CiberLATAMbywhalemate
Intelligence report

Uruguay Cybersecurity Situation, August 2026

August ended with 49 verified incidents in Uruguay, regulatory dominance, 8 ransomware or extortion cases, and 5 fraud or phishing cases.

Sep 1, 202615 min read
Uruguay Cybersecurity Situation, August 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are completed automatically with the verified dated facts within the period. Each one states its basis and counting criterion, so the figures reconcile across modules. They are the recurring month-to-month read, and the analysis that follows develops the cases without repeating this summary.

Indicator window: 49 dated facts in August 2026 · 2 from prior months (comparative frame, not monthly volume). Facts from prior months are used only as a comparative frame in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Verified signal monthly dashboard August 2026 · Uruguay Main threat: Regulation (16 of 49 events). Coverage: 49 dated events in August 2026 · 2 prior months… VERIFIED EVENTS 49 period base: all counts measured from below against this total RANSOMWARE / EXTORTION 8 8 unclassified with the material UNCLASSIFIED INCIDENTS 6 breaches or outages without declared threat type FRAUD / PHISHING 5 documented fraud campaigns documented REGULATION 16 rules, resolutions, or sanctions UNIQUE CVEs 0 none in the analyzed material (does not imply absence in the region)
Verified signal monthly dashboard — Base: 49 verified dated events for Uruguay.
MONTHLY FIXED MODULE Threat-axis distribution August 2026 · Uruguay Each event is counted in only one axis, so the total is exactly 49. "Unclassified incidents" is the remainder. Regulation 16 Unclassified 14 Ransomware 8 Incidents 6 Fraud 5
Threat-axis distribution — Each event is assigned to one axis based on its classification; the total reconciles to the 49 events in the period.
MONTHLY FIXED MODULE Sectoral distribution of signal August 2026 · Uruguay Base: 49 events in the period · total 62 because 11 events are classified in more than one sector. Public sector / OIV 21 Telecom 13 Other / no sector ident… 12 Energy 5 Technology 4 Retail / Consumer 3 Financial Services 2 Healthcare 2
Sectoral distribution of signal — Heuristic classification by victim sector. One event may involve more than one sector, so the total may exceed the base.
FIXED MONTHLY MODULE Critical infrastructure in Uruguay August 2026 · Uruguay 10 of 49 facts in the period involve critical infrastructure. One fact may appear in more than one category. Public sector / government 21 Energy / utilities 5 Telecom / connectivity 8
Critical infrastructure in Uruguay — Verified facts on public sector, utilities and essential services

Executive summary for the month in Uruguay

August 2026 in Uruguay was defined by regulation, with 49 verified events, 16 regulatory moves, and a clearer signal in compliance than in technical intrusion. There were 6 unclassified incidents, 8 cases of ransomware or extortion as the primary theme, and 5 documented fraud or phishing episodes. The only critical CVE mentioned in the material was an active Zimbra vulnerability, with no other critical issues recorded in the period analyzed.

The most consistent development was regulatory. The Central Bank of Uruguay advanced the framework for Virtual Asset Service Providers, enabled the digital process for authorization and registration, and continued refining information and transparency rules on other financial fronts, including the warning about exchange-rate risk in foreign-currency deposits and the open finance debate. At the same time, URCDP kept up a high pace of rulings and registrations of personal databases, confirming sustained administrative activity in privacy and compliance.

On the operational side, the most relevant ransomware case was Vigilia, a healthcare provider, with a claim from the Global group and a threat to leak data, although the material does not specify whether there was encryption, only exfiltration, or just a claim on a leak site. Claims attributed to Criba and Agroland also appeared in trackers and leak sites, but the scope in Uruguay was partial or unverified. In fraud, the scam using UTE's name and redirecting victims to eBROU to steal credentials and arrange loans was the clearest local case and the most sensitive because it targeted older adults.

