CiberLATAMbywhalemate
Intelligence reportJul 13, 202617 min read

Situación Nacional de Ciberseguridad - Junio 2026 - Perú

June brought 22 incidents in Peru, 8 ransomware cases, and an intense regulatory agenda focused on personal data and open finance.

Situación Nacional de Ciberseguridad - Junio 2026 - PerúwhalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are automatically filled with verified facts and sources from the period. They are the recurring month-to-month reading; the later analysis develops the cases without repeating this summary.

CIBERLATAM / WHALEMATE Verified Signal Monthly Dashboard June 2026 · Peru INCIDENTS 22 breaches or leaks with source RANSOMWARE 8 documented cases CVEs 0 no single CVE FRAUD 4 documented phishing REGULATION 10 rules or sanctions TOP THREAT Incidents 22 events
Verified Signal Monthly Dashboard — Fixed-period summary for Peru.
MONTHLY FIXED MODULE Threat axis breakdown June 2026 · Peru Incidents 22 Regulation 10 Ransomware 8 Fraud 4
Threat axis breakdown — Heuristically classified verified incidents by threat type.
MONTHLY FIXED MODULE Sectoral distribution of signal June 2026 · Peru Public sector / OIV 20 Other 19 Finance 10 Telecom 5 Energy 3 Retail / Consumer 2 Technology 2 Education 2
Sectoral distribution of signal — Heuristic classification of verified events by affected or mentioned sector.
MONTHLY FIXED MODULE Critical Infrastructure in Peru Verified facts on public sector, utilities, and essential services Public sector / government 20 Energy / utilities 4 Telecom / connectivity 4 Classified facts 8
Critical Infrastructure in Peru — Verified facts on public sector, utilities, and essential services

Monthly executive summary for Peru

June 2026 closed in Peru with a pattern dominated by concrete, visible incidents, not by critical vulnerabilities or CVE exploitation. The most sensitive case was the alleged hack of the website of the Policía Nacional del Perú, with 300,000 folders of sensitive data reportedly offered for sale and the institutional portal taken offline while the investigation moved forward. That was followed by Integrated Digital Security Alert No. 096-2026-CNSD, published by the PCM on June 15, which consolidated an interagency response to attacks detected in Peru’s digital environment.

The month also brought extortion signs with sector-wide impact. The Nova group claimed responsibility for an attack on SUNASS and threatened to publish allegedly stolen data if negotiations did not begin. Days later, Galaxy Warden listed San Silvestre School as a victim of Krybit, with internal files exfiltrated. In parallel, Red Piranha reported that Peru registered four ransomware victims in the week of June 23 to 29, confirming the operational continuity of this type of attack during the period.

On the regulatory front, Peru saw intense activity. The ANPD sanctioned a company for improper use of personal data with fines of up to S/ 194,000. Reniec approved an integrated policy that includes information security and data protection. In addition, the SBS continued advancing its open finance and BaaS framework, with cybersecurity as an entry requirement and a regulatory sequence that begins in July 2026 and extends toward 2028.

The risk reading for Peru in June is high. Not because of a single isolated event, but because of the combination of public incidents with data exposure, ransomware extortion, regulatory pressure, and announced mandatory compliance adjustments in personal data and open finance. The month’s picture points to an active threat environment, with exposed attack surface across government, education, public services, and the financial sector.

Peru, June 2026: regulatory focusANPD, sanctionup to S/ 194,000Data Officerexpired on 30/06SBS, BaaSopen finance 2028Reniecintegrated policy
Regulatory and compliance intensity in Peru — Regulatory actions documented in June 2026.

National overview for the month in Peru

The leading threat in Peru during June was incident reporting, with 22 documented events in the period. That volume, combined with eight cases tied to ransomware or extortion and four episodes of fraud or phishing, points to a month in which operational exposure outweighed the presence of a specific technical vulnerability. No critical CVEs were mentioned in the material, so the risk was driven by campaigns, intrusions, leaks, and control failures rather than by exploitation of widely known software flaws.

