CiberLATAMbywhalemate
Intelligence report

Paraguay Cybersecurity Situation, August 2026

More phishing, more regulation, and less ransomware: August closed with 55 verified incidents and 11 documented banking fraud cases.

Sep 1, 202618 min read
Paraguay Cybersecurity Situation, August 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are filled automatically with verified dated facts from within the period. Each one states its source base and counting criterion, so the figures reconcile across modules. They are the recurring month-to-month reading, while the analysis that follows expands on the cases without repeating this summary.

Indicator window: 55 dated facts in August 2026. Facts from previous months are used only as comparative context in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Monthly verified signal dashboard August 2026 · Paraguay Top threat: Unclassified (20 of 55 items). Coverage: 55 dated items in August 2026 VERIFIED FACTS 55 period base: all counts measured from below on this total RANSOMWARE / EXTORTION 0 no classification available UNCLASSIFIED INCIDENTS 11 breaches or outages with no declared threat type FRAUD / PHISHING 11 documented fraud campaigns documented REGULATION 11 rules, resolutions, or penalties UNIQUE CVEs 3 CVE-2026-48286 / CVE-2026-48448
Monthly verified signal dashboard — Base: 55 verified dated items in the period for Paraguay.
MONTHLY FIXED MODULE Distribution by threat axis August 2026 · Paraguay Each incident is counted in only one axis, so the total is exactly 55. "Unclassified incidents" is the remainder. Unclassified 20 Fraud 11 Regulation 11 Incidents 11 Vulnerabilities 2
Distribution by threat axis — Each incident is assigned to one axis based on its classification; the total reconciles to the 55 incidents in the period.
FIXED MONTHLY MODULE Sector Distribution of Signals August 2026 · Paraguay Base: 55 events in the period · total 69 because 12 events are classified in more than one sector. Public sector / OIV 29 Other / no sector ident… 15 Finance 14 Telecom 5 Technology 4 Energy 2
Sector Distribution of Signals — Heuristic classification by victim sector. One event may affect more than one sector, so the total may exceed the base.
MONTHLY FIXED MODULE Critical infrastructure in Paraguay August 2026 · Paraguay 12 of 55 period findings involve critical infrastructure. One finding may appear in more than one category. Public sector / government 29 Energy / utilities 35 Telecom / connectivity 4
Critical infrastructure in Paraguay — Verified findings on the public sector, utilities, and essential services

Executive monthly summary for Paraguay

August 2026 recorded 55 verified cybersecurity incidents in Paraguay, with a clear shift from July. Primary ransomware vanished, documented fraud and phishing increased, and regulatory activity intensified. The month was dominated by account drainings, impersonation scams, and policy debate, with medium-high operational severity driven by the concentration of financial cases and the persistence of social engineering campaigns.

The most visible case was the draining of Deputy Rocío Vallejo’s account, which led to arrests, raids, and a wave of technical explanations involving trojans, RATs, and cloned online banking pages. That episode was accompanied by other bank thefts, fake traffic fines, a cryptocurrency fraud, and official alerts about phishing aimed at state portals and digital investment channels. Most of those incidents were directly confirmed by sources, although several technical details remained in the realm of journalistic or police hypotheses.

At the same time, the regulatory front moved forcefully. DNIT advanced General Resolution No. 47/2026 on cryptoassets, while Congress kept the Cybersecurity Bill under discussion and analyses circulated about Law No. 7,593/2025 on Personal Data Protection, which is still not fully in force. The Paraguayan system is showing greater regulatory pressure, but also operational gaps that continue to weigh on the institutional response.

The dominant reading of the month is that the risk did not come from a single, concentrated campaign, but from the overlap of banking fraud, portal impersonation, phishing, regulatory tensions, and critical vulnerabilities in widely used software.

August 2026 in ParaguayRocío VallejodrainingFake trafficfineDDoSclaimedDNITcryptoassetsData lawpersonalCases financial,state phishingand regulatorypressure definedthe month.

August 2026 in Paraguay, cybersecurity milestones — The month’s most visible verified events, focusing on fraud, regulation, and critical alerts.

