CiberLATAMbywhalemate
Intelligence report

Public Sector and Government Agencies, June 2026

June brought breaches, phishing, and a fake mass alert in Brazil; regional risk was high, with public agencies in focus.

Jul 28, 202625 min read
Public Sector and Government Agencies, June 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are automatically populated with verified dated events from within the period. Each one states its basis and counting criteria, so the figures can be reconciled across modules. This is the recurring month-by-month reading, while the analysis that follows expands on the cases without repeating this summary.

Indicator window: 133 dated events in June 2026 · 3 from earlier months (comparative frame, not this month’s volume) · 1 without confirmed date (excluded from the indicators). Events from earlier months are used only as a comparative frame in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Verified Signal Monthly Dashboard June 2026 · Latin America Top threat: Incidents (56 of 120 events). Coverage: 133 dated events in June 2026 · 3 prior months… VERIFIED EVENTS 120 period base: all counts measured below this is based on total RANSOMWARE / EXTORTION 11 11 not classifiable with the available material UNCLASSIFIED INCIDENTS 56 breaches or outages with no threat type declared FRAUD / PHISHING 16 documented fraud campaigns documented REGULATION 3 standards, resolutions, or penalties UNIQUE CVEs 0 none in the analyzed material (does not imply absence in the region)
Verified Signal Monthly Dashboard — Base: 120 verified dated incidents for Latin America.
MONTHLY FIXED MODULE Threat-axis distribution June 2026 · Latin America Each incident is counted in only one axis, so the total is exactly 120. "Unclassified incidents" is the remainder. Incidents 56 Unclassified 29 Fraud 16 Ransomware 11 Vulnerabilities 5 Regulation 3
Threat-axis distribution — Each incident is assigned to a single axis based on its classification; the total reconciles to the 120 incidents in the period.
FIXED MONTHLY MODULE Sectoral Distribution of Signals June 2026 · Latin America Base: 120 incidents in the period · total 157 because 28 incidents are classified in more than one sector. Public sector / OIV 75 Other / no sector ident… 23 Telecom 21 Healthcare 11 Finance 9 Energy 7 Education 6 Technology 5
Sectoral Distribution of Signals — Heuristic sector classification by victim sector. One incident may affect more than one sector, so the total may exceed the base.
MONTHLY FIXED MODULE Geographic Distribution of Coverage June 2026 · Latin America Each incident is assigned to a single country or to regional coverage, so the total is exactly 120 out of 120 incidents … Regional 42 Brazil 22 Mexico 22 Colombia 14 Peru 9 Argentina 7 Bolivia 4
Geographic Distribution of Coverage — Verified incidents from the period grouped by country or regional coverage; each incident is counted once.

Executive Monthly Brief

The month’s most disruptive event was the incident affecting the Interface de Divulgação de Alertas Públicos in Brazil’s Defesa Civil Alerta system. According to the Ministry of Regional Integration and Development, there were 10 unauthorized alerts between 23:41 on June 19 and 1:23 on June 20, reaching about 30 million users across at least eight federal units. The public response was immediate, extreme alert messages in the early morning hours, system shutdown, a referral to the Federal Police, and preservation of logs for forensic review. The severity was not in data loss, but in the simultaneous damage to public trust, operational continuity, and emergency communications.

That episode drew much of the region’s attention, but it was not the only significant issue for the public sector. In Argentina, June brought two sensitive developments around RENAPER and other state databases. On June 3, a new leak tied to the people registry was reported, based on commercial activity offering access to an API with data on Argentine citizens. Later, on June 24, LV16 reported that, after a major international operation, Argentina’s Federal Police identified and located in Spain the alleged cybercriminal known as @Gov.eth, attributed to attacks against public agencies and private companies between 2024 and 2026, with RENAPER and DNRPA as the main targets. At the same time, coverage mentions the leakage and sale of personal databases and attacks on national media, suggesting a persistent monetization ecosystem built around state data.

Colombia had a particularly active month across its government attack surface. ColCERT reported phishing campaigns impersonating the National Civil Registry in the context of the presidential runoff, with malicious emails that managed to bypass SPF, DKIM and DMARC and led to compressed files containing scripts designed to steal information and credentials. That was followed by alert AL-20260619-101 on the global FortiBleed campaign, which affected Colombia’s public sector and exposed VPN credentials potentially reusable for remote access. There was also a reported incident against Bogotá’s Secretaría Distrital de Movilidad, where attackers claimed they had accessed data and altered traffic citations, although the only material confirmation was a sample containing 238 JSON objects and four real infractions. The Colombian picture was shaped by a mix of impersonation, credential exposure and intrusion claims whose full scale could not be verified in every case.

