Paraguay: cybersecurity landscape, June 2026
June brought ransomware against healthcare and industry, regulatory progress, and a facial recognition complaint before the IACHR.
Key findings
- The month’s most severe impact was ransomware that forced clinics and private medical companies to operate manually.
- Krybit and Nightspire put Paraguayan industry and conglomerates in the extortion spotlight over data.
- Only some ransomware cases could be confirmed as involving encryption; in the rest, the source was insufficient to distinguish exfiltration from a simple leak site mention.
- Paraguay accelerated its regulatory agenda on personal data, AI, biometrics, election propaganda, and digital assets.
- The complaint before the IACHR over facial recognition heightened the debate on state surveillance and privacy.
- The IPS showed that internal manipulation of systems can also generate fraud with material impact.
- The month’s risk reading is high because of the combination of operational disruption, sensitive data, and regulatory implementation gaps.
Monthly reference modules
These modules are automatically completed with verified dated facts within the period. Each one states its basis and counting criterion so the figures reconcile across modules. They are the recurring month-to-month readout, and the analysis that follows expands on the cases without repeating this summary.
Indicator window: 66 dated facts in June 2026 · 3 from prior months (comparative framework, not month volume) · 1 without confirmed date (excluded from indicators). Facts from prior months are used only as a comparative frame in the analysis, never as volume for this period.
Monthly executive summary for Paraguay
June 2026 sent a clear signal in Paraguay on two fronts: ransomware that caused real operational disruption in private healthcare and industry, and a faster regulatory debate over personal data, artificial intelligence, and biometric surveillance. The most visible case was the attack that brought down systems at clinics and private medical companies, forcing manual handling of admissions, consultations, payments, and records management. At the same time, the Krybit group claimed an attack on Enrique Remmele S.A.C.I., and Nightspire’s leak site added the Grupo Riquelme conglomerate as a victim, with threats to disclose banking, accounting, customer, and human resources data.
The month also showed that the impact was not limited to classic extortion. In healthcare, the disruption of appointments, medical records, and patient service channels had an immediate and sensitive operational component. In industry and conglomerates, the information exposed or threatened points to business continuity, reputation, and possible legal pressure. Of the cases observed, only part allowed confirmation of asset encryption; in the rest, the material was not enough to distinguish precisely between encryption, exfiltration, or only a claim posted on a leak site.
The regulatory front also moved decisively. Law 7593/2025 on Personal Data Protection continued to drive analysis of its future impact, while June saw initiatives to regulate AI, ban indiscriminate biometric surveillance in election advertising, set rules for tax monitoring of cryptoassets, and adapt consumer and digital payments rules. There was also a complaint before the IACHR over secret facial recognition use in Asunción, filed by EFF, TEDIC, and CEJIL. Taken together, these developments point to a country entering a more formal regulatory phase, but still with implementation gaps and open disputes over state transparency.
The month’s risk reading is high. Not because of overwhelming volume, but because of the mix of concrete disruption in sensitive sectors, extortion over data with high exposure potential, and a regulatory agenda that is still being built. The regional backdrop matched that pattern, with comparative and contextual material placing Paraguay within a Latin American wave in which attackers prioritize critical services, use double extortion, and exploit exposed attack surfaces, while states move more slowly than the market on data protection, AI, and cryptoassets.
Paraguay national monthly overview
June 2026 in Paraguay was uneven, but one trend stood out clearly. The most serious operational signal was ransomware affecting private health care, where response had to revert to paper and manual processes. That meant degraded service, overloaded staff, and direct risk to patients. At the same time, industry and business groups faced pressure through extortion tied to possible database exposure, which affects continuity, intellectual property, accounting, and labor relations.
The severity came not only from the names of the victims, but from the nature of their functions. Private health care and medicine are sectors that hold highly sensitive information and have very little tolerance for downtime. Industry and conglomerates, meanwhile, are attractive targets for ransomware actors looking to negotiate using financial and business data. The month also showed that attackers are using leak portals and pressure campaigns, even when public material does not always make it possible to confirm whether there was encryption or only the victim’s publication on a leak site.
