Logistics, Ports, Airports and Transport, Aug. 2026
August ended with incidents, ransomware and breaches across airports, ports, urban transit and logistics, with Argentina and Brazil dominating the picture.
Key findings
- August 2026 recorded 67 verified incidents and shifted the focus from vulnerabilities to real events in logistics, ports, airports and transport.
- Argentina and Brazil were the most exposed countries in the month, with Oldelval, Córdoba, Argentine airports, LATAM Pass and ICN as key cases.
- Ransomware showed different profiles: only one case had confirmed encryption, two aligned with exfiltration without encryption, three landed on leak sites, and nine could not be classified.
- Physical continuity was maintained in several cases, but the impact was concentrated in IT, personal data, email, portals and administrative systems.
- Regulatory moves were a key signal of the month, with notifications to CNV, ANPD and internal audits as part of the response.
- The most sensitive subsegments were urban transit, airline loyalty programs, outsourced logistics, ports and transport energy.
- The main operational need is to strengthen segmentation, tested backups, third-party control and pre-incident notification processes.
Monthly reference modules
These modules are populated automatically with verified dated facts from within the period. Each one states its basis and counting criterion, so the figures reconcile across modules. They are the recurring month-to-month readout, while the analysis that follows develops the cases without repeating this summary.
Indicator window: 67 dated facts in August 2026 · 3 from prior months (comparative frame, not monthly volume). Facts from prior months are used only as a comparative frame in the analysis, never as volume for this period.
Monthly executive summary
August 2026 sent a sharp, uneven signal across logistics, ports, airports, and transportation in Latin America. The month closed with 67 verified events, a heavier concentration of operational incidents than vulnerabilities, and a mix of breaches, ransomware, regulatory moves, and one documented phishing case. The regional picture was dominated by Oldelval, LATAM Pass, ICN, Uber Freight, Córdoba’s urban transit system, and North Carolina ports, with Argentina and Brazil standing out as the most visible poles of exposure and response.
The dominant threat was uncategorized incidents, with 27 of 67 events. That category includes disruptions, unauthorized access, and operational impacts where the material did not always make it possible to determine whether there was encryption, exfiltration, or only persistence on a leak site. Among cases with ransomware or extortion as the primary focus, there were 15 events, but the most useful detail for an operational reader is not the total, it is the shape of the impact: only one case showed confirmed encryption, two were aligned with exfiltration without encryption, three were referenced on leak sites, and nine did not allow the exact mechanism to be determined from the available evidence.
The sectoral breakdown shows a clear tension between operational continuity and data exposure. Oldelval and North Carolina Ports show that administrative systems, operating portals, and dispatch flows can be affected without necessarily stopping the physical movement of cargo or crude oil. LATAM Pass and the attack on the three Argentine airports, by contrast, put the focus on traveler data, customer identifiers, and satellite mobility services, with the impact centered on privacy and possible follow-on fraud. At the same time, the Córdoba case showed that an urban transit system can accumulate credentials, databases, identity documents, and even remote control capability, although in that episode the problems were corrected before malicious exploitation.
The most relevant reading for security teams is that the region did not see only data theft or extortion campaigns. There were also signs of structural weakness in third-party governance, in the segmentation between IT and operations, and in the exposure of accessory platforms that support the core business. Most of the events were directly confirmed by sources, with a declared proportion of 94%, which reinforces that the month was not low-quality noise but an accumulation of concrete cases involving mobility, logistics, and transportation infrastructure.
Compared with July, August was tougher in volume and in the diversity of attacked surface. The prior month had fewer events and a greater focus on vulnerabilities, while August shifted the center of gravity toward real incidents, confirmed breaches, and regulatory response. The sector mix also changed, since the previous month’s material was more concentrated, and in August there were seven sectors with at least one documented event. That does not suggest healthy dispersion, but the opposite, an expansion of the exposure front across critical transportation and logistics chains.
The 10 regulatory moves deserve separate attention because they show that notification is no longer a marginal issue. Oldelval was a clear example of disclosure forced by Argentina’s capital markets regime, while LATAM reported the case to Brazil’s ANPD and informed potentially affected customers. Taken together, the material suggests that pressure for transparency is advancing, but in a fragmented way and often driven by rules outside sector-specific cybersecurity.
Regional overview for the month
August stood out in the region for volume, severity, and the range of impacts, with a high-risk reading for logistics, ports, airports, and transportation across Latin America. The picture was not driven by a single disruptive attack, but by a buildup of breaches and ransomware operations, along with exposure in satellite systems and regulatory intervention. When one month includes airports, a pipeline operator, an airline, a military shipping company, a freight platform, and an urban transit system, the attack surface is no longer peripheral.
