CiberLATAMbywhalemate
Intelligence report

Latin America Ransomware Activity, June 2026

June ended with Brazil, Mexico, and Paraguay under ransomware pressure, more leak-site extortion cases, and a focus on healthcare.

Jul 28, 202628 min read
Latin America Ransomware Activity, June 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are completed automatically with the verified dated facts within the period. Each one states its basis and counting criterion, so the figures reconcile across modules. They are the recurring month-to-month reading; the analysis that follows develops the cases without repeating this summary.

Indicator window: 86 dated facts in June 2026 · 7 from previous months (comparative frame, not month volume). Facts from previous months are used only as a comparative frame in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Verified signal monthly dashboard June 2026 · Latin America Top threat: Ransomware (56 of 74 events). Coverage: 86 dated events in June 2026 · 7 prior months… VERIFIED EVENTS 74 period base: all counts below is measured against this total RANSOMWARE / EXTORTION 56 1 encrypted asset confirmed · 1 exfiltration no encryption (simple extortion) UNTYPED INCIDENTS 11 breaches or outages without declared threat type FRAUD / PHISHING 1 documented fraud campaigns REGULATION 1 rules, resolutions, or sanctions UNIQUE CVEs 0 none in the material analyzed (does not imply absence in the region)
Verified signal monthly dashboard — Base: 74 verified dated events for Latin America.
MONTHLY FIXED MODULE Threat Axis Distribution June 2026 · Latin America Each event is counted on only one axis, so the total is exactly 74. "Unclassified incidents" is the remainder. Ransomware 56 Incidents 11 Unclassified 5 Fraud 1 Regulation 1
Threat Axis Distribution — Each event is assigned to a single axis based on its classification; the total reconciles to the 74 events in the period.
MONTHLY FIXED MODULE Sectoral Distribution of Signals June 2026 · Latin America Base: 74 incidents in the period · total 83 because 11 incidents are classified in more than one sector. Other / unclassified 28 Public sector / OIV 19 Healthcare 11 Finance 9 Technology 5 Telecom 4 Retail / Consumer 4 Energy 3
Sectoral Distribution of Signals — Heuristic classification by victim sector. One incident may affect more than one sector, so the total may exceed the base.
MONTHLY FIXED MODULE Geographic Distribution of Coverage June 2026 · Latin America Each incident is assigned to only one country or to regional coverage, so the total is exactly 74 of 74 incidents… Regional 37 Mexico 13 Paraguay 13 Brazil 11
Geographic Distribution of Coverage — Verified incidents in the period grouped by country or regional coverage; each incident is counted once.

Executive Monthly Summary

June 2026 sent a clear signal across the region: ransomware remained the dominant threat, but the available material points to a fragmented reality, with few full confirmations of encryption and a much heavier concentration of cases in leak sites, publication threats, and operational reporting than in detailed technical descriptions of damage. Across 74 verified events in the period, 56 were linked to ransomware or extortion as the primary driver. Within that set, the material allows for only one confirmed encryption case, one exfiltration case without encryption, a single mention on a leak site, and 53 situations where the exact classification could not be determined with precision.

The regional picture combines two layers. On one side, leak site trackers and weekly radar reports show sustained activity from groups such as TheGentlemen, Krybit, LockBit5, Threeam, Direwolf, Dragonforce, Incransom, Killsec, Gunra and Stormous. On the other, cases with verifiable operational impact were concentrated in sensitive sectors, especially health care, finance, industry, business services, transportation and logistics, manufacturing, consumer-facing businesses, and public administration or educational infrastructure. That mix best explains the month’s risk reading, which should be placed at high due to event volume, sector reach, and the presence of organizations with critical operations.

The clearest operational episode came from Paraguay, where several reports converged on a ransomware attack that forced private clinics and medical companies to fall back on paper and manual operations. The reporting is not limited to one entity, it covers sanatorios Migone, Británico, Las Lomas and Santa Clara, as well as companies tied to private medicine and health insurance. The most detailed source describes delays in admissions, consultations, tests, payments and customer service channels, suggesting a broad interruption to continuity of care. The same material does not provide a robust confirmation of public data leakage, so the verified impact is primarily operational.