The qualitative risk reading for Paraguay is high, based on the combination of 65 verified events during the period, 18 cases with ransomware or extortion as the primary focus, 8 unclassified incidents, and 16 documented regulatory moves. That mix points to an environment with sustained offensive pressure and, at the same time, an institutional capacity still taking shape. The absence of a massive case count does not reduce the seriousness of the confirmed impacts, because several of them affected critical services, sensitive data, and operators with public exposure.
In the Latin American context, Paraguay does not stand alone. This month’s material places it in the same regional dynamic where ransomware groups combine pressure over data, selective leaks, public negotiation, and posting on extortion sites. At the same time, the regional policy debate is accelerating around personal data, AI, surveillance, and digital assets. Paraguay is part of that trend with one key difference, the regulatory front is advancing, but it still coexists with fragmented sector ecosystems and incidents that show operational gaps that remain very costly.
Paraguay threat indicators
| Indicator | Value |
|---|---|
| Verified incidents in the period (basis for all indicators) | 65 |
| Indicator time window | 66 incidents dated in June 2026, 3 from prior months (comparative frame, not monthly volume), 1 without confirmed date (excluded from indicators) |
| Unclassified incidents (breaches or outages) | 8 |
| Cases with ransomware or extortion as the primary focus | 18 |
| Ransomware breakdown by impact type: confirmed asset encryption | 3 |
| Ransomware breakdown by impact type: impact could not be determined from the material | 15 |
| Documented fraud or phishing cases | 3 |
| Documented regulatory actions | 16 |
| Critical CVEs mentioned | 1 |
| Sectors with at least one documented incident | 8 |
| Predominant threat of the month | Unclassified (19 of 65 incidents) |
| Incidents with direct source confirmation | 74% |
| Aggregated telemetry figures excluded from volume | 1 (aggregated attempts or blocks, not incidents with confirmed impact) |
Relevant Incidents in Paraguay
Private clinics and medical providers, operational impact from ransomware
The month’s most sensitive case was the attack that hit private clinics and medical companies in Paraguay. Coverage by La Tribuna and El Nacional describes systems being shut down, manual operations, and delays in admissions, tests, appointments, payments, and services for insured patients. Specific institutions were also named, including Migone, Grupo Británico, Las Lomas, Santa Clara and Reyva. The analytical value of the case is not only the ransomware attribution, but the degradation of clinical service, which forces real-time process redesign and exposes providers to direct tension between operational continuity and handling clinical information.
The public source does not confirm a ransom payment or a completed data leak at the time of the report. It does make clear that the operational impact was severe enough to force manual procedures back into use. In health care, that kind of disruption affects more than technology: it alters records, waiting times, and potentially the traceability of care.
Enrique Remmele S.A.C.I. and Krybit
On June 17, 2026, Malware.news and ransomware.live listed Enrique Remmele S.A.C.I. as a Krybit victim. The available public information points to an early documentation stage: the tracking portal lists Paraguay and an estimated attack date of June 17, with some third-party credentials compromised, but no full inventory of the damage. The material does not provide a closed detail on the type of exfiltration or on confirmed encryption in this case.
What matters for the national report is that ERSA appears as an industrial victim with public exposure in a ransomware group that was already operating as RaaS and using double extortion techniques. For Paraguay, that adds a risk signal for manufacturing and process industries, where downtime and reputational pressure often go hand in hand.
Grupo Riquelme and Nightspire
On June 25, 2026, DeXpose reported that Nightspire claimed responsibility for an attack on the Paraguayan conglomerate Grupo Riquelme. Ransomware.live dates the case to June 13 and details categories of information allegedly compromised, such as databases, banking and financial data, accounting records, customer information, human resources data, and data from critical business applications. Breachsense added that the attributed leak reaches 133 GB, although that figure does not by itself prove the exact content or the scale of operational damage.
In this incident, the source clearly places it in the logic of data extortion. What it does not allow is a conclusive confirmation of whether assets were encrypted or whether the focus was on the threat of disclosure. For analytical purposes, the case should therefore be read as extortion with potential exposure of multiple layers of corporate information.