The defining feature of the period is that many cases affected business continuity without fully shutting down physical operations. Oldelval kept pumping without interruptions, and North Carolina Ports returned to normal gates while still working in manual mode. That points to an important pattern for the region, cyber intrusions target IT first, then administration, portals, and identity, and only later can they escalate into operational control. In several cases, the evidence showed exactly that boundary, with containment limited to administrative or support systems.
A second risk line also appeared, quieter but persistent, the exposure of traveler, customer, and user data. LATAM Pass compromised personal data from loyalty program participants, the attack on three Argentine airports exposed email addresses, phone numbers, license plates, and postal codes tied to parking and booking services, and the system in Córdoba revealed access to identity documents, banking credentials for recharges, and administrative accounts. For transportation operations, that combination is critical because it blends fraud, social engineering, account takeover, and service tampering.
The comparison with July also reinforces the change in tone. The previous month was dominated by vulnerabilities, with fewer events and less sector diversity. In August, the pressure shifted toward concrete incidents, public disclosures, and regulatory moves. That is not an improvement in the region’s security posture, but a sign that the material captured more realized events and more formal responses. The operating trend is clear, exposure maturity is more visible than the ability to contain it consistently.
Period indicators
| Indicator | August 2026 | Previous month | Change |
|---|---|---|---|
| Verified facts for the period (base of all indicators) | 67 | 23 | +44 |
| Indicator time window | 67 facts dated in August 2026 · 3 from prior months (comparative frame, not monthly volume) | Same frame | N/A |
| Unclassified incidents (breaches or disruptions) | 27 | 3 | +24 |
| Cases with ransomware or extortion as the primary focus | 15 | 5 | +10 |
| Confirmed asset encryption | 1 | n/d | n/d |
| Exfiltration without encryption (simple extortion) | 2 | n/d | n/d |
| Leak site mention only | 3 | n/d | n/d |
| Classification could not be determined from the material | 9 | n/d | n/d |
| Documented fraud or phishing cases | 1 | 1 | no change |
| Documented regulatory moves | 10 | 0 | +10 |
| Critical CVEs mentioned | 1 | 4 | -3 |
| Sectors with at least one documented fact | 7 | 3 | +4 |
| Dominant threat of the month | Incidents (27 of 67 facts) | Vulnerabilities (8 of 23 facts) | Shift in focus |
| Facts directly confirmed by the source | 94% | n/d | n/d |
The table points to a signal in which operational incidents outweighed vulnerability disclosures. That shift matters because it moves the discussion from potential exposure to damage that has already materialized, or at least been confirmed by the source. The ransomware breakdown also shows that public attribution and real impact do not always line up. In nine of the 15 cases with ransomware or extortion as the primary focus, the material did not make it possible to determine whether there was encryption or exfiltration, a limitation that requires close reading of each source.
Relevant incidents
Oldelval and crude continuity
Oldelval was the month’s most sensitive case because of the combination of scale, critical infrastructure and contained impact. The company reported an information security incident to the CNV that affected administrative systems, but crude transport continued without interruption and the affected platforms were restored. Different reports converge on the event being confined to IT and administrative functions, with no evidence of disruption to pumping.
The case matters not only because of the attack itself, but because of how it became public. People of Internet noted that the disclosure was made under the capital markets material event regime, not under a specific critical cybersecurity reporting obligation. That is relevant for the region because it shows an indirect regulatory path for exposing incidents that might otherwise remain closed off or be reported later. The company operates a network that carries about 75% of Vaca Muerta crude, so any incident in its administrative perimeter carries reputational and governance impact beyond the immediate technical effect.
The material also points to uncertainty around attribution and method. Infobae and other outlets picked up claims on social media or leak sites by The Gentlemen, but the company did not publicly confirm that attribution. Ransomware.live provided a more precise timeline, with discovery on August 4 and an estimated attack date of August 3. Operationally, Oldelval shows a pattern worth watching in energy and transport, intrusion into support systems, public exposure through the capital markets, and physical continuity preserved.
LATAM Pass and loyalty risk
LATAM Pass closed August as one of the most delicate cases for regional air transport because it affected customer personal information, not flight operations. LATAM Airlines Group reported an unauthorized access identified on July 29, with improper queries to registration data and information linked to LATAM Pass accounts. In August, coverage уточified that the affected group was limited, although TechTimes estimated the potential universe of impacted users could reach a subset of about 54 million loyalty program members.