Mexico accounted for the other major block of the month, both in the number of victims recorded by specialized monitoring and in the public debate that opened around the financial system. Ransomware.live listed victims attributed to Krybit, Threeam, Stormous, Incransom, LockBit5, Dragonforce and Killsec, with sectors including manufacturing, education, consumer services and institutions linked to finance. Banxico also confirmed in its financial stability report that by 2026 there had already been eight cyber incidents in financial institutions through May, twice the total for all of 2025, and that the first incident of the year was a ransomware attack identified as LockBit against a bank. That figure does not expand June’s volume, but it does frame the context: Mexico’s financial sector entered June on an upward trajectory and with sustained exposure.

Brazil again emerged as structurally exposed, although the material does not always allow identification at the individual victim level. Breachsense placed the country at 18 victims in June and identified TheGentlemen as the most active group globally for the month, with 94 claimed victims. Daniel Donda also tracked Brazilian organizations on extortion sites, including ws.com.br, MHE9 Logística Ltda, Clínica Vida, Silmquinas e Equipamentos and sweetome.com, spreading the signal across business services, transportation and logistics, health care, manufacturing and consumer sectors. Dexpose also reported a direct claim by Krybit against Coemi Imóveis, along with a threat to publish sensitive data if negotiations did not begin. The pattern is not uniform, but it is consistent: Brazil remains a major target for extortion campaigns and leak-site pressure.

The month also produced relevant signals in Colombia and in the regional infrastructure-critical environment. Infobae, based on ERC Colombia, reported more than 10 trillion cyberattack attempts over the last year and a meaningful share of successful regional incidents, affecting sectors such as health care, education, BPO and corporate environments. While that telemetry is not a count of incidents with direct impact, it helps explain why organizations across the region see ransomware as a natural extension of earlier intrusion vectors, phishing and credential abuse. Cyberix.cl, meanwhile, echoed alerts from Latin American CSIRTs about an escalation in ransomware aimed at disrupting the continuity of essential services.

TIMELINE Verified events in the period 1/6 ESETpublisheda pieceofcontent 1/6 Securelist Latampublished a 1/6 EbizLatampublished anarticle 1/6 That samearticle about 1/6 The analysis oncybersecurity 2/6 The samearticleof

Timeline of verified events, June 2026 — Confirmed-date milestones within June 2026. Events from earlier months are outside the timeline and are used only as a point of comparison.

Regional snapshot for the month

June’s regional picture shows an ecosystem under heavy attack pressure, but with far more noise than precision in public attribution. The material points to a sharp gap between the number of organizations named on leak sites and the technical detail available on how each intrusion happened. That means three layers have to be kept separate: victim publication, confirmation of operational impact, and proof of exfiltration or encryption. In June, most cases stayed at the first layer, while the other two were the exception.

Even with that limitation, the dominant trend is clear. Ransomware remained the month’s most visible attack type, with a broad presence across health care, finance, industry, business services, transportation, logistics, manufacturing, consumer sectors, education, and public infrastructure. This is not just a volume problem. The material also shows that attackers continue to prioritize assets where downtime carries immediate economic, reputational, and regulatory costs. In health care, an outage is measured not only in hours offline, but also in rescheduling, manual care, loss of traceability, and clinical risk. In finance, the damage shows up in disruptions to payments, transfers, and access to digital services. In industry, the impact is reflected in operational continuity, technical documentation, and supply chains.

The region remained under sustained malicious activity overall, but this report focuses on ransomware with confirmed or signaled victims in Latin America. Under that filter, Brazil, Mexico, and Paraguay accounted for the clearest incidents of the month, while Chile and Bolivia appear in a regional reference tied to Qilin that the source itself marks as uncertain in attribution. Colombia, by contrast, provides the best context for understanding the scale of the problem, even if not necessarily the largest number of confirmed individual ransomware cases in this document set. Argentina and Peru appear only tangentially or for comparison, with no specific verifiable victims in the June file.

