Telecom and ISP Threats in LATAM, Aug 2026
August 2026 brought attacks, outages, and regulatory pressure to LATAM telecom and ISPs, led by Brazil, Chile
Key findings
- August 2026 showed high risk for telecom and ISPs in LATAM due to the coexistence of ransomware, espionage, physical cuts, and connectivity failures.
- Chile was the main cyberespionage front of the month, with an investigation involving Entel, Movistar, and Telmex and possible ShadowPad use.
- Colombia saw the most visible operational impact, with ransomware at the Ministry of Justice, a BGP disruption, Movistar failures, and regulatory risk for small ISPs.
- Brazil produced multiple ransomware claims and the highest telecom attack volume in media-cited telemetry, but that telemetry did not translate into incidents.
- Mexico showed availability fragility, with the gob.mx outage, massive internet failures, and physical cuts affecting users of different providers.
- The rise in unclassified events versus the previous month indicates more public activity, but also more uncertainty about the real scope of several cases.
- No critical CVEs were recorded in the analyzed material, so the month’s technical focus was on campaigns and disruptions, not exploitation of identified CVE flaws.
Monthly reference modules
These modules are completed automatically from the verified dated facts within the period. Each one states its basis and counting criterion so the figures reconcile across modules. They serve as the recurring month-by-month reading, while the later analysis expands on the cases without repeating this summary.
Indicator window: 123 dated facts in August 2026 · 5 from prior months (comparative frame, not monthly volume). Facts from prior months are used only as a comparative frame in the analysis, never as volume for this period.
Executive monthly summary
August 2026 sent a strong but uneven signal for telecommunications and connectivity providers in Latin America. The month combined espionage and ransomware campaigns, large-scale connectivity outages, routing disruptions, and new regulatory pressure. The dominant picture was one of high risk, not because of a single event type, but because verified incidents clustered in Brazil, Chile, Colombia, and Mexico, with effects ranging from leak site claims to visible outages for users and public services.
The most sensitive part of the month was in Chile, where the PDI and the Fiscalía investigated possible cyberattacks by Lilac Typhoon against Entel, Movistar, and Telmex. Local and international coverage converged on one point: the focus appears to have been persistent access and network reconnaissance, with possible use of ShadowPad, and as of the date of the material there was no confirmed data breach or verifiable list of stolen records. That distinction matters, because it places the case closer to cyberespionage than to immediate operational disruption.
Brazil produced two different signals. On one hand, the telecom sector again appeared with a high volume of cyberattacks in Check Point telemetry cited by local media, although that figure belongs to the measurement layer and not to incidents with confirmed impact. On the other hand, ransomware claims surfaced against Grupo Rái and Intranet Gov Brasil, both tied to different groups and with different levels of confirmation. In neither case was there enough public evidence to establish the true scope, leaving a significant share of the month in incomplete classification.
Colombia concentrated the most visible operational activity. The Ministry of Justice confirmed a ransomware attack that degraded digital public services and forced containment protocols to be activated, while ColCERT kept the ransomware risk level