Peru Cybersecurity Snapshot, Aug. 2026
Ransomware led August in Peru, with 64 verified incidents, 25 extortion cases and 15 regulatory moves, plus fraud and health data leaks.
Key findings
- Ransomware remained the top threat in Peru, with 25 of 64 verified incidents and a higher share of claims on leak sites than confirmed encryption.
- Digital fraud intensified: documented cases rose from 2 in July to 8 in August, driven by spoofing, bank impersonation, deepfakes and synthetic identities.
- The regulatory agenda accelerated with 15 documented moves, up from 1 the previous month, focused on SBS, INACAL, OSIPTEL, SUSALUD and Indecopi.
- Health and finance concentrated the most sensitive incidents, including the sanction of Clínica Delgado, the EsSalud Lambayeque case and alerts on medical data and banking authentication.
- The ransomware cases of OSI, Movitecnica and Global Go show sustained pressure on health, manufacturing and transport, but public victim confirmation is still absent in several of them.
- No critical CVEs were recorded in the analyzed material, so the month’s risk was driven by extortion, fraud and intensified enforcement, not exploitation of named vulnerabilities.
- Institutional response advanced more through secondary regulation and supervision than through a general cybersecurity law, which still does not appear as an autonomous bill under parliamentary review.
Monthly reference modules
These modules are completed automatically with the verified facts dated within the period. Each one states its basis and counting criterion so the figures can be reconciled across modules. They are the recurring month-to-month reading, and the analysis that follows develops the cases without repeating this summary.
Indicator window: 66 dated facts in August 2026 · 1 after the period (excluded). Facts from earlier months are used only as comparative context in the analysis, never as volume for this period.
Executive Monthly Summary for Peru
August closed in Peru with ransomware as the dominant threat and a broader risk surface than in July, marked by 64 verified incidents, 25 extortion-focused cases, 10 uncategorized incidents, and 15 regulatory moves. The month combined claims on leak sites against local organizations, high-value financial fraud, and an intense sequence of rules on privacy, oversight, and digital security.
The most visible operational case was the fraud against EsSalud Lambayeque, where five unauthorized transfers totaling S/ 1,406,991 were reported after social engineering and remote access. At the same time, the health sector was exposed by SUSALUD's fine against Clínica Delgado for disclosing Nadine Heredia's medical record, and by Centro Médico Especializado OSI appearing in ransomware listings attributed to Kazu, although the victim was not publicly confirmed.
In banking and financial services, the month showed two different fronts. On one side, alerts multiplied around spoofing, deepfakes, synthetic identities, and authentication fatigue. On the other, the SBS and other agencies pushed regulatory changes on open finance, authorization of entities, electronic notification, operating limits, and anti-fraud cooperation with the Public Prosecutor's Office. The result is real pressure on data, identity, and payment channels, with a more active institutional response than in July.
The risk reading for the country is high because of the combination of criminal extortion, financial fraud, exposure of sensitive data, and greater regulatory density. No critical CVEs were mentioned in the material analyzed, but that does not reduce the operational pressure seen in sectors such as health, banking, transport, and manufacturing.
National overview for the month in Peru
Peru posted a concentrated risk pattern in August, centered on extortion, digital fraud, and compliance. Ransomware was the main threat, with 25 of 64 incidents, but the month also logged 8 documented fraud or phishing cases and 15 regulatory moves, a mix that helps explain the tone of the period, more reactive than preventive.
The underlying signal is twofold. On one hand, criminal groups kept exploiting the mix of impersonation, remote access, and leak sites to monetize both productive sectors and sensitive services. On the other, the state and regulators moved ahead with rules on data, continuity, digital identity, open finance, and third-party oversight, trying to close governance gaps without a general cybersecurity law yet moving through Congress.
Sector coverage was spread across seven sectors with at least one documented incident, led by health care and finance. There were also signs in transportation, manufacturing, the public sector, telecommunications, and digital services. That dispersion does not mean the risk was uniform, because several of the most sensitive cases involved medical data, credentials, and institutional accounts.
In the regional context, Peru was not an exception. Ransomware activity in Latin America continued to show leak site campaigns and double extortion, and the technical reports cited place Qilin and Kazu among the most active actors in August. The local difference was the combination of an intense regulatory agenda with high-impact reputational incidents in health care and banking.
Peru period indicators
The following table reproduces the indicators calculated for August 2026 using the reported base and time window. It does not include aggregated telemetry such as incidents, and it does not reclassify ransomware categories beyond what was already identified in the source material.
| Indicator | August 2026 | Previous month | Change |
|---|---|---|---|
| Verified events in the period (base for all indicators) | 64 | 47 | +17 |
| Indicator time window | 66 events dated August 2026 · 1 after the period (excluded) | ||
| Unclassified incidents (breaches or outages) | 10 | 14 | -4 |
| Cases with ransomware or extortion as the primary focus | 25 | 25 | unchanged |
| Confirmed asset encryption | 5 | n/d | n/d |
| Leak site mention only | 7 | n/d | n/d |
| Material did not allow classification | 13 | n/d | n/d |
| Documented fraud or phishing cases | 8 | 2 | +6 |
| Documented regulatory moves | 15 | 1 | +14 |
| Critical CVEs mentioned | 0 | n/d | n/d |
| Sectors with at least one documented event | 7 | 6 | +1 |
| Leading threat of the month | Ransomware (25 of 64 events) | Ransomware (25 of 47 events) | unchanged |
| Events with direct source confirmation | 58% | n/d | n/d |
| Aggregated telemetry figures excluded from the volume | 2 (aggregated attempts or blocks: not incidents with confirmed impact) | n/d | n/d |
Relevant incidents in Peru
August brought few incidents with full public confirmation, but several carried significant operational or reputational weight. The clearest evidence focused on health care, banking, and financial services, with ransomware claims on leak sites and a large financial scam at EsSalud Lambayeque.