Bolivia contributed a clear case of ransomware or extortion against a state health agency. On June 12, Krybit added aisem.gob.bo, which belongs to the Agencia de Infraestructura en Salud y Equipamiento Médico, to its public listing and claimed to have compromised the entity. DeXpose reported a threat to leak sensitive data if the group’s demands were not met, while Ransomware.live later updated the victim profile with 97 employees and 121 compromised users. The source does not specify whether encryption occurred, but it does confirm a public extortion pattern against a government agency tied to health infrastructure.

In volume terms, the month’s signal was dominated by incidents, with 56 events classified in that category out of a base of 120 verified events for the period. The rest of the material was split between ransomware or extortion, phishing and fraud, and regulatory moves. The source’s 83 percent direct confirmation rate suggests a relatively solid archive for editorial reading, though still uneven in technical traceability. No critical CVEs were mentioned in the material analyzed, which requires careful reading, it does not mean the region lacked severe vulnerabilities, only that this monthly file did not document them.

June leaves a regional public administration exposed through three overlapping vectors. First, compromise or suspected compromise of access surfaces such as VPNs and perimeter firewalls. Second, the leakage and commercialization of personal data and credentials, with strong reputational and legal impact. Third, manipulation or disruption of services with broad social reach, such as Brazil’s alert system. The political component was also significant, because some of the events involved election processes, civil defense, citizen identities and health entities.

Regional snapshot for the month

June’s regional read is one of high risk. Not because of a single broad campaign, but because several high-impact incidents hit government bodies at the same time, each with the potential to damage public trust, service continuity, and the handling of sensitive data. The month brought confirmed intrusions, leaks attributed to criminal actors, phishing aimed at election infrastructure, extortion against a health agency, and a cyber incident that disrupted Brazil’s emergency alert system nationwide. When one public sector vertical is under that much pressure at once, the issue is no longer isolated, it becomes systemic.

A common thread also stands out, attackers were not targeting confidentiality alone. June showed sustained interest in availability and operational legitimacy. The Brazilian case hit alert issuance capabilities; the Colombian case put credential integrity and the risk of fraud against election systems at risk; the Argentine case exposed personal data circulation and access to government databases; the Bolivian case involved threats to publish data from a state entity. In other words, Latin America’s public sector is being attacked across the entire trust chain, from initial access to the public exposure of the damage.

TIMELINE Verified events for the period 1/6 The DFIof the 1/6 A note from El 3/6 According to ElStrategic and 3/6 The specializedmedia outlet 3/6 Darkweb Informerreported that 3/6 ThearticlebyReseller
Timeline of verified events, June 2026 — Milestones with confirmed dates within June 2026. Events from earlier months are excluded from the timeline and used only as context.

Geographically, the month was especially dense in Brazil, Argentina, Colombia, and Bolivia, with additional signals in Mexico as context for leaks and unauthorized access to public programs, although the focus of this report remains the government sector. No single dominant tactical pattern emerged in June. Some vectors did repeat, including phishing campaigns impersonating institutions, abuse of VPN or perimeter credentials, data exposure on forums or leak sites, and extortion messages without always being able to prove encryption. That mix of vectors makes defense harder, because it forces teams to respond at once at the perimeter, in identities, in email, and in leak monitoring.

The political context adds another layer of friction. In Colombia, digital security became tied to the presidential runoff and public debate around the Registraduría. In Brazil, the Civil Defense incident had a government emergency communications dimension, affecting tens of millions of people. In Argentina, RENAPER and other personal databases are once again at the center of public discussion because of their resale value. When the attacked infrastructure belongs to the state, the cost is measured not only in downtime or exposed credentials, but also in the erosion of institutional trust.

