Latin America Cybersecurity Landscape, July 2026
July ended with regulatory pressure, banking fraud, ransomware in healthcare, and attacks on government and energy across the region.
Key findings
- The month’s dominant threat was regulatory, with 261 documented incidents and a strong shift toward notification, sanctions, and data governance.
- Digital fraud remained the most common vector, with AI, vishing, WhatsApp impersonation, and banking phishing as dominant tactics.
- Brazil saw the clearest pressure on healthcare, energy, and the corporate perimeter, with ransomware and actively exploited vulnerabilities across multiple fronts.
- The Ecopetrol attack was the most sensitive corporate incident of the period due to unauthorized access, possible extortion, and data exposure.
- Mendoza became the region’s most active regulatory laboratory, with proposals on cybersecurity, personal data, reporting, and even ethical hackers.
- Chile advanced on deepfakes, stronger authentication, and CSIRT alerts, consolidating a mature response to fraud and digital identity.
- AI is now a multiplier for offensive and defensive activity in the region, especially in identity fraud, OT, and campaign automation.
Monthly reference modules
These modules are filled automatically with the verified dated facts within the period. Each one states its basis and counting criteria so the figures reconcile across modules. They are the recurring month-by-month readout; the analysis that follows develops the cases without repeating this summary.
Indicator window: 867 dated facts in July 2026 · 9 from prior months (comparative frame, not month volume) · 41 without confirmed date (excluded from indicators) · 6 after the period (excluded). Facts from prior months are used only as a comparative frame in the analysis, never as volume for this period.
Monthly executive summary
July 2026 produced a regional picture shaped by two forces moving in parallel. The first was regulatory. The month closed with 261 documented regulatory-related events in the verifiable database, making that axis the period's leading threat. The second was operational, with a mix of digital fraud, ransomware, and attacks on public agencies and critical sectors that again showed Latin America under sustained pressure, most visible in banking, healthcare, government, and energy.
The most consequential incident in terms of impact was the attack on Ecopetrol in Colombia. The company confirmed unauthorized access on July 17, activated its internal protocol, coordinated with the Fiscalía and the MinTIC to remove leaked files, and filed a 6-K with the SEC. The public attribution to the group The Gentlemen, along with the claim that it had up to one terabyte of information, was not validated by the company, but the episode stood out as one of the month's main events because it combined extortion, data exposure, and corporate and regulatory sensitivity.
Brazil carried the clearest pressure on critical infrastructure and healthcare. The country continued to appear as the regional epicenter of healthcare ransomware, with multiple reports involving hospitals, clinics, and healthcare providers, as well as incidents targeting energy and utilities. Global Secret Group listed SPDM and Sinop Energia on its leak site, while Blackwater appeared linked to msgas.com.br. At the same time, CERT.br and CTIR Gov warned about critical vulnerabilities actively being exploited in VPNs, SharePoint, and Ivanti, a set of issues that helps explain why the country sustained very high exposure across both corporate and state perimeters.
Argentina, meanwhile, combined a regulatory agenda with a wave of digital fraud especially visible in banking and digital wallets. The Central Bank stepped up its anti-fraud messaging, published formal complaint guidelines, and alerts multiplied around vishing, WhatsApp impersonation, synthetic identities, and the use of AI to speed up scams. At the same time, Mendoza became the region's most active regulatory laboratory in the month, with bill proposals on cybersecurity, data protection, data governance, ethical hacking, and rapid incident notification. The province was also caught in a politically sensitive moment, as the legislative debate moved forward and the Senate website was breached in a politically motivated attack.
Chile added another strong regulatory thread, with the deepfake bill advancing in the Chamber of Deputies and new CSIRT alerts about OpenSSH, Ivanti, Citrix, SharePoint, and vulnerabilities in exposed environments. Chile's monthly picture combines three layers, technical pressure on the perimeter and appliances, regulatory adjustments to address fraud and impersonation in the financial system, and a growing legislative debate over digital identity and AI-generated content.
July's regional signal was not a single major shock, but an ecosystem hardening on several layers at once. Criminal groups kept exploiting credentials, VPNs, and exposed services. Banks and fintechs accelerated identity and authentication controls. Governments, especially in Argentina, Chile, Colombia, and Brazil, strengthened reporting, sanctioning, and governance frameworks. And AI emerged as a multiplier in both defense and attack, especially in identity fraud and assisted operations across OT and administrative environments.
Regional outlook for the month
The risk picture for Latin America in July 2026 is high. Not because of a single outlier campaign, but because several threat layers are hitting at once. There was extortion and ransomware targeting health care, energy, and the public sector. There was banking fraud and identity theft across several markets. There were critical vulnerabilities being exploited in widely used products. And there was an aggressive regulatory push that, while positive for institutional maturity, also shows the problem has reached the center of the public agenda.
The most repeated technical pattern was initial access through exposed surfaces and credential abuse. In ransomware, the month showed continuity in classic vectors, such as vulnerable VPNs, remote access services, exposed hypervisors, and poor configurations in third-party infrastructure. On the fraud side, the evidence pointed to social engineering, identity cloning, vishing, banking phishing, fake profiles, and the use of AI to clone voices, generate deepfakes, or automate contact with victims. The region is not facing abstract threats, but very concrete tactics that exploit operating habits and weak customer service channels.
Pressure on the financial sector was broad-based. In Argentina, the BCRA toughened its information stance and reinforced the need to use formal channels for fraud complaints. In Chile, the CMF pushed changes to stronger authentication, and banks reiterated that they never ask for passwords or codes over the phone. In Mexico, the industry acknowledged the need to bring cybersecurity and anti-fraud agendas together. In Colombia, complaint channels and account takeover patterns reflected a financial market with growing exposure. The regional trend is clear, fraud is no longer a byproduct, but a criminal business line with its own industrial scale.
At the same time, regulation stopped being background noise and became a central part of the threat map. Mendoza debated a provincial cybersecurity law covering data governance, penalties, mandatory reporting, and responsibilities for public agencies and critical service providers. Chile moved ahead on deepfakes and strengthened its fraud framework. Colombia consolidated rules on safe digital environments for minors. Brazil kept expanding the regulatory perimeter around platforms, big techs, and sensitive data. The result is a region where cybersecurity is no longer discussed only in technical terms, but also as an architecture of compliance, accountability, and oversight.
The severity picture differs by country, but the underlying issue is the same, exposure is growing faster than the ability to reduce risk. That is visible in the volume of regulatory reports, the repeated fraud campaigns, the persistence of ransomware, and the emergence of actors combining AI with well-known tactics. The risk is high because incidents continue to show operational reach, data exposure, reputational pressure, and, in some cases, potential impact on essential services.
Period indicators
| Indicator | Value | Reference or breakdown |
|---|---|---|
| Verified events in the period | 854 | Base for all indicators, calculated only from facts dated within July 2026 |
| Time window for the indicators | 867 facts dated in July 2026 · 9 from previous months (comparative frame, not monthly volume) · 41 without confirmed date (excluded from indicators) · 6 after the period (excluded) | Declared time window for the file |
| Untyped incidents | 85 | Breaches or disruptions without precise classification |
| Cases with ransomware or extortion as the primary focus | 126 | Single ransomware or extortion category |
| Confirmed encryption of assets | 21 | Ransomware breakdown |
| Exfiltration without encryption, simple extortion | 4 | Ransomware breakdown |
| Mention only on leak site | 3 | Ransomware breakdown |
| Cases whose classification cannot be determined from the material | 98 | Ransomware breakdown |
| Documented fraud or phishing cases | 101 | Documented cases in the period |
| Documented regulatory moves | 261 | Predominant threat of the month |
| Critical CVEs mentioned | 22 | Critical vulnerabilities mentioned in the material |
| Sectors with at least one documented event | 8 | Sectors reached by the signal |
| Predominant threat of the month | Regulation | 261 of 854 facts |
| Events with direct source confirmation | 93% | Direct confirmation based on the verifiable record |
| Aggregate telemetry figures excluded from volume | 13 | Aggregated attempts or blocks, not incidents with confirmed impact |
The table shows a regional signal heavily skewed toward regulation, but that should not be read as an automatic reduction in operational risk. On the contrary, regulatory intensity is often the response to an ecosystem where fraud, extortion and data exposure are already persistent. Telemetry should also be kept separate from incidents, detection, attempt and blocking figures appear in the material as background noise, not as verified intrusions.
Relevant incidents
Ecopetrol and the extortion attributed to The Gentlemen
The most sensitive case of the month in Colombia was Ecopetrol. The company reported an unauthorized access on July 17, confirmed that it had not identified disruptions in operations or impacts on production or essential services, and later said it was working with the Attorney General's Office and the Ministry of ICT to remove leaked files from the internet. It also filed a Form 6-K with the SEC, which elevated the incident into a regulatory and financial sphere outside the country.
The public attribution to the The Gentlemen group, along with the claim that the actor had up to one terabyte of information with drilling records, payroll data, banking data, medical histories, biometrics and VPN credentials, was not corroborated by the company. Even so, the incident falls into the category of exfiltration with extortion pressure, because the available evidence points to leakage and demands for information rather than disruptive system encryption. For the region, the message is clear, reputational damage and exposure of sensitive data are already affecting strategic infrastructure and high-profile companies.