The type of data matters. Brasil 247 and TecMundo reported full names, dates of birth, email addresses, phone numbers, addresses, membership number, program tier, mileage balance and qualifying points. LATAM’s own communication, as cited, said more sensitive banking data would not have been obtained. Even so, the combination of identity, contact details, program affiliation and mileage balance is enough for fraud campaigns, account takeover and customer impersonation.
The case also had a clear compliance component. Brazil Stock Guide reported that LATAM notified potentially affected customers and reported the case to Brazil’s ANPD, along with containment measures and stronger cybersecurity controls. That sequence is useful for the sector because it shows the response did not stop at technical remediation. In a loyalty program, reputational damage comes from the mix of privacy expectations and the commercial value of accumulated data.
Argentine airports and satellite services
The attack on three Argentine airports illustrated a class of incident that often sits at the edge of the public narrative, but has high operational value. TN specified that the compromised data belonged to a parking and reservation management service linked to those airports. It also clarified that flight control systems and aviation infrastructure were not affected. That boundary reduces concern over direct operational safety, but it also confirms an intrusion useful to criminals because it exposes traveler and vehicle logistics information.
The leaked material included email addresses, phone numbers, vehicle license plates and postal codes for customers. The risk is not abstract. With that data, attackers can build highly credible fraud campaigns, exploit the link between travel, vehicles and home locations, or even extend the reach to other airport-related services. The weak point was not the aviation core, but the layer of customer service and mobility around it.
For airport teams, the case leaves a concrete warning. Reservation, parking, payment, loyalty and customer management platforms should be treated as sensitive assets, not secondary services. The separation between flight operations and support services worked as partial containment in this event, but the exposure of identities and travel data remains a meaningful commercial and reputational risk.
Córdoba and the urban transport system
Córdoba’s urban transport system was the month’s most striking technical exposure case. Ignacio Navarro reported critical failures across an ecosystem that integrated buses, taxis, card recharging, in-vehicle cameras, personal information and administrative accounts. According to Clarín, he gained access to that environment and then reported the findings to the vendor and the national CERT. The coverage says the problems were fixed before malicious actors could exploit them.
A technical interview published on YouTube expanded the scope of the finding. It described access to databases, banking credentials used to top up transit cards, more than 20,000 digitized identity documents stored without adequate protection, and the ability to send commands to bus terminals to shut engines off, turn lights on or activate panic alarms. The most serious point is not any single component, but the way they were chained together. A system managing urban mobility ended up combining personal data, recharge finance and remote control functions.
The institutional response also stood out. Cadena 3 reported that the municipality learned of the hack from the press and from the report through CERT.ar, and announced an internal audit of the vendor and a review of technology contracts. Derecha Diario added that the municipality found out through news articles. The sequence confirms a common asymmetry in urban transport, technical detection can come before formal incident management.
Uber Freight and third-party logistics
Uber Freight stands out as an important case because it is a logistics operator with activity in Brazil and because of the type of data involved. Reuters reported that the company was investigating a data security incident after a claim by the Helix group. TechCrunch and Security Magazine added that the attackers said they had accessed email inboxes, cloud storage, accounts payable records and dispatch documents, while the company said its operations were still running.
The analytical value of the case lies in the boundary between operations and data. If commercial logistics continues but communication channels, document repositories and payment accounting are compromised, the damage can be delayed and then grow later. The alleged leak of about 1 million files, mentioned by Security Magazine, was not conclusively confirmed by the company. Even so, the material is enough to classify the event as an unauthorized access incident with extortion and contractual exposure potential.
Brazilian coverage from MixVale echoed that Helix claimed responsibility for the intrusion and information leak, but kept the same verification limits. For logistics, that is the sensitive point, there is no need to stop cargo to create pressure, it is enough to compromise email, manifests, dispatch documents or accounts payable. The case makes clear that the risk perimeter includes global operators serving the region, not only Latin American companies.
ICN and ransomware with confirmed encryption
Itaguaí Construções Navais was the only case in the month with confirmed encryption in the material analyzed. Jornal Atual reported that the company detected a ransomware attack on the night of August 9 that reached its information technology environment and encrypted data. Later coverage said email servers, systems, files and databases were affected, although backups were preserved and there were no public signs of data leakage at the time of reporting.
The significance of the case goes beyond the company itself. ICN operates in the Itaguaí naval complex, an environment tied to submarine construction, so ransomware with confirmed encryption in IT has national security and industrial implications. There is still no official confirmation on attribution or total scope, but the material does show that the company was able to rely on backups to safeguard information and avoid an irreversible loss of continuity.