Facial recognition in Asunción, petition before the IACHR
EFF, TEDIC and CEJIL filed a complaint before the Inter-American Commission on Human Rights against the Paraguayan state for refusing to provide information about facial recognition systems used for mass surveillance. The petition was formalized on June 19, according to El Notariado, and EFF says the case centers on cameras installed since 2019 in Asunción and the lack of access to protocols for the use and handling of biometric data.
Although this is not a cyber intrusion, it is a digital security and governance issue with direct impact on privacy and democratic oversight. The case shows that the cybersecurity debate in Paraguay now goes beyond malware or fraud, and also includes state transparency, biometrics and fundamental rights.
IRS, record tampering and computer fraud
The Internal Audit report of the IPS documented a scheme to alter records in the REI system in order to hide employer debts and transfer them to fictitious or deceased identities. The available material describes an internal manipulation of data, not a classic external intrusion, but it is still a case of computer fraud with financial impact. The pattern is different from ransomware, although the effect on data integrity is similar in terms of trust and traceability.
For the national reading, the case serves as a reminder that security risks do not come only from outside. Manipulation of internal systems by users with access can also cause material damage, fraud and control problems.
Threats and active campaigns in Paraguay
Ransomware and extortion: confirmed encryption
In June, encryption of assets was confirmed in three cases in the country, but only one was described with enough operational clarity in the source material: the attack against private medical clinics and healthcare companies, which left systems paralyzed and forced manual operations. That picture is consistent with encryption or severe unavailability caused by ransomware, although the public source provides no forensic details on the payload or recovery.
To avoid overstating what was not proven, it is worth separating that case from others in which the source only describes a claim on a leak portal or a threat to disclose data. In Paraguay’s June threat picture, that distinction matters because the risk assessment changes significantly depending on whether there was encryption, exfiltration, or only victim publication.
Ransomware and extortion: exfiltration or pressure on data without determinable encryption
Grupo Riquelme fits this category better. Nightspire claims the attack and the exposure of sensitive data, and ransomware.live lists the compromised categories. However, the material does not make it clear whether the operation included system encryption, only exfiltration, or a combination of both. A similar case applies to ERSA, where public visibility centers on the Krybit claim, the warning about data publication, and the victim listing on monitoring sites, but not on a full technical postmortem.
That distinction matters for defensive and compliance teams. Not every case listed by a group on its portal necessarily means loss of availability. Sometimes the pressure is on confidentiality and negotiation, not on operations. In others, such as private healthcare, the operational damage was visible from the start.
Ransomware and extortion: leak site mention only
The June material also includes cases where the public signal is mainly a mention on leak sites or threat intelligence pages. That does not, by itself, confirm total impact, but it does show actor interest and exposure that could escalate. In the national report, this category helps avoid mixing verified facts with campaigns that are still at the claim stage.
Fraud and phishing
The material documents three fraud or phishing cases during the period. The clearest is the internal scheme detected at IPS, where data was manipulated to transfer debts and create an appearance of regularity. Although this is not phishing in the strict sense, it is documented fraud involving misuse of systems. In addition, the technical information on Krybit describes targeted phishing as an access vector, but that appears as an attribute of the actor and not as a separate local incident in Paraguay.
APT, espionage, or hacktivism
The month’s material did not include a Paraguayan case clearly classified as APT or hacktivism with confirmed impact. The dominant threat focus remained ransomware, extortion, and internal fraud. That does not mean espionage or activism risk is absent, only that the verified facts were not enough to support that classification.
Critical vulnerabilities with impact in Paraguay
| CVE | Software | Exploitation | Source |
|---|---|---|---|
| CVE-2024-55591 | FortiOS / FortiProxy | Mentioned as an authentication bypass leveraged by NightSpire in at least one technical case, within the analyzed material on the group’s TTPs | Mallory |
Regulation and compliance in Paraguay
June was a particularly active month for regulation. Paraguay already has Law 7593/2025 on Personal Data Protection, with a vacatio legis until November 2027, and that continued to drive analysis around internal compliance, consent, transparency, proportionality, and impact assessments. The key issue is not only legal, but operational: which systems use sensitive data, how purpose is documented, and who has access to automated processing.