Mendoza Senate, breach and legislative agenda
Mendoza saw an unusual sequence over just a few days. As debate advanced on a Cybersecurity Law bill, the provincial Senate website was breached and displayed an image with a message against Argentina. Local press reported the incident as a cyberattack on the institutional site, and some coverage said a link to the legislative debate could not be ruled out, although that connection remained speculative.
Beyond attribution, the episode carried symbolic weight. The province had been presenting its initiative as a comprehensive framework to protect critical infrastructure, data and public services, with components for reporting within 72 hours, citizen notification, creation of a provincial cybersecurity system, an executive committee, an operational authority and even a provincial incident registry. The fact that the legislative chamber was altered while the debate was underway highlighted the gap between the policy design and the reality of the digital perimeter.
Global Secret Group, SPDM and Sinop Energia
Brazil produced two very different cases, but both were tied to the same criminal logic. On one side, healthcare provider SPDM appeared on Global Secret Group's leak site with a claim of 847 GB of stolen data. On the other, Sinop Energia, the operator of a hydroelectric plant in Mato Grosso, was also listed by the same group with an estimated exfiltration of 300 GB. In both cases, the available material confirms publication on leak sites and data exposure, but does not document operational encryption of assets.
The reading of these cases is twofold. First, energy and health remain high-value targets for extortion actors, because of the sensitivity of the data and the potential for reputational pressure. Second, the leak site remains a coercive tool strong enough to sustain campaigns even when there is no public evidence of total outage. In Brazil, that overlaps with a very broad attack surface and with official alerts about active exploitation of vulnerabilities in exposed appliances and servers.
Msgas.com.br and the Blackwater campaign
Also in Brazil, the site msgas.com.br was linked to Blackwater in a ransomware incident with data publication on July 25. The available technical analysis indicates that the group said it had stolen personal customer information, contracts and internal data. According to that coverage, the case fits more cleanly into an extortion scheme with data exposure than into large-scale operational sabotage.
The analytical value of the episode lies in the sector. Energy and public services remain attractive because they combine operational criticality with the commercial value of information. When personal data, contracts and internal documents are combined, the attacker does not need to take down the entire operation to create enough pressure. Exfiltration becomes the main weapon.
AFA and unauthorized access to an institutional account
Although smaller in scale than the cases above, the unauthorized access to an institutional AFA account showed another pattern that is highly relevant for the region. The organization said emails were sent from that account without authorization. The confirmation does not mention encryption or major public exfiltration, but it does indicate compromise of institutional identity, a vector that can enable secondary phishing, impersonation and abuse of trust.
That kind of incident matters because it feeds the rest of the criminal ecosystem. A compromised institutional account becomes a platform for fraud, social engineering or malware distribution, especially when it comes from a highly visible organization. In Latin America, where trust in known senders remains a decisive factor, this type of event can spread farther than the initial damage suggests.
Threats and active campaigns
Ransomware and extortion
The month confirmed that ransomware in the region is not concentrated in a single sector or tied to one model. In Argentina, pressure on the Ejército Argentino surfaced through Qilin, with leak site activity and references to associated credential compromise. In Brazil, Global Secret Group was linked to health care and energy victims, while Blackwater appeared in a gas case. In Colombia and Mexico, different reports described intrusions and campaigns that combine data theft, extortion pressure and, in some cases, attacks on public services.
Most of the cases did not allow for a precise determination of whether assets were encrypted. That matters methodologically. The material makes it possible to distinguish several scenarios, but in many notes the confirmed fact is the appearance on a leak site or mention of leaked data, not system unavailability. When the material does not specify the operational effect, that should be stated clearly and the impact should not be overstated. Even so, the regional pattern is clear, extortion with exfiltration is gaining ground over purely disruptive ransomware.
In Brazil, pressure on health care was the most intense. ESET reported that in the first half of 2026 the country accumulated more than 100 ransomware victims, while sector-specific material noted that Brazilian health care faced pressure far above the global average. That context does not turn every case into a total outage, but it does point to a sustained chain of exposure across hospitals, clinics and providers.
In Argentina, Qilin and The Gentlemen show two complementary styles. Qilin appears as an extortion actor with a leak site, while The Gentlemen sits within the orbit of threats that use leaks and public pressure. In both cases, the gap between "claim" and "confirmed breach" must remain clear. Appearance on leak sites is a sign of risk, but it does not by itself prove encryption, full exfiltration or final operational impact.
Fraud and phishing
Digital fraud was likely the most common threat of the month. Argentina showed a particularly dense picture, with vishing campaigns, "paid likes" scams, identity theft through WhatsApp, techniques that block home banking and then impersonate the bank, and variants that use AI to clone voices or images. The BCRA responded with more precise guidance on what to do after a scam, what information to gather and why the first complaint should go through the financial institution.
The signal is not only local. Mercado and Sumsub showed a regional jump in AI-generated identity fraud, with Argentina, Chile and Colombia among the countries where the phenomenon accelerated. BioCatch, cited in several reports, pointed to a sharp increase in social engineering and impersonation. In Mexico, CONDUSEF reported impersonation of financial institutions and the press again focused on banking phishing, fake profiles and fraudulent loan offers. In Colombia, account takeovers, mule accounts and spoofing became a very active combination.
The new development this month is that fraud no longer depends only on traditional human deception. It increasingly relies on technical layers, deepfakes, voice cloning, bots for initial contact, synthetic documents and automation of the interaction with the victim. The operational consequence is clear. Static controls are not enough. Contextual verification, transactional behavior monitoring, risk monitoring and stronger authentication barriers are needed.
APT, hacktivism and AI abuse
In the APT space, or among actors using more advanced techniques, the month produced two very different signals. The first was PhantomEnigma, a campaign that abused Brazilian government domains to distribute malware and targeted banks and public agencies. The value of the case is not only in the malware, but in the trust abuse involved in using compromised .gov.br domains as a delivery vector. The second was the AI-assisted intrusion against Mexican government organizations and a water utility in Monterrey, where Dragos and Gambit Security said the attacker used models such as Claude and GPT to speed up reconnaissance, credential generation and password spraying.
In both cases, the key takeaway is that AI is already operating as a multiplier in different phases of the attack. It does not necessarily introduce a new offensive technique, but it does speed execution, reduce time and widen the target set. That is enough to change the economics of campaigns. The adversary can explore more, faster and at lower operational cost.
Critical vulnerabilities
| CVE | Software | Exploitation | Source |
|---|---|---|---|
| CVE-2026-25243 | Redis OSS/CE, Redis Software, RedisTimeSeries | PoC circulating, authenticated exploitation possible, RCE and memory corruption | CGII Bolivia, 2026-07-23 |
| CVE-2026-25588 | Redis OSS/CE, Redis Software, RedisBloom | PoC circulating, authenticated exploitation possible, RCE and memory corruption | CGII Bolivia, 2026-07-23 |
| CVE-2026-25589 | Redis OSS/CE, Redis Software, RedisBloom | PoC circulating, authenticated exploitation possible, RCE and memory corruption | CGII Bolivia, 2026-07-23 |
| CVE-2026-23479 | Redis OSS/CE, Redis Software | PoC circulating, authenticated exploitation possible, RCE and memory corruption | CGII Bolivia, 2026-07-23 |
| CVE-2026-23631 | Redis OSS/CE, Redis Software | PoC circulating, authenticated exploitation possible, RCE and memory corruption | CGII Bolivia, 2026-07-23 |
| CVE-2024-24919 | Check Point VPN gateways | Active exploitation confirmed, sensitive memory reading and compromise in Brazilian organizations | CERT.br and Check Point, 2026-07-22 / 2026-07-23 |
| CVE-2026-56291 | Balbooa Forms for Joomla | Active exploitation, unauthenticated file upload and RCE | CTI Pilot, SentinelOne, Cyberwald, 2026-07-09 to 2026-07-10 |
| CVE-2024-6387 | OpenSSH | Active exploitation confirmed according to CSIRT Chile | CSIRT Government of Chile, 2026-07-24 |
| CVE-2026-50522 | Microsoft SharePoint Server | Known exploitation, RCE, theft of machine keys and KEV listing | CISA, CTIR Gov, Datawiza, Zetik, 2026-07-22 to 2026-07-24 |
| CVE-2026-58644 | Microsoft SharePoint Server | Known exploitation, included in KEV | Security Affairs, 2026-07-23 |
| CVE-2023-46805 | Ivanti Connect Secure | Active exploitation, chained with CVE-2024-21887 | CSIRT Government of Chile, 2026-07-23 |
| CVE-2024-21887 | Ivanti Connect Secure | Active exploitation, chained with CVE-2023-46805 | CSIRT Government of Chile, 2026-07-23 |
| CVE-2024-22024 | Ivanti | Active exploitation reported | CSIRT Government of Chile, 2026-07-23 |
| CVE-2024-22026 | Ivanti | Active exploitation reported | CSIRT Government of Chile, 2026-07-23 |
| CVE-2024-22028 | Ivanti | Active exploitation reported | CSIRT Government of Chile, 2026-07-23 |
| CVE-2024-22029 | Ivanti | Active exploitation reported | CSIRT Government of Chile, 2026-07-23 |
| CVE-2024-22030 | Ivanti | Active exploitation reported | CSIRT Government of Chile, 2026-07-23 |
| CVE-2026-15409 | SonicWall SMA1000 | Critical firmware vulnerability, flagged by INCIBE and cited regionally | Moncloa and INCIBE, 2026-07-15 |
| CVE-2026-15410 | SonicWall SMA1000 | Critical firmware vulnerability, flagged by INCIBE and cited regionally | Moncloa and INCIBE, 2026-07-15 |
| CVE-2026-23479 | Redis OSS/CE, Redis Software, RedisTimeSeries | Redis security advisory, high severity | CGII Bolivia, 2026-07-22 |
| CVE-2026-25243 | Redis OSS/CE, Redis Software | Redis security advisory, high severity | CGII Bolivia, 2026-07-22 |
| CVE-2026-25588 | Redis OSS/CE, Redis Software, RedisBloom | Redis security advisory, high severity | CGII Bolivia, 2026-07-22 |
| CVE-2026-25589 | Redis OSS/CE, Redis Software, RedisBloom | Redis security advisory, high severity | CGII Bolivia, 2026-07-22 |
| CVE-2026-23631 | Redis OSS/CE, Redis Software | Redis security advisory, high severity | CGII Bolivia, 2026-07-22 |
The vulnerability block shows a very consistent pattern. The exposed products are almost all part of the remote access layer, web collaboration, or critical databases. In other words, they are exactly the components attackers value most because they can be used to breach the perimeter, steal keys, or reach internal infrastructure. The region should read these alerts less as isolated events and more as a list of likely attack vectors for the coming weeks.