Monthly national overview in Paraguay

Paraguay closed August with a moderately high risk signal, based on the volume and nature of the verified incidents: 11 documented fraud or phishing cases, 11 regulatory moves, and 11 uncategorized incidents, in a month with no confirmed ransomware as the primary focus. The picture is of an ecosystem where the most visible harm was concentrated in bank accounts, digital identities, and trusted channels, rather than in encryption or classic extortion.

Financial cases accounted for a notable share of the month. It began with the Vallejo case and continued with another affected entrepreneur, a report of diversion at a medical firm, a cryptocurrency fraud, and multiple warnings about fake fines, cloned sites, and phishing campaigns. Operationally, this points to a pattern of credential abuse and social engineering that stood out more than the rest of the month’s events.

The regulatory debate was also central. There was activity around cybersecurity, personal data, cryptoassets, e-commerce, and information sharing among agencies, but it did not close the gap left by the absence of a strong sector-specific response framework. In practice, that means greater compliance pressure on financial and digital players, with denser rules, but not necessarily more detection or containment capacity.

At the regional level, Paraguay’s agenda resembled that of other markets in the region where banking phishing, messaging scams, and digital asset regulation are advancing at the same time. The difference this month was that Paraguay showed sharper signs of internal policy debate and very high public exposure around online banking and state portals.

Paraguay period indicators

Indicator August 2026 Previous month Change
Verified incidents in the period 55 51 +4
Indicator time window 55 incidents dated August 2026 51 incidents dated July 2026 N/A
Unclassified incidents (breaches or outages) 11 15 -4
Cases with ransomware or extortion as the primary focus 0 11 -11
Ransomware breakdown by impact type No ransomware cases classifiable in the period No classifiable cases N/A
Documented fraud or phishing cases 11 0 +11
Documented regulatory moves 11 1 +10
Critical CVEs mentioned 3 No comparable data N/A
Sectors with at least one documented incident 5 6 -1
Dominant threat of the month Unclassified (20 of 55 incidents) Unclassified (19 of 51 incidents) +1 incident
Incidents with direct source confirmation 69% No comparable data N/A

Relevant Incidents in Paraguay

Rocío Vallejo account drain and police investigation

The month’s most visible incident was the draining of Deputy Rocío Vallejo’s account, with more than 35 million guaraníes stolen, a fiscal and police investigation, one arrest, and references to possible trojan malware or a RAT. The source did not settle on a single technical attribution, but it did confirm the financial impact, the open investigation, and the theory that a cloned home banking page was used.

The sequence included the detention of a suspect, a raid in San Lorenzo, and public explanations of how trojans, credential stealers, and fake pop-up windows work. The case became the month’s reference point for the entire financial system, not only because of the amount involved, but because it exposed how fragile web access can be and how dependent it is on credentials and tokens.

Date Event Impact Status
August 3 to 4 Rocío Vallejo account drained More than 35 million guaraníes Confirmed and under investigation
August 4 Arrest of linked suspect Operational response Confirmed
August 6 Raid in San Lorenzo Investigation advanced Confirmed

Banking phishing and second victim reported in August

The month did not end with the Vallejo case. A businesswoman also reported losing 43 million guaraníes after entering a page that imitated her bank’s site, and reports circulated about another draining that used an almost perfect replica of the official website. The technical pattern was consistent, credentials were captured in a fake environment, funds were moved afterward, and the victim reacted too late.

The repeated use of the same vector suggests the main problem was not a single piece of malware, but the combination of cloned sites, social engineering, and payment or verification channels that attackers exploited effectively. In practice, that puts banks and users at risk of impersonation rather than a sophisticated intrusion into core infrastructure.

Fake traffic fines and Portal Paraguay impersonation

Diario HOY and other outlets described a campaign involving fake traffic fines sent by email and SMS, and MITIC also warned about a fraudulent site impersonating Portal Paraguay to capture data from people seeking to receive Tekoporã. These are two versions of the same problem, trust-based phishing, with the state used as a brand to make the scam look legitimate.