At the same time, lawmakers documented a bill on election advertising on social media that bans microtargeting based on ideological profiles or political affiliations without consent and creates a mandatory registry of accounts for digital political advertising. It was also reported that legislators are pushing a strategy to regulate AI and implement the data law, with risk-based classification, a ban on indiscriminate biometric surveillance, and a public registry of AI systems. That points to an agenda trying to close several gaps at once, although still at the design stage.
The digital assets front also moved forward. Revista Plus and Atlas21 reported on regulatory work to apply securities market rules to digital assets and on new reporting obligations for bitcoin and other cryptocurrency transactions above 5,000 dollars per year. InfoNegocios, meanwhile, noted that Paraguay still lacks a fintech law and a single comprehensive framework for digital assets, forcing operators to work under partial rules from several authorities. The result is greater oversight, but still fragmented.
The complaint filed by EFF, TEDIC and CEJIL before the IACHR over the secret use of facial recognition adds a different dimension. This is not only about compliance, but about the democratic governance of surveillance technologies. For organizations working with biometrics, video surveillance or automated analytics, the message is clear: the regulatory transition period is no longer theoretical.
Most affected sectors in Paraguay
The month’s sectoral signal centered on private healthcare, industry, legal and compliance services, and the public sector tied to surveillance and data management. Private healthcare was the sector with the clearest operational impact. The reason is straightforward, a down clinical system affects scheduling, medical records, admissions, billing and patient care. In that kind of environment, digital continuity is not a convenience, it is part of the service.
Industry appears because of the ERSA case and also because of exposure affecting conglomerates such as Grupo Riquelme. The concern there is availability, trade secrets, accounting, customer data and the continuity of administrative processes. The extortion logic is different, but just as sensitive. If a business group runs several lines of business, a single incident can cut across more than one operational front.
The public sector also appears, though for other reasons. IPS was not a documented external intrusion, but a case of internal manipulation of records. Even so, the damage is comparable in terms of data integrity and institutional trust. The complaint over facial recognition, meanwhile, opens a privacy and state surveillance front with cross-cutting effects for the entire administration.
The set of events also shows a closer relationship between technology, regulation and public services. Health, finance, surveillance, consumer markets and cryptoassets appear linked by the need for clear rules, access traceability and incident response. These are not isolated sectors, but overlapping layers of a digital infrastructure that is still maturing.
Trends and signals to watch in Paraguay
There is no month-over-month comparison baseline because this is the first archived period with this indicator format for Paraguay. For that reason, it would not be appropriate to invent an increase or decrease rate versus May. What June did leave, however, was a mix of active ransomware, data extortion and regulatory expansion that warrants close attention in July.
The first signal to watch is private healthcare. If incidents continue to require manual operations, that means resilience and recovery plans are still not absorbing the burden of attacks of this type. The second is industry and conglomerates. The exposure of ERSA and Grupo Riquelme suggests attackers are still finding value in companies with multiple business units and high-impact financial or workforce data.
The third is the maturation of the regulatory agenda. Law 7593/2025, the initiatives on AI, election propaganda rules and digital asset regulations point to a real acceleration in compliance. For security teams, that changes the focus, incident response is no longer enough, they also need to document processing, access, monitoring and the use of biometrics.
The fourth signal is the tension between surveillance and privacy. The CIDH case could become a regional reference if it moves forward. If that happens, Paraguay would need to review not only the legality of the deployment, but also the transparency and impact assessment of facial recognition technologies.
Finally, it is worth tracking the technical evolution of Krybit and Nightspire. The June material describes groups using RaaS, double extortion, legitimate tools, RDP abuse and, in Nightspire’s case, an intrusion technique that in some scenarios reaches exploitation of CVE-2024-55591. That does not mean Paraguay is facing a single campaign, but it does mean it is dealing with actors that combine opportunistic access and public pressure.