The risk reading for Uruguay in August is medium, with a high bias toward compliance and exposure to financial fraud and opportunistic extortion. The material for the month did not include any critical CVEs other than Zimbra, but it did show exposed surfaces in email, financial accounts, digital identity, and public services.

Cronología de señal verificada en Uruguay, agosto 2026Línea de tiempo con hitos de regulación, fraude, ransomware y vulnerabilidades activas durante agosto de 2026 en Uruguay.6 AugGURI leak19 AugDecree 16821 Augdigital PSAV27 AugUTE scam28 AugVigilAugust 2026Verified events in Uruguay

Uruguay, August 2026, signal timeline — Verified milestones of the month, with a regulatory focus and occasional spikes in fraud, ransomware, and active vulnerabilities.

National Outlook for Uruguay in August

Uruguay showed a concentration of verifiable signals in August around regulation, digital identity, and data control, with moderate operational pressure from fraud and extortion. The dominant trend was regulatory, which shifts risk toward implementation, oversight, and compliance rather than a wave of large-scale intrusions. Even so, the point severity was notable in health care, banking, and public services.

The local picture was driven by three parallel fronts. First, the BCU tightened obligations on virtual assets, dollar deposits, and open finance. Second, URCDP continued registering databases and promoting training for public agencies. Third, the state advanced practical cybersecurity measures, with Decree No. 168/026 for incidents in public agencies, a CERTuy workshop on threat intelligence, and an agreement to strengthen the electronic DNI.

Regionally, Uruguay aligns with a broader Latin American push toward greater regulatory formalization in cryptoassets, personal data, and online gambling, but with one important difference: the volume of signals was more legal than incident-driven. That does not reduce the risk, it shifts it. Where attention once centered on vulnerabilities and breaches, this month made it clearer that the immediate focus is on data governance, digital authentication, and socially engineered fraud.

Period indicators in Uruguay

Indicator August 2026 Previous month Change
Verified events in the period (base for all indicators) 49 72 -23
Time window for the indicators 49 events dated in August 2026 · 2 from previous months (comparative frame, not monthly volume) 72 events dated in July 2026 n/a
Unclassified incidents (breaches or outages) 6 9 -3
Cases with ransomware or extortion as the primary focus 8 17 -9
Ransomware breakdown by impact type: Not determinable from the material 8 n/a n/a
Documented fraud or phishing cases 5 2 +3
Documented regulatory moves 16 17 -1
Critical CVEs mentioned 0, none in the material analyzed (does not imply absence in the region) no comparable data for the previous month n/a
Sectors with at least one documented event 8 7 +1
Leading threat of the month Regulation (16 of 49 events) Vulnerabilities (18 of 72 events) shift in focus
Events with direct source confirmation 73% n/a n/a

Relevant incidents in Uruguay

Vigilia and the Global group ransomware claim

The month’s most sensitive case was Vigilia, a healthcare provider in Uruguay, which the Global group claimed on a leak site. The source confirms the claim and the threat to publish a full leak if negotiations did not begin, but it does not say whether assets were encrypted, data was actually exfiltrated, or the victim was only mentioned on the leak site. That ambiguity matters because it changes the operational and legal impact.

Dexpose placed the post on August 28, and ransomware.live added an estimated attack date of August 6. That provides timing context, but no independent forensic validation. For a response team, the useful detail is not only the attribution to the group, but that the target belongs to the health sector, where continuity demands and data sensitivity often increase extortion pressure.

UTE scam and banking identity theft in eBROU

The Lavalleja Police Headquarters warned about a scam that uses UTE’s name to offer fake discounts on electricity bills and convince victims to log into eBROU. The goal is to capture personal and banking data and then take out loans and make transfers in the victims’ names. Telenoche added that the scheme is aimed mainly at retirees and pensioners.