These cases show the fraud was not limited to online banking. It also reached social programs, fake notifications, and the collection of personal data through forms that appear official. The breadth of the vector matters because it expands the risk to non-banking users and to digital services used at scale.

Fraud channel Impersonated target Objective Source
Email and SMS Traffic fines Steal data or money Diario HOY, 1000 Noticias
Website Portal Paraguay Capture personal data ABC Color, MITIC
Cloned banking page Home banking Drain accounts ABC Color, Hoy, La Tribuna

Copaco fund diversion and computer forensics

The Prosecutor’s Office opened a computer forensic review of Copaco’s administrative and financial system over the alleged diversion of about 1.100 billion guaraníes into personal accounts. Although the material did not allow the incident to be classified as a breach or a closed-form internal abuse case, it did point to possible misuse of systems and credentials at a strategic public company.

The case matters not only because of the amount involved, but because it affects a sensitive digital infrastructure component for the national ecosystem. Copaco appears here not as just another victim, but as an entity whose operations can have a broader impact on services and technology support.

Active Threats and Campaigns in Paraguay

Banking fraud and phishing

The most active front in August was banking fraud built on phishing, cloned pages, and credential theft. There were specific cases with high losses, multiple matching accounts about fake home banking, and official alerts on how to respond to suspicious links, emails, and forms. The volume of this trend explains much of the increase in documented incidents compared with July.

The operational takeaway is not that phishing is new, but that this month it was better documented and had a clearer economic impact. The Vallejo case served as the media trigger, but it was not an isolated one. The reports point to a trust impersonation campaign focused on banking and state entities as well.

Hacktivism and DDoS against Paraguayan state sites

In August, claims circulated of DDoS attacks against the Ministry of Foreign Affairs and the National Secretariat of Culture, attributed on social media to the group The Garuda Eye and, in a preventive alert, treated as unconfirmed by the monitoring source itself. There was not enough public evidence to turn those attributions into closed operational incidents, but they did remain as signs of pressure on government portals.

This block sits in a different space from financial fraud. It does not show money theft or confirmed exfiltration, but rather a campaign of political visibility and reputational pressure. From a risk perspective, that requires separating attribution noise on social media from technical confirmation of outage or compromise.

Ransomware and extortion

No typifiable ransomware cases were recorded during the period. There were also no confirmed incidents of extortion with encryption as the primary element, or of exfiltration with simple extortion that could be sustained by the material provided. The only related detail was a contextual reference to cooperatives emerging from a ransomware attack, but the source did not provide enough detail to include it as an incident for the month.

Type Status in August 2026 Observation
Confirmed asset encryption Not recorded No verifiable cases in the material
Exfiltration without encryption Not recorded Not enough typification
Mention on leak site Not recorded No documented case

Critical vulnerabilities with impact in Paraguay

August’s material mentioned three critical CVEs, all in products widely used outside the country, but relevant for Paraguayan environments because of technical and institutional exposure. There was no confirmed exploitation in Paraguay based on those advisories, although official and technical references do justify monitoring because of their possible impact on corporate and government networks.

CVE Software Exploitation Source
CVE-2026-77537 UniFi Protect Application Command injection, remote unauthenticated RCE CERT.LV, Ubiquiti, SCWorld, Mallory.ai
CVE-2026-77550 UniFi OS Server Authentication bypass through CRLF injection, remote unauthorized access Canadian Centre for Cyber Security, Mallory.ai
CVE-2026-77554 UniFi Talk Application Command injection, critical RCE CVSS 10.0 OpenCVE, CERT.LV, Ubiquiti

The strongest signal came from Ubiquiti, which published Advisory Bulletin 067 with 22 vulnerabilities in the UniFi family, including three maximum-severity flaws. There were also advisories on Samba and Joomla, but the month’s material did not allow them to be linked to confirmed Paraguayan incidents. Even so, for local teams, these are patches that should not be left out of the remediation cycle.