Period indicators

Indicator Value
Verified events in the period (base for all indicators) 120
Time window for the indicators 133 events dated in June 2026, 3 from earlier months (comparative frame, not monthly volume), 1 without confirmed date (excluded from the indicators)
Unclassified incidents (breaches or disruptions) 56
Cases with ransomware or extortion as the primary focus 11
Ransomware breakdown by impact type Classification could not be determined from the material: 11
Documented fraud or phishing cases 16
Documented regulatory moves 3
Critical CVEs mentioned 0, none in the material analyzed (does not imply absence in the region)
Sectors with at least one documented event 8
Predominant threat of the month Incidents (56 of 120 events)
Events with direct source confirmation 83%
Aggregate telemetry figures excluded from the volume 13, aggregated attempts or blocks, not incidents with confirmed impact

Relevant Incidents

Brazil, Civil Defense Alert

The Brazilian episode was the month’s most significant incident, both in scope and symbolism. MIDR reported an intrusion into the Public Alert Disclosure Interface of the Defesa Civil Alerta system and detailed 10 unauthorized triggers between 11:41 p.m. on June 19 and 1:23 a.m. on June 20. Official and media coverage agree it was an unauthorized send, classified as an "extreme alert," with messages reaching millions of people on mobile phones across several cities and states.

The institutional response was swift. MIDR said no evidence of structural damage was found in the DCA system, but it blocked all external access to IDAP, suspended the accounts involved, and preserved logs for the Federal Police. Reuters added that the investigation was referred to the federal authority and that the government was working to restore the system. At the same time, public debate intensified because the alerts reached the population in the middle of the night, with the characteristic phone sound and a message that, according to coverage, contained only the word "misantropia."

The significance for the public sector is twofold. First, it shows that a centralized state notification platform can be turned into a vector for operational disinformation, even without technical destruction of the system. Second, it exposes how hard it is to maintain public trust when an official channel emits invalid messages during emergency situations. This was not just an IT incident, but a public communications governance problem. In this case, system security and message credibility became tightly linked.

UFJF’s later coverage underscored that the case revealed a real vulnerability in Brazil’s alert architecture and argued for redundancy through Cell Broadcast, SMS, radio, TV, official apps, sirens and community protocols. That observation carries editorial weight because it connects the incident to institutional resilience, not to an isolated technical failure. The operational lesson is clear, if a single notification channel is compromised or manipulated, the state may be left unable to distinguish a legitimate alert from malicious noise.

Argentina, RENAPER and the network attributed to @Gov.eth

Argentina drew several references in June to state databases and their monetization. On June 3, El Estratégico reported a new RENAPER data leak based on commercial activity offering public access to an API with data on Argentine citizens. Although the text uses cautious wording, the value of this piece is that it once again places the population registry among assets of high interest to criminal markets. On June 1, the same editorial line also mentioned the dismantling of a network that was trading RENAPER and PAMI personal data through Telegram, with the investigation said to have begun in October 2025 according to the report.

LV16’s June 24 coverage added another layer. In the context of a major international operation, the Argentine Federal Police identified and located in Spain the alleged cybercriminal known as @Gov.eth, tied to operations between 2024 and 2026 that affected public agencies and private companies. The report lists RENAPER and DNRPA as primary targets, with personal databases leaked and sold, in addition to attacks on national media. That case, by its journalistic attribution alone and its intersection with an international police action, points to a stolen-data economy that does not depend on a single event, but on the sustained exploitation of agencies holding sensitive information.

The critical issue is not only the leak itself, but its transformation into a market. The cited reports show an ecosystem in which state data is published, resold, reused for fraud and turned into input for new attacks. In a civil registry, that affects identity, verification and potential access to other services. In exposure terms, RENAPER again stands out as a structurally attractive attack surface because it concentrates identity value, traceability and cross-use potential.

Bolivia, AISEM and Krybit

On June 12, Krybit listed aisem.gob.bo, the domain associated with Bolivia’s Agency for Health Infrastructure and Medical Equipment, as a victim on its public attack list. DeXpose reported that the group claimed to have attacked the agency and threatened to leak sensitive data if its terms were not met. Ransomware.live later updated the entry with estimates of 97 employees and 121 users compromised, and repeated that it is a Bolivian government health infrastructure entity.

This requires careful classification. The material supports saying there was a public attack claim and an extortion threat involving possible data publication, but it does not specify whether assets were encrypted. For that reason, the case should be read as extortion or ransomware with incomplete technical classification, not as a confirmed encryption incident. That distinction matters because operational risk and legal risk are not the same. A post on a leak site without evidence of encryption does not imply service disruption, although it may indicate exfiltration, reputational pressure and forced negotiation.

The sector relevance is high because AISEM belongs to health infrastructure, a subsegment that combines clinical sensitivity, dependence on continuity and limited crisis absorption capacity. The attack, or at least its public claim, places June within a pattern already familiar in the region, public health remains a valuable target for both extortion and data exposure.

