CiberLATAMbywhalemate
Intelligence report

Peru Cybersecurity Snapshot, Aug. 2026

Ransomware led August in Peru, with 64 verified incidents, 25 extortion cases and 15 regulatory moves, plus fraud and health data leaks.

Sep 1, 202619 min read
Peru Cybersecurity Snapshot, Aug. 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are completed automatically with the verified facts dated within the period. Each one states its basis and counting criterion so the figures can be reconciled across modules. They are the recurring month-to-month reading, and the analysis that follows develops the cases without repeating this summary.

Indicator window: 66 dated facts in August 2026 · 1 after the period (excluded). Facts from earlier months are used only as comparative context in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Verified Signal Monthly Dashboard August 2026 · Peru Primary threat: Ransomware (25 of 64 incidents). Coverage: 66 dated incidents in August 2026 · 1 after the … VERIFIED INCIDENTS 64 period baseline: all counts measured from below on this total RANSOMWARE / EXTORTION 25 5 encrypted assets confirmed · 7 mention only in leak site · 13 not classified UNCLASSIFIED INCIDENTS 10 breaches or outages without threat type stated FRAUD / PHISHING 8 documented fraud campaigns REGULATION 15 standards, resolutions, or sanctions UNIQUE CVEs 0 none in the material analyzed (does not imply absence in the region)
Verified Signal Monthly Dashboard — Base: 64 verified incidents dated within the period for Peru.
MONTHLY FIXED MODULE Threat-axis distribution August 2026 · Peru Each event is counted in only one axis, so the total is exactly 64. "Unclassified incidents" is the remainder. Ransomware 25 Regulation 15 Incidents 10 Fraud 8 Unclassified 6
Threat-axis distribution — Each event is assigned to one axis based on its classification; the total reconciles to the 64 events in the period.
FIXED MONTHLY MODULE Sectoral Distribution of Signals August 2026 · Peru Base: 64 incidents in the period · total 98 because 22 incidents are classified in more than one sector. Public sector / OIV 28 Other / no sector ident… 17 Healthcare 16 Technology 11 Telecom 9 Finance 8 Energy 7 Retail / consumer 2
Sectoral Distribution of Signals — Heuristic classification by victim sector. One incident may affect more than one sector, so the total may exceed the base.
MONTHLY FIXED MODULE Critical Infrastructure in Peru August 2026 · Peru 5 of 64 facts from the period involve critical infrastructure. One fact may appear in more than one category. Public sector / government 28 Energy / utilities 1 Telecom / connectivity 5
Critical Infrastructure in Peru — Verified facts on public sector, utilities, and essential services

Executive Monthly Summary for Peru

August closed in Peru with ransomware as the dominant threat and a broader risk surface than in July, marked by 64 verified incidents, 25 extortion-focused cases, 10 uncategorized incidents, and 15 regulatory moves. The month combined claims on leak sites against local organizations, high-value financial fraud, and an intense sequence of rules on privacy, oversight, and digital security.

The most visible operational case was the fraud against EsSalud Lambayeque, where five unauthorized transfers totaling S/ 1,406,991 were reported after social engineering and remote access. At the same time, the health sector was exposed by SUSALUD's fine against Clínica Delgado for disclosing Nadine Heredia's medical record, and by Centro Médico Especializado OSI appearing in ransomware listings attributed to Kazu, although the victim was not publicly confirmed.

In banking and financial services, the month showed two different fronts. On one side, alerts multiplied around spoofing, deepfakes, synthetic identities, and authentication fatigue. On the other, the SBS and other agencies pushed regulatory changes on open finance, authorization of entities, electronic notification, operating limits, and anti-fraud cooperation with the Public Prosecutor's Office. The result is real pressure on data, identity, and payment channels, with a more active institutional response than in July.

The risk reading for the country is high because of the combination of criminal extortion, financial fraud, exposure of sensitive data, and greater regulatory density. No critical CVEs were mentioned in the material analyzed, but that does not reduce the operational pressure seen in sectors such as health, banking, transport, and manufacturing.

National overview for the month in Peru

Peru posted a concentrated risk pattern in August, centered on extortion, digital fraud, and compliance. Ransomware was the main threat, with 25 of 64 incidents, but the month also logged 8 documented fraud or phishing cases and 15 regulatory moves, a mix that helps explain the tone of the period, more reactive than preventive.