The qualitative risk reading for Latin America in June is high. Severity did not come from a single devastating campaign, but from the combination of multiple active hotspots, sensitive verticals, and heavy reliance on leak sites as a pressure mechanism. When a month includes clinics forced to operate manually, industrial companies facing data publication threats, financial institutions under regulatory review, and extortion groups with sustained activity, the risk is no longer hypothetical. The problem is not only the intrusion, but the attackers’ ability to turn any partial disruption into forced negotiation.

On the tactical side, there are also patterns consistent with initial access campaigns involving compromised credentials, exposed remote services, and abuse of poorly segmented infrastructure, something Banxico and Dinamio mention when discussing exposed RDP, VPN, and RDWeb services, as well as compromised credentials. The eSoft and ColCERT report adds another layer, digital identity, Phishing-as-a-Service, and a shift to Rust and Go to improve evasion and performance. These are different pieces of the same puzzle. They do not prove a single group behind all of the month’s activity, but they do describe an environment where attack industrialization keeps advancing.

Period indicators

Indicator Value
Verified facts in the period 74
Time window for the indicators 86 facts dated in June 2026 · 7 from prior months (comparative frame, not monthly volume)
Unclassified incidents (breaches or disruptions) 11
Cases with ransomware or extortion as the primary focus 56
Confirmed asset encryption 1
Exfiltration without encryption (simple extortion) 1
Leak site mention only 1
Type could not be determined from the material 53
Documented fraud or phishing cases 1
Documented regulatory moves 1
Critical CVEs mentioned 0, none in the material analyzed (does not imply absence in the region)
Sectors with at least one documented fact 8
Dominant threat of the month Ransomware (56 of 74 facts)
Facts with direct source confirmation 89%
Aggregated telemetry figures excluded from volume 12 (aggregated attempts or blocks, not incidents with confirmed impact)

Relevant incidents

Private clinics and healthcare in Paraguay

Paraguay was the clearest operational case in the month. Coverage by La Tribuna, El Nacional and El Independiente points to a large ransomware attack that hit private clinics and private health care companies in Paraguay. The institutions named include Migone, Grupo Británico, Reyva, Británico, Las Lomas and Santa Clara. The overlap among local outlets helps narrow the room for ambiguity about the real impact, although it does not fully resolve attribution of the attacking group.

The most relevant part of the episode is not just the list of victims, but the type of disruption. The clinics had to operate manually, with delays in admissions, tests, appointments, payments and other procedures. That points to unavailability of core systems and a direct hit to clinical continuity. In health care, once staff go back to paper, the issue is no longer an abstract alert, but a functional degradation that affects care, coordination and traceability. The source also suggests the attack took place about two weeks before publication, which points to a period of persistence before the public announcement.

La Tribuna adds that the attackers may have encrypted confidential data and would be demanding money to restore service, but that part is framed as a journalistic hypothesis, not a technical confirmation. For that reason, the damage that can be stated with certainty is operational, not exfiltration or the encryption of sensitive information as an established fact. That distinction matters because it avoids conflating unavailability with leakage, two different impacts from a legal and response standpoint.

Krybit against Coemi Imóveis in Brazil

Dexpose reported that Krybit claimed responsibility for an attack against Coemi Imóveis in Brazil and threatened to publish sensitive data if negotiations did not begin. The clearest signal here is not encryption, but pressure tactics, classic extortion with leak site language. The source does allow for identification of a forced negotiation attempt and an explicit promise to expose information, but it does not provide enough to conclude whether encryption was confirmed or whether the case remained at the exfiltration stage with a threat of publication.

This type of case is especially useful for reading group behavior in June. Activity does not always show up as a visible outage. Sometimes the tactical value for the attacker lies in the credible threat of leaking data, especially when the victim depends on reputation, contract compliance or public-facing service. In real estate, as in other document-heavy services, exposure of contracts, personal data or financial information can be enough to push a negotiation.