EsSalud Lambayeque and the diversion of S/ 1,4 million
EsSalud reported five unauthorized bank transfers totaling S/ 1,406,991 from the Lambayeque Care Network in a case described by the coverage as a phone and digital scam involving social engineering and remote access. The episode led to complaints filed with the Police, the Public Ministry, and actions to freeze recipient accounts.
The sequence points to a classic abuse of trust pattern, not a sophisticated technical intrusion. According to the cited coverage, tools such as AnyDesk and UltraViewer were used, passwords were provided by internal staff, and bank support was impersonated to operate on the institutional account.
SUSALUD sanctions Clínica Delgado over Nadine Heredia's medical record
SUSALUD imposed a fine of 13 UIT on Clínica Delgado for handing over Nadine Heredia's full medical record to the Public Ministry without consent or a court order. The case became the month's leading example of improper exposure of health data and reignited debate over clinical confidentiality and compliance.
The significance of the case is not limited to the sanction. It also became a regulatory warning for the broader health sector, because the MINSA statement itself warned of administrative, civil, or criminal liability for disclosing confidential patient information without authorization.
Centro Médico Especializado OSI, ransomware claim attributed to Kazu
Centro Médico Especializado OSI appeared in several threat intelligence entries as a victim attributed to the Kazu group on August 23. The sources agree on the centromedicoosi.com domain and on references to sensitive medical data or possible exfiltration, but the material does not allow confirmation of asset encryption, only a leak site or an actual data leak.
The geographic mismatch in some tracking databases, which alternate between Peru and Mexico, means the case should be treated cautiously. What can be verified is OSI's presence in the ransomware monitoring ecosystem and its identification as a health care provider based in Lima.
Movitecnica, Qilin claim, and published leak
Movitecnica was listed by Qilin on leak sites and by several aggregators as a victim in Peru on August 19. In this case, the material does suggest actual publication of information, since Darkfield and other sources describe the status as "data leaked," although there is no public confirmation from the company.
The available record does not specify whether there was operational encryption. It does show a double extortion logic, with pressure to negotiate based on data publication and references to files that would include credentials.
Global Go and the Killsec claim
Global Go, a Peruvian transportation company, was claimed by Killsec on leak sites and incident aggregators. Unlike the Movitecnica case, the evidence here opens the door to an exfiltration confirmed by the monitoring source, but there are no details on volume or type of information, and no public signal from the victim.
The case remains classified as an unconfirmed claim by the company. Its informational value lies in the convergence of several tracking platforms that match on date, sector, and country.
Active threats and campaigns in Peru
August's criminal pressure was driven more by the mix of extortion, fraud, and social engineering than by technical vulnerability exploitation. Ransomware remained the main thread, but phishing and identity impersonation became more visible in banking and payments.
Ransomware and extortion in Peru
The month recorded 25 cases with ransomware or extortion as the primary focus, with 5 confirmed encryption cases, 7 mentions only on leak sites, and 13 where the available material does not allow the exact impact to be determined. That breakdown matters because not every case carries the same operational severity.
At the most sensitive end is the case with confirmed encryption, which in this month's material does not appear alongside a robust public confirmation from the victim. At the other end are the leak-site entries, where the only available evidence is the actor's claim and the post on the extortion platform.
Kazu against the health sector
Kazu showed a clear concentration in health care. On August 23, it posted several healthcare victims in a single day, including Centro Médico Especializado OSI, and technical reports describe a broad campaign against hospitals, clinics, telemedicine, and clinical software. For Peru, that leaves a concrete warning for healthcare providers and medical data supply chains.
The material does not allow a claim that OSI's assets were encrypted. It does support the conclusion that sensitive medical data was claimed and threatened with disclosure, with ransom estimates in some monitoring databases.
Qilin against manufacturing and services
Qilin kept pressure on Movitecnica and other regional targets, with the Peruvian case placed in manufacturing. The sources reviewed point to data published on the leak site and to double extortion, with signs of stolen files that would include credentials.
Operationally, Qilin continued to target mid-sized organizations, combining exfiltration with reputational pressure. The material does not support a claim of service disruption in the Peruvian case.
Killsec and transportation
Killsec claimed Global Go, a transportation company, and aggregators classify it as a data breach or data leak incident. Although there is no public confirmation from the organization, the case is useful for showing how transportation also remains exposed to campaigns aimed at monetizing internal information or credentials.
The evidence is not enough to confirm encryption. What remains is the publication on leak sites and the claim's persistence across multiple threat databases.
Digital fraud and phishing in banking
Banco de la Nación warned about fraudulent calls and messages using phone spoofing, while Infobae described synthetic identities, deepfakes, and password fatigue as recent digital fraud techniques in the country's banks. The most visible element was impersonation of institutions, manipulation of caller ID, and attempts to capture passwords or security codes.
These cases are not ransomware, but they do share the goal of accessing accounts and draining funds. The mix of AI, social engineering, and messaging channels expanded the fraud surface for users and merchants.
Data exposure and unclassified breaches
Kambista reported a possible exposure of sensitive data in its cloud infrastructure, although it said it found no evidence of exfiltration at the time of the notice. That kind of case falls into the unclassified incident zone because no completed breach or operational disruption is verified.