Colombia, Registraduría and the FortiBleed ecosystem

Colombia recorded multiple fronts in June. Ahead of the presidential runoff, Mobile Time reported that ColCERT warned about a phishing campaign impersonating the National Civil Registry with at least three malicious emails sent between June 1 and 2. The messages were able to bypass SPF, DKIM and DMARC, and redirected victims to the download of compressed files with malicious scripts designed to steal information and credentials. That places institutional email and digital identity among the top attack surfaces during electoral processes.

To this was added ColCERT’s PMU Ciber Electoral No. 005 bulletin, which reported exposure of institutional credentials from the National Electoral Council and cases of alleged personal data exposure tied to the electoral ecosystem, notified to data controllers and to the Prosecutor’s Office and the Superintendence of Industry and Commerce. The document also clarified that, as of June 20, no incidents were recorded on electoral infrastructure associated with DoS or the WAF during the runoff. That signal matters because it separates political noise from technical evidence: there were concerns and findings, but no confirmed collapse of the election system as voting infrastructure.

At the same time, ColCERT issued alert AL-20260619-101 on FortiBleed, a global campaign of mass credential abuse that compromises the perimeter security of Fortinet FortiGate devices. The alert focused on the impact on Colombia’s public sector, while other technical coverage described the exposure of VPN credentials from roughly 73,000 devices worldwide. MuchoHacker.lol added that at least 27 Colombian organizations may have been exposed, including public and health entities, although the source makes clear that there is no official individual confirmation of each compromise. The technical vector is clear, remote access credentials and perimeter firewalls, with the potential for lateral movement and internal network compromise.

Bogotá, District Mobility Secretariat

On June 28, MuchoHacker.lol reported that a group of attackers claimed to have compromised the systems of Bogotá’s District Mobility Secretariat and obtained data on more than 4.5 million users, with the ability to modify, record and delete traffic tickets. The piece, however, carefully notes that these are the attackers’ claims and that there is no official confirmation or independent evidence of deleted or modified tickets.

The data sample analyzed by the site contained 238 JSON objects with four real violations and a detailed structure by record. That detail changes the reading, because this is no longer just a leak site claim, but a sample that appears to contain part of existing information. Even so, it does not allow confirmation of scope or breach origin. For the public sector, the operational issue is sensitive, urban mobility, traffic fines and transit procedures are transactional systems where trust in record integrity is as important as confidentiality.

Mexico, unauthorized access and leaks tied to public services

Although the report’s thematic focus is the public sector in Latin America, Mexico contributed cases that reinforce the pressure on state agencies. Diario El Independiente reported that, following unauthorized access to information from some committees in the La Escuela es Nuestra program, the Digital Transformation and Telecommunications Agency activated cybersecurity protocols, identified the irregular activity, contained it and launched permanent monitoring and new controls. The report does not detail the number of records affected or the exact scope of the information accessed, but it does confirm an institutional response.

In addition, TV Azteca aired a complaint about a purported mass leak in Mexico’s health system, with a database said to contain around 1.7 million electronic clinical records. The report does not provide a detailed official position from the Health Ministry on the scope, so it should be treated as an allegation rather than a verified breach. Moncloa.com, for its part, reported the leak of data from 45,000 Movistar Mexico users, adding pressure to the critical services ecosystem and the user identity environment.

These events do not change the report’s main focus, but they do show that June was not an isolated month for the region. In several countries, public entities and social programs were exposed on at least two levels, unauthorized access and data leakage.

Active threats and campaigns

Ransomware and extortion

The month logged 11 cases with ransomware or extortion as the main focus, and in all of them the available technical labeling did not allow a precise split between encryption, exfiltration, or a mere claim on a leak site. That does not weaken the signal, but it does require a cautious classification. The material does make clear that extortion remains a very active way to pressure public agencies and their affiliated offices, especially when the information has identity, health, or mobility value.

In Bolivia, Krybit published AISEM and threatened to leak sensitive data. In this case, the source does not specify whether encryption occurred. In Argentina, references to networks trading RENAPER and PAMI data over Telegram suggest criminal monetization of state information, even if the extortion logic is not always explicit. In Colombia, the claim that attackers would have erased fines in Bogotá fits more as an extortion narrative than as a technically verified incident. In Mexico, the discussion of leaks in health and unauthorized access to public programs shows how pressure on state bodies can come without encryption, but with threats of publication or misuse of data.

The operational takeaway for public-sector teams is that ransomware should no longer be assessed only as server encryption. The full cycle includes proof publication, reputational pressure, leak threats, and the use of stolen credentials. The incident may not stop a system, but it can weaken its legitimacy and force a negotiation. That was the most common form of damage in June, at least according to the available material.