This is one of the clearest social engineering fraud cases of the month. It does not rely on malware or a technical flaw, but on brand impersonation, phone-based manipulation, and abuse of trust in financial channels. The mix of energy, digital banking, and personal identity makes it especially sensitive for banks, utilities, and customer service teams.

Operation Aureus and convictions for computer fraud

The Ministry of the Interior reported that Operation Aureus ended with the conviction of two people for computer fraud. The detail is limited, but it confirms concrete police action against this type of crime and fits a month in which fraud gained public visibility. The coverage does not describe the technique used or the scope of the scheme, so it should not be overstated.

Incident in the MIEM Public Consultation System

The Ministry of Industry, Energy and Mining announced a period of unavailability for the Public Consultation System due to security update work related to Microsoft products. The notice suggests a planned outage, not a confirmed intrusion incident. Even so, the fact is relevant because it shows dependence on exposed platforms and the need for preventive maintenance to reduce operational risk.

Public debate over a supposed hack of Estadio Charrúa

ESPN published statements from Javier Noblega, of Montevideo City Torque, who said a match was suspended because the system had been hacked. The source provides no technical evidence or independent confirmation, so the episode should be read as an attributed claim, not a verified incident. Its value is more symptomatic than probative, since it shows how the word hack is still used to explain infrastructure failures.

Active threats and campaigns in Uruguay

Ransomware and extortion, with incomplete classification in the source material

The month produced 8 ransomware or extortion cases as the primary focus, but in every one the source did not allow the impact type to be determined with confidence. The material includes claims involving Vigilia, Criba, and Agroland, as well as references to trackers and leak sites, but it does not always confirm encryption, exfiltration, or simply the publication of the victim.

In practice, that means these cases have to be treated as extortion signals with unresolved impact. For defense and business continuity, the ambiguity matters. A leak site can foreshadow reputational and operational damage even before there is public confirmation of encryption or a full data leak. In health care and agriculture, the time between the claim and validation is often enough to trigger preventive containment.

Global against Vigilia

Global is the only case this month with a more direct Uruguay context. The leak site claimed Vigilia had been compromised and threatened to release full information if there was no negotiation. Dexpose adds that the service belongs to the health sector and that sensitive patient or medical care data may have been exposed, although that remains in the realm of journalistic attribution, not a technical confirmation of scope.

DragonForce and Criba, with data that touches Uruguay but does not confirm it

Criba appeared in several trackers as a victim attributed to DragonForce, and some descriptions mention data from Argentina, Uruguay, and other countries. However, the company is based in Argentina, and the material does not prove a direct Uruguayan victim. For Uruguay, the value of the case lies in the cross-border nature of the leaks and in the possibility that data from Uruguayan people or customers was exposed within a regional database.

Qilin and Agroland, a sign of agroindustrial risk

Agroland S.A. was listed by Qilin in several trackers and breach sites, with descriptions presenting it as an agroindustrial company based in Uruguay or with the RO region. The material does not confirm the intrusion or detail the type of information allegedly compromised. Even so, the case adds another signal of pressure on the agroindustrial sector, which often combines operational sensitivity, logistics, and commercial data.

Fraud and phishing, with a focus on consumer services and banking

The 5 fraud or phishing cases documented in August shared a common pattern, social engineering built around well-known brands and high-trust channels. The clearest was the one involving UTE and eBROU. There were also alerts about fake Netflix SMS messages targeting Uruguayan users to steal banking data and credentials.

In both scenarios, the attacker tries to move the conversation out of the formal channel and into an environment he controls. That sharply reduces the effectiveness of purely technical controls and makes it necessary to strengthen user education, brand impersonation monitoring, and out-of-band verification. The exposure of Latam Pass also serves as a reminder that even when full card numbers are not compromised, the combination of personal data and partial financial data is enough for later fraud.

APT, hacktivism, and unconfirmed campaigns

The only indication of hacktivism or coordinated pressure was VECERTRadar's preventive alert about a supposed #OpUruguay campaign against state portals. The publication itself labeled it unconfirmed, so it should not be treated as an incident. It is useful only as a monitoring lead for public infrastructure, especially since it mentions high-visibility government portals.