The leak of police intelligence data on Telegram and the earlier circulation of "Dirin leaks" also remained a sign of exposure, but without a new confirmed hack in 2026 according to the PNP itself, as cited by the press.
Critical vulnerabilities with impact in Peru
No critical CVEs were mentioned in the material reviewed for August 2026. That does not mean there were no exploited vulnerabilities in the region, only that none were documented in the sources reviewed for this report.
| CVE | Software | Exploitation | Source |
|---|---|---|---|
| No critical CVEs were recorded in the material analyzed | n/a | n/a | Period indicator |
Regulation and compliance in Peru
August was a heavily regulatory month. SBS, INACAL, OSIPTEL, SUSALUD, Indecopi and PCM moved on privacy, continuity, identity, notification, digital governance, and consumer protection. The pattern is consistent with regulation expanding faster than the cybercrime framework law.
SBS advanced on several fronts. These included streamlining authorization for new financial and insurance companies, changing the rules for notifications through electronic mailboxes, adjusting cash limits and risk controls, and adding new rules for temporary access to credit history for entities still in the approval process. Draft measures tied to open finance and pension payments through digital wallets and apps were also released.
The most relevant issue for information security was open finance. Ozone API, citing SBS Resolution No. 01747-2026, described a model with board-approved policies, prior risk assessments, continuous monitoring of third parties, contracts with minimum clauses, and periodic reports to SBS. At the same time, the reform of authorization rules for financial entities introduced prequalification, maximum deadlines, and controlled access to consolidated credit reports during the review period.
INACAL approved NTP-ISO/IEC 29100:2026, on privacy, and NTP-ISO/IEC 27031:2026, on ICT readiness for business continuity. These are technical references, not criminal or regulatory obligations in themselves, but they clearly point compliance and resilience projects in a set direction.
SUSALUD and MINSA reinforced the confidentiality standard for clinical records after the Clínica Delgado case. OSIPTEL, meanwhile, ruled that mobile service can only be reactivated after a stolen phone is recovered once identity has been verified, a measure aimed at stopping impersonation and fraud tied to line recovery.
On consumer protection and privacy, Indecopi sanctioned Interbank for spam calls and BCP for violating a consumer's privacy through debt collection communications sent to third parties. These are separate from the purely cyber domain, but they help frame the month: compliance on data handling, commercial contact, and consent remains under sustained scrutiny.
| Organism | Measure | Security or privacy impact | Source |
|---|---|---|---|
| SBS | Reform of the authorization rules for financial and insurance entities | Temporary and controlled access to credit reports, prequalification, and security measures | El Peruano, Infobae Perú |
| SBS | Agreement with the Public Prosecutor's Office | Greater exchange of financial information for cyber fraud, extortion, and AML/CFT | El Peruano |
| SBS | Amendment to the electronic mailbox notification rules | Notification adjustments and institutional compliance | Normas Legales Online |
| INACAL | NTP-ISO/IEC 29100:2026 and NTP-ISO/IEC 27031:2026 | Privacy and ICT business continuity | El Peruano, Andina |
| SUSALUD | Fine against Clínica Delgado | Confidentiality of medical records and health data | La República, Infobae Perú |
| OSIPTEL | Identity verification to reactivate stolen lines | Prevention of impersonation and fraud through service recovery | OSIPTEL |
Most affected sectors in Peru
Health and finance were the most exposed sectors this month, not only because of the number of incidents but also because of the scale of potential harm. Health combined an exemplary confidentiality sanction with ransomware claims against a specialized provider, alongside the backdrop of medical data breaches that continue to surface in public debate.
In finance, the pressure did not come from a single incident, but from a buildup of digital fraud, phishing, regulatory changes and identity alerts. Traditional banking faced spoofing, fake calls, fines for unsolicited communications and campaigns that exploit deepfakes and synthetic identities. The SBS responded with stricter rules on third parties, operational risk and access to sensitive information.
Transport and manufacturing also appeared on the extortion radar. Global Go and Movitecnica show that ransomware groups did not stay confined to the financial or health sectors, but kept looking for organizations with marketable data and reputational leverage. In both cases, the public signal came mainly from leak sites and specialized aggregators.
The public sector had its own layer of exposure, with leaks of police intelligence information and discussion of institutional capabilities against cybercrime. Although the material does not confirm a new hack against DIRIN in August, it does show that the data is circulating and remains exploitable in open or semi-public channels.
Trends and signals to watch in Peru
Compared with July, verified activity rose sharply from 47 to 64 incidents, while unclassified cases fell and fraud, phishing, and regulation all increased markedly. Ransomware remained the dominant threat, but the month tilted much more toward public extortion, financial fraud, and compliance rules.
The most visible shift was in regulation. Going from 1 to 15 regulatory moves in one month reflects more than a heavier flow of bulletins, it points to a state and regulators moving faster to build rules for digital identity, open finance, continuity, and data handling. At the same time, the advance of technical standards suggests a growing standardization of the language of privacy and resilience.
The fraud mix also changed. Documented cases rose from 2 in July to 8 in August, driven by spoofing campaigns, bank impersonation, and narratives involving deepfakes and synthetic identities. That points to an environment where operational risk is increasingly concentrated in authentication, customer service, and account recovery rather than in malware itself.
In ransomware, the volume held at 25 cases, but public visibility changed. August showed more signs of leak sites and extortion than confirmed encryption. That distinction matters for response teams, because media and legal pressure can build even when disruption is not proven.
Security recommendations for teams in Peru
Security teams should prioritize controls over identity, customer service channels, and third parties. The month showed that the costliest attack does not always begin with malware, but with a call, a link, or a reused credential.
