operations. The weight of campaigns tied to compromised identities also grew, which aligns with Sophos’ finding that 64% of ransomware attacks originated in credentials, phishing, or brute force.

On the regulatory side, the movement was smaller than in July, but deeper. The debate is no longer about broad principles, but about how to operationalize reporting, deadlines, authentication, continuity and sanctions. The next development to watch is whether a possible delay of Law 21.719 moves forward and how far it goes, because that could change compliance timelines across entire sectors without altering the underlying requirements.

In vulnerabilities, the signal points to persistent exposure in common enterprise software. Zimbra and Spring Security dominated the month on the technical side, while ANCI showed preventive concern about supply chains and AI tools. Monitoring should focus on email, authentication, open integrations, and any product that combines remote administration with Internet exposure.

Security recommendations for teams in Chile

Security teams in Chile should treat August as a preparation month for a more demanding second half of the year. The mix of ransomware, AI-assisted fraud, regulatory pressure, and critical vulnerabilities requires closing gaps in access, monitoring, continuity, and communications, not just technical controls.

First, strengthen defenses against compromised identities. This month’s material shows that this was the most repeated vector in ransomware and also in digital fraud. Teams should review whether MFA is truly enforced, harden account recovery, limit reused credentials, and monitor anomalies in remote access, admin consoles, email, and VPNs. In environments with Zimbra, Spring Security, or embedded LDAP workflows, exposure should be prioritized.

Second, review how incidents are reported and escalated. Law 21.663 and its regulations already impose short notice and update windows for PSE and OIV. That requires operational runbooks, clear owners, time tracking, and communication templates. In practice, many organizations fail not because they cannot detect an incident, but because they cannot organize the sequence of reporting, containment, and evidence.

Third, harden defenses against AI-driven fraud. This month’s coverage shows vishing with voice cloning, highly personalized messages, and impersonation of authorities. That requires dual verification for sensitive operations, stronger protection for voice and email channels, very specific internal awareness campaigns, and monitoring for behavioral patterns rather than fixed rules. The fraud team needs to work with cybersecurity and customer service.

Fourth, prepare for leak sites and unconfirmed claims. August brought several cases of that kind. The practical recommendation is to treat those notices as intelligence signals, but not as final proof of impact without a minimum internal validation. If the organization is named, it should trigger exposure review, log correlation, backup protection, and public response scripts.

Frequently Asked Questions

What changed between July and August ransomware pressure in Chile?

August ended with 24 cases where ransomware or extortion was the primary focus, compared with 9 in July, while regulatory developments fell from 24 to 16. The shift was not only in volume, but also in the dominant threat, because ransomware overtook regulation as the month’s main risk.

Which sectors combine the most technical and regulatory risk in Chile?

Healthcare, telecommunications, and financial services carry the most sensitive signal. Healthcare had the clearest ransomware case, telecommunications came under investigation for possible cyberespionage, and the financial sector absorbed fraud, ARC, SFA, and reporting obligations under Law 21.663. The pattern is spread across Incidents, Regulation, and Sectors.

What type of ransomware dominated in Chile during August?

Extortion dominated, with incomplete certainty about the final impact. Of the 24 cases, 3 involved confirmed encryption, 1 was exfiltration without encryption, 3 were limited to a leak site, and 17 could not be further classified from the available material. That means each claim should be read cautiously, not as proof of effective encryption.

What concrete obligations did Law 21.663 and ARC bring for banks and other actors?

ARC replaced the coordinate card as the general mechanism starting August 1, and Law 21.663 imposes very short reporting deadlines for significant incidents, with early warning, updates, an action plan, and a final closeout. Those requirements apply to banking, financial services, and payment methods, according to the month’s regulatory material.

Which vulnerabilities should a Chilean IT team prioritize today?

This month’s short list includes Zimbra Collaboration, Spring Security, Haiwell IoT Cloud HMI Gateway, and PAN-OS. Zimbra stands out for confirmed active exploitation, Spring Security for critical severity, and Haiwell for its potential impact on industrial environments. The vulnerabilities table summarizes the status of each one.

Why does August point to something more complex than just more attacks?

Because the month combined attacks, leak site claims, AI-enabled fraud, scrutiny of telecommunications, and an intense regulatory agenda. That creates simultaneous pressure on operations, compliance, and communications. An incident was not always confirmed, but it was still enough to force a review of exposure and response times.

Material limitations

This report was built exclusively from the facts dated August 2026 included in the provided material. No internet was used, and no external information was added. Facts without a confirmed date were left out of the indicators and were not counted in any total for the period.

A zero indicator, especially for CVEs or any other axis, means it did not appear in this month’s analyzed material, not that it did not exist in Chile or across the region. In this specific snapshot, 6 critical CVEs were mentioned, but that still does not allow any inference about the absence of other active vulnerabilities outside the received corpus.

The time window for the indicators is the same one stated above, 76 facts dated August 2026. The comparative data comes from the previous month according to the prior report, and it was used only for contrast. Detection telemetry, blocks, or scans were not added to the incident counts.

Sponsored sources, commercial releases, advertorials, and consumer social media not included in the permitted list were also left out as primary evidence. When the material only provided leak-site claims or preliminary alerts, they were treated as such and not as confirmed breaches. In ransomware, that is key to avoiding confusion between a mention and verified impact.

Sources