Regulation and Compliance
Argentina, Mendoza, and the shift toward rapid notification
Argentina was the country with the most visible regulatory activity in the month. Mendoza province concentrated several parallel proposals. One, backed by the executive branch, seeks to create a Provincial Cybersecurity System to coordinate prevention, detection, response, and recovery. Another, introduced by Fuerza Patria, proposes a law against cybercrime and for personal data protection across provincial and municipal public agencies. Both texts share elements that are already standard across the region: incident notification within 72 hours, appointment of data officers, privacy by design, and traceability in data processing.
The debate is no small matter. Mendoza also added notions of data governance, information life cycle, an operational authority separate from the committee, tiered sanctions, and even a regime for ethical hackers, or white hats. That points to an unusually ambitious regulatory push for a subnational jurisdiction. If enacted, the province could become a reference point for other local governments, although it remains to be seen whether the proposed architecture can withstand implementation.
At the national level, Resolution 725/2026 in the Official Gazette updated police protocols for cybercrime, especially when minors are involved. At the same time, the BCRA strengthened its anti-fraud regime, with specific recommendations and a more formalized complaint process. The institutional message is that digital fraud damage is no longer treated only as a user problem, but as an operational and regulatory risk for the financial system.
Chile and digital identity as the focus
Chile had a particularly active month in cybersecurity regulation. The Chamber of Deputies approved in general the bill on deepfakes, which is moving forward in the legislative process and seeks to regulate the creation and dissemination of realistic digital imitations of image, body, or voice. The logic of the text is clear, protect digital identity and integrity against AI-generated content and give tools to remove content, sanction harm, and hold platforms and legal representatives accountable.
At the same time, guidance from the Central Bank and the Financial Market Commission kept a hard line on fraud involving cards and financial instruments. The country consolidated a standard in which issuers must offer free 24/7 channels, block inactive instruments, periodically report affected users, and provide itemized information to the CMF. On authentication, the new ARC is pushing banks and fintechs to strengthen multifactor authentication and abandon weak schemes such as coordinate cards.
The other side of the picture is operational. CSIRT Chile issued alerts on OpenSSH, Ivanti, Citrix, and SharePoint. That shows an institutional setup that not only regulates, but also issues timely warnings about exploited flaws. The country thus stands out as one of the region’s most complete cases in the overlap of prevention, reporting, and enforcement.
Brazil, platforms, data, and oversight
Brazil continued to move on two tracks. On one, it tightened the regulatory environment for platforms and data, with a set of changes that also affect digital governance and supervision. On the other, its technical bodies, such as CERT.br and CTIR Gov, issued alerts about active exploitation of vulnerabilities in VPNs, SharePoint, Ivanti, and other exposed surfaces. Brazil’s regulatory picture is not limited to a single topic. It spans big tech, data protection, AI in health, and increasingly concrete security requirements.
At the same time, the LGPD continued to serve as the enforcement backbone for the compliance ecosystem. Although the material does not reconstruct a single major regulatory leap in July, it does show ongoing oversight and a more sophisticated institutional approach. The political takeaway is obvious, Brazil already operates with a more developed enforcement apparatus than much of the region, and its economic weight means that any shift in standards spreads to banks, healthcare, retail, and platforms.
Colombia, minors, and digital co-responsibility
Colombia issued Decree 0769 of 2026, which regulates Law 2489 of 2025 and sets out shared responsibilities among platforms, schools, and families to ensure safe digital environments for girls, boys, and adolescents. The focus is on cyberbullying, exploitation, online sexual abuse, and inappropriate content. It also requires platform providers, apps, video games, and AI services to identify risks, adopt protective measures, provide complaint mechanisms, and report periodically to the Ministry of ICT.
The shift matters because it reflects a broader digital safety policy that is no longer centered only on financial fraud or critical infrastructure, but also on minors’ exposure and the responsibility chain of digital intermediaries. In a country with high fraud volumes and significant financial exposure, the decree broadens the regulatory perimeter and forces platforms and providers to take on part of the problem.
Guatemala, Mexico, and Peru
Guatemala continued debating its Initiative 6347 on cybercrime, with penalties of up to nine years for conduct such as unlawful access, attacks on system integrity, computer fraud, and misuse of devices. Mexico, for its part, showed a more fragmented regulatory debate, with references to AI, minors, digital fraud, and impersonation of financial institutions, but without a single consolidated rule in the material reviewed. Peru kept a relevant front open with the SBS warning about identity theft in financial products and the BCRP deepening changes in payments and transfers, although much of that material appears more as a compliance framework than a specific risk incident.
Latin America’s most affected countries
Argentina
Argentina combined three layers of pressure. First, financial fraud and identity theft, with recurring BCRA advisories, vishing campaigns, fraudulent WhatsApp messages, home banking lockouts, and the use of AI for more sophisticated scams. Second, Mendoza’s regulatory agenda, which was the most visible in the region during the month for a subnational jurisdiction. Third, the Argentine Army case on Qilin’s leak site and the intervention on the Mendoza Senate website, which left a clear sign of institutional exposure.
The technical takeaway is that the country is dealing with two different surfaces. One is financial, where fraud is scaling through social engineering. The other is state-linked, where the cybersecurity debate is already translating into bills, reporting requirements, and governance. The bridge between both is data protection and the need to strengthen digital identity.
Brazil
Brazil had the broadest and, at the same time, most varied ecosystem. It saw ransomware cases in health care, energy, and gas. It had official alerts about active exploitation of VPNs, SharePoint, and Ivanti. It also saw campaigns abusing government domains. On top of that, telemetry showed very high volumes of phishing attempts and ransomware activity, although those figures should be read as detection volume, not as confirmed incidents with impact.
On the sector side, health care was the most sensitive node. But the country also showed pressure on electric infrastructure and service providers. That means Brazil’s attack surface is not concentrated in a single vertical. It stretches from hospitals to utilities and platforms, with a corporate perimeter that remains a preferred target.
Chile
Chile stands out as the country with the strongest regulatory density and one of the most committed efforts to close gaps in authentication and exposure. The deepfakes bill, the Central Bank’s guide on card fraud, the ARC, and CSIRT alerts make up a fairly coordinated state response. At the same time, the country is not free from technical pressure. Warnings about OpenSSH, Ivanti, Citrix, and SharePoint confirm that exposure remains a serious issue.
Chile’s financial system appears to have understood earlier than others the link between fraud, authentication, and issuer liability. That gives it an advantage, but it does not eliminate risk. Banks’ repeated reminders that they never ask for passwords or codes by phone show that social engineering is still widespread.
Colombia
Colombia had an intense month because of the Ecopetrol case and the financial fraud front. The country was already facing high exposure to social engineering, impersonation, account takeover, and mule accounts. The attack on Ecopetrol raised the stakes because it involved a flagship company, with possible extortion and exposure of sensitive data. At the same time, the decree on safe digital environments for minors broadened the security agenda into a more social and regulatory space.
The Colombian case shows how two layers of risk coexist. One is patrimonial, where banking fraud and impersonation are highly industrialized. The other is corporate and critical, where energy companies and essential services become targets for more complex campaigns. The appearance of new AI tactics and exposed remote access reinforces that reading.
Mexico
Mexico appears in the material more as a setting for debate and high-impact attacks than as a country with a single dominant trend. There were reports of banking fraud, impersonation of institutions, phishing, AI-driven campaigns, and the alleged SIDAC breach, as well as the AI-assisted intrusion against Mexican government bodies and the water utility in Monterrey. There was also debate over whether AI regulation should move sector by sector or through a general law.
The strongest signal is that Mexico is highly exposed both to financial impersonation and to attacks on government and public services. The coexistence of mass fraud and complex intrusions forces different controls depending on the type of asset. A bank account is not defended the same way as a state system holding citizen data.