FalconFeeds.io mentioned a possible link to LockBit 5.0 based on threat intelligence sources, although without official confirmation from the victim. That distinction matters, because the case shows the difference between a leak site listing and an attribution validated by the affected organization. Here, there is a hard fact for the regional report, a ransomware event with verified data encryption at a sensitive company in Brazil’s maritime and naval ecosystem.
North Carolina Ports and manual operations
Although it is not in Latin America, the North Carolina Ports case is included as an operational comparison because it shows how a port authority behaves when intrusion hits shared IT. The Supply Chainer explained that common IT infrastructure forced core systems to be isolated and all three state logistics hubs to shift to manual mode at the same time. Shieldworkz added that the intrusion disabled OCR portals for trucks, TWIC verification and TOS workflows, forcing manual tasks for container positions, inventory and EDI messaging.
The lesson for Latin American ports is direct. Damage does not need to reach cranes, PLCs or vessel traffic to create delays and logistics friction. Cyberinfos.in and WECT indicated that the contingency plan was activated, with intervention from the U.S. Coast Guard and state agencies, while operations remained partly manual. The key point is that the authority reported the incident contained and with no public signs of compromise of sensitive data, but continuity was maintained at a degraded operational level.
That model helps interpret ports in the region. If a TOS, an OCR portal or an access check fails, the operator can keep moving cargo manually for a time, but operating costs rise quickly. North Carolina’s experience shows that shared IT across facilities expands the blast radius and turns the container yard, the gate and messaging into bottlenecks.
Active Threats and Campaigns
Ransomware and extortion with uneven impact
The set of ransomware and extortion cases was broad, but operational quality varied widely. Only one case showed confirmed asset encryption, ICN. Two other incidents aligned with exfiltration without encryption, Uber Freight and LATAM Pass, where the material describes unauthorized access and improper data leakage or consultation. Three cases were only mentioned on a leak site, Oldelval, Integraduanas and Flecha Bus, without official confirmation of the full impact. Nine cases did not allow the mechanism to be determined precisely from the available evidence.
That distinction matters because it changes the defense posture. When encryption is confirmed, the priority is recovery, segmentation, backups and forensic preservation. When exfiltration dominates, the focus shifts to notification, fraud, customer protection and identity controls. When a case appears only on a leak site, the team should treat it as a risk signal, not as a closed incident. The month showed all three forms coexisting in the same sector.
Oldelval was the clearest example of a mention with continuity preserved. Integraduanas and Flecha Bus were left as third-party claims without official confirmation in the material reviewed. Metaencryptor and The Gentlemen also appear as recurring names across different sources, suggesting a RaaS ecosystem or opportunistic extortion rather than a single, uniform campaign. Analytical caution is required, because not every name on a leak site means the same level of impact.
Fraud and phishing
The month produced a single documented fraud or phishing incident, but its potential impact is high because of the type of data exposed. The LATAM Pass case points to a very clear fraud risk, even if it was not described as a phishing campaign in the strict sense. The combination of names, email addresses, phone numbers, addresses, membership number and miles balance is useful material for impersonation and targeted social engineering against customers likely to respond.
In transportation and airlines, the line between breach and fraud is crossed quickly. Loyalty data can be used to reset passwords, simulate travel notifications, request false validations or attempt fraudulent point redemptions. For that reason, customer notification and coordination with the ANPD are part of damage control. At the regional level, the key point is not that there was only one fraud case, but that the documented material shows a database large enough for that fraud to grow later.
APT and hacktivism
This month's material did not show a consolidated regional APT campaign against logistics, ports, airports or transportation in Latin America. There was a reference to Lazarus linked to exploitation of a Windows zero-day in campaigns against defense and aerospace in several countries, including Brazil, through fake job offers. That event did not turn into a direct incident in the vertical covered by this report, but it does signal targeting of environments close to sensitive infrastructure.
The only case that comes close to an activist or demonstration-style action is the one in Córdoba, where a researcher carried out tests and disclosed critical flaws, but the material frames it as ethical hacking and a report to CERT.ar, not as a hostile intrusion. It is important to distinguish that from a hacktivist campaign. For the month analyzed, there is not enough evidence to describe an APT or hacktivist operation against the vertical based on verified facts in the region.