Critical vulnerabilities affecting Uruguay

The month produced a single critical vulnerability with operational confirmation in the material, CVE-2026-73570, tied to Zimbra Collaboration Suite and under active exploitation. No other critical CVEs were recorded in the August material reviewed, which does not mean there were no regional vulnerabilities, only that none were verified in this document set.

CVE Software Exploitation Source
CVE-2026-73570 Zimbra Collaboration Suite Active exploitation confirmed, command injection, arbitrary command execution as the zimbra user CNCS Uruguay, NVD, The Hacker News, CSA, runZero, Canadian Centre for Cyber Security

The local relevance is direct because Uruguay’s CNCS warned about active exploitation and recommended applying patches immediately. The government notice itself is the main reference here. Technical coverage added that the issue affects versions earlier than 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. In self-hosted email environments, that means exposure, versions, and logs need to be reviewed.

Regulation and compliance in Uruguay

Uruguay saw a notable cluster of regulatory decisions and draft rules in August, with direct implications for information security, personal data, and digital identity. The most structural move was the framework for Virtual Asset Service Providers, but it was not the only one. Open finance also advanced, along with warnings on currency risk, protections for minors on social networks, and the legal framework for online gambling.

Stack regulatorio de Uruguay en agosto 2026Barras comparativas con los principales movimientos regulatorios documentados durante agosto de 2026 en Uruguay.Documented regulatory developmentsNotable for their volume and cross-cutting impactVASPs and virtual assetsOpen financePersonal data URCDPElectronic ID and minorsOnline filingConsent and secrecyRegistered databasesPlatform oversight

Uruguay, August 2026, regulatory stack — Normative and administrative moves that shaped the month in security, data, and digital services.

Virtual assets and BCU supervision

The BCU opened an online process to request authorization and registration as a PSAV, aimed at legal entities that exchange, transfer, custody, or manage cryptoassets and digital tokens. The framework requires prior authorization from the Superintendency of Financial Services and a stricter compliance model, including information security, anti-money laundering measures, and audits, according to the regulations cited in the material.

At the same time, the regulatory review of stablecoins and virtual asset services makes clear that Uruguay still did not have an operating, specific VASP license, because bill 20.345 remained pending. That means the ecosystem continues to operate under existing corporate structures, commercial registry requirements, and prudential rules, while the BCU sandbox serves as an interim channel for financial innovation.

Dollar deposits and exchange rate risk

BCU Circular 2509 set a new warning for foreign currency deposits. The document must inform customers about exchange rate risk, and it may be provided to new depositors starting October 1, 2026. Existing customers have until December 31, 2026. The rule also allows notice by email or through a prominent alert in digital channels for a minimum period of ten business days.

This move is not cybersecurity in the strict sense, but it does touch on financial information, consent, and transparency. In practical terms, it strengthens the duty to explain risks to users and shows regulatory sensitivity around the bank-customer relationship. The same climate appeared in the open finance debate, where the BCU said express, informed consent remains the backbone of the system.

Open finance and bank secrecy

The Competitiveness and Cost of Living Reduction bill included the creation of an open finance system that allows the matching and sharing of financial data between entities. The issue sparked political debate over the scope of bank secrecy, and the Senate added a safeguard so that a user’s refusal to authorize the use or exchange of their data cannot condition procedures or access to products. That lowers the risk of commercial coercion, although tensions over data governance remain.

Personal data and databases registered by URCDP

The URCDP registered several databases in August, including SMART of Ducsa, VISTARA SERVICIOS AL CLIENTE S.A.S., Employees of Aduro S.A., Aplexi of ANTEL, Devoto Hnos video surveillance cameras, and Agesic Human Resources. The pattern shows steady administrative activity and the continued application of Law 18.331. It also opened enrollment for a course aimed at public agencies, with content on artificial intelligence, video surveillance, and minors’ data.