Education and infrastructure in Mexico with LockBit5

Ransomware.live listed the subdomain idefeey.yucatan.gob.mx as a LockBit5 victim, with discovery on 20 June and an estimated attack date of 17 June. The case matters because it combines education and electricity-related infrastructure in Yucatán, a detail that broadens the potentially affected institutional surface. The material does not describe the scope of encryption or outage publicly, but the presence of the asset on the victim map alone places the incident within the pattern of public visibility that dominated the month.

The significance of this case also lies in where it sits. When organizations with mixed responsibilities appear, such as education and services linked to energy or state support, the risk stops being purely sectoral. The impact can extend to multiple agencies, internal users and associated services. The material does not support a claim of broad disruption, so the report keeps it as a published victimization case, not a confirmed systemic interruption.

Mexican victims linked to Krybit, Threeam, Stormous, Incransom, Dragonforce and Killsec

Ransomware.live and other sources from the period show a relevant spread of Mexican victims across different groups. Copamex appears attributed to Dragonforce, csinsurance.mx to Killsec, ford.mx to Krybit, acemacon.org to Threeam, impulso-store.com to Stormous and jktornel to Incransom. That mix of actors, sectors and exposure patterns suggests Mexico is not facing a single wave, but several fronts in parallel. Industrial, commercial, service and financial entities, or organizations tied to the corporate ecosystem, all appear.

The impulso-store.com case provides more detail, because the description refers to access to full customer and buyer data, as well as designs and orders. Here there is a clearer sign of exfiltration with an implicit or explicit threat of later use. By contrast, the jktornel case emphasizes unauthorized access to confidential files, including customer data and intellectual property, but the source does not specify whether encryption occurred. That leaves the incident somewhere between data exposure through intrusion and extortion, without allowing a fully precise classification into a single category.

Banxico and the Mexican financial front

Banxico confirmed, through its Financial Stability Report cited by national media, that by May 2026 there had been eight cyber incidents in financial institutions, twice as many as in all of 2025. It also specified that the first incident of the year was a ransomware case identified as LockBit, which temporarily affected electronic transfer services at a bank in January. Although that event does not belong to June’s volume, it is central to understanding why Mexico’s financial sector entered the second half of the year with high sensitivity.

The cautious reading is twofold. First, ransomware is not limited to data theft, it can also degrade critical payment and transfer services. Second, the country’s financial ecosystem had already accumulated several incidents in a few months, including banks, Sofipos, a Socap and an Electronic Payment Funds Institution. That makes any June signal especially relevant, even if the file does not provide a complete list of attacks with confirmed impact in that window.

Enrique Remmele S.A.C.I. in Paraguay

On 17 June, malware.news reported that Krybit claimed an attack against Enrique Remmele S.A.C.I. (ERSA), a Paraguayan industrial company, and threatened to publish data if negotiations did not begin. Ransomware.live also listed the ersa.com.py domain as a Krybit victim. This case reflects a common pattern in the region, the combination of leak site visibility, a publication warning and limited technical detail about the initial vector or the scope of damage.

Unlike the Paraguayan health care block, this material does not describe a generalized shutdown or a return to manual work. The value of the case is that it confirms Krybit activity in Paraguay during June and expands the list of affected sectors into industry. The extortion points to an actor able to pressure targets through data exposure or operational disruption, although the available text does not allow a determination of which of those two levers was primary.

Coemi Imóveis in Brazil

Krybit’s claim against Coemi Imóveis adds another piece to the same pressure campaign. Dexpose makes clear that the group threatened to publish sensitive information if negotiations did not take place. The fact is relevant because it reinforces Krybit’s presence in Latin America during June and shows a monetization tactic based on negotiation, not immediate visible damage.

This kind of publication often works as a message to the market of potential victims. The group’s public communication is part of the attack. A reader does not need to see an encrypted system for there to be reputational, regulatory and response costs. Operationally, the threat of leakage can be as disruptive as encryption when the organization depends on commercial trust, personal data handling or contract compliance.