Critical Vulnerabilities
The material reviewed mentioned a single critical CVE, CVE-2026-68820, tied to a Lazarus campaign against the defense and aerospace sectors in several countries, including Brazil. No other critical CVEs were recorded in this month’s evidence. That does not mean critical vulnerabilities were absent from exploitation in the region, only that they did not appear in the corpus reviewed for this report.
| CVE | Software | Exploitation | Source |
|---|---|---|---|
| CVE-2026-68820 | Windows | Zero-day exploitation linked to campaigns against defense and aerospace, with fake job offers used to compromise systems and escalate privileges | CyberSec Brazil |
This should not be read as a structural improvement in exposure. It instead suggests that August was shaped more by materialized incidents than by the disclosure of new critical flaws. In a month where the focus shifted to breaches, ransomware, and regulatory responses, CVE visibility declined. The technical risk remains, but it was not the main documented signal in this period.
Regulation and Compliance
Regulation took center stage in August because several cases forced disclosure, escalation, or contract reviews. Oldelval had to report the incident to the CNV under the material event regime, and People of Internet pointed out that this was the legal framework that made the disclosure public. In practice, that means transparency came from a market disclosure obligation, not from any specific critical cybersecurity rule.
LATAM followed a different but still regulatory path. The company reported the incident to Brazil’s ANPD and notified customers who may have been affected. That response separates an internal operational problem from an exposure that triggers personal data oversight. For airlines and loyalty programs, coordination among security, privacy, and customer service is no longer optional.
In Córdoba, the municipal government announced an internal audit of the company that provides the transportation system, along with a review of technology contracts. That matters for public agencies and mobility operators because the incident does not end at the technical layer. When third parties have access to sensitive data and remote control, contractual and oversight measures matter as much as patching vulnerabilities.
The regulatory takeaway for the month is that Latin America still relies on fragmented frameworks to force incident disclosure. Capital markets, data protection, and administrative audits emerged as the channels for transparency. In the material reviewed, there was no equivalent sign of regional sector coordination for ports, airports, or land transportation.
Countries and most affected subsegments
Argentina
Argentina accounted for a substantial share of the signal because of the combination of Oldelval, Córdoba, the airports, and mentions of Flecha Bus and Integraduanas. The pattern was not uniform. In oil and energy logistics, Oldelval maintained physical continuity. In urban transportation, Córdoba showed much deeper technical exposure, with access to databases, credentials, and potential control of equipment. At airports, the damage was concentrated in customer data and parking and reservation services.
The country-level reading is that Argentina showed both critical infrastructure and vulnerable satellite services. It also showed the difference between learning about an incident through the press, as the Córdoba municipal government said, and managing one through formal channels. The most exposed subsegment was not a single vertical, but the technology integration layer between mobility, customer service, and operations.
Brazil
Brazil was the other main focus of the month, with LATAM Pass, ICN, and the reference to Lazarus. The airline case was linked to personal data and compliance with the ANPD. ICN, by contrast, was a ransomware incident with confirmed encryption of IT systems and possible data preservation through backups. Together, the two cases point to a country facing simultaneous exposure in air transport, shipbuilding, and corporate data environments.
What stands out in Brazil is the coexistence of privacy breaches and operational ransomware. The issue is not only data theft, but also how repositories, backups, and notification channels are protected. The fact that ICN was able to preserve data thanks to backup copies is useful, but it should not obscure the fact that files were encrypted in a sensitive environment.
Mexico
Mexico appears with lower volume, but with signs of extortion against Integraduanas, a logistics, supply chain, and warehousing company focused on foreign trade. The available material did not confirm the incident through an official source, but it does include a public claim by Qilin and a warning about a possible data leak. For a foreign trade operator, that kind of mention is enough to trigger monitoring of credentials, document exchange, and customer exposure.
Most exposed subsegments
The most affected subsegments were urban transportation, airports, third-party logistics, ports, and transport energy. Each showed a different kind of damage. Córdoba showed potential control over mobile assets. Argentine airports and LATAM Pass showed exposure of personal data. Oldelval and North Carolina Ports showed degraded but uninterrupted continuity. Uber Freight, along with the claims involving Flecha Bus and Integraduanas, suggests that outsourced logistics remains a highly attractive target for extortion and data theft.
Trends and signals to watch
The comparison with the previous month is clear. August rose from 23 to 67 verified incidents, with a sharp jump in unclassified incidents, from 3 to 27, and in regulatory actions, from 0 to 10. The shift in the dominant threat, from vulnerabilities to incidents, shows that the month’s corpus was much more concentrated on events that had already materialized than on theoretical exposure. That requires regional teams to prioritize detection, containment, and reporting, not just patch management.