Security recommendations for teams in Paraguay
- Put operational continuity first in healthcare, industry, and public-facing services. If ransomware forces a move to manual mode, the organization is already too late on its response plan. Recovery, segmentation, and restoration need to be tested with real exercises.
- Review remote access, RDP, and legitimate administration tools. The actors seen in the material use remote access, administration, and exfiltration software that can go unnoticed without tight behavioral controls.
- Strengthen internal identity and privilege controls. The IPS case shows the threat can also come from inside, with users altering data, account statuses, or traceability.
- Prepare inventories of sensitive data and automated processing. Law 7593/2025 and the debate over AI, biometrics, and surveillance require knowing what data is processed, on what legal basis, and who can access it.
- Review the use of biometrics and video surveillance under data minimization, transparency, and impact assessment criteria. The facial recognition case before the IACHR could raise the expected standard for public and private entities.
- Segment clinical, accounting, and customer service systems. The combination of encryption and extortion means a single outage can affect several critical functions at the same time.
- Monitor exposed attack surfaces in edge services and public applications. The technical material on ransomware in June emphasizes vectors such as targeted phishing and exploitation of unpatched exposed services.
- Align security with regulatory compliance in digital assets and payments. The new crypto reporting rules and tax exemptions for PSAV and fintech imply documentation processes and traceability controls that should not be left out of the security area.
Material limits
This report was prepared exclusively from the material provided for Paraguay in June 2026. There was no access to the internet or to external sources beyond the authorized list. The indicator window includes 66 dated facts from June 2026, 3 facts from earlier months used only as comparative context, and 1 undated fact, which was excluded from the indicators.
A key methodological point is that an indicator at zero, particularly the CVE indicator if that had been the case, means only that it was not recorded in the material analyzed, not that there was no activity or critical exploitation in the region. This month, the critical CVE indicator mentioned 1 case, so the absence of other names should not be interpreted as the absence of vulnerabilities in Paraguay or in Latin America.
It is also necessary to distinguish between incidents and telemetry. The figure of 734.5 million cyberattack attempts cited by La Nación and attributed to Fortinet corresponds to automated attempts or blocks in 2025, not to incidents with confirmed impact in June 2026. For that reason, it is not included in the month's total and, by itself, cannot be used to measure the real damage.
On sources, consumer social media, sponsored content and notes whose value was mainly promotional were excluded. When a claim depended only on material with uncertain attribution, it was treated as such and not as fact. The report prioritizes confirmed facts, notices from the outlet itself or the technical tracker, and regulatory or institutional documentation available in the provided archive.
Sources
- Ciberataque masivo afecta a sanatorios y empresas de medicina privadaLa Tribuna
- Ciberataque paraliza sistemas de importantes sanatorios privados y obliga a operar de forma manualEl Nacional (Paraguay)
- El ciberataque que obligó a los sanatorios a volver al papel y reabre el debate sobre la ciberseguridadEl Independiente (Paraguay)
- Krybit Ransomware Strikes Paraguayan Industry Leader ERSAmalware.news
- Victim: ersa.com.pyransomware.live
- Nightspire Ransomware Strikes Paraguayan Conglomerate Grupo Riquelme - DeXposeDeXpose
- EFF, TEDIC and CEJIL Challenge Secrecy in the Use of Face ...Electronic Frontier Foundation
- Regulación de IA y Ley de Datos en Paraguay | Diario ParaguayoDiario Paraguayo