Regulation and compliance in Paraguay

The month was marked by regulatory expansion on three fronts, personal data, cryptoassets, and cybersecurity. Law No. 7,593/2025 appeared repeatedly in legal and compliance analyses, while DNIT launched General Resolution No. 47/2026 on cryptoasset transactions and Congress kept the Cybersecurity Bill alive. The underlying signal is more regulation, but also more friction over scope, proportionality, and implementation timelines.

Rule or initiative Status in August 2026 Relevant point
Law No. 7,593/2025 on Personal Data Protection Enacted, not yet fully in force Provides for sanctions and creates the ANPDP under MITIC
DNIT General Resolution No. 47/2026 In force Requires cryptoasset transactions to be reported in Marangatu
Cybersecurity Bill Under review Still awaiting parliamentary consideration
Update to the e-commerce law Being drafted Adds AI, cybersecurity, and digital sales

Law No. 7,593/2025 was described as inspired by GDPR-type standards and carrying fines that, according to the cited analysis, range from 20 to 2,500 minimum wages, with higher tiers for sensitive data and minors. The key point for August is that the law was still not fully in force, so the operational gap remained open while its practical effects were debated.

DNIT, meanwhile, moved ahead with an annual informational reporting requirement for cryptoassets, with the first filing due in March 2027 and a USD 5,000 threshold for determining who must report. The legal debate was intense. Critics questioned the necessity and proportionality of the requested data, and exchanges asked for a technical working group before the deadline. That makes the measure a cybersecurity and privacy issue, not just a tax one.

At the same time, the Cybersecurity Bill remained under technical and institutional review, with criticism over broad definitions, overlapping concepts, and uncertainty around critical infrastructure. The public hearing ended with another working group, a sign that the text still lacked enough consensus.

Regulatory Activity, August 2026Verified Facts by Topic Area1111115DataProtectionCryptoassetsCybersecurityTradeand banking

Regulatory Activity in Paraguay, August 2026 — Number of highlighted initiatives and rules by topic area, based only on verified facts from the period.

Sectors most affected in Paraguay

The financial sector was again the most exposed this month, but not because of a single incident type. It faced account draining, phishing, web banking alerts, cryptocurrency fraud, and regulatory pressure on intermediaries. Traditional banks, cooperatives, and payment services all showed the same pattern, credential abuse and interface spoofing.

The second most affected block was the public sector. Phishing attacks against government portals, claimed DDoS attacks against government sites, data protection debates, and the rollout of tax controls on crypto assets all appeared in the same space. In other words, the attack surface was not limited to banks. It also reached the state as a trust mark and as service infrastructure.

A third front, smaller in volume but strategically important, was telecommunications and corporate systems, with Copaco as the reference case. There were not enough incidents to speak of a systemic crisis in that sector, but there was a fiscal intervention on internal systems that deserves follow-up.

The month’s sector distribution points to a concentration in digital trust rather than in critical infrastructure in the strict sense. The most damaging events for users and organizations relied on deception, site cloning, and credential capture, not on destructive malware or large-scale exploitation of local vulnerabilities.

Compared with July, three major shifts stand out: fewer unclassified incidents, the disappearance of the ransomware/extortion axis, and a sharp rise in documented fraud and phishing. That shift does not mean the country is "better". It means the visible damage moved toward social engineering, banking fraud, and regulation, with a response agenda that is more dispersed and less centered on a single major incident.

Regulatory activity also rose sharply. It went from 1 documented move in July to 11 in August, focused on personal data, cryptoassets, cybersecurity, and e-commerce. This suggests the state is trying to close gaps, but the open debate over proportionality, jurisdiction, and vacatio legis shows the framework is still not stable.

The dominant threat remained "unclassified," although with one more case than in July. That is not a sign of analytical blind spots, but of a real mix of events that do not fit a single taxonomy. In August there was too much fraud, too much regulation, and too much uncertain attribution to compress the month into one technical category.

For monitoring, three signals deserve attention: whether ransomware cases reappear in cooperatives or critical entities, whether the DNIT adjusts the cryptoassets resolution under operational pressure, and whether the Cybersecurity Law bill adds more precise definitions of critical infrastructure and institutional authority. The month made clear that the cost of regulatory disorganization quickly reaches end users and the financial sector.