First, organizations should strengthen out-of-band verification for sensitive operations, account recovery, changes to personal data, and access reversals. The spoofing and remote access cases at EsSalud show that social engineering is still enough to compromise funds or enable transfers.
Second, health care and finance need specific procedures for sensitive data. In health care, clinical confidentiality should be treated as a first-tier operational control, with access traceability, judicial order checks, and strict handling of medical records. In finance, the focus should be on risk-based authentication, session monitoring, and protection against MFA fatigue.
Third, third-party programs should include real monitoring and clear clauses. The open finance framework and SBS reform on new entities point to an environment where controlled information sharing will be more frequent, but also more exposed to vendor failures, weak integrations, and misuse of temporary data.
Fourth, ransomware response should be separated from exposure response. A mention on a leak site does not prove encryption, but it does require review of credentials, tokens, remote access, and possible information leaks. If data is also published, legal and communications management moves to the front line.
FAQ
What changed more in Peru between August and July, fraud or regulation?
Regulation changed more. In August, 15 regulatory moves were documented, compared with 1 in July, while fraud or phishing cases rose from 2 to 8. The mix points to stronger institutional response and more visible criminal activity at the same time, as shown in Regulation and compliance in Peru and Trends and signals to monitor in Peru.
Did the month’s ransomware cases always involve system encryption?
No. The material distinguishes 5 cases with confirmed encryption, 7 mentioned only on a leak site, and 13 where the exact impact cannot be determined. For that reason, a ransomware claim in Peru does not automatically mean operational disruption. The classification appears in Period indicators in Peru and Active threats and campaigns in Peru.
Which sectors were most exposed because of the combination of incidents and rules?
Health care and finance were the most exposed. Health care included the fine against Clínica Delgado and the OSI case attributed to Kazu, while finance concentrated spoofing, digital fraud, changes at SBS, and sanctions for improper commercial contact. The cross-reading is developed in Most affected sectors in Peru and Regulation and compliance in Peru.
Were any critical vulnerabilities exploited in Peru during August?
No critical CVE was mentioned in the material reviewed. That does not mean vulnerabilities were not exploited in the region, only that they were not documented in the month’s sources. The nuance appears in Critical vulnerabilities with impact in Peru and in Limitations of the material.
Which August case mattered most for health care and privacy?
Clínica Delgado’s case, because it combined a SUSALUD fine with public debate over medical confidentiality, sensitive data, and consent obligations. At the same time, the OSI case added pressure through ransomware and a possible leak of medical data. The two events complement each other in Relevant incidents in Peru and Active threats and campaigns in Peru.
What should a Peruvian SOC look at after reading this report?
It should look at authentication, privileged accounts, recovery of lines or accounts, use of remote access software, and exposure on leak sites. It also needs to track the regulatory shift on third parties, privacy, and continuity. The practical response is summarized in Recommendations for security teams in Peru, cross-referenced with the cases of EsSalud, Banco de la Nación, and SBS.
Material limitations
This report was built exclusively from the material provided for Peru and August 2026. The indicator window includes 66 dated facts from August 2026 and excludes 1 fact dated after the period. Undated facts were not counted.
A zero value for any indicator, especially critical CVEs, means it did not appear in this month’s analyzed material, not that no critical vulnerabilities existed in the region. The same applies to any category that was not observed. Its absence from the report does not mean the phenomenon did not occur.
The calculation base for the indicators is 64 verified facts from the period, and the predominant threat was ransomware, with 25 of 64 facts. Two aggregated telemetry figures were also excluded, as they correspond to automated attempts or blocks and not to incidents with confirmed impact.
Consumer social media and sponsored or commercial posts were left out of the body as primary evidence, except when the information was corroborated by permitted and relevant sources. When a source was only a leak site claim or an unconfirmed account, the report treated it as such and did not elevate it to independent confirmation.
Sources
- A Look at Peru: Two Open Finance Paths at Once - Ozone APIOzone API
- EsSalud: cuatro funcionarios en la mira por presunto peculado en LambayequeDiario Correo
- SBS publica proyecto de norma sobre lavado de activos y financiamiento del terrorismoAgencia Andina
- PCM: facultades legislativas promueve medidas para fortalecer la modernización del EstadoAgencia Andina