Brazilian victims listed in the weekly radar

Daniel Donda’s weekly radar for 8 to 15 June recorded five Brazilian organizations on ransomware extortion sites: ws.com.br, MHE9 Logística Ltda, Clínica Vida, Silmquinas e Equipamentos and sweetome.com. The sector spread is useful because it shows attackers are not focused on a single vertical. Business services, transport and logistics, health care, manufacturing and consumer services all appear in the same window.

The material also identifies the groups behind the cases: threeam, gunra, direwolf, thegentlemen and lockbit5. That should not be overread. The radar by itself does not prove the technical scope of each case, but it does confirm victim publications and provides a consistent signal of activity. In a region where public evidence often arrives before technical evidence, this kind of monitoring remains a useful piece of the puzzle.

Clínica Vida in Brazil and the Direwolf group

CronUp reported that Clínica Vida appeared among 56 victims published in leak site monitoring during the previous 48 hours and attributed that publication to the Direwolf group. That mention reinforces the presence of the health sector in the month’s sample. This is not an isolated case, but part of an environment where clinics, hospitals and private medical providers repeatedly appear as extortion targets.

The problem for health care is not only leakage or the threat of leakage. It is also the loss of administrative continuity and the need to keep care running in degraded mode. That is why these cases, even when they do not detail confirmed encryption, deserve separate treatment. In Latin America, the health sector remains one of the most sensitive to any interruption, because operational cost quickly becomes patient care impact.

Active threats and campaigns

Ransomware and simple extortion

June’s roster of active groups shows a scattered but sustained pattern. TheGentlemen was identified by Breachsense as the month’s most active group with 94 claimed victims worldwide, and its activity overlaps with the Brazilian cases of Silmquinas e Equipamentos and Mackay Sugar mentioned by Kaseya. LockBit5 appears in Daniel Donda’s reporting and in the Mexican victimization of idefeey.yucatan.gob.mx and sweetome.com. Krybit appears repeatedly in Brazil, Paraguay and Mexico. Direwolf, Threeam, Gunra, Incransom, Stormous, Dragonforce and Killsec also appear.

Taxonomically, extortion is the dominant signal. The material allows for only one confirmed file-encryption case, the Paraguayan healthcare block, and one exfiltration case without encryption on the Mexican domain impulso-store.com. There is also a single victim mention on a leak site with no data published yet, as in the case of Mackay Sugar flagged by Kaseya. The remaining 53 incidents do not allow for a precise determination of whether there was encryption, leakage, or both. That opacity is a finding in itself, in June public visibility far outpaced technical precision.

TheGentlemen’s presence is especially useful for reading the month. Breachsense places it at the top of global activity, and Kaseya’s source shows a classic leak-site pattern, naming the victim before any data is published. That fits a staged pressure strategy. First the name is exposed. Then the response is measured. Later, if the victim does not negotiate, data publication or a second wave of exposure can follow.

Confirmed encryption, exfiltration without encryption, and only a mention

The distinction is not cosmetic. When encryption is confirmed, the impact appears in downed systems, halted processes and technical recovery. When there is exfiltration without encryption, the risk shifts to compliance, privacy and exposure-based extortion. When there is only a leak-site mention, the organization is already under public pressure, even if there is still no proof of a breach. June was dominated by the third scenario and, to a lesser extent, the second.

The Paraguayan case shows the first scenario relatively clearly, because institutions had to return to paper and operate manually. The impulso-store.com case shows the second, with access to complete customer and buyer data, as well as designs and orders. The Mackay Sugar case shows the third. That sequence matters for any regional CISO, because it requires severity indicators to be adjusted. The same group may be negotiating, leaking or encrypting depending on the target and the victim’s defensive maturity.

Fraud and phishing

Although this report focuses on ransomware, the material includes a specific signal of fraud and phishing. ITware Latam, based on the Fortinet 2026 Report, said phishing accounts for 76% of the attack vectors identified by industrial organizations in Latin America. CronUp, for its part, reported infostealer campaigns distributed through fake Spotify Premium promotions and pirated games. These are not ransomware, but they are part of the ecosystem that feeds initial access, credential theft and compromises that can later lead to extortion.