Peru
Peru had a narrower signal, but not an insignificant one. The SBS warned about identity theft in financial products, and the BCRP continued adjusting the payments system and transfer rules. It is a country where the regulatory layer is advancing and financial controls are becoming more formalized, although the month’s material did not show the same volume of incidents seen in Brazil, Colombia, Mexico, Argentina, or Chile.
Paraguay, Bolivia and the United States
Paraguay was absent from the month’s verified impact picture, although the file includes regulatory and comparative context. Bolivia had a relevant intervention with the CGII alert on Redis, a useful regional signal of technical response to critical CVEs. The United States appears only indirectly, as a regulatory or ecosystem reference, with no region-specific facts during the period.
Trends and signals to watch
There is no month-over-month comparative baseline of our own for this indicator format in Latin America, so it would be incorrect to invent a month-to-month change. What can be read instead is the consolidation of trends that were already taking shape and became clearer in July.
The first signal is the growth of AI-assisted identity fraud. The material from Argentina, Chile, Colombia, and Mexico repeats deepfakes, impersonation, voice cloning, synthetic profiles, and automated outreach. At the same time, banks are tightening authentication and regulators are pushing procedural changes. The signal to watch is whether that technical escalation starts to translate into stricter contextual validation requirements and more friction for users.
The second signal is the persistence of ransomware with a focus on health care, energy, and the public sector. Brazil accounts for the most visible share of that pressure, but Argentina, Colombia, and Mexico also saw related events or campaigns. The point to monitor is not only which groups are attacking, but which vectors they use, especially VPNs, exposed services, hypervisors, and leaked credentials.
The third signal is the maturation of the regulatory response. Mendoza, Chile, Colombia, and Brazil moved ahead with tougher rules on reporting, penalties, notification, authentication, and platforms. This does not eliminate risk, but it does change the cost of operating without controls. The key question is which jurisdictions manage to turn the rule into practice and which remain on paper.
The fourth signal is that AI is no longer just a defensive story. In several incidents it appeared as an offensive accelerator across government, OT, fraud, and the generation of fake identities. The question is not whether AI is present, because it already is. The question is which stage of the attack it helps most, and how controls are prioritized to cut off that advantage.
Recommendations for security teams
First, harden the remote access layer. This month’s material again shows VPNs, gateways, appliances, and exposed services as recurring attack vectors. That means prioritizing real MFA, configuration reviews, credential rotation, minimal exposure, and continuous monitoring for anomalous access. A patch being available is not enough if the perimeter stays open or authentication remains weak.
Second, strictly separate fraud controls from intrusion controls. Digital fraud in the region already uses social engineering, AI, and impersonation. Teams need contextual validation, transaction behavior analysis, out-of-band verification, and adaptive friction rules. In banking and fintech, treating everything as generic phishing is not enough.
Third, review detection and response capabilities for institutional accounts. The AFA showed how a single compromised account can be enough to spread unauthorized messages. Teams should protect high-privilege accounts, strengthen identity recovery, control forwarding, and monitor for sending anomalies from legitimate accounts.
Fourth, treat health care, energy, and government as top-priority verticals. July’s pattern shows those sectors are still preferred targets for extortion and exfiltration. That calls for segmentation, tested backups, privileged access control, an inventory of exposed assets, and restoration tests that do not rely on optimistic assumptions.
Fifth, build data governance and traceability into security controls, not just compliance. The Mendoza debate and Chilean regulations show that the region is already demanding greater transparency around data, incidents, and responsibilities. Organizations without fine-grained traceability across the information lifecycle will be exposed both technically and legally.
Sixth, review third-party contracts and exposure. In several cases, from health care to utilities, the attack surface runs through vendors, exposed software, or external services. Supply chain risk remains one of the cheapest paths for attackers and one of the hardest to close without monitoring the full ecosystem.
Material limitations
This report was prepared exclusively from the material provided for July 2026 and from facts dated within the period window. Undated facts were left out of the indicators, although some may add qualitative context. Facts from earlier months that reached the file through coverage published in July were used only as a comparative frame and never as July volume.
One important nuance also applies to the indicators. When an indicator appears as zero, that means it did not appear in the material analyzed for this period, not that the event did not occur in the region. This is especially true for CVEs and for any category where the absence of a mention does not equal the absence of real activity. This month, critical CVEs were mentioned, so that number should be read as a signal present in the material, not as a complete universe of regional vulnerabilities.
Aggregated telemetry, such as phishing attempts, scans, or automated blocks, was excluded from the incident volume. If it is mentioned, it should be understood as an exposure measurement, not as a confirmed intrusion. Sponsored content, commercial press releases, or consumer publications that are not on the approved citation list were also not used as evidence of trend.
Finally, the report does not introduce external sources beyond the provided corpus, nor does it attribute incidents where the material offers only a leak site claim, a journalistic conjecture, or an assertion not verified by the source. When a fact did not allow a distinction between encryption, exfiltration, or a leak site mention, that ambiguity was preserved rather than forcing a classification.
Sources
- Mientras se debate la Ley de Ciberseguridad, el kirchnerismo presentó su propio proyecto contra el ciberdelitoLos Andes
- Ley de Ciberseguridad en Mendoza avanza en el SenadoEpelbyte
- Newsletter de Economía del Dato, Privacidad y Ciberseguridad - Julio de 2026Garrigues
- Blindar a los usuarios mexicanos frente al fraude digital: la industria acuerda unir las agendas de ciberseguridad y antifraudeInfobae
- https://www.diariosanrafael.com.ar/tras-presentar-la-ley-contra-ciberataques-hackearon-la-web-de-la-legislatura/Diario San Rafael
- Hackearon la web del Senado de Mendoza con un mensaje contra ArgentinaIdentidad Correntina
- Modificaron el protocolo de las fuerzas de seguridad por las amenazas en las escuelas por redes socialesInfobae
- La nueva estafa en Argentina en la que es muy fácil caer y puede dejar la cuenta bancaria en ceroMDZ Online
- La estafa de los “likes pagos”Gobierno de la Ciudad de Buenos Aires
- "Suplantación de identidad": alerta por la nueva modalidad de estafa con whatsappYouTube
- La nueva muralla digital: cómo la IA está frenando las estafas bancarias en ArgentinaEcos365 (Rosario3)
- Identidades creadas con IA: el nuevo peligro de las estafasInfosertecla
- Alerta por ciberestafas en WhatsApp: cómo funciona la suplantación de identidad con la foto de perfil y cómo prevenirlaInfozona
- Fraudes con identidades generadas por IA crecen 180% en Latinoamérica, según SumsubRevista Mercado (mercado.com.ar)
- Comunicación B 13208/2026Boletín Oficial de la República Argentina / BCRA
- Video Semanal de Ciberseguridad: La estafa del «Falso Kevin Costner» y cómo protegerte de la ingeniería socialInfosertecla
- Un especialista en ciberseguridad explicó cómo operan las organizaciones detrás de las estafas digitalesInfobae
- Ransomware en el primer semestre de 2026: qué grupos atacan y qué sectores son los más afectadosESET / WeLiveSecurity
- IA y ciberdelincuencia, peligro inminenteEl Financiero
- La llegada de los “carteles” al mundo digital: alertan por nuevo modelo de cibercrimen que ya afecta a LatinoaméricaADN Radio / ESET
- Proyecto de ley para proteger la identidad digital de las personas despierta consenso, pero enfrenta retosDiario Financiero