- SBSPerú Proposes New Regulation to Combat Money ...Coinfomania
- La inviolabilidad de los datos médicosLa República
- Minsa advierte sanciones por difundir información confidencial de pacientes sin autorizaciónExitosa Noticias / MINSA
- Gobierno presenta al Congreso pedido de facultades legislativas por 120 díasRPP
- Minsa advierte sanciones por difundir información confidencial de pacientes sin autorizaciónExitosa Noticias
- SBS permitirá que nuevas financieras y aseguradoras accedan a historial crediticio de los clientes antes de abrirInfobae Perú
- Investigaciones fiscales accederán a más información financiera: SBS y Ministerio Público cooperanEl Peruano
- SBS optimiza autorización de empresas del sistema financiero y de segurosEl Peruano
- SBS amplía los montos de operaciones en establecimientos financieros y EEDE para impulsar la inclusión ruralHazlo Digital
- Consejo de Ministros aprueba proyecto de ley de delegación de facultades legislativasAgencia Andina
- Nadine Heredia: Susalud sanciona a Clínica Delgado por entregar su historia clínica sin consentimientoCaretas
- Clinica Delgado Fined Over Nadine Heredia Medical RecordsThe Nation View
- Sancionan a la Clínica Delgado por entregar la historia clínica de Nadine HerediaInfobae Perú
- Dilema fintech ante una posible exposición de datosiupana
- Identidades sintéticas y técnicas de fatiga: contraseñas ya no frenan el fraude digital y bancos en Perú encienden las alertasInfobae Perú
- El regulador financiero de Perú flexibiliza los calendarios de pago de empresas y ciudadanos por 'El Niño'Notimérica
- Fuga de datos personales en Perú: lo que proponen tres empresas israelíes de ciberseguridadGestión
- SBS amplía el límite diario para retiros y depósitos en establecimientos de operaciones básicasLP Derecho
- El Peruano te informa: consulta aquí las principales normas legales para hoy miércoles 26 de agosto del 2026El Peruano
- Susalud sanciona a clínica Delgado por entregar historial clínico de Nadine Heredia sin autorización a FiscalíaLa República
- Cómo videos hechos con IA destruyeron la vida digital de mujeres víctimas de deepfakesAndina
- Operaciones financieras: conoce los nuevos límites en establecimientos de operaciones básicasEl Peruano
- Redacted data breach — Kazu ransomware leak (2026)Darkfield (Orizon)
- Resolución SBS Nº 02040-2026Actualidad Empresarial
- Perú pone fecha a FRTB e IRRBB: qué tiene que decidir la bancaLa Sala Estratégica
- EsSalud retira a dos funcionarios de Lambayeque tras fraude de S/1.4 millonesDiario Correo
- Peru Data Protection & Privacy Regulation MonitorDataProtection.gi / GDPRI
- Yield Farming Web3 en Perú: Guía Comparativa 2026Peru Yield Desk
- Controversias tributarias: SBS fija nuevo tratamiento contable para pagos de entidades supervisadas | NoticiasPerucontable
- SBS prevé una "revolución de competencia" en el mercado financiero peruano con las Finanzas Abiertas - Blog de Cuánto está el dólarCuánto está el dólar
- Senador Carlos Caballero visita Secretaría de Gobierno y Transformación DigitalCongreso de la República del Perú
- Prisión preventiva para 10 investigados por presunta red de extorsión en QuitoFM Mundo / NotiMundo
- Call center de extorsión en Quito: la empresa intervenida constaba activa y tenía USD 50.000 de capitalExtra
- Resolución SBS Nº 02040-2026Actualidad Penal
- Listado de víctimas Kazu en XIntel and Breaches (X)
- Killsec Strikes Peruvian Firm Global GoDexpose.io
- La Contra / Colectivo PAS - bloque sobre transferencias no reconocidas en EsSaludYouTube
- SBS fija nuevo tratamiento contable para pagos de entidades supervisadasEl Peruano
- Perú alista Estrategia Nacional de Ciberseguridad: trabaja marco de gobernanza digitalAgencia Andina
- SBS dispone medidas temporales para flexibilizar el pago de créditos de deudores afectados por el fenómeno de El NiñoGestión
- Ciberseguridad en el sector financiero: cómo prevenir el fraude sin afectar al clienteEl Noticiero
- AFP: SBS propone pagar aportes con billeteras digitales y appsRevista Economía
- Un ciudadano chino dirigía una red acusada de usar imágenes manipuladas para presionar a deudores desde QuitoInfobae América
- Indecopi multa a tres bancos con más de S/281.000 por impedir que usuarios presenten reclamosLa República
- Ciberseguridad en el sector financiero: cómo prevenir el fraude sin afectar al clienteCS TIC TV
- Resolución SBS Nº 02104-2026Actualidad Penal
- Kazu Ransomware Targets Centro Médico Especializado OSI in PeruDexpose
- Centro Médico Especializado OSI: Healthcare Solutions — KAZU Ransomware AttackBreach House
- Centro Médico Especializado OSI: Healthcare Solutions — KAZURansomware.live
- La lucha contra la corrupción de datos en el Perú: entre filtraciones masivas y un marco legal que avanzaRuwamux
- Global Go Listed by killsec Ransomware GroupGalaxyWarden
- Global Go — KILLSEC Ransomware AttackBreach House
- Ransomware Group kazu hits Centro Médico Especializado OSI: Healthcare SolutionsHookPhish
- Victim: Global Go - KillsecRansomware.live
- Ransomware Group killsec Hits: Global GoHookPhish
- Victim: Centro Médico Especializado OSI: Healthcare Solutions – kazuRansomware.live
- Política de Privacidade - MiraMira
- O Peru está preparando uma plataforma criptografada para denúncias de extorsão a fim de proteger a identidade das vítimasNotiBrasil