The underlying signal is twofold. On one hand, criminal groups kept exploiting the mix of impersonation, remote access, and leak sites to monetize both productive sectors and sensitive services. On the other, the state and regulators moved ahead with rules on data, continuity, digital identity, open finance, and third-party oversight, trying to close governance gaps without a general cybersecurity law yet moving through Congress.

Sector coverage was spread across seven sectors with at least one documented incident, led by health care and finance. There were also signs in transportation, manufacturing, the public sector, telecommunications, and digital services. That dispersion does not mean the risk was uniform, because several of the most sensitive cases involved medical data, credentials, and institutional accounts.

In the regional context, Peru was not an exception. Ransomware activity in Latin America continued to show leak site campaigns and double extortion, and the technical reports cited place Qilin and Kazu among the most active actors in August. The local difference was the combination of an intense regulatory agenda with high-impact reputational incidents in health care and banking.

Cronología de incidentes y medidas clave en Perú, agosto 2026Línea de tiempo con hitos del mes: fraude en EsSalud, ransomware en Movitecnica y Global Go, sanción a Clínica Delgado y normas de SBS e INACAL.EsSaludS/1.4M fraudAug 19MovitecnicaQilin leak 19AugGlobal GoKillsec claimAug 23Clínica DelgadoSUSALUD fine 26AugSBS and INACALmore regulations27 to 31 Aug
Timeline of key incidents and actions in Peru, August 2026 — Verifiable milestones of the month: fraud, ransomware, and regulation.

Peru period indicators

The following table reproduces the indicators calculated for August 2026 using the reported base and time window. It does not include aggregated telemetry such as incidents, and it does not reclassify ransomware categories beyond what was already identified in the source material.

Indicator August 2026 Previous month Change
Verified events in the period (base for all indicators) 64 47 +17
Indicator time window 66 events dated August 2026 · 1 after the period (excluded)
Unclassified incidents (breaches or outages) 10 14 -4
Cases with ransomware or extortion as the primary focus 25 25 unchanged
Confirmed asset encryption 5 n/d n/d
Leak site mention only 7 n/d n/d
Material did not allow classification 13 n/d n/d
Documented fraud or phishing cases 8 2 +6
Documented regulatory moves 15 1 +14
Critical CVEs mentioned 0 n/d n/d
Sectors with at least one documented event 7 6 +1
Leading threat of the month Ransomware (25 of 64 events) Ransomware (25 of 47 events) unchanged
Events with direct source confirmation 58% n/d n/d
Aggregated telemetry figures excluded from the volume 2 (aggregated attempts or blocks: not incidents with confirmed impact) n/d n/d
Comparativa mensual de señal verificada en PerúBarras comparando julio y agosto de 2026 en hechos verificados, fraude o phishing e incidentes sin tipificar, con ransomware estable y regulación al alza.JulyAugust47 incidents64 incidents2 fraud8 fraud14 unclassified10 unclassified25 ransomware in both monthsNote: comparison based on the indicators provided for August and the previous month's baseline.
Monthly comparison of verified signal in Peru — August surpassed July in incidents, fraud, and regulation, with ransomware steady.

Relevant incidents in Peru

August brought few incidents with full public confirmation, but several carried significant operational or reputational weight. The clearest evidence focused on health care, banking, and financial services, with ransomware claims on leak sites and a large financial scam at EsSalud Lambayeque.

EsSalud Lambayeque and the diversion of S/ 1,4 million

EsSalud reported five unauthorized bank transfers totaling S/ 1,406,991 from the Lambayeque Care Network in a case described by the coverage as a phone and digital scam involving social engineering and remote access. The episode led to complaints filed with the Police, the Public Ministry, and actions to freeze recipient accounts.

The sequence points to a classic abuse of trust pattern, not a sophisticated technical intrusion. According to the cited coverage, tools such as AnyDesk and UltraViewer were used, passwords were provided by internal staff, and bank support was impersonated to operate on the institutional account.

SUSALUD sanctions Clínica Delgado over Nadine Heredia's medical record

SUSALUD imposed a fine of 13 UIT on Clínica Delgado for handing over Nadine Heredia's full medical record to the Public Ministry without consent or a court order. The case became the month's leading example of improper exposure of health data and reignited debate over clinical confidentiality and compliance.

The significance of the case is not limited to the sanction. It also became a regulatory warning for the broader health sector, because the MINSA statement itself warned of administrative, civil, or criminal liability for disclosing confidential patient information without authorization.