The second change is diversification. The previous month had only three sectors with at least one documented incident, while August reached seven. That expansion matters because it reduces the chance of assuming the problem affects only one subindustry. When airports, ports, urban transport, oil, airlines, and digital logistics all appear together, the right reading is systemic.
The third signal is that the month produced more administrative incidents than total operational outages. That can be read as a relative positive, but it would be misleading. Intrusions into IT, accounts, portals, reservations, and email are enough to create fraud, delays, and recovery costs. Physical continuity does not equal full resilience.
The final signal is regulatory. Without formal moves, many incidents would have remained invisible or limited to tech press coverage. The fact that 10 events led to communication, audit, or notification shows that pressure for transparency is rising. For regional security, that means preparing the incident exit as carefully as the technical response.
Security team recommendations
First, business and operational domains need to be separated more rigorously. This month showed several times that damage enters through satellite systems, not the physical core. Airports, ports, and urban transport should immediately review segmentation across reservations, parking, loyalty, email, TOS, OCR, card top-ups, and control systems. If a vendor manages those environments, the contract must require telemetry, notification timelines, and recovery tests.
Second, exfiltration should be treated as a first-tier threat, even without encryption. LATAM Pass and Uber Freight show that data access can be as damaging as ransomware. That means strengthening DLP, monitoring unusual access, alerting on large downloads, controlling administrative accounts, and reviewing email and cloud repositories. In loyalty programs and document logistics, stolen data can fuel later fraud.
Third, restore backups in practice, not just on paper. ICN preserved data thanks to backup systems, but that outcome cannot be assumed. Teams should rehearse restores from immutable backups, validate recovery times, and confirm whether the backup is isolated from the same compromised identity. In ports and transport, real RTOs are often longer than the plan promises.
Fourth, expand monitoring of third parties and the integration ecosystem. The Córdoba system exposed administrative accounts, cameras, top-ups, documents, and remote functions. That means a poorly segmented vendor can open a large attack surface. Reviews should include an inventory of integrations, MFA for admins, credential rotation, centralized logs, and a least-privilege policy that extends to subcontractors.
Fifth, prepare public notification and response templates before an incident. Oldelval, LATAM, and the municipality of Córdoba ended up responding under pressure from the press, CNV, ANPD, or CERT. It is better to have prewritten texts, workflows, and assigned owners. In logistics and transport, delayed information often amplifies reputational damage more than the initial intrusion.
Sixth, strengthen detection of abuse across portals and peripheral services. The Argentine airports were exposed in parking and reservations, not in flight control. That kind of surface deserves session review, credential review, adaptive captchas, database segregation, and integrity controls. When personal data is the target, the attacker does not always touch the most visible system.
Frequently Asked Questions
What changed since July in the transportation and logistics axis?
August showed a sharp jump from July, with more verified cases, more unclassified incidents, more affected sectors, and 10 documented regulatory moves. Last month, the dominant theme was vulnerabilities. In August, real incidents, breaches, and formal response took center stage, especially in Argentina and Brazil.
Which case had the clearest confirmed operational impact?
The case with the clearest impact on continuity was North Carolina Ports, used here as an operational comparison because it forced manual operations. In Latin America, Oldelval kept crude transport running without interruption, while ICN had confirmed encryption in IT. Operational severity depended more on the type of system affected than on the name of the actor.
Which incidents exposed travelers' or customers' personal data?
LATAM Pass and the attack on three Argentine airports accounted for the main exposure of personal data. In LATAM, names, birth dates, emails, phone numbers, addresses, and loyalty program data appeared. At the airports, emails, phone numbers, license plates, and postal codes tied to a parking and reservations service were compromised.
Was there ransomware with confirmed encryption in the regional vertical?
Yes, the only case with confirmed encryption in the material was ICN, in Brazil. Oldelval had claims and a mention on a leak site, but the company said the incident was confined to administrative systems and did not interrupt transport. For the rest of the extortion cases, the available evidence did not allow the mechanism to be determined precisely.
What should sector security teams prioritize?
They should prioritize segmentation between operations and satellite services, protection of personal data, tested backup restoration, third-party monitoring, and regulatory notification readiness. This month’s cases show that harm enters through email, loyalty programs, parking, reservations, document logistics, and administrative systems, rather than through the main physical operation.
Material limitations
This report was built exclusively from the facts provided for August 2026, plus three facts from earlier months used only as a comparative frame and always with their month stated explicitly. No internet or any other source outside the allowed material list was used. Aggregated telemetry was also not included, because the material did not provide it.