- Hackearon la web del Senado de Mendoza y publicaron una imagen de Chiqui Tapia con un llamativo mensaje contra la ArgentinaTN
- Chile advances bill to strengthen protection of digital copyrightEuropean Innovation Council and SMEs Executive Agency
- Estafas virtuales: las claves para evitar caer y qué hacer si ya fuiste víctimaRosario3
- Robos y fraudes en el uso de tarjetas e instrumentos financierosBiblioteca del Congreso Nacional de Chile / Banco Central de Chile
- Ransomware.live 👀 — Map ARRansomware.live
- Victim: Ejército ArgentinoRansomware.live
- Qilin Ransomware Group Targets Ejército ArgentinoDexpose
- Qilin ransomware lists Argentina's army on its leak siteIntelFusions
- "Una señal de alarma": la empresa hackeada por una IA de OpenAI lanzó una advertencia que preocupaiProUP
- RansomLook — Open ransomware intelligenceRansomLook
- Ciberataque al Senado de Mendoza: alteraron la web oficial con una imagen de Chiqui TapiaEl Litoral
- Ciberataque en una provincia: hackearon la página del Senado y pusieron un foto de Chiqui TapiaClarín
- Ciberseguridad en Mendoza: Fuerza Patria marcó posición con el proyecto de Ciberseguridad y presentó el de Protección de DatosMendoza Today
- DPL News Spotlight Política Digital #3DPL News
- Ciberataques en Mendoza: el proyecto de Ley de Ciberseguridad comenzó su tratamiento en la LegislaturaMNews
- Guatemala propone castigar con hasta nueve años de cárcel a quienes cometan delitos cibernéticosInfobae
- Recomendaciones del Banco Central para evitar estafas virtualesEl Litoral
- El BCRA alertó sobre una modalidad de estafa que permite vaciar cuentas bancarias: cómo evitar caer en el fraudeEs Re Viral
- Guatemala propone castigar con hasta nueve años de cárcel a quienes cometan delitos cibernéticosInfobae
- Los ciberataques contra el Estado aumentaron: impulsan una ley que habilita a los hacker éticosDiario San Rafael
- Avanza en el Senado el proyecto de Ley de Ciberseguridad de Mendoza: de qué se trataMendoza Today
- Nuevas normas de protección de niños en internet en Colombia: ¿servirán?El Tiempo
- Gobierno fija responsabilidades para proteger a menores de edad en internetRadio Santa Fe
- Sophos AI Security Report 2026ITware Latam
- Alerta por estafas virtuales que vacían cuentas bancarias: qué es lo que nunca se debe hacer, según el BCRAInfobae
- Cayeron los "Hackers del Home Banking"Stopenlinea
- Ciberseguridad financiera: prevenir fraude sin dañar la experienciaInfosertecla
- BCRA ajusta régimen informativo para proveedores de créditoIndicadores.ar
- Reforma Carta Orgánica BCRA, VASP, ciberseguridad y AMLEl Cronista
- Ciberseguridad de los organismos del Estado e infraestructura crítica de la informaciónBiblioteca del Congreso Nacional de Chile
- Delitos informáticosBiblioteca del Congreso Nacional de Chile
- SBS Perú: 24 horas para reportar incidentes de ciberseguridadEcosistema Startup
- Plataformas digitais têm novas regras a partir desta 2° feiraPoder360
- Fallos Negligencia del usuario: El banco no es responsable del daño sufrido por el cliente a causa de operaciones que no se produjeron por una falla en el funcionamiento del sistema bancarioMicrojuris Argentina
- Decreto 12.975: o que muda pra quem vive de internet (dever de cuidado explicado)YouTube
- Plataformas digitais têm novas regras a partir desta 2ª feiraPoder360
- Decretos sobre responsabilização de big techs por conteúdo entram em vigorPortal Tela
- Brasil: el Gobierno implementa medidas contra las big techLa Nación (agencias)
- Sem decisão pelo Congresso, decretos sobre big techs entram em vigorDiário de Pernambuco
- Brazil Replaces Judicial Takedown Orders With a Two-Hour Clock and a Regulator Still Writing Its Own RulebookPeople of Internet
- Brazil's New Platform Decrees Turn a Court Ruling Into a Standing Compliance RegimePeople of Internet
- PDL 460/2026Senado Federal do Brasil
- Especialistas alertam para riscos em decretos de Lula sobre big techsCNN Brasil
- ANPD em 2026: principais regulamentos, consultas públicas e tendênciasLicks Attorneys
- Consejos del Banco Central para evitar estafas virtuales y cuidar las cuentas bancariasSur24
- Brasil Endurece las Reglas Para Publicidad de Apuestas OnlineZona de Azar
- ¿Es legal que retengan o fotografíen tu DNI al ingresar a un local? Esto dice la ANPD y así puedes denunciarInfobae Perú
- TSE firma acordos com plataformas para combater desinformaçãoPoder360
- ANPD lista potenciais prioridades regulatórias para próximo biênioRPN as Redes
- Ataque hacker expõe dados de 500 mil pacientes e leva ANPD a investigar falhas na proteçãoO Hoje
- Guatemala: La Comisión de Economía del Congreso avanzó en la definición de delitos de ciberseguridad y discusión de la Ley Nacional del Sistema PortuarioInfobae
- Ecuador busca regular el uso de inteligencia artificial en la justicia con un proyecto que fija límites y sancionesInfobae
- Federación Mexicana de Futbol es multada por violaciones en uso del Fan ID889 Noticias
- The Gentlemen amenaza con filtrar datos de Mercado Libre Argentina tras presunto ciberataqueFortuna y Poder
- Un hackeo mundial: el ciberataque a la Asociación del Fútbol ArgentinoWeLiveSecurity
- Marco Legal da Cibersegurança põe cooperativas em alertaBrCooperativo
- ANPD apura vazamento de dados de 500 mil pacientesPoder360
- Qué dice la Ley de Ciberseguridad que presentó Cornejo para combatir amenazas digitalesMDZ Online
- Presentan un proyecto de ley para fortalecer la ciberseguridad y proteger los datos de los mendocinosDiario San Rafael
- Comentario sobre cláusulas de confidencialidad en contratos de software vinculadas al proyecto mendocino de ciberseguridadCuenta Marce_I_P en X
- Mendoza puede tener la primera Ley de Ciberseguridad del país: buscan blindar al Estado de ataques hackersLos Andes
- Mercado Libre, afectada por un ataque de ransomwareEscudo Digital
- La ciberseguridad abre una nueva agenda legislativa para la seguridad de MendozaGobierno de Mendoza
- Mendoza quiere una Ley de CiberseguridadLinkedIn (Santiago Paravano)
- El avance de la infraestructura de ciberseguridad en LatinoaméricaQuanti
- Boletín mensual Observatorio Legislativo | Junio 2026CELE - Observatorio Legislativo
- Se intensifican los ciberataques a telecomunicaciones: millones de datos de usuarios quedan expuestos en América LatinaInteligenciaArgentina.ar
- Multas LGPD 2026: quem a ANPD já sancionou e por quêTurivius
- Lei Geral de Proteção de Dados (LGPD) - BNDESBNDES
- Los cambios en ciberseguridad que trae la nueva Rendición de CuentasEl Observador
- Kimi K3 AI Agent Finds Redis RCE Vulnerabilities in Just 27 MinutesCyberPress
- Aviso de seguridad: Circulación de pruebas de concepto para el lote de vulnerabilidades que afecta a servidores RedisCentro de Gestión de la Información e Informática (CGII) - Gobierno de Bolivia
- nuevos exploits vuelven a vulnerar la seguridad de RedisSecurityLab
- Kimi K3 Agents Found Redis Zero-Days and Built RCE ...The Hacker News
- Vulnerabilidades Zero-Day Críticas en Redis Permiten Ejecución Remota de CódigoIngeniería Telemática
- Critical Redis Vulnerability CVE-2024-27348 Enables Remote Code Execution via RESTORE Command: Risk Analysis and Mitigation StrategiesRescana
- Redis RCE 2026: Five Patched CVEs and an AI DiscoveryStingrai
- Боливия рассматривает интеграцию USDT в национальную платёжную систему на фоне дефицита долларовCoinalert News
- La Bolivie envisage d’ajouter l’USDT au système national de paiementLider Media
- Gobierno de Bolivia analiza la integración de USDT en el sistema de pagos nacionalCointelegraph en Español
- USDT considerado para pagos nacionales en BoliviaBitget News
- Noticias – Monitoreo de encargados de datos por la ANPDCiberLATAM
- Brasil BCB Resolución 580: PSAVs como Tipo 3PtyCoin
- Top 5 Ransomware Groups in Q2 2026: Who They Are ...Brandefense
- Ransomware groups are hammering your vulnerable VPNsCSO Online
- Ransomware Groups Increasingly Deploy EDR Killers to Sidestep DefensesInfosecurity Magazine
- A fiscalização da ANPD e o fim da cultura do improvisoJornal do Brasil
- Akira group profileransomware.live
- PhantomEnigma Infects Organizations with Malware via Hijacked Government WebsitesHackRead
- Sinop Energia Data Breach in 2026BreachSense
- Actualité cybersécurité — Veille quotidienneFactualRisk
- Sinop Energia Listed by Global Secret Group Ransomware GroupGalaxyWarden
- IA a visar a Tecnologia Operacional: Novas Perspetivas de AmeaçaCryptonomist
- Energy & Utilities – Brazil victims listingransomware.live
- Healthcare sector victims in Brazilransomware.live
- Compliance para Saúde: LGPD, HIPAA, CFM, ANVISAVantico
- Victim: SPDMGlobal Secret Group (ransomware.live)
- Spdm Listed by Global Secret Group Ransomware GroupGalaxy Warden
- Impact Analysis of Ransomware Attacks on EMEA HealthcareFlare.io
- Ransom! msgas.com.br (JUL-2026)Hendry Adrian
- msgas.com.br — BLACKWATER Ransomware AttackBreach House