Severity was also shaped by the types of entities involved. The attack attributed to the PNP and the exposure of thousands of folders containing sensitive data, along with the SUNASS case and the inclusion of a private school on a ransomware leak site, show that hostile actors targeted public agencies and organizations with valuable or highly sensitive operational information. At the same time, regulatory progress on personal data and open finance confirms that the digital security agenda is no longer a side issue, but an operating condition for several sectors.

Qualitatively, the month's risk is high. The volume of events, the concentration of incidents with potential reputational and legal impact, and the sustained presence of ransomware-driven extortion justify that assessment. The country is not facing a singular technical weakness, but a combined period of pressure on its institutions, its data, and its response processes.

Regionally, Peru is moving in step with other Latin American markets that are tightening data protection rules, raising requirements in the financial system, and at the same time dealing with ransomware campaigns and leaks. What stands out in Peru's case in June is the coexistence of a more visible institutional response with public incidents that continue to affect state agencies and sectors holding high-value information.

Peru period indicators

Indicator Value
Documented incidents 22
Documented ransomware or extortion cases 8
Documented fraud or phishing cases 4
Documented regulatory moves 10
Critical CVEs mentioned 0
Sectors with at least one documented event 7
Dominant threat of the month Incidents (22 events)
Events with direct source confirmation 73%

Relevant Incidents in Peru

Hack of the Peruvian National Police portal and offer of folders with sensitive data

On June 3, La República reported that the Peruvian National Police website had been hacked and that, after the incident, 300,000 folders with sensitive citizen data were being offered for sale, including DNI numbers and family information. Subsequent coverage by Infobae and Radio Yaraví added that the official site remained down and that the institution had issued no formal statement clarifying the scope of the episode. The situation is especially serious because of the type of data allegedly exposed and the effect on trust in a public safety agency.

The same case was described in operational detail by La República, Infobae and Radio Yaraví as an intrusion that may have affected servers linked to Dirandro, with the material being sold on the dark web for 700 dollars and a volume of about 7.8 GB. Beyond the specific attribution, the main issue for the month is the persistence of incidents targeting police infrastructure and the immediate impact on availability and information exposure.

Integrated digital security alert No. 096-2026-CNSD

On June 15, the PCM published Integrated Digital Security Alert No. 096-2026-CNSD, with a report and technical analysis of attacks on public entities and private companies observed that day in Peru. The document was prepared jointly by the Secretariat of Government and Digital Transformation, the Joint Command of the Armed Forces, the Army, the Navy, the Air Force, the National Intelligence Directorate and the National Police, among other institutions. That coordinated effort shows a state response aligned around events from that day.

The significance of this alert lies not only in its content, but also in what it reveals about the readiness of the public ecosystem. The existence of an interagency product of this kind suggests there was enough activity to trigger consolidation, analysis and dissemination capabilities. In a month marked by incidents, that material serves as a sign that national coordination was used as a containment and visibility mechanism.

Unauthorized access incident in Sismate

An Infobae report on the episode that occurred on May 20, but was published in June, said the Ministry of Transport and Communications confirmed unauthorized access to the Sismate system through the account of provider Consorcio Everbridge. From that infrastructure, mass messages with false information and political content were allegedly sent. The case matters because of the third-party vector and the misuse of an official alert platform, although the incident itself took place in May and was revisited in June as a relevant precedent.

CNSD cyberattack drill announced for July

The CNSD announced that on July 16 it would carry out a 2026 Cyberattack Drill to assess and strengthen the response capacity of the country’s CSIRTs. Although it is not an incident, it does signal that the state is trying to test coordination and response processes. In the context of the month, the announcement fits the volume of events observed and the need to validate response times and escalation procedures.

Threats and Active Campaigns in Peru

Ransomware and Extortion

The Nova case against SUNASS was one of the clearest extortion episodes of the month. Dexpose reported that the group claimed to have breached the Superintendencia Nacional de Servicios de Saneamiento and threatened to publish sensitive data if no negotiation took place. The key point is not only attribution, but the pattern of public pressure, with direct communication from the leak site and a threat to disclose the data.