A zero indicator, especially for critical CVEs, means none were recorded in the material analyzed, not that no critical vulnerabilities existed in the region. The same applies to any missing category. The time window for the indicators is the one declared at the start of the document, 67 facts dated in August 2026 and 3 from earlier months used only as a comparative frame, not as monthly volume.
Consumer social media and sponsored content or press releases were excluded as evidence, and no source outside the available source list was cited. Facts without a confirmed date were not used because they are not part of the indicators. When the material did not allow a distinction between encryption, exfiltration, or a mere mention on a leak site, that ambiguity was kept in the text rather than assigning a label that was not supported by the source material.
Technical appendix: indicators of compromise and TTPs
No verifiable IoCs were published in the material allowed for this report. Nor were hashes, domains, IPs, or TTP lists documented with enough detail and a citable source within the analyzed corpus. For that reason, this section is omitted without adding speculative content.
Frequently Asked Questions
What is the difference between an administrative incident and a full operational outage?
An administrative incident affects email, data, portals, or support repositories, while a full operational outage disrupts the main physical function. Oldelval and LATAM showed administrative or data impacts, and North Carolina Ports served as a reference for degraded operations without necessarily implying a total shutdown of the main service.
How much weight did regulation have in August?
It was one of the clearest features of the month. Oldelval disclosed its incident under a capital markets obligation in Argentina, LATAM reported it to Brazil's ANPD, and the municipality of Córdoba opened an internal audit. Regulation did not stop the incident, but it did push transparency and public traceability.
Which subsegments of the vertical were most exposed?
The most exposed were urban transport, airports, outsourced logistics, ports, and transport energy. Córdoba showed potential control over mobile assets, Argentine airports and LATAM Pass exposed personal data, and Oldelval and ICN combined critical continuity with IT disruption. The most sensitive surface was satellite systems and administration.
Why does the material say the month was high risk?
Because there were 67 verified events, 27 incidents without a defined category, 15 ransomware or extortion cases as the primary focus, 10 regulatory moves, and 7 sectors with at least one documented event. The impact also reached airports, urban transport, pipelines, logistics, and ports, with effects affecting both data and operations.
Countries and most affected subsectors
Chile and airlines
The only incident tied to a company with broad regional reach was LATAM Pass, which affected LATAM Airlines Group and exposed member data from the loyalty program. From an industry perspective, the most exposed subsector was airline loyalty, because it combines identity, travel history, and economic value accumulated in points or miles.
Urban transport and mobility
Córdoba showed that urban mobility can be exposed by poorly segmented technology integrations. The system reviewed by Ignacio Navarro included buses, taxis, cameras, reloads, and identity documents. That means urban transport has to be seen as a complex technology platform, not just a fleet of vehicles.
Ports and cargo logistics
Ports and cargo logistics were represented by North Carolina Ports, Uber Freight, and complaints involving Integraduanas and Flecha Bus. The common pattern is the value of email, shipping documents, the TOS, and gate processes. Disruption does not need to reach cranes to affect timing, coordination, and costs.
Security team recommendations
About customer data and loyalty programs
Separate loyalty, identity, and payments databases, review access to balances and points, and enable alerts for changes to email, phone number, or password recovery. When a breach exposes names, birth dates, and program details, the risk of follow-on fraud rises quickly. The response must include clear communication to users.
About ports and terminals
Isolate TOS, OCR, EDI, gate systems, and third-party access, and test manual operations without relying on the same identity environment. The North Carolina Ports incidents show that manual continuity can be maintained, but with delays. In Latin American ports, that delay may be the first visible sign of a larger compromise.
About reporting and governance
Define in advance who notifies the CNV, ANPD, CERT, or sector authorities, and which thresholds trigger each channel. August made it clear that transparency can come through different channels. If the organization expects to improvise that part during the incident, reputational damage will widen.