- Republicanos dos EUA pedem pressão sobre Brasil por PL que regula big techsUOL
- Ransomware avança 17,8% e mira o Brasil e toda a LATAMEstado de Minas
- Brasil vira epicentro de ransomware na saúde na América Latina; especialistas alertam para riscos de IA sem governançaPortal Information Management
- Golpe da falsa central bancária fica mais sofisticado e liga o alerta da FebrabanO Banco Digital Notícias
- Fraudes digitais se consolidam como maior crime patrimonial do país, com mais de 250 golpes por horaO Globo
- Oposição pede urgência para derrubar decreto de Lula sobre big techsPoder360
- Deepfake Íntimo Agora É Crime: Decreto 12.976/2026 e MultasRibeiro Cavalcante Advocacia
- Fenasbac and GASA Report Outlines a Cross-Sector Response to Digital Scams in BrazilGASA / Fenasbac
- Setor de saúde lidera ranking mundial de ataques cibernéticosSINDPD
- Incidentes cibernéticos crescem em pequenas e medias empresas no paísG1
- A ressalva que ficou de fora: o decreto da moderação copiou modelo europeu, mas não trouxe exceção eleitoralAtlas Público
- Brasil concentra 51% dos ataques de ransomware ao setor ...Brasilia e Aqui
- Marco Civil da Internet ganha novas regras e amplia deveresSampi
- Entenda o que muda com os decretos de Lula para as big techsPoder360
- Plataformas digitais têm novas regras a partir desta segunda (20); Jess e Mehero comentamYouTube / programa jornalístico
- Ransomware Wing — víctimas, grupos y patronesPulse (Kalir.io)
- Decretos que aumentam responsabilidade de big techs entram em vigor, apesar de projetos no CongressoEstadão
- Decretos sobre big techs estão em vigorFolha de Alphaville
- Plataformas digitais tem novas obrigações no Brasil a partir desta segunda-feira, dia 20Rádio Educadora
- Decreto define prazos para plataformas digitais retirarem do ar conteúdos de violência contra mulheresAgência Gov
- Entrada de blog técnica sobre Banana RAT / SHADOW-WATER-063Igor Urraza
- Brasil lidera ataques de ransomware na américa latina em 2026 e expõe falhasLucas Alcaraz
- ANPD formaliza contratação de técnica gerencial com salário de R$ 10,3 milO Tempo
- Decreto que estabelece diretrizes de proteção às mulheres na internet já está em vigorMinistério das Mulheres - Governo Federal do Brasil
- STF ajusta tese sobre responsabilidade civil de plataformas digitaisSMAB Advogados
- Especialistas revelam por que o Brasil virou alvo prioritário do ransomwareDireto Notícias
- Ransomware Tracker - Derp.caDerp.ca
- Qilin Leads Global Ransomware Victim Claims Across ...Mallory.ai
- ANPD abre consulta sobre novas regras para plataformas digitais: o que pode mudar para usuários e empresasAdvemFoco
- Ataques cibernéticos disparam no Brasil e superam média globalSindpd
- Banco Central estuda restringir acesso ao Pix para instituições com falhas de cibersegurançaDestak News Brasil
- 20+ Hijacked Government Websites Became an Attack ChannelAllSec.sh / The Hacker News
- Hijacked Websites: When Trusted Sites Turn DangerousPendergrass Consulting
- Pix com mudanças? Entenda o que BC estuda sobre segurança cibernéticaMetrópoles
- PL 4752/2025 - Senado FederalSenado Federal
- ANPD em 2026: principais regulamentos, consultas públicas e tendênciasLHBM Advogados
- Il ransomware cambia bersaglio e assedia la filiera sanitariaTom's Hardware Italia
- Brazil May Cut Off Pix Access for Cyber-Weak BanksThe Rio Times
- Banco Central ameaça tirar Pix de bancos que descumprirem novas regrasFDR
- BC estuda restringir Pix para instituições com falhas de segurançaNC News
- No solo pasa en Europa: estos países restringen las redes sociales para adolescentes en 2026Semana
- Radar Defender360 — 13 de julho de 2026Defender360
- CVE-2026-56291: RCE no Balbooa Forms com Exploração AtivaDFT Info / JRT Technology Solutions
- CISA Agrega Vulnerabilidades Críticas de Extensiones Joomla iCagenda y Balbooa Forms al catálogo KEVDevel Group
- Vulnerabilidad crítica en Balbooa Forms para JoomlaTechConsulting
- 'Deepfakes' impulsionam fraudes em contratos e desafiam fintechsFinsiders Brasil
- CVE-2026-56291 — Balbooa Forms for Joomla: unauthenticated file-upload RCE exploited as a zero-dayCTI Pilot
- Ataque de ransomware contra o Isac registra vazamento de dados de 500 mil pacientesTI Inside
- Banco Central endurece regras do Pix e bancos que não se adequarem podem perder acesso ao sistemaEstado de Minas
- CVE-2026-56291: Balbooa Forms Joomla Extension RCESentinelOne
- ANPD investiga ataque hacker que atingiu dados de pacientes em AlagoasO Jornal Extra (Alagoas)
- Brasil é epicentro de ransomware em saúde na América LatinaCISO Advisor
- Brasil concentra el 51% de los ataques de ransomwareCiberLATAM
- CVE-2026-56291 - Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1CVEfeed
- CVE-2026-56291 - Kritische RCE-Lücke in Balbooa FormsCyberwald
- ANPD abre processo contra Isac após ataque hacker expor dados de 500 mil pacientesCyberSec Brazil
- Após ataques hackers, BC quer restrições para instituições frágeisPoder360
- Ataque cibernético vaza dados de 500 mil pacientes e empresa é alvo de investigação federalO Globo
- Instituição de saúde que atua no RS é alvo de processo por falhas na proteção de dados de 500 mil pacientesGaúchaZH
- ANPD instaura processo de sanção contra OS por falha na proteção de dados de 500 mil pacientesLegismap
- Banco Central reforça arcabouço antifraude e de governança no Pix e no sistema de pagamentosCSMV
- O Novo Paradigma do Pix: Banco Central Eleva Risco Cibernético ao Nível de Capital e Liquidez na SupervisãoGazeta Mercantil
- ANPD sanciona a Isac por filtrar 500 mil datos de pacientesLinkedIn (Consejo de Seguridad de la Información y Ciberseguridad)
- Elytron aponta alta de ransomware na saúde no BrasilIT Section
- ANPD investiga ataque hacker contra organização que administra unidades de saúde em ALCada Minuto
- Banco Central planeja mudanças no sistema Pix; entendaDOL (Diário Online)
- Marco Legal da Cibersegurança põe cooperativas em alertaBR Cooperativo
- BC estuda limitar acesso ao Pix e reforçar segurançaDiário do Comércio
- Brasil concentra 51% dos ataques de ransomware ao setor de saúde na América LatinaSaúde Digital News
- Leia a íntegra do projeto que aumenta punição a crimes sexuais on-linePoder360
- Pente-fino no Pix: Banco Central prepara nova fiscalização que pode bloquear recurso de instituições por falhas de segurançaND Mais
- PL 3066/2025Senado Federal
- Senado aumenta punição a crimes sexuais online contra criançasFolha de Vilhena
- ¿Qué es el ransomware y cómo proteger tu empresa en 2026?Aufiero Informática
- Brasil concentra maior número de ataques de ransomware ao setor de saúde na América LatinaSantotech
- Fiscalização LGPD 2026: ANPD vira agência reguladoraVisie
- Brazil's National Data Protection Authority: How regulators investigate and enforce its data protection lawCompliance Week
- Projeto de Lei nº 2338, de 2023Senado Federal do Brasil
- Ley Marco de Ciberseguridad (Ley 21.663): Implicancias y Desafíos para los Operadores Críticos en ChileCámara Franco Chilena
- La inteligencia artificial: cuestión de ética y capacidades en América Latina y el CaribeEl País
- Si te dicen esto, es vishing: la estafa telefónica por la que los bancos en Chile están alertandoEl Mostrador
- Chile busca multar la difusión de ‘deepfakes' creados con IA por hasta 760.000 dólaresEl Comercio
- Cámara aprueba proyecto para regular uso de deepfakesTVN (Exponencial)
- Más de $700 millones: Avanza proyecto que busca multar a quienes usen IA para estafarT13
- Alerta por cambio en los bancos: ya cambiaron los requisitos para transferir dineroEl Mostrador
- Avanza proyecto que busca multar a quienes usen IA para estafarT13
- Debate y votación en Sala del proyecto de ley sobre deepfakesYouTube / Registro Cámara de Diputadas y Diputados
- ALERTA 65/2026 – Vulnerabilidade crítica que afeta o SharePointGSI – CTIR Gov (Gobierno de Brasil)
- Vulnerabilidad crítica en OpenSSH (CVE-2024-6387)CSIRT de Gobierno de Chile
- Cámara aprueba proyecto que sanciona las deepfakes creadas con IA con multas de hasta $716 millonesBioBioChile
- Si te dicen esto, es vishing: la estafa por la que alertan los bancos en ChileEl Mostrador
- Alerta de seguridad: vulnerabilidades en IvantiCSIRT de Gobierno de Chile
- SharePoint enfrenta una falla crítica de ejecución remota explotada activamenteDiario Bitcoin
- U.S. CISA adds Microsoft SharePoint and Check Point flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs
- Critical Unauthenticated Remote Code Execution Vulnerability in Microsoft SharePoint Server CVE-2026-50522SecureVerifyConnect
- Copec, Aguas Andinas, Nuevo Pudahuel y decenas de grandes empresas quedan bajo el nuevo régimen de ciberseguridadDiario Financiero
- Diputados aprobaron en general proyecto que regula la IA y combate los "deepfakes"Radio Cooperativa