Fraud and phishing

The clearest case was the campaign that impersonated Colombia's Registraduría Nacional. The use of emails that pass authentication filters and end up in scripts for credential theft points to a well-built operation, aimed at both initial access and identity capture. The electoral context makes it more effective, because recipients are more alert to urgent messages and validation requests.

Also worth mentioning is the ecosystem of fake sites and fraud tied to the 2026 World Cup in Mexico, although several of those cases were presented in the material as telemetry or context from another period, not as incidents in this report. The useful signal for the public sector is methodological: when a fraud campaign relies on institutional identity, the line between citizen deception and access to state systems becomes blurred. The same pattern can be seen in RENAPER, in health systems, and in social programs.

The common mechanism is the exploitation of trust. The impersonation email, the fake domain, the compressed file with scripts, the page that imitates a government process or alert. June showed that fraud is no longer only a financial problem. In the public sector, it is used to open doors, steal credentials, and capture data that later feeds leaks or extortion.

APT, hacktivism and political pressure

In this area there is less technical certainty, but a lot of political noise. Argentine coverage of @Gov.eth describes a criminal actor or alias active between 2024 and 2026 against public agencies and private companies. This is not a state APT, but a cybercriminal focused on government data and media. Bolivia's reference to a

Critical Vulnerabilities

No critical CVEs were recorded in the June 2026 material reviewed. That does not mean critical vulnerabilities were absent or not exploited in the region, only that this monthly file did not document them in a verifiable way.

CVE Software Exploitation Source
Not recorded in the material reviewed Not applicable Not applicable No critical CVEs were mentioned in the sources for the period

Regulation and Compliance

The period saw three relevant regulatory or compliance moves, although none of them amounts to a sweeping reform on its own. The first was Brazil's own institutional response, with MIDR, Civil Defense, Anatel and the Federal Police stepping into the investigation of the incident and the restoration of the system. That sequence matters because it shows interagency coordination in response to an event involving critical public infrastructure.

The second case is Colombia. ColCERT did not just issue alerts, it also notified data controllers, the Attorney General's Office and the Superintendency of Industry and Commerce in connection with cases of alleged exposure of personal data in the electoral ecosystem. That traceability matters for compliance because it suggests cybersecurity incidents are no longer handled only as technical issues, but also as matters of data protection, due process and administrative oversight.

The third move appeared in Mexico, where the Digital Transformation and Telecommunications Agency activated cybersecurity protocols after unauthorized access to data from some committees of La Escuela es Nuestra. Although the material does not detail sanctions or regulatory changes, it does point to an institutional response built around containment, continuous monitoring and new controls. For government teams, that means regulatory maturity is no longer measured only by whether a rule exists, but by the ability to activate a response, preserve evidence and escalate to the relevant authorities.

Countries and most affected subsectors

Brazil

Brazil was the country hit by the month’s largest incident. The impact on Defesa Civil Alerta affected millions of users and exposed a resilience problem in the official emergency notification platform. The damage was both operational and reputational. Post-incident academic coverage also stressed that the event revealed a real vulnerability in the alert architecture. In the public sector, the takeaway is uncomfortable but clear, a system that informs the public about risk can also be exploited to spread confusion at massive scale.

Argentina

Argentina saw the most pressure on identity registries, personal databases and criminal monetization networks. RENAPER remains a recurring target, and DNRPA is also included in the attribution to @Gov.eth. The hardest-hit subsector is citizen identity and vehicle registration, two areas with high resale value and wide potential for fraud. The reference to PAMI adds the health and benefits angle, expanding the potential impact on older adults and social program beneficiaries.

Colombia

Colombia showed a combination of electoral risk, credential exposure and perimeter attack surface. The Registraduría and the CNE stand out as critical nodes because of their link to democratic processes. FortiBleed opened another layer of exposure across public and health sectors through VPN credentials that were compromised or potentially reusable. The Secretaría Distrital de Movilidad, meanwhile, represents a subsector of urban administration where database integrity has direct operational value.

Bolivia

In Bolivia, the focus was the health infrastructure agency. AISEM is not just an administrative body, it is an actor that supports healthcare equipment and infrastructure. For that reason, an attack claim or a leak threat involving that entity carries broader implications than a simple data leak. The public health subsector again appears as one of the region’s most sensitive.