A second high-interest case was the appearance of San Silvestre School on Krybit's leak site on 25 June. Galaxy Warden said the group claimed to have exfiltrated internal files from the educational institution. ransomware.live already lists it as a victim associated with Krybit and Qilin, with an initial link to Qilin in January 2026. This shows continued targeting of the education sector and reuse of victims in the leak ecosystem.

There was also a reference to Corporación Primax as a victim listed by Aurora, although that mention was attributed to a specialized source and was not described with the same level of confirmation as the earlier cases. Even so, the case adds to the set of signals pointing to large companies with a broad operational footprint.

Red Piranha, in its report for 23 through 29 June, recorded four ransomware victims in Peru during that week. The data confirms that these were not isolated cases, but part of a weekly pattern of ransomware activity in the country.

Fraud and Phishing

HP highlighted AI-driven phishing attacks and deepfake-based scams as relevant risks for the Peruvian market in 2026. DPL News, citing Bitdefender's Consumer Cybersecurity Survey 2025, said more than 28 million Peruvians are exposed to digital scams. Among the most common practices are identity impersonation, fake giveaways or promotions, phishing through direct messages, and fraud powered by AI-generated images or videos.

That backdrop did not translate into a single dominant public campaign in June, but it did reflect sustained pressure on users and organizations. For security teams, the practical takeaway is that reference material now includes AI on both the defensive and offensive sides, changing the quality of deception and the speed at which malicious messages spread.

APT and Hacktivism

There was not enough verifiable material to identify a formal APT campaign during the period. The only element with hacktivist or organized-threat traits was the PNP case, where a press report mentioned a group calling itself Latam Fuckers offering data on the dark web. However, the available material does not support a persistent campaign attribution with the rigor needed to state it as such.

Critical vulnerabilities with impact in Peru

CVE Software Exploitation Source
No critical CVEs were reported N/A N/A Research for the period

Regulation and compliance in Peru

June was more a month of enforcement than abstract announcements. ANPD reported sanctions against a company for improper use of personal data, with fines of up to S/ 194 mil. That figure alone draws a clear line around the kinds of violations still carrying direct financial consequences in the country.

Law No. 29733 and the directive on the personal data officer continued to shape the compliance agenda. Garrigues said covered entities had until June 30, 2026 to align with the appointment of the personal data officer, and that the requirement applies to companies with annual sales above 2300 UIT that fall under the scenarios set out in the directive. It also noted that ANPD has published a list of appointed officers since April, adding a layer of public verification.

Reniec approved, through Jefatural Resolution No. 000065-2026/JNAC/RENIEC, its Integrated Policy and Objectives for Quality, Anti-Bribery, Information Security, Governance and Data Protection. From an internal management perspective, the move suggests security is no longer treated as a technical silo and is being folded into broader corporate governance and institutional quality frameworks.

SBS also took center stage. Ecosistema Startup and El Peruano reported that the regulator moved ahead with its Banking-as-a-Service and open finance framework, with cybersecurity as a core requirement. The BaaS regulation would be published in July 2026 and the general open finance rule in early 2027, with a one-year adjustment period and a formal start to exchanges in 2028. Open access would first be mandatory for the country’s four largest banks, then expand to other entities that can demonstrate technical capability, risk management and strong controls.

Universidad Wiener reinforced that framing by noting that current SBS circulars require robust information security risk management systems. At the same time, the Stakeholders article added that Marsh proposes five pillars to respond to the rise in cyberthreats: governance and culture, cyber risk management, controls, response capability and business continuity. Together, these signals point to a regulatory approach that no longer stops at data protection, but is beginning to condition access to open financial ecosystems.