The link to ransomware is direct from an operational standpoint. Phishing campaigns and exposed credentials remain among the most profitable access paths for actors who then deploy data theft, persistence and lateral movement. June’s file does not document a major standalone fraud campaign with confirmed corporate victims in Latin America, but it does confirm that phishing remains central to the attack chain.

APT and critical infrastructure

The material analyzed does not include a classic APT campaign with enough detail to make it the main section. It does, however, point to a converging reading of critical infrastructure and operational continuity. Cyberix.cl reported alerts from Latin American CSIRTs about an escalation in ransomware aimed at compromising essential services. eSoft and ColCERT reinforce the picture of quieter intrusions, with compromised identity and automation, while Banxico shows how sensitive financial systems are to any disruption.

In other words, June does not bring a major classic APT case with formal attribution, but it does show a persistent intrusion environment in which ransomware acts as a strategic pressure tool against essential sectors. The operational result can resemble that of a prolonged access campaign, even if the monetization logic is different.

Critical vulnerabilities

No critical CVEs were recorded in the June material analyzed. That does not mean there were no exploited vulnerabilities in the region, only that the available corpus for this report did not include verifiable critical CVE identifiers.

CVE Software Exploitation Source
Not recorded in the material analyzed Not determined Not determined N/A

Regulation and compliance

June also left a regulatory signal that should not be separated from the operational picture. ITware Latam reported that 89% of industrial leaders surveyed in Latin America expect cybersecurity regulations to increase over the next five years. That is not a specific rule issued this month, but it is a broad enough view to show the issue is no longer purely technical.

Banxico is the clearest case on compliance and oversight. The authority confirmed that cyber incidents in Mexico's financial system doubled in 2026 compared with 2025 and said the first event of the year was ransomware. That puts financial institutions under closer scrutiny for continuity, reporting, and operational resilience. The public debate generated by those figures could lead to stricter demands for controls, segmentation, and traceability.

At its core, June showed a clear convergence between technical risk and regulation. When an attack forces an organization back to paper, or when a bank sees electronic transfers interrupted, the issue stops being only about security and becomes one of corporate governance, compliance, and resilience. That is why the region's regulatory focus should not be limited to incident notification. It should also cover recovery times, third-party dependence, identity management, and realistic continuity testing.

Countries Most Affected in Latin America

Brazil

Brazil stands out as one of the month’s main hubs. Breachsense attributed 18 ransomware victims to it in June, and Daniel Donda lists five Brazilian organizations on extortion sites. That is reinforced by Krybit’s claim against Coemi Imóveis and TheGentlemen’s mention of Mackay Sugar. The sector mix is broad, including business services, transportation and logistics, healthcare, manufacturing, and consumer services.

The most important point is not just the number of names, but the persistence of public exposure. Brazil remains a profitable target for groups running leak sites, because the scale of its economy and the digital footprint across multiple sectors increase the leverage available in negotiations. The material does not let us determine how many of those cases involved confirmed encryption, but it does show that the country absorbed a significant share of the month’s pressure.

Mexico

Mexico has the highest density of specific cases in the file. Ransomware.live records victims such as Copamex, csinsurance.mx, impulso-store.com, jktornel, idefeey.yucatan.gob.mx, ford.mx, and acemacon.org, tied to several different groups. The financial sector also stands out, with Banxico confirming eight incidents in 2026 through May and a reference to LockBit ransomware against a bank in January.

The mix of victims points to a wide attack surface, spanning industry, insurance, retail, education, state infrastructure, and financial ecosystems. The country does not show a single threat pattern, but rather multiple campaigns and groups. That raises the level of complexity for defense teams, because it requires tracking exposed services, credentials, vendors, and remote administration surfaces.