Mexico

Mexico added evidence of unauthorized access in a social program and breach claims in health. The social policy subsector, through La Escuela es Nuestra, and the public health subsector, through the allegation involving AAMATES, show that pressure on the state is not limited to central agencies. The same pattern of leakage also appears in consumer services such as Movistar, which, while outside the public vertical, helps illustrate the broader exposure environment for credentials and data.

There is no month-over-month baseline because this is the first archived period with this indicator format for Latin America. Even so, the material points to signals likely to continue in July.

The first is the consolidation of remote access surfaces as a top target. FortiBleed and references to VPNs in Argentina point to credentials and perimeter systems as high-value areas. Criminal actors do not always need a new exploit if they can reuse valid secrets or exposed credentials. That access economy remains the most profitable way to attack public agencies.

The second signal is the persistence of targeted phishing against institutional identity. The case involving Colombia’s Registraduría shows that email remains enough to compromise users or collect credentials, even in environments with stronger authentication. If the message looks official and urgent, the success rate rises. In election periods or public service campaigns, that urgency is a force multiplier.

The third signal is the expansion of attacks on public communication systems. Brazil offers a very clear warning, official alert channels should be treated as highly sensitive critical infrastructure. Securing the backend is not enough. The full issuance chain, permissions, remote access, and channel redundancy all need validation.

The fourth signal is the continuing monetization of identity data. Argentina again appears as a market for personal databases and records with high criminal value. RENAPER, DNRPA and PAMI are surfaces that may continue to appear in leaks, resale, or downstream fraud campaigns.

Signal themes in JuneIllustrative count based on the period’s indicators, excluding aggregated telemetry.IncidentsPhishingRansomwareRegulation5616113
Signal by threat type — Qualitative distribution of the main themes observed in this month’s material.

Security team recommendations

  1. Immediately review and restrict remote access surfaces, especially VPNs, perimeter firewalls, and administrative consoles exposed to the internet. FortiBleed and related perimeter cases show that valid credentials remain attackers' main shortcut.

  2. Strengthen validation of institutional emails and awareness campaigns during election periods, social benefits periods, or emergencies. Phishing that impersonates the Registraduría shows that SPF, DKIM, and DMARC are not enough on their own when the end user trusts the message narrative.

  3. Clearly separate operational continuity from the public communications channel. Platforms such as Defensa Civil Alerta need authentication, privilege controls, integrity monitoring, and multichannel contingency plans. Redundancy must be functional, not decorative.

  4. Improve response to identity leaks with playbooks that include revocation, credential rotation, fraud alerts, and coordination with legal and citizen service teams. When the data is personal, the crisis often extends beyond infrastructure.

  5. Record evidence and preserve traceability from minute one. In June, several cases were only partially categorized because the sources offered only claims or partial samples. Public sector teams need logs, chain of custody, and clear documentation to support or refute attribution.

  6. Add resilience testing tailored to high-impact social systems, such as emergency alerts, identity registries, transit, health, and social programs. It is not enough to simulate a server outage. Teams must test channel diversion, unauthorized access, false publishing, and integrity degradation.

  7. Coordinate with data protection and regulatory teams from the start. In several incidents this month, the technical response and notification to oversight authorities were central to the handling. In the Latin American public sector, incident management no longer ends in the SOC.

Material limits

This report was built exclusively from the material provided for June 2026 and the attached comparative framework. The indicator window includes 133 dated facts from June 2026, 3 facts from earlier months used only for comparison, and 1 undated fact, which was excluded from the indicators. No external sources or internet material were used.

An indicator at 0, especially the one for critical CVEs, means no critical CVEs were recorded in the material analyzed, not that no critical vulnerabilities were exploited in the region. The same applies to other absences: what does not appear in the file should not be read as a lack of activity, but as a lack of verifiable documentation for this period.

The ransomware and extortion taxonomy is also constrained by the evidence itself. In 11 cases, the source does not allow a determination of whether there was asset encryption, exfiltration without encryption, or only a mention of the victim on a leak site. For that reason, this report preserves that ambiguity and does not force an artificial classification.

Aggregated telemetry figures, automated attempts or blocks, and weekly vendor metrics were also excluded from the indicators. If any of those figures are mentioned in the analysis, they are used only as methodologically bounded context, never as an incident with confirmed impact.

Consumer social media and any material not included in the list of allowed sources were also left out. When notes appeared with weak claims, unconfirmed attributions, or content based exclusively on attackers' statements, they were treated as such and not as settled facts.

The result is an accurate view of the available file, but not an exhaustive one of all regional activity. June left very clear signals about the public sector, although several pieces remain open or only partially confirmed.

Sources