Centro Médico Especializado OSI, ransomware claim attributed to Kazu

Centro Médico Especializado OSI appeared in several threat intelligence entries as a victim attributed to the Kazu group on August 23. The sources agree on the centromedicoosi.com domain and on references to sensitive medical data or possible exfiltration, but the material does not allow confirmation of asset encryption, only a leak site or an actual data leak.

The geographic mismatch in some tracking databases, which alternate between Peru and Mexico, means the case should be treated cautiously. What can be verified is OSI's presence in the ransomware monitoring ecosystem and its identification as a health care provider based in Lima.

Movitecnica, Qilin claim, and published leak

Movitecnica was listed by Qilin on leak sites and by several aggregators as a victim in Peru on August 19. In this case, the material does suggest actual publication of information, since Darkfield and other sources describe the status as "data leaked," although there is no public confirmation from the company.

The available record does not specify whether there was operational encryption. It does show a double extortion logic, with pressure to negotiate based on data publication and references to files that would include credentials.

Global Go and the Killsec claim

Global Go, a Peruvian transportation company, was claimed by Killsec on leak sites and incident aggregators. Unlike the Movitecnica case, the evidence here opens the door to an exfiltration confirmed by the monitoring source, but there are no details on volume or type of information, and no public signal from the victim.

The case remains classified as an unconfirmed claim by the company. Its informational value lies in the convergence of several tracking platforms that match on date, sector, and country.

Active threats and campaigns in Peru

August's criminal pressure was driven more by the mix of extortion, fraud, and social engineering than by technical vulnerability exploitation. Ransomware remained the main thread, but phishing and identity impersonation became more visible in banking and payments.

Ransomware and extortion in Peru

The month recorded 25 cases with ransomware or extortion as the primary focus, with 5 confirmed encryption cases, 7 mentions only on leak sites, and 13 where the available material does not allow the exact impact to be determined. That breakdown matters because not every case carries the same operational severity.

At the most sensitive end is the case with confirmed encryption, which in this month's material does not appear alongside a robust public confirmation from the victim. At the other end are the leak-site entries, where the only available evidence is the actor's claim and the post on the extortion platform.

Kazu against the health sector

Kazu showed a clear concentration in health care. On August 23, it posted several healthcare victims in a single day, including Centro Médico Especializado OSI, and technical reports describe a broad campaign against hospitals, clinics, telemedicine, and clinical software. For Peru, that leaves a concrete warning for healthcare providers and medical data supply chains.

The material does not allow a claim that OSI's assets were encrypted. It does support the conclusion that sensitive medical data was claimed and threatened with disclosure, with ransom estimates in some monitoring databases.

Qilin against manufacturing and services

Qilin kept pressure on Movitecnica and other regional targets, with the Peruvian case placed in manufacturing. The sources reviewed point to data published on the leak site and to double extortion, with signs of stolen files that would include credentials.

Operationally, Qilin continued to target mid-sized organizations, combining exfiltration with reputational pressure. The material does not support a claim of service disruption in the Peruvian case.

Killsec and transportation

Killsec claimed Global Go, a transportation company, and aggregators classify it as a data breach or data leak incident. Although there is no public confirmation from the organization, the case is useful for showing how transportation also remains exposed to campaigns aimed at monetizing internal information or credentials.

The evidence is not enough to confirm encryption. What remains is the publication on leak sites and the claim's persistence across multiple threat databases.

Digital fraud and phishing in banking

Banco de la Nación warned about fraudulent calls and messages using phone spoofing, while Infobae described synthetic identities, deepfakes, and password fatigue as recent digital fraud techniques in the country's banks. The most visible element was impersonation of institutions, manipulation of caller ID, and attempts to capture passwords or security codes.

These cases are not ransomware, but they do share the goal of accessing accounts and draining funds. The mix of AI, social engineering, and messaging channels expanded the fraud surface for users and merchants.

Data exposure and unclassified breaches

Kambista reported a possible exposure of sensitive data in its cloud infrastructure, although it said it found no evidence of exfiltration at the time of the notice. That kind of case falls into the unclassified incident zone because no completed breach or operational disruption is verified.

The leak of police intelligence data on Telegram and the earlier circulation of "Dirin leaks" also remained a sign of exposure, but without a new confirmed hack in 2026 according to the PNP itself, as cited by the press.

Critical vulnerabilities with impact in Peru

No critical CVEs were mentioned in the material reviewed for August 2026. That does not mean there were no exploited vulnerabilities in the region, only that none were documented in the sources reviewed for this report.

CVE Software Exploitation Source
No critical CVEs were recorded in the material analyzed n/a n/a Period indicator

Regulation and compliance in Peru

August was a heavily regulatory month. SBS, INACAL, OSIPTEL, SUSALUD, Indecopi and PCM moved on privacy, continuity, identity, notification, digital governance, and consumer protection. The pattern is consistent with regulation expanding faster than the cybercrime framework law.

SBS advanced on several fronts. These included streamlining authorization for new financial and insurance companies, changing the rules for notifications through electronic mailboxes, adjusting cash limits and risk controls, and adding new rules for temporary access to credit history for entities still in the approval process. Draft measures tied to open finance and pension payments through digital wallets and apps were also released.

The most relevant issue for information security was open finance. Ozone API, citing SBS Resolution No. 01747-2026, described a model with board-approved policies, prior risk assessments, continuous monitoring of third parties, contracts with minimum clauses, and periodic reports to SBS. At the same time, the reform of authorization rules for financial entities introduced prequalification, maximum deadlines, and controlled access to consolidated credit reports during the review period.

INACAL approved NTP-ISO/IEC 29100:2026, on privacy, and NTP-ISO/IEC 27031:2026, on ICT readiness for business continuity. These are technical references, not criminal or regulatory obligations in themselves, but they clearly point compliance and resilience projects in a set direction.

SUSALUD and MINSA reinforced the confidentiality standard for clinical records after the Clínica Delgado case. OSIPTEL, meanwhile, ruled that mobile service can only be reactivated after a stolen phone is recovered once identity has been verified, a measure aimed at stopping impersonation and fraud tied to line recovery.

On consumer protection and privacy, Indecopi sanctioned Interbank for spam calls and BCP for violating a consumer's privacy through debt collection communications sent to third parties. These are separate from the purely cyber domain, but they help frame the month: compliance on data handling, commercial contact, and consent remains under sustained scrutiny.

Organism Measure Security or privacy impact Source
SBS Reform of the authorization rules for financial and insurance entities Temporary and controlled access to credit reports, prequalification, and security measures El Peruano, Infobae Perú
SBS Agreement with the Public Prosecutor's Office Greater exchange of financial information for cyber fraud, extortion, and AML/CFT El Peruano
SBS Amendment to the electronic mailbox notification rules Notification adjustments and institutional compliance Normas Legales Online
INACAL NTP-ISO/IEC 29100:2026 and NTP-ISO/IEC 27031:2026 Privacy and ICT business continuity El Peruano, Andina
SUSALUD Fine against Clínica Delgado Confidentiality of medical records and health data La República, Infobae Perú
OSIPTEL Identity verification to reactivate stolen lines Prevention of impersonation and fraud through service recovery OSIPTEL

Most affected sectors in Peru

Health and finance were the most exposed sectors this month, not only because of the number of incidents but also because of the scale of potential harm. Health combined an exemplary confidentiality sanction with ransomware claims against a specialized provider, alongside the backdrop of medical data breaches that continue to surface in public debate.

In finance, the pressure did not come from a single incident, but from a buildup of digital fraud, phishing, regulatory changes and identity alerts. Traditional banking faced spoofing, fake calls, fines for unsolicited communications and campaigns that exploit deepfakes and synthetic identities. The SBS responded with stricter rules on third parties, operational risk and access to sensitive information.

Transport and manufacturing also appeared on the extortion radar. Global Go and Movitecnica show that ransomware groups did not stay confined to the financial or health sectors, but kept looking for organizations with marketable data and reputational leverage. In both cases, the public signal came mainly from leak sites and specialized aggregators.

The public sector had its own layer of exposure, with leaks of police intelligence information and discussion of institutional capabilities against cybercrime. Although the material does not confirm a new hack against DIRIN in August, it does show that the data is circulating and remains exploitable in open or semi-public channels.

Compared with July, verified activity rose sharply from 47 to 64 incidents, while unclassified cases fell and fraud, phishing, and regulation all increased markedly. Ransomware remained the dominant threat, but the month tilted much more toward public extortion, financial fraud, and compliance rules.

The most visible shift was in regulation. Going from 1 to 15 regulatory moves in one month reflects more than a heavier flow of bulletins, it points to a state and regulators moving faster to build rules for digital identity, open finance, continuity, and data handling. At the same time, the advance of technical standards suggests a growing standardization of the language of privacy and resilience.

The fraud mix also changed. Documented cases rose from 2 in July to 8 in August, driven by spoofing campaigns, bank impersonation, and narratives involving deepfakes and synthetic identities. That points to an environment where operational risk is increasingly concentrated in authentication, customer service, and account recovery rather than in malware itself.

In ransomware, the volume held at 25 cases, but public visibility changed. August showed more signs of leak sites and extortion than confirmed encryption. That distinction matters for response teams, because media and legal pressure can build even when disruption is not proven.

Security recommendations for teams in Peru

Security teams should prioritize controls over identity, customer service channels, and third parties. The month showed that the costliest attack does not always begin with malware, but with a call, a link, or a reused credential.

First, organizations should strengthen out-of-band verification for sensitive operations, account recovery, changes to personal data, and access reversals. The spoofing and remote access cases at EsSalud show that social engineering is still enough to compromise funds or enable transfers.

Second, health care and finance need specific procedures for sensitive data. In health care, clinical confidentiality should be treated as a first-tier operational control, with access traceability, judicial order checks, and strict handling of medical records. In finance, the focus should be on risk-based authentication, session monitoring, and protection against MFA fatigue.

Third, third-party programs should include real monitoring and clear clauses. The open finance framework and SBS reform on new entities point to an environment where controlled information sharing will be more frequent, but also more exposed to vendor failures, weak integrations, and misuse of temporary data.

Fourth, ransomware response should be separated from exposure response. A mention on a leak site does not prove encryption, but it does require review of credentials, tokens, remote access, and possible information leaks. If data is also published, legal and communications management moves to the front line.

FAQ

What changed more in Peru between August and July, fraud or regulation?

Regulation changed more. In August, 15 regulatory moves were documented, compared with 1 in July, while fraud or phishing cases rose from 2 to 8. The mix points to stronger institutional response and more visible criminal activity at the same time, as shown in Regulation and compliance in Peru and Trends and signals to monitor in Peru.

Did the month’s ransomware cases always involve system encryption?

No. The material distinguishes 5 cases with confirmed encryption, 7 mentioned only on a leak site, and 13 where the exact impact cannot be determined. For that reason, a ransomware claim in Peru does not automatically mean operational disruption. The classification appears in Period indicators in Peru and Active threats and campaigns in Peru.

Which sectors were most exposed because of the combination of incidents and rules?

Health care and finance were the most exposed. Health care included the fine against Clínica Delgado and the OSI case attributed to Kazu, while finance concentrated spoofing, digital fraud, changes at SBS, and sanctions for improper commercial contact. The cross-reading is developed in Most affected sectors in Peru and Regulation and compliance in Peru.

Were any critical vulnerabilities exploited in Peru during August?

No critical CVE was mentioned in the material reviewed. That does not mean vulnerabilities were not exploited in the region, only that they were not documented in the month’s sources. The nuance appears in Critical vulnerabilities with impact in Peru and in Limitations of the material.

Which August case mattered most for health care and privacy?

Clínica Delgado’s case, because it combined a SUSALUD fine with public debate over medical confidentiality, sensitive data, and consent obligations. At the same time, the OSI case added pressure through ransomware and a possible leak of medical data. The two events complement each other in Relevant incidents in Peru and Active threats and campaigns in Peru.

What should a Peruvian SOC look at after reading this report?

It should look at authentication, privileged accounts, recovery of lines or accounts, use of remote access software, and exposure on leak sites. It also needs to track the regulatory shift on third parties, privacy, and continuity. The practical response is summarized in Recommendations for security teams in Peru, cross-referenced with the cases of EsSalud, Banco de la Nación, and SBS.

Material limitations

This report was built exclusively from the material provided for Peru and August 2026. The indicator window includes 66 dated facts from August 2026 and excludes 1 fact dated after the period. Undated facts were not counted.

A zero value for any indicator, especially critical CVEs, means it did not appear in this month’s analyzed material, not that no critical vulnerabilities existed in the region. The same applies to any category that was not observed. Its absence from the report does not mean the phenomenon did not occur.

The calculation base for the indicators is 64 verified facts from the period, and the predominant threat was ransomware, with 25 of 64 facts. Two aggregated telemetry figures were also excluded, as they correspond to automated attempts or blocks and not to incidents with confirmed impact.

Consumer social media and sponsored or commercial posts were left out of the body as primary evidence, except when the information was corroborated by permitted and relevant sources. When a source was only a leak site claim or an unconfirmed account, the report treated it as such and did not elevate it to independent confirmation.

Sources