Paraguay

Paraguay saw the month’s strongest operational impact. Sanatoriums and private medical companies had to shift to manual operations, and local coverage describes delays in care, tests, payments, and admissions. The incident also reached an industrial company, ERSA, attributed to Krybit. That two-front hit, healthcare and industry, shows that extortion is not limited to large economies or to a single sector.

The country deserves close attention because the material shows concrete operational impact. When continuity of care and administrative processes are affected to the point that paper becomes necessary again, the priority shifts from prevention to response. The sources do not allow us to confirm the scope of exfiltration, but they do confirm that the operational damage was significant.

Colombia

Colombia does not include in this file a confirmed ransomware victim comparable to the cases in Brazil, Mexico, or Paraguay, but it does provide key context. ERC Colombia, cited by Infobae, reported more than 10 billones of cyberattack attempts in the last year and a significant share of successful incidents in the region in May. It also pointed to impacts across healthcare, education, BPO, and corporate sectors, placing the country in a constant pressure environment.

Colombia matters for this report not because of the number of published cases, but because of what it says about the operating environment. When compromised credentials, application vulnerabilities, and webshells appear as recurring vectors, the path from intrusion to extortion gets shorter. The average cost of a data leak cited by ERC Colombia also helps explain why ransomware continues to attract attackers.

Chile

Chile appears indirectly in the material, through El Heraldo de Puebla’s report on a campaign attributed to Qilin that would also have affected a Chilean clinic. However, the source itself marks that attribution as uncertain. For editorial integrity, this report does not turn that mention into a confirmed June case. What it does show is a signal that healthcare sectors across the region remain on the radar of international groups.

In practical terms, Chile does not add a verifiable victim here with the same documentary weight as other countries, but it remains part of the regional exposure picture. The most prudent reading is one of watchfulness, not counting.

Argentina

Argentina does not appear in the month’s confirmed ransomware incident volume with a clear individual case in the file, although it does appear in earlier comparative material on cyberattack pressure per organization. That does not allow any inference about June volume. It does suggest a regional environment in which more connected economies face high and persistent exposure.

For this report, Argentina remains a country without a clearly documented ransomware victim in the June material, but still among the jurisdictions that need close monitoring for the same mix of phishing, compromised credentials, leak sites, and pressure on essential services.

Bolivia, Peru, and the United States

Bolivia and Peru do not have sufficiently detailed ransomware victims in the June file for a country-by-country reading. Regional references do appear, such as the list of Krybit victims, which includes aisem.gob.bo, but that mention comes from a monitoring source that does not break out a comparable Peruvian case. The United States, for its part, appears only indirectly in comparative or contextual material and is not part of the month’s regional volume.

There is no archived comparison baseline for June in this indicators format, so it is not appropriate to discuss month-over-month change using a single metric from the report. A qualitative trend can still be drawn from the available facts. The first is the consolidation of leak sites as a central pressure point. TheGentlemen, Krybit, LockBit5, Direwolf, Threeam, and other groups do not just post victims. They build a coercive narrative that mixes the organization’s name, a threat to leak data, and, at times, partial details about the data.

The second signal is the persistence of highly sensitive sectors. Health care and finance remain at the center of operational harm, but June also includes industry, manufacturing, logistics, education, and public or mixed infrastructure. That suggests attackers are still targeting places where operational stoppages are costliest. The manual response by Paraguayan sanatoriums and Banxico’s reference to a temporary interruption of transfers are two different examples of the same logic.

The third signal is that initial access remains the main enabler. Context sources point to exposed credentials, poorly secured remote services, automated exploitation, and phishing. It does not take a sophisticated exploit to turn a broad environment into an extortion case. In June, several parts of the material point to exactly that, intrusions driven more by identity abuse and exposed attack surface than by critical vulnerabilities with explicit CVEs.

The fourth signal is the growing weight of groups with multiregional activity. Krybit appears in Brazil, Paraguay, and Mexico. TheGentlemen leads the month globally in volume and touches a Brazilian case. LockBit5 reappears in Mexico and in the weekly radar. That movement reinforces the idea that Latin American incidents cannot be analyzed as isolated events. They are part of campaigns that cross countries and sectors quickly.