- Chile busca multar la difusión de 'deepfakes' creadas con IA por hasta 760.000 dólaresSwissinfo / EFE
- CVE-2026-50522: SharePoint Machine Key TheftDatawiza
- CISA Adds SharePoint RCE CVE-2026-50522 to KEV, Orders Fixes by July 25Zetik
- Novas regras passam a exigir mais responsabilidade das big techs no paísSindpd
- Novas regras para big techs entram em vigor e reforçam segurança digital no BrasilPortal Amazonas
- Congresso dos EUA pede ação contra o Brasil por projeto de big techsTribuna do Norte
- Alerta por cambio en los bancos: ya cambiaron los requisitos para transferir dineroEl Mostrador
- Law 21.663 and data protection in ChileQuarancle
- Alerta de seguridad: vulnerabilidades en Citrix NetScaler ADC y GatewayCSIRT de Gobierno de Chile
- Multas de hasta $2.800 millones: el reto de las empresas ante las nuevas leyes de ciberseguridadTivit
- INCIBE alerta de dos vulnerabilidades críticas en SonicWall SMA1000Moncloa.com
- ALERTA 56/2026 — Campanha envolvendo Joomla Content Editor (JCE) vulnerávelGabinete de Segurança Institucional da Presidência da República (CTIR Gov)
- Guía de ciberseguridad y cumplimiento normativo en Chile (Ley 21.663 y 21.719)Prey Project
- Information Technology 2026 - ChileChambers and Partners
- 102 Alerta Red de Retransmisión Operativa CHARLIEColCERT
- Prepara tu eCommerce: ley de datos personales Chile 2026BigBuda / Garrigues
- CCS lanza guía esencial de protección de datos personales para pequeñas y medianas empresasCámara de Comercio de Santiago (CCS)
- Al-2026-0036 – Ransomware WallstreetECUCERT
- Attackers exploit critical Adobe ColdFusion vulnerability (CVE-2026-48282)Help Net Security
- El INCIBE alerta de una vulnerabilidad crítica de Path Traversal en Adobe ColdFusion (CVE-2026-48282) que ya está siendo explotada activamenteMoncloa.com / INCIBE-CERT
- APSB26-68 - Adobe Security BulletinAdobe
- CVE-2026-48282: Mitigating a Critical Vulnerability in Adobe ColdFusionAkamai
- Chile recibió 8,8 billones de intentos de ciberataque en 2025 y expertos advierten que las empresas siguen tardando meses en detectar una intrusiónG5 Noticias
- Fintech chilenas necesitarán expertos en IA, ciberseguridad y regulación hacia 2030Chócale
- INCIBE alerta de seis vulnerabilidades en NetScaler ADC y Gateway de CitrixMoncloa.com
- Múltiples vulnerabilidades en NetScaler de CitrixINCIBE-CERT
- Ciberseguridad, Protección de Datos y Gestión Digital - Cambios regulatorios en Chile (Ley 21.663 y Ley 21.719)Goose
- Publicación sobre desafíos de implementación y plazos de la nueva ley de protección de datos en ChileValentina Palma (LinkedIn)
- Colombia's Ecopetrol says cyberattack stole data tied to 3,300 accountsReuters
- Ciberataque a Ecopetrol: 15 empresas del grupo afectadas y hackers están extorsionando tras robar datos de 3.300 cuentasEl Colombiano
- La Fiscalía investiga el ciberataque contra Ecopetrol: se habría infiltrado información sensibleInfobae Colombia
- Un ciberataque a Ecopetrol expone información del negocio y de sus empleadosEl País América Colombia
- Ecopetrol activo protocolo por ciberataque: está coordinando con la Fiscalía y el MinTIC el retiro de archivos filtradosInfobae Colombia
- Alerta por fraude cibernético en Bucaramanga: 866 denuncias y tres claves para proteger sus cuentasVanguardia
- Vulnerabilidades y ransomware elevan el riesgo operativo para industrias estratégicas, advierte KaseyaITware Latam / Kaseya
- Casos de ciberataques aumentan 38% en México, empresas registran escalada en diversos sectoresInfobae
- Versiones falsas de Google y archivos PDF atacan gobiernos y empresas en LatinoaméricaInfobae
- Fraude con tarjetas de créditoMinisterio de Justicia y del Derecho de Colombia
- Fábricas de fraude: cuatro presiones críticas sobre bancos y fintechsIupana
- Fraude financiero: Crecen las estafas con identidades generadas con IATabulado
- Fraude fintech 2026: 4 presiones críticas que debes conocerEcosistemaStartup
- El 'spoofing', la modalidad de estafa digital que tiene en la cárcel al hijo de un reconocido exfutbolistaSemana
- ¡No caiga! Ojo con engaños por llamadas o con inteligencia artificial; capturaron a un futbolistaCanal de televisión colombiano (YouTube)
- Denunciar una estafa en Colombia: banco, pruebas y FiscalíaColombia en Regla
- El fraude con IA dominará los ciberataques en 24 meses y multiplicará las pérdidas: CEO de IncodeEl Cronista
- Entró en vigencia decreto para proteger a niños y adolescentes en entornos digitalesSeguridad (canal de noticias)
- Congreso estudia proyecto para restringir redes sociales a menores de 16 años en Colombia: habría multas de hasta $8.500 millonesCol Mundo Radio
- “Tenemos en riesgo la mayor parte de nuestros niños por ciberacoso”: MinTicCaracol Radio
- Colombia busca fortalecer protección de niños en entornos digitalesPrensa Latina
- Gobierno nacional expide decreto para fortalecer entornos digitales sanos y seguros de niñas, niños y adolescentesAlcaldía de Santiago de Cali / Gobierno nacional
- Gobierno nacional expidió decreto para proteger a menores de edad con respecto al uso de internetInfobae Colombia
- ¿Protege el nuevo decreto a los menores en internet? Expertos encuentran vacíosUniversidad El Bosque
- Gobierno firma decreto con medidas para proteger a niños y adolescentes en entornos digitalesYouTube / Canal de noticias colombiano
- Prohibición de redes sociales para menores: Nuevo decreto y proyecto de leySin Carreta
- Expertos alertan sobre una creciente táctica de ransomware: hackers imprimen demandas de rescate durante ataques en América LatinaTrendTIC
- Radican proyecto para prohibir uso de redes sociales a menores de 16 añosEL TIEMPO
- Tecno: en Colombia, ley para prevenir violencias y delitos digitales contra niñosLa Nación (agencia)
- Errores de configuración que alimentan el ransomware: lecciones de Colombia y MéxicoCarmona.mx
- Extorsión BitLocker: el esquema XEntry con impresorasHelpRansomware
- BitLocker Extortion: The XEntry Printer Ransom SchemeHelpRansomware
- Gobierno niega irregularidades en contrato de ciberseguridad y aclara fecha de adjudicaciónInfobae Colombia
- Ecopetrol descarta afectación a sus operaciones tras ciberataqueEl Espectador
- Bancos suspenderán cobro de cuotas y eliminarán reporte en DataCrédito: ley comienza a regir tras aprobación de Corte ConstitucionalRed+ Noticias
- Brazil Is Quietly Building the Research Docket for Its Next Wave of Martech EnforcementEmailExpert
- Colombia refuerza la protección digital infantil: claves del Decreto 0769 de 2026 y sus nuevas obligacionesPulzo
- ¿Lo suplantaron y sacaron un crédito a su nombre? Esta es la nueva ley que lo protegeEl Colombiano
- Aclaran futuro del Banco de Talentos Patria Milagro: plataforma de Abelardo De La Espriella despeja duda de quienes buscan trabajoRed+ Noticias
- Suplantación de identidad: empresas deberán frenar cobros y corregir reportes mientras investigan el fraudeInfobae Colombia
- Nueva campaña de GodDamn ransomware combina captura de credenciales, acceso remoto y cifrado de sistemasCSIRT Asobancaria
- Colombia registró 10,9 billones de intentos de ciberataques y concentra el 8% de los incidentes de América LatinaSemana
- IA y fraude financiero: por qué los datos contextuales son la nueva línea de defensaACIS
- Qué hacer si no estoy conforme con un servicio financiero o existen diferencias con un banco, aseguradora o compañía de financiamientoMinisterio de Justicia y del Derecho de Colombia
- Publicación de A3Sec - LinkedInA3Sec
- Biometría facial en la banca mexicana: qué exige la nueva resolución de la CNBVFacephi Observatory
- Regulación de IA en México genera posturas encontradas en el CongresoRadioNet
- El Gobierno de México abre un debate nacional para regular el uso de la IA y las redes sociales en menoresInfobae México
- San Luis Potosí deroga ley que regulaba el uso de la IA y amenazaba la libertad de expresiónInfobae México
- Vulneran SIDAC y exponen 400 mil peticiones dirigidas a PresidenciaMaya Comunicación
- Hackean Sistema de Atención Ciudadana de la PresidenciaDailymotion
- Reportan hackeo en la Presidencia de México que habría comprometido 400 mil denunciasYucatán.com.mx
- ¿Hay una iniciativa de ley para regular que menores usen redes sociales? Sheinbaum aclara campaña de concientizaciónInfobae México
- Las Noticias Más Importantes de IA HoyTrend Micro
- IA sí, responsabilidad no: el modelo nacionalExpansión Política
- La IA dirigida a la tecnología operativa: perspectivas sobre amenazas emergentesCryptonomist
- AI Targeting Operational Technology: Emerging Threat InsightsThe Cryptonomist (versión en inglés)
- Sin contrapesos: ¿El gobierno ya no está obligado a justificar previamente el acceso a tus datos personales?Infobae México
- CONDUSEF alerta por suplantación de 11 instituciones financieras: cómo evitar caer en fraudes en 2026El Debate