Recommendations for security teams in Paraguay

Review authentication and anti-phishing controls in web banking and customer service portals, with emphasis on cloned-site detection, domain validation, and hardening of secondary screens or token flows. The month’s cases show that impersonated interfaces were the dominant vector, not brute force.

Tighten fraud response with simple, public procedures: immediate account blocking, a single reporting channel, evidence preservation, and coordination with Policía, Fiscalía and CERT-PY. At the same time, train users and operators to recognize emails, SMS messages, and forms that mimic the State or a financial institution.

Prioritize patches in environments with Ubiquiti, Samba and Joomla, especially if remote administration is exposed or they are used in corporate and government networks. Although the material did not confirm exploitation in Paraguay, the advisories published in August were severe enough to enter the maintenance cycle without delay.

Review how data collected under tax and regulatory obligations is handled, especially in cryptoassets. The debate over necessity and proportionality is not abstract, it affects operators, exchanges, and legal teams, and it can ultimately affect data architecture, retention, and traceability.

Priority Action Affected area
High Validate official domains and forms Banking, State
High Patch Ubiquiti, Samba and Joomla IT infrastructure
Medium Review data retention and minimization Compliance
Medium Formalize fraud playbooks Customer service, SOC

Frequently Asked Questions

What changed in Paraguay between August and July 2026?

August had fewer unclassified incidents, dropping from 15 to 11, and the primary ransomware signal that appeared in July disappeared. At the same time, fraud and phishing rose from 0 to 11, and regulatory activity increased from 1 to 11. The shift is discussed in the Indicators and Trends sections.

Did the month show confirmed ransomware in Paraguay?

No. The August material did not allow any ransomware or extortion case to be classified as a primary theme. There was a contextual mention of cooperatives emerging from a ransomware attack, but it was not enough to include it as a verifiable incident for the period. That distinction is developed in Active Threats and Campaigns and in Material Limitations.

What risk was most visible for Paraguayan banks and users?

Phishing fraud and web banking impersonation. The Vallejo case, the entrepreneur who lost 43 million, and the alerts about cloned sites point to a pattern of credential theft and account draining. The operational reading is covered in Relevant Incidents, Active Threats, and Most Affected Sectors.

What is the relationship between the personal data law and the cryptoassets resolution?

Law No. 7.593/2025 establishes a data protection framework that is not yet fully in force, while DNIT has required an informative declaration of cryptoasset operations since August 2026. Together, these measures push organizations to review proportionality, minimization, and data traceability. That is addressed in Regulation and Compliance.

What vulnerabilities should Paraguayan teams watch, even without confirmed local exploitation?

The three critical Ubiquiti-linked CVEs, CVE-2026-77537, CVE-2026-77550, and CVE-2026-77554, because they allow unauthenticated remote execution or authentication bypass. Teams should also monitor the alerts affecting Samba and Joomla. The technical table is in the Critical Vulnerabilities with Impact in Paraguay section.

Which sectors were most exposed in August?

Mainly financial services, because of the concentration of fraud, phishing, and account draining, and the public sector, because of portal impersonation alerts, claimed DDoS activity, and new regulations. A third front was telecommunications and corporate systems, with the Copaco case. The analysis appears in Most Affected Sectors in Paraguay.

Material limitations

This report was built exclusively from the dated facts from August 2026 included in the provided material. The indicators reflect that time window and do not include aggregated telemetry, blocked attempts, or external signals not documented in the corpus.

A zero value, especially for CVEs or ransomware, means that no typifiable case appeared in the material analyzed for this period, not that there was no activity in Paraguay or the region. That distinction is key to reading the indicators correctly and avoiding improper extrapolations.

Uncorroborated social media posts, sponsored content, and any material not included in the list of permitted sources were excluded as evidence. The report also avoided treating as established fact anything that the sources themselves framed as a hypothesis, unconfirmed attribution, or preventive alert.

Sources