Graphics
Sources
- Ciberdelincuentes atacaron a tres aeropuertos y robaron información de viajeros: ¿a qué riesgos quedaron expuestos?TN (Todo Noticias)
- Un hacker cordobés detectó fallas de seguridad en el sistema de transporte urbanoEl Resaltador
- Se infiltró y vulneró el sistema de transporte de importantes empresas | con Ignacio NavarroYouTube
- La Municipalidad de Córdoba se enteró del hackeo al sistema de transporte por la prensaDerecha Diario
- ¿Qué dijo la Municipalidad tras el hackeo al sistema de transporte?Cadena 3
- Ransomware a Oldelval: la gobernanza que le falta a Vaca ...Datatrends Latam
- BSides Las Vegas: un argentino mostró cómo pudo hackear todo el sistema de transporte de CórdobaClarín
- Victim: Oleoductos del Valle – incransomRansomware.live
- Argentina's Main Oil Pipeline Was Hacked. The Oil Kept MovingThe Rio Times
- La operadora del oleoducto por el que circula el 75% del petróleo de Vaca Muerta sufrió un ciberataque a sus sistemasInfobae
- La operadora del oleoducto por el que circula el 75% del petróleo de Vaca Muerta sufrió un incidente de seguridad informática que afectó sus sistemas administrativosDiario Neuquino / Energy Report
- Argentina's Oldelval Cyberattack Disclosure Shows Securities Law, Not Cyber Law, Is Doing the WorkPeople of Internet
- LM Mobilidade avança em retomada de operações após ataque cibernéticoValor Econômico
- Ransomware Alert: ICN - Itaguaí Construções Navais listed as LockBit 5.0 victimFalconFeeds.io
- Latam Pass Data Breach: Exposed BIN Data Creates Fraud Risk Beyond Partial Card ClaimsTechTimes
- LATAM Pass sofre ataque cibernético e expõe dados de clientesMinuto da Segurança
- Latam confirma vazamento limitado de dados de clientes do Latam PassBrasil 247
- LATAM Pass sofre invasão cibernética e expõe dados de clientesTecMundo
- LATAM confirma incidente de vazamento de dados de clientesBrazil Stock Guide
- Hackers reivindicam ataque e Uber Freight apura violação de dadosMixVale
- Ataque cibernético atinge sistemas da ICN em ItaguaíJornal Atual
- Lazarus mira setor de defesa e aeroespacial no Brasil com zero-day do WindowsCyberSec Brazil
- Uber Freight reportedly investigating after hacking group claims data breachTechCrunch
- Uber Freight investigating data security incident after Helix claims breachSC World
- Uber Freight says its investigating cyber incident following hacker claimsReuters
- Ataque cibernético paralisa sistemas da ICN em ItaguaíJornal Atual
- North Carolina Ports Cyberattack Exposes Shared IT as a Critical Operational RiskThe Supply Chainer
- North Carolina Ports cyberattack: What happened, what we know and what we still don'tShieldworkz
- CoinbaseCartel Targets Argentine Transport Giant Flecha BusDexpose
- Ransomware Alert: Grupo Integraduanas (https://t.co/KL6vwKEmcn ...FalconFeeds.io
- Qilin Ransomware Strikes Integraduanas in MexicoDexpose
- Cybersecurity Weekly Report : August 3-9, 2026Cyberinfos.in
- North Carolina Ports Authority Faces Major Cyberattack, Operations DisruptedSamSearch
- Outside group hacks IT systems at N.C. ports, breach containedYahoo News / WNCT
- NC Ports operating manually after cyberattack disrupts statewide systemsWECT
- North Carolina Ports Authority Cyberattack Disrupts IT Systems and Port Operations at Wilmington, Morehead City, and Charlotte Inland PortRescana
- Cyberattack disrupts operations at NC Ports in Wilmington, Morehead City, CharlotteWECT
- Oldelval Cyberattack Hits Argentina's Top Oil Pipeline - The Rio TimesThe Rio Times
- Oldelval, the company that operates the largest oil pipeline in Argentina, suffered a cyberattackDerecha Diario
- Ransomware Group Emperador Hits: Capitol MechanicsHookPhish
- Capitol Mechanics — EMPERADOR Ransomware AttackBreach House
- Capitol Mechanics Listed by Emperador Ransomware GroupGalaxyWarden
- METAENCRYPTOR Ransomware Gang: 7 Victims in 24 Hours Cross-Sector Blitz Targeting Transportation, Energy and HealthcareSecurityArsenal
- Listing of Metaencryptor victims including Trailer Transit IncIntel and Breaches (X)
- Trailer Transit Inc Listed by Metaencryptor Ransomware Group | 2026-08GalaxyWarden
- Trailer Transit Inc — METAENCRYPTOR Ransomware AttackBreach House
- Trailer Transit Inc Listed by Metaencryptor Ransomware Group | 2025-09GalaxyWarden
- Cyberattack Hits North Carolina Ports, Disrupts OperationsProtect Computer
- Coast Guard says it is monitoring cyberattack that disrupted North Carolina portsCyberScoop
- Maritime Cybersecurity Bulletin - August 7th, 2026Cydome