Digital identity and electronic ID

The National Civil Identification Directorate and Agesic signed an agreement to develop an app that will allow the electronic ID card to be used for identification and digital signatures in online services, reading the chip temporarily and without storing data on devices, servers, or in the cloud. The design aims to reduce identity exposure, provided implementation respects that no-persistence principle.

Minors, social networks, and platform penalties

The bill to prevent minors under 15 from creating social media profiles and to restrict adolescents aged 15 to 17 put the focus on digital platforms, with financial penalties and sanctioning authority assigned to AGESIC. Although the bill is still under discussion, its relevance for cybersecurity lies in age verification, the handling of minors’ data, and platform responsibility for compliance with protection rules.

Online gambling and digital security

CUOASEC promoted a bill to regulate online gambling with state authorization, the exclusive .bet.uy domain, a National User Registry, traceability, data protection, anti-money laundering measures, cybersecurity, and self-exclusion. The material makes clear that this is a sector initiative, not current law. Even so, its mere introduction shows local operators already see security and compliance as market entry conditions.

Most affected sectors in Uruguay

The month’s impact was spread across financial regulation, public administration, health, digital commerce, and, to a lesser extent, agribusiness. Not every sector faced the same pressure, but several were exposed to a mix of compliance issues, fraud, and extortion claims across different assets. The concentration of incidents was not uniform, although it was clear in banking, government, and sensitive services.

The financial sector saw the most activity, both in volume and in regulatory depth. BCU took up several lines on the agenda with PSAV, dollar deposits, and open finance. Fraud cases targeting bank accounts, identities, and payment methods added to that. Operationally, the risk is not only technical intrusion, but also impersonation, poorly managed consent, and abuse of trusted digital channels.

The public sector also had a strong presence. AGESIC, URCDP, CERTuy, the MIEM, the DNIC, and the Ministry of the Interior appeared with concrete actions, from decrees and resolutions to workshops and agreements. That points to an active state apparatus, but also to a broad area of technological dependence. When the state issues maintenance notices, protection courses, or new digital procedures, it is also acknowledging that its exposure is growing.

Health appeared in the Vigilia case, which stands out for the sensitivity of the data potentially involved and for the likelihood of extortion pressure. Agribusiness came up through Agroland, although the material did not confirm any impact in Uruguay beyond the company mention. Commerce and digital consumption were represented by the Netflix scam and by the partial exposure of Latam Pass data, two examples of how stealing personal information remains profitable without compromising entire systems.

Month-over-month comparison shows fewer total incidents than in July, but a mix that tilts more toward regulation and fraud. The count fell from 72 verified incidents to 49, with declines in unclassified incidents, ransomware or extortion, and regulatory moves that were only slightly lower. At the same time, fraud or phishing cases rose from 2 to 5, and the dominant threat shifted from vulnerabilities to regulation.

That does not mean the pressure has eased. It points instead to a reallocation of attention. In July, the material was more heavily weighted toward vulnerabilities. In August, the center of gravity moved to regulatory design, with direct effects on banking, personal data, and digital platforms. For security teams, the practical signal is that the most immediate risk combines compliance and process abuse, not just technical exploitation.

The second signal to watch is the persistence of ransomware with incomplete classification. August cut those cases from 17 to 8, but attribution quality remains uneven. Trackers and leak sites continue to publish claims that do not always turn into confirmed incidents. In that environment, the first operational decision is to classify what is known and what is not yet known.

The third signal is the rise in fraud across trusted channels. UTE, eBROU, Netflix, and other brand names show that the adversary is prioritizing social engineering over exploits. That strategy scales more easily and costs less than compromising infrastructure. If July was more about vulnerabilities, August made clear that the user remains the most profitable entry point.