- Paraguay se prepara para un cambio fundamental en el manejo de la información personalYouTube
- DPL Spotlight Política Digital WeeklyDPL News
- Desarrollo de data centers demandará mayor atención en ...La Nación / Nación Media
- Activos digitales: el desafío de regular un mercado que evoluciona más rápido que las leyesInfoNegocios Paraguay
- Día 1 - SSIG 2026 EspañolYouTube
- Krybit ransomware group - Discover all the information about themBreach House
- Court of Auditors of Senegal - ENRIQUE REMMELE SACI (ERSA)FalconFeeds
- Ransomware Group krybit Hits: www.courdescomptes.snHookPhish
- Victim: Grupo Riquelme – nightspireransomware.live
- Ransom! Grupo Riquelme (JUN-2026)Hendry Adrian
- Grupo Riquelme Data Breach in 2026Breachsense
- Grupo Riquelme Data Breach Reported - GalaxyWardenGalaxyWarden
- Paraguay ante la CIDH: organizaciones denuncian el uso secreto de reconocimiento facial y exigen transparencia estatalEl Notariado
- AI Regulation in Paraguay: Status and RulesLevellers.ai
- Regulación de la IA en Paraguay: estado y normasLevellers.ai
- Protección de datos en Paraguay: el nuevo desafío que transformará la gestión empresarial antes de 2027Mundocalidad
- Ley 6534 Paraguay: datos de crédito 2025WhiteJaguars
- Herramientas digitales en el trabajo: límites legales en ParaguayIrunVillamayor
- Paraguay | Global AI Ethics and Governance ObservatoryUNESCO
- Incidentes de Seguridad y Políticas de Ciberseguridad en ParaguayUniversidad Americana / Studocu
- Paraguay inicia proceso de regulación de activos digitalesRevista Plus
- Paraguay: new monitoring rules for Bitcoin transactions over 5000Atlas21
- World Watch - Global Rules & Events MapAnurag Verma
- Krypto-Steuern Paraguay 2026: Bitcoin, Ethereum und ...Paraguay-Steuerfrei
- El país apuesta por la formación en IA para impulsar el empleoLa Nación / Nación Media
- Paraguay instalará 1,600 kits de Starlink para conectar escuelas y hospitales ruralesDPL News
- Paraguay deploys Starlink to connect rural schools and clinicsTelecompaper
- Paraguay Partners With Starlink To Connect 1600 Schools To High-Speed InternetAsuncion Times
- Starlink connects schools in remote areas of Paraguay to the internetZamin
- Inklusion durch Satellitentechnik: Paraguay bekämpft die digitale Isolation vulnerabler ZonenWochenblatt
- COPACO inició instalación de internet a zonas más alejadasEconomía Virtual Paraguay
- Acto de lanzamiento y presentación de los kits de Starlink para escuelas y comunidadesGobierno de Paraguay
- Confirmado por Educación | Elon Musk llevará Starlink a las escuelas de estos municipiosEl Cronista (Colombia)
- Paraguay Savings Certificates To Go Digital, Promising A More Active MarketAsuncion Times
- Decreto 475/2026: exención del impuesto al cheque para PSAVsJFC Attorneys
- Sedeco atualiza Código de Defesa do Consumidor para compras online e IAPytagua
- Bitdefender Threat Debrief | May 2026Netmon Asia
- The "Krybit" Ransomware Siege on the Cour des Comptes du SénégalBrinztech
- NightSpire | MalloryMallory
- NightSpire 勒索軟體濫用管理工具發動攻擊,全球33 國含台灣企業與 ...DreamJtech
- NightSpire Ransomware Hits Manufacturers: NC SMB Defense ...PreferredData
- Weekly Ransomware Intelligence Report, June 8, 2026Scrutex.ai
- Krybit Ransomware Lists Ford de México as a VictimBreached.company
- NightSpire:ランサムウェアの闇世界に現れた覇王を気取る攻撃者Barracuda
- G**** R****l*e Ransomware Attack by Nightspire (2026) | Cyber Threat IntelligenceCyber Threat Intelligence
- Regulación de propaganda electoral en redes socialesdiarioparaguayo.com
- Gobierno presenta ley para data centers con beneficiosdiarioparaguayo.com
- PrivacyTEDIC
- Denuncian fallas en sistemas de sanatorios privados y crecen los reclamos de pacientesRDN
- IPS: Usaron a fallecido para tapar deuda e intentar sacar un créditoÚltima Hora
- Empresas con deudas ocultadas en IPS fueron multiproveedorasÚltima Hora
- Auditoría del IPS detectó más de 50 casos en esquema que ocultó deudasÚltima Hora
- Golpe de G. 7.000 millones al IPS: borraron registros de deudas patronalesABC Color
- Jubilada del IPS figura con deuda de casi G. 300 millonesTelefuturo