Regulatory move Entity Date Operational read
Sanction for improper use of personal data ANPD, Ministry of Justice and Human Rights June 8 Reinforces the cost of noncompliance
Deadline to appoint personal data officer ANPD June 30 Mandatory alignment expires
Reniec integrated policy Reniec June 21 Integrates security and data protection
BaaS regulation announced SBS June 24 Opens the path to open finance
General open finance rule SBS June 24 Sets a 2027 start
Formal start of open finance SBS June 24 First phase in 2028

Most affected sectors in Peru

The public sector absorbed some of the month’s most sensitive signals. The PNP was the most visible case, with potential exposure of personal data belonging to citizens and officers, along with operational disruption on its institutional website. SUNASS also surfaced on the radar of ransomware extortion. When the month’s material puts public entities front and center, the problem is not only technical, but also one of service continuity, institutional reputation and the protection of third-party data.

Education was also exposed. San Silvestre School was listed on a ransomware leak site and, according to Galaxy Warden’s coverage, may have suffered exfiltration of internal files. The point matters because it shows that attackers are not limiting their interest to organizations with critical state functions; they are also targeting educational institutions with sensitive information on students, families and staff.

The financial system and regulated digital services appeared more through the regulatory route than through specific public incidents. The SBS made cybersecurity a requirement for open finance and BaaS, which means banks, fintechs and associated providers face higher expectations for readiness. At the same time, references from HP, DPL News and Stakeholders show that the Peruvian market is under growing pressure from phishing, deepfakes and digital fraud, forcing banks and customer service platforms to tighten verification and channel monitoring.

There were also signals for energy and fuels, although they were less defined. Gestión mentioned finance, mining and energy as exposed sectors, and Primax’s mention as a presumed ransomware victim confirms that the risk surface includes operators with wide logistical reach. The material does not allow for more precise sector-by-sector incidence measurement than what was already provided, but it does point to a convergence between government, education, finance and large-scale companies.

There is no comparative baseline because this is the first archived period with this indicator format for Peru. That prevents a strict month-to-month comparison, but it does make it possible to identify the month’s structural signals.

The first trend is the normalization of incidents with public exposure. The country is not just accumulating incidents, several were visible enough to make it into press coverage and official alerts. The second is ransomware’s persistence as an extortion tool focused on institutions and well-known brands. The third is regulatory maturation, with a state that is tightening personal data compliance and laying the groundwork for open finance with explicit security requirements.

In parallel, two fronts are worth tracking. One is the institutional response, because the announcement of the CNSD drill and the publication of the integrated alert show a coordination architecture that could become more frequent. The other is compliance, since the June 30 deadline for personal data officers and the rollout of the BaaS/open finance scheme will put concrete pressure on legal, security and technology architecture teams.

Security guidance for teams in Peru

  1. Review privileged access and third-party accounts, with attention to portals exposed to vendors and external integration schemes. The Sismate case showed that the risk is not only in the core system, but across the access chain.
  2. Prioritize personal data protection and verify technical and organizational controls. ANPD is already issuing sanctions, and the cost of failing to demonstrate adequate measures is no longer theoretical.
  3. Strengthen anti-phishing controls with email filtering, contextual training and out-of-band verification for sensitive operations. This month’s material points to more convincing campaigns, with AI use and impersonation.
  4. Prepare a specific response for ransomware extortion, including playbooks for leak sites, legal negotiation, evidence preservation and external communications.
  5. Inventory dependencies on critical suppliers and contracts with security, audit and notification clauses. This month’s events show that the third-party link can trigger large-scale incidents.
  6. For financial institutions and fintechs, align governance, risk and cybersecurity with the requirements that SBS is already beginning to set for open finance and BaaS.
  7. Validate backups, segmentation and restoration, especially in educational and public organizations, where operational continuity is often affected by intrusion and exfiltration.

Material limits

This report was prepared exclusively from the material provided for June 2026 and without internet access. No external sources, unsupported inferences, or data not present in the research were added.

Some facts are attributed by the source as not fully confirmed, particularly several mentions of leak sites, alleged data volumes, and certain market references. In those cases, they were kept only as context signals, not as categorical claims when the material did not support direct validation.

No critical CVEs were identified in the period, and no IoCs or TTPs were explicitly published by the cited sources. For that reason, no technical compromise indicators section was included.

Sources