- https://skyportsystems.net/ransomware-actors-exploit-bitlocker-and-corporate-printers-in-latin-americaSkyport Systems (blog técnico)
- El nuevo gran riesgo del sistema financieroPortafolio
- Kaspersky Security Services Identifies Ransomware Actors Using BitLocker and Printers in Latin AmericaTMCnet Insight
- Límites a la Inteligencia Artificial: la postura del PAN en San Luis PotosíEl Heraldo de México
- Presunto hackeo al gobierno de Sinaloa habría expuesto cerca de un millón de registros...Infobae
- Suman siete reportes de posibles ciberataques a sistemas públicos de Sinaloa en julioEl Sol de Sinaloa
- México regula la inteligencia artificial por sectores mientras aplaza la ley generalEl Economista
- Regulación la IA, discusión obligada para el Congreso: Kenia LópezVertigo Político
- Ataque atribuido a modelos de IA reabre debate sobre control tecnológicoGaceta Mexicana
- Phishing bancario: Así opera el fraude que pretende vaciar tu cuenta y cómo detectarlo a tiempo para evitarloEl Imparcial
- New ransomware group uses printers to deliver ransom notesSC World
- Hackeo en Sinaloa: Habrían sido filtrados datos de 4000 pacientes, cuentas bancarias y másDebate
- Panorama de ransomware en México | Ransomware ResponseRansomware Response
- Ciberataque a gobiernos de Sinaloa expone datos de casi un millón de personasProceso
- Hackeo en Sinaloa: Habrían sido filtrados datos de 4,000 pacientes, cuentas bancarias y másDebate
- Nova extorsão com BitLocker: abuso de RDP, MSSQL e RMMSecurelist Brasil / Kaspersky
- El IMSS lanza importante aviso sobre el trámite que ahora se debe hacer en líneaInfobae
- Diputada mexicana promueve iniciativa para sancionar amenazas a través de medios digitalesInfobae (agencias)
- Resumen Semanal PLD: 11 al 17 de Julio de 2026PLD.mx
- El laberinto constitucional de la regulación de la IA en MéxicoEl Universal
- Nuevo intento por penalizar la IAEl Economista
- Prueba de Vida: Nuevo requisito obligatorio para la apertura de cuentas digitalesHelp-AI México
- PT propone incluir inteligencia artificial en los planes de estudio de México con reglas para proteger datos y orientar su uso en clases y evaluacionesEl Imparcial
- DragonForce Posts Eighteen Victims Across Eight Countries in 48 HoursDaily Security Review
- Nu recibe autorización final para operar como banco en México | avances 2026Mundi
- Entre la regulación de la IA y la ley mordaza, una agenda polémica divide a San LázaroEl Debate
- Biometría bancaria en México: quién queda afueraLadonware
- Bancos pedirán huella dactilar o reconocimiento facial para retiros y depósitos mayores a 140,000 pesos con una nueva regulación de la CNBV para reducir fraudes financieros en MéxicoEl Imparcial (citando Expansión)
- El reto de los bancos no es reconocer rostros, sino protegerlosMilenio
- El reto de los bancos no es reconocer rostros, sino protegerlosMilenio
- El fraude de identidad sintética con IA alcanza el 48.3% de los casos en América LatinaEl Economista
- Nuevo requisito bancario en México 2026: ¿Por qué pedirán biométricos e INE para retirar o depositar efectivo?El Debate
- Regular la inteligencia artificial: un primer paso en propiedad industrial, muchos pendientes por delanteECIJA
- Regulación de redes sociales y de IA: Estos son los temas primordiales para Morena en el CongresoEl Financiero
- Qué es KYC en México: Guía para Bancos y FintechsFIMPE
- Morena busca regular la Inteligencia Artificial; ¿qué contempla la ley?XEU Noticias
- Alertan por ola de ciberataques en México - Periódico AMPeriódico AM
- León Investigates Alleged Attack on Citizen Services SystemSecurity Tribune
- Organização social é investigada por vazamento de dados de pacientesAgência Brasil
- Condusef recibe 12 denuncias por fraude financiero cada minutoInformador
- El truco del correo falso: el silencioso método con el que los hackers están vulnerando a las víctimasInfobae
- Las quejas por fraude bancario escalan un 31.5% ante la Condusef en 2026, pero las instituciones financieras rechazan reembolsar el 75.7% de los montos reclamados tras los robos de dinero mediante engaños digitalesEl Imparcial
- La CNBV exige a bancos mexicanos verificar a sus clientes ...Cointelegraph en Español
- Facial Biometrics in Mexican Banking: What the New CNBV Resolution Requires and How to Be Compliant by NovemberFacephi Observatory
- CNBV endurece reglas de biometría y ciberseguridad en la bancaImagen Radio
- Security articles – infraestructura de phishing modular contra instituciones financieras mexicanasMinistang.com
- Todo sobre la regulación para retailers en MéxicoPirani Risk
- Filtran datos de 400 mil denunciantes tras fallo de seguridad en PresidenciaMaya Comunicación
- Promueven regular el uso de dronesLa Nación (Paraguay)
- La Ley de Datos: multas de hasta 10.000 jornales que ninguna empresa puede ignorarABC Color
- Ley N° 7593/2025 de Protección de Datos Personales: la Guía de Cumplimiento para Empresas y Empleadores en ParaguayAvanzia Legal
- Paraguay avanza hacia una economía digital más segura con la nueva ley de datos personalesLa Nación (Paraguay)
- Crece la alarma por el incremento de estafas y ataques digitales a empresas privadasLa Política Online
- En caso de ciberespionaje intentaron instalar recolector de datos estatalesLa Tribuna
- Paraguay ya sufrió ciberataques chinos y su defensa tiene ...Mucho Texto
- Conductores de plataforma piden acelerar estudio de proyecto de leyAgenda Paraguay
- BCP fija topes de tarifas en servicios del SipapLa Nación (Paraguay)
- Diputados pide informes sobre supuestos ciberataques de China al gobierno de Santiago PeñaABC Color
- La Fiscalía de Paraguay abrió una causa penal por los ciberataques atribuidos a China contra sistemas del EstadoInfobae América Latina
- China nega acusação de ataque hacker contra o ParaguaiExame
- Venezolano que vive hace 10 años en Paraguay defiende al paísLa Nación Paraguay
- Convención Bancaria Paraguay 2026 analizará el impacto de la inteligencia artificial y los nuevos desafíos del sistema financieroPrensa Cooperativa
- 개인정보 보호법 제정과 적용 산업- 파라과이는 '개인정보 보호법(Ley de Protección de Datos Personales)'을 제정해 공공·민간의 개인정보 수집과 활용에 대한 규제를 강화함EMERiCs
- Publicación de Marcela Pallero sobre "Ransomware obliga a sanatorios de Paraguay a volver al papel"LinkedIn
- Según el CERT-PY, suman 4 mil ciberataques desde el año 2023Última Hora
- Claude Code para empresas en Perú: guía 2026Duotach
- El Consejo de Ministros de Perú acuerda las primeras medidas sobre seguridad y empleoInfobae (agencia EFE)
- Ejecutivo solicita facultades para legislar por 120 días: ¿qué materias están incluidas?Caretas
- Revise las principales normas legales publicadas del 19 al 25 de julio del 2026El Peruano
- Gobierno pide facultades legislativas en seguridad, economía y empleoLa Razón
- Ransomware incidents involving Peru (map view)ransomware.live
- La suplantación de identidad en productos financierosSuperintendencia de Banca, Seguros y AFP (SBS)
- Bancos, cajas y financieras deberán permitir transferencias inmediatas con número de celular, DNI o QR tras nueva norma del BCRPEnfoque Real
- Circular N.º 0017-2026-BCRPActualidad Civil
- Pagos instantáneos en Perú: BCRP dispone que todos los bancos acepten transferencias inmediatas con QR, DNI o celularInfobae Perú
- Más de 50 fintech serían supervisadas por el BCRP, ¿pasarán la prueba de fuego?Gestión
- El 2026 regulatorio cambió las reglas para fintech peruanasTraxxia
- SBS cambia las reglas para bancos, cajas y financieras - RPP NoticiasRPP Noticias
- Bancos, cajas y financieras deberán permitir transferencias inmediatas con número de celular, DNI o QR tras nueva norma del BCRPRPP Noticias
- Perú establece su primer marco regulatorio para el modelo de Banking as a Service (BaaS)LinkedIn
- SBS regula el Banking as a Service (BaaS): ¿qué es y cómo cambiará a los bancos en Perú?La República
- SBS impone nuevas reglas a bancos y financieras: así cambiará la atención al clientePerú Retail
- Entidades financieras del Perú deberán informar oportunamente incidentes que afecten a sus clientesNivel4 Blog
- Comentario sobre Resolución SBS 01741-2026 y protección de usuarios financierosLP Derecho / Estudio Camus y Márquez Abogados
- Un solo clic puede vaciar tu cuenta: las tácticas de los ciberdelincuentes en América LatinaInfobae
- Una IA autónoma sorprendió al ejecutar acciones no previstas durante una prueba de ciberseguridadUnivision
- Grupo de cibercrimen evoluciona a plataforma de servicios criminalesSercolombiano
- ESET: 4 de cada 10 empresas en América Latina operan a ciegas ante los ciberataquesCanalnews
- Ransomware gangs go after EMEA healthcare's supply chainHelp Net Security
- ESET: 4 de cada 10 empresas en América Latina operan a ciegas ante los ciberataquesESET / CanalNews EC
- La grieta abierta de la IA: la dependencia de América Latina ante modelos cerrados y chinosTuring Magazine