Security recommendations for teams in Uruguay

This month’s priorities should center on four fronts: email, financial fraud, data compliance, and extortion response. CNCS’s alert on Zimbra calls for a review of patches and mail server exposure. The UTE case and Netflix SMS messages require stronger anti-phishing controls, identity verification, and monitoring for brand impersonation.

For financial institutions and fintechs, consent flows, traceability, and user notices should be reviewed. The open finance debate and Circular 2509 show that the regulator is focusing on how disclosures are handled and how authorization is captured. If third-party integrations are in place, access governance and the ability to revoke permissions must be clearly documented.

For data and privacy teams, August confirms that technical security alone is not enough. URCDP continues to demand documentation discipline, records, training, and reviewable measures. Any organization that handles personal data needs to prove its controls are implemented, not just stated. That applies to internal databases as well as video surveillance, customer service, and children’s data.

Against ransomware and leak-site claims, the approach has to be fast and conservative. If a mention appears, such as the one involving Vigilia, the right step is to trigger internal verification, indicator hunting, and containment, without waiting for outside confirmation before preparing a response. In cross-border campaigns such as Criba or Agroland, it is also worth checking whether data from Uruguayan customers, partners, or users is present in regional environments.

Frequently Asked Questions

What changed in Uruguay between August and July in the main threat and fraud categories?

August shifted from a month dominated by vulnerabilities to one led by regulation, while fraud or phishing rose from 2 to 5 cases and ransomware fell from 17 to 8. Taken together, the data suggests the focus moved toward compliance, identity, and trust abuse, not a broad drop in risk.

How should the Vigilia case be read alongside the Criba and Agroland trackers?

Vigilia is the only Uruguayan case with a direct claim involving a local health provider, but the source does not specify the type of impact. Criba and Agroland appear in trackers and leak sites with references that come close to Uruguay, though they do not always confirm a direct Uruguayan victim. The threat section explains that difference.

What is the relationship between the Zimbra advisory and the recommendations for teams in Uruguay?

CVE-2026-73570 affects Zimbra with active exploitation, and Uruguay's CNCS called for immediate patching. That ties directly to the recommendation to review self-hosted email, logs, and exposure. There were no other critical CVEs recorded in the August material, so this is the month's clear technical priority.

Which regulatory items have the biggest impact on data and cybersecurity this month?

The most relevant are the regime for PSAV, Circular 2509 on dollar deposits, the open finance debate, URCDP resolutions, and the agreement to use electronic ID online. Together, they require stronger authentication, traceability, consent, and personal data management across the public and financial sectors.

What type of fraud was most visible in Uruguay during August?

The most visible scam impersonated UTE to push victims toward eBROU and obtain loans or transfers. There were also fake Netflix SMS messages aimed at stealing banking data. Both cases show social engineering around familiar brands and directly affect users, banks, and customer support teams.

Material limitations

This report was built exclusively from the facts dated August 2026 included in the provided material. Facts from July 2026 were used only as a comparison frame and are explicitly identified as such where relevant. No internet search was performed, and no source outside the authorized list was incorporated.

A value of 0, especially for critical CVEs, means no verifiable mention appeared in the material analyzed during this period. It does not mean there were no critical vulnerabilities in Uruguay, or in the region, only that there was no documentary record in this set. The same applies to any indicator with no available comparison.

Facts without a confirmed date were excluded from the indicators. Aggregate telemetry on attempts or blocks was also not counted, because the material did not provide it as incident volume. In ransomware, the distinction was also maintained between confirmed encryption, exfiltration without encryption, and mere mention on a leak site. When the material did not allow that to be determined, it was marked as undeterminable classification.

Consumer social networks and any publication not listed among the permitted sources were left out of the main basis, as were sponsored or promotional materials when they were not corroborated by a primary source. The sector and regulatory reading prioritized official agencies, CSIRT/CERT advisories, regulators, and, secondarily, media coverage that reproduces or contextualizes those facts.

Sources