- Centro Médico Especializado OSI: Healthcare Solutions — ficha de víctima ransomwareDragons Community
- Global Go data breach — Killsec ransomware leak (2026)Orizon Darkfield
- Kazu gang posts eight healthcare targets in one leak dayMedRisk.io
- [Intel MX] 2026-08-23 Kazu golpea la telemedicina: una plataforma de salud usada en México en la miraransomware.mx
- Fotos alteradas con IA y amenazas: así operaba la presunta red de extorsión en un call center de QuitoEcuavisa
- Peruanos abandonan dinero en bancos por más de S/ 100 millones al año, ¿por qué?Gestión
- Revise las principales normas legales publicadas del 16 al 22 de agosto del 2026El Peruano
- Spoofing: la modalidad de estafa que suplanta a las entidades financieras en llamadasLatina Noticias Perú
- Banco de la Nación alerta a sus clientes por nuevas llamadas y mensajes fraudulentos para robar dineroEl Machete Perú
- QILIN Ransomware Gang: 15 New Victims Posted in 72 Hours — Cross-Sector Campaign Targeting Energy, Hospitality & ManufacturingSecurity Arsenal
- SBS capacitó a cooperativas de ahorro y crédito para evitar riesgos que las quiebrenInfobae Perú
- Situación de la inteligencia artificial en nuestro paísExpreso
- Falha de Segurança Expõe Dados de Clientes em Programa de Fidelidade do Setor AéreoDPO Net
- Latam Pass Data Breach: Exposed BIN Data Creates Fraud Risk Beyond Partial Card ClaimsTechTimes
- El fin de AFOCATU: SBS cancela registro de la asociación y le impide otorgar certificados contra accidentes de tránsitoInfobae Perú
- Así fue el robo de S/1,4 millones de EsSalud Lambayeque: la falsa llamada, el acceso remoto y las transferencias que nadie detuvoInfobae Perú
- Ciberdelincuentes acceden a claves y token bancario de EsSalud Lambayeque para robo millonarioInfobae Perú
- Clientes del Banco de la Nación bajo ataque: Estafadores siguen llamándoles para robar su dineroInfobae Perú
- Renovación Popular intenta criminalizar la libertad de opiniónLa República
- LATAM Pass sofre ataque cibernético e expõe dados de clientesMinuto da Segurança
- ¿Ministro del Interior ‘se rinde’ ante criminalidad?: “Tienen mejor tecnología que nosotros”, aseguró ante CongresoInfobae
- 83 victims for Peruransomware.live
- ANPD avalia como plataformas digitais atuam para prevenir conteúdos criminosos e proteger crianças e mulheres na internetLegismap
- A fiscalização da ANPD e os desafios de conformidade à LGPD para as empresasBSA Advogados
- Red Prestacional Lambayeque archivosEl Machete
- Nota sobre denuncia de EsSalud y sustracción de S/1,4 millones en LambayequeYo Soy Independiente
- Resolución SBS Nº 02052-2026Actualidad Empresarial
- Movitecnica Data Breach in 2026BreachSense
- OCURRE AHORA | segmento sobre estafa en EsSalud LambayequeYouTube
- EsSalud: Denuncian sustracción de S/1,4 millones mediante transferencias bancariasDiario Correo
- Resolución SBS Nº 02052-2026Actualidad Penal
- Renovación Popular propone ley que castigue con cárcel a quienes hagan “apología del delito” durante crisis políticaInfobae
- Ransomware Group Qilin Hits: MovitecnicaHookPhish
- Publicación sobre posible víctima de ransomware Movitecnica en PerúVenariX en Español (X)
- Movitecnica — QILIN Ransomware AttackBreach House
- Movitecnica data breach — Qilin ransomware leak (2026)Darkfield (Orizon)
- Movitecnica Listed by Qilin Ransomware GroupGalaxyWarden
- Movitecnica: Unconfirmed Breach Claims & DoxxScan RatingRecentBreaches
- Suplemento Jurídica: ¿Qué leyes necesita el Perú para impulsar la transformación digital y atraer inversión?El Peruano
- (Perú) ANP: Proyecto de ley amenaza libertad de prensa y criminaliza labor periodísticaPressenza
- SBS propone modificación al marco regulatorio del sistema financiero y asegurador para garantizar adecuado funcionamiento de las EAFEl Comercio
- SBS propone nuevas formas de pagar aportes a las AFPLa República
- Resolución SBS Nº 02038-2026Actualidad Penal
- Brazil's ANPD emerges as a powerful enforcer of data privacyManageEngine
- Brazil's regulator shuts down biometric matching for classroom attendanceBiometric Update
- Denuncian presunto fraude informático por S/1.4 millones en agravio de EsSalud en LambayequeLa República
- Ciberdelitos con inteligencia artificial: Suplantación de voz y comprobantes falsos, el nuevo riesgo en Yape y WhatsAppInfobae Perú
- EsSalud denuncia desvío de casi 1.5 millones de solesAmérica Televisión - Canal N
- EsSalud denuncia robo millonario: Sustraen más de S/ 1,4 millones de cuenta institucionalInfobae Perú
- Roban más de S/1.4 millones de cuenta de EsSalud en Lambayeque y reclaman a ScotiabankInfobae Perú
- Resolución SBS Nº 02037-2026Actualidad Penal
- Alerta de monitoreo sobre publicaciones de cibercrimen con menciones a organizaciones de Perú (actividad no confirmada)VECERT (radar público en X/Twitter)
- Indecopi sanciona a Interbank por llamadas spamConsumidor.gob.pe / Indecopi
- Indecopi dispuso sancionar a Interbank por realizar llamadas spamForbes Perú
- Riesgo de mercado: SBS somete a consulta nuevo reglamento para entidades financierasEl Peruano
- El Peruano te informa: consulta aquí las principales normas legales para hoy martes 18 de agosto del 2026El Peruano
- Suplemento Jurídica: ¿qué leyes necesita el Perú para impulsar la transformación digital y atraer inversión?El Peruano