The fifth signal is technical opacity. Many reports publish victims but do not confirm whether there was encryption, leakage, or both. For defense teams, that means absence of technical detail should not be mistaken for absence of risk. A case without a technical file can still have legal, reputational, and operational impact if the organization was named on a leak site or had to keep services running manually for hours or days.

Recommendations for security teams

First, review the real ability to operate in degraded mode. The Paraguayan case shows that a return to paper is not a metaphor, but an operational necessity when systems fail. Security teams should verify which critical processes can keep running without core applications, how long that mode can be sustained, and what minimum data must remain available to maintain continuity.

Second, prioritize exposure of identities and remote services. The comparative and contextual material points to compromised credentials, exposed RDP, VPN, and RDWeb, along with the growth of phishing. Defense cannot depend only on EDR or perimeter controls. It requires phishing-resistant MFA, an inventory of remote access, privilege segmentation, and frequent review of orphaned or oversized accounts.

Third, treat leak sites as an operational phase of the incident, not as a simple press publication. When a group names an organization, it is already trying to shift its negotiating position. Teams need a specific playbook for the moment the victim appears listed, even if there is still no evidence that data has been published. That includes legal coordination, communications, forensic retention, and an early decision on whether to notify third parties.

Fourth, strengthen separation between IT, OT, and clinical or financial systems where applicable. Although the ITware Latam material shows improved segmentation in industrial environments, a significant share of organizations still report intrusion across both layers. In health care, finance, and mixed infrastructure, segmentation cannot be only logical. It must include containment testing, emergency paths, and privileged account control.

Fifth, improve protection for sensitive data that attackers can use for extortion without encryption. The impulse-store.com case and the mention of Coemi Imóveis show that pressure through data leakage remains profitable. That calls for information classification, encryption at rest and in transit, exfiltration monitoring, and controls over document repositories, ERP, CRM, and shared folders.

Sixth, incorporate intelligence on groups and leak sites into routine monitoring. Watching classic IOCs is not enough. In June, much of the useful signal came from victim names, claiming groups, and shifts in the narrative on extortion sites. Visibility into those spaces makes it possible to anticipate reputational pressure and prepare a response before the incident escalates publicly.

Seventh, review the third-party chain. The month’s material shows a region where the attack surface crosses sectors and vendors. Private medical organizations, industries, retailers, and public entities appear in the same risk map. That requires asking third parties for minimum backup, segmentation, and notification controls, and not blindly outsourcing continuity to software or infrastructure providers.

Material limits

This report covers only the material provided for June 2026 and uses, as its volume, only the facts dated within that period. Facts from earlier months that appear in the file were used only as a comparative frame of reference, always with their month explicitly stated in the text, and are not included in the monthly counts. The declared time window for the indicators is 86 facts dated in June 2026 and 7 facts from earlier months as contextual reference, not as volume.

A zero indicator, particularly for critical CVEs, means none were recorded in the material analyzed, not that exploited vulnerabilities did not exist in the region. The same applies to any absence of victims or sectors in the country section, it reflects only what appeared in the available corpus, not the full scope of the regional phenomenon. In particular, ransomware classification remains incomplete in many cases because the material reports victim names or group names, but does not always confirm encryption, exfiltration, or only a mention on a leak site.

Aggregate telemetry figures, attempts, blocks, scans, and weekly vendor averages were also left out of the counts. Those data points provide context, but they are not incidents with confirmed impact. When they are mentioned in this report, it is stated explicitly that they are attempts or automated blocks, not verified intrusions. Likewise, consumer networks and sponsored posts that are not included in the list of available sources for citation were excluded from the evidence.

Finally, regional coverage is heavily uneven across countries. Brazil and Mexico account for most of the verifiable operational mentions, Paraguay provides the clearest case of functional impact, and Colombia contributes mainly context on pressure and exposure. That means the month should be read as a signal of elevated risk, but also as a partial snapshot shaped by the quality and granularity of the available sources.

Sources