- Facultades legislativas: tras cuatro sesiones del Consejo de Ministros, el pedido sigue sin llegar al CongresoEl Comercio
- Boletín normativo del 18 de agosto de 2026Mercurio Legal
- Empresas de seis sectores tienen hasta el 10 de septiembre para adecuarse a las primeras reglas de IA en PerúHazloDigital.pe
- Resolución SBS Nº 02051-2026Actualidad Penal
- Proponen modificar regulación para funcionamiento de Empresas Administradoras de FondosNotiPerú
- Estas son las normas legales más importantes del lunes 17 de agosto de 2026Andina
- Filtración expone datos de inteligencia policial, operativos con drones y miles de registros de ciudadanos venezolanos en TelegramInfobae Perú
- Bancos y aseguradoras listos para administrar jubilaciones en Perú si se aprueba nuevo reglamento SBSInfobae
- Resolución SBS Nº 02051-2026ActualidadCivil.pe
- Cobertura de noticias vinculadas a Interbank y supervisión de la SBSGestión
- El Peruano te informa: principales normas legales para el lunes 17 de agosto de 2026El Peruano
- ¿Qué tan segura es la identidad digital en el Perú para las operaciones financieras?NotiPerú
- SBS estableció nuevas medidas para reforzar la protección del dinero de los ahorristasAndina
- Perú.- SBS estableció nuevas medidas para reforzar la protección del dinero de los ahorristasNotiPerú
- Nueva Ley de Protección de Datos: claves para evitar multas de S/275 milSeccioN Noticias
- Nueva agenda de seguridad entre Perú y Estados Unidos: implicancias para el sector financieroDLA Piper
- How Banks in Latin America Ensure Compliant Customer CommunicationsDocPath (iagovernance.com / global.docpath.com)
- La proporcionalidad ordena la gobernanza de la IA financiera en América LatinaReal OneAmerica
- Protección de Datos e IA en Latinoamérica: guía país por paísIA Governance
- Deepfakes y estafas románticas: así usan la IA los ciberdelincuentes para manipular a sus víctimas en PerúInfobae Perú
- Empresas de Gobierno | olvidamisdatosOlvidaMisDatos
- SBS fija nuevas multas para bancos, AFP y aseguradorasBaker Tilly Perú
- Ley 31814: cómo prepara tu equipo el plazo de setiembreMissyera
- IA y regulación en Perú: multas y sectores con mayor exposiciónGestión
- ALERTA LEGAL – SE ACERCA EL PLAZO PARA LA ADECUACIÓN A LAS NUEVAS OBLIGACIONES DEL REGLAMENTO DE INTELIGENCIA ARTIFICIALSRPM Abogados
- Expediente 14601/2025-CR – Proyecto de Ley que Promueve la Incorporación Progresiva, Ética y Fiscalmente Responsable de la Inteligencia Artificial y la Automatización Robótica de Procesos en la Gestión PúblicaCongreso de la República del Perú
- Expediente 14530/2025-CR – Proyecto de Ley que Modifica la Ley N.º 31297, Ley del Servicio de Serenazgo MunicipalCongreso de la República del Perú
- Expediente 14760/2025-CR – Proyecto de Ley que fortalece la lucha contra el cibercrimen mediante la regulación del uso ilícito de inteligencia artificial y la protección de la identidad digitalCongreso de la República del Perú
- Proyecto de Ley que Promueve la Incorporación Progresiva, Ética y Fiscalmente Responsable de la Inteligencia Artificial y la Automatización Robótica de Procesos en la Gestión Pública (PL 14601/2025-CR, Perú)Sistemas de Algoritmos Públicos – Universidad de los Andes
- Proyecto de Ley que Modifica la Ley N.º 31297, Ley del Servicio de Serenazgo Municipal, para fortalecer su interoperabilidad tecnológica, profesionalización y modernización (PL 14530/2025-CR, Perú)Sistemas de Algoritmos Públicos – Universidad de los Andes
- SBS propone incluir cuatro seguros agrícolas en régimen simplificado de debida diligenciaNotiPerú
- Revise las principales normas legales publicadas del 9 al 15 de agosto del 2026El Peruano
- ¿Tu Información personal y familiar está segura? Protección penal y administrativa de datos sensibles en el PerúZH Consultores Perú
- Resolución SBS Nº 02022-2026Actualidad Empresarial
- Proyecto de Ley que Establece estándares Mínimos de Inteligencia Artificial en el Sistema Universitario Nacional (PL 14710/2025-CR)Sistemas de Algoritmos Públicos – Universidad de los Andes
- Proyecto de Ley, Ley que modifica el Código Penal para prevenir y sancionar la violencia sexual digital mediante inteligencia artificialSistemas de Algoritmos Públicos – Universidad de los Andes
- Proyecto de Ley, Proyecto de Ley que Complementa y Fortalece el Marco de Gobernanza, Transparencia, Control y Responsabilidad en el Uso de la Inteligencia ArtificialSistemas de Algoritmos Públicos – Universidad de los Andes
- Publicación de alerta sobre foros de ciberdelincuencia y menciones a portales de gobierno y sistemas socialesCuenta VECERT Analyzer en X
- Proyecto de Ley, Proyecto de Ley que fortalece la lucha contra el cibercrimen mediante la regulación del uso ilícito de inteligencia artificial y la protección de la identidad digitalSistemas de Algoritmos Públicos – Universidad de los Andes
- Revise las principales normas legales publicadas del 2 al 8 de agosto del 2026El Peruano
- SBS fija nuevas multas para bancos, AFP y aseguradorasBaker Tilly Perú
- Pagos digitales aceleran cierre de sucursales: sistema financiero peruano perdió una agencia física cada cinco días desde 2021Infobae Perú
- SBS propone incluir cuatro seguros agrícolas en régimen simplificado de debida diligenciaAgencia Andina
- Últimas noticias de la SBSRPP Noticias
- Open Finance: 5 riesgos de ciberseguridad ante la apertura de los datos financieros en PerúHazloDigital.pe
- MonitorIA: herramienta de la SBS usa IA para detectar riesgos en la conducta de mercadoEl Peruano
- Estafas virtuales en Perú: cómo operan y cómo denunciarLa República
- Personas podrán transferir dinero al instante con número de DNI, ¿desaparecerán celular y QR?Peru Contable
- El grupo parlamentario Ahora Nación presentó un proyecto de ley que modifica el Código Penal criminalizando la creación de contenido sexual mediante inteligencia artificialActualidad Penal
- Ola de más de 350 mil ciberataques eleva la demanda de seguros informáticos en PerúInfobae Perú
- TAPP redefine la estrategia tecnológica de los bancos en Perú: construir, integrar o colaborarStakeholders Perú
- Diputada Marleny Arminta propone ley para sancionar la violencia sexual digital cometida mediante inteligencia artificialOficina de Comunicaciones del Congreso de la República del Perú
- SBS: Empresas de un mismo grupo financiero ya no podrán operar con reglas distintas de riesgo desde 2027Infobae Perú
- RESOLUCIÓN 01976-2026: resumen e impacto · MercurioMercurio Legal
- THEGENTLEMEN Ransomware Gang: 25 New Victims Posted, Sector Targeting Analysis and Detection RulesSecurity Arsenal
- Regulación sobre IA en América Latina y el CaribeUniversidad de los Andes (Colombia) – Proyecto Algoritmos
- INKA Group GmbH Co Listed by The GentlemenGalaxy Warden
- Publicación sobre ataque de Krybit a HYMIASA con impacto en operaciones en PerúTweetThreatNews (X)
- Presentan proyecto para sancionar uso de inteligencia artificial en creación de imágenes sexuales no consentidasÉxitosa Noticias
- Plantean pena de hasta seis años de cárcel por creación de contenido sexual mediante inteligencia artificialLP Derecho
- PNP frustra presunto fraude de más de S/700 000 y detiene a tres personasPolicía Nacional del Perú / YouTube
- Indecopi multa con más de S/118.000 a Pacífico Seguros por realizar llamadas spam a consumidoresLa República
- Congreso: Estos son los proyectos con los que abre su agenda mientras el pedido de facultades del Gobierno sigue en compás de esperaEl Comercio
- Confirman multa al BCP por enviar cartas notariales de cobranza a terceros ajenos a la deuda [Res. 352-2026/Indecopi-AQP]LP Derecho
- Ley 29733 de Protección de Datos Personales de Perú | Régimen sancionadorSMARTFENSE
- Ciberataques al sector público peruano crecen y amenazan servicios críticosEl Peruano
- Indecopi pone contra las cuerdas al BCP: banco fue sancionado por exponer la deuda de un clienteEl Popular
- Latin America's public bodies keep appearing on leak sitesIntelFusions
- Nota sobre la Resolución SBS Nº 01741-2026 y la obligación de informar públicamente incidentes de ciberseguridadBrújula Digital
- Conozca las nuevas normas técnicas aprobadas para gestión, privacidad y ciberseguridadEl Peruano
- El Peruano te informa: consulta aquí las principales normas legales para hoy lunes 31 de agosto del 2026El Peruano
- Estas son las normas legales más importantes del lunes 31 de agosto de 2026Agencia Andina
- SBS Perú: cómputo en la nube en el sistema financieroRenaiss.io
- QILIN Ransomware Gang: 26 New Victims Posted in 100-Posting Window, APAC Expansion, Government Targeting and Detection RulesSecurityArsenal
- KAZU Ransomware Gang: 9 Healthcare & Professional Services Victims Posted in Single-Day Surge — Targeting Analysis & Detection RulesSecurityArsenal
- Qilin Ransomware Targets MovitecnicaDexpose
- Qilin Ransomware Group Expands Extortion Targets to Include Federal Agency ATF and Major Private EnterprisesBrinzTech
- Document Tech Firm Hit as New Cyber Gang Expands ReachBankInfoSecurity
- Victim: Movitecnica – qilinransomware.live
- Meducar: Telemedicine and Patient Management System — KAZU Ransomware AttackBreach House
- Inteligencia artificial incrementa ciberataques en Perú: más de 350 mil amenazas digitales registradas en 2026Diario Viral
- Perú superó más de 350 mil amenazas digitalesYouTube
- Tres empresas israelíes buscan blindar al Perú de los ciberataquesYouTube
- Meta, TikTok y Roblox son claves para investigar ciberdelitos: Perú suma 785 condenasLa República
- ¿Cómo robaron S/4 millones de una empresa?: Cayeron tras fraude informático en LimaYouTube
- Miles de nombres, direcciones y números de teléfono: ¿PNP hackeada otra vez?YouTube
- OSIPTEL frente a robo de celulares: usuarios recuperarán su línea tras verificación de identidadOSIPTEL
- Resolución Nº 000224-2026-GG/OSIPTELActualidad Civil
- RESOLUCIÓN SBS N° 02027-2026 Modifican la Resolución SBS N° 04131-2025 y el Reglamento de Notificación vía Casilla Electrónica de la SBSNormas Legales Online
- DNI digital: Reniec aprueba su implementación y anuncia emisión gratuitaInfobae Perú
- Multan con más de S/ 400 mil a banco peruano por llamadas spamInfobae Perú
- Indecopi multa al BCP por métodos abusivos de cobranza a tercerosLa Lupa
- Lexacaucho Ransomware Claim (2026) — What’s Alleged & Am I Affected?RecentBreaches
- Lexacaucho — THEGENTLEMEN Ransomware Attack | Breach HouseBreach House
- Lexacaucho Listed by thegentlemen Ransomware GroupGalaxyWarden
- Lexacaucho: Unconfirmed Breach Claims & DoxxScan™ RatingRecentBreaches
- Lexacaucho Data Breach in 2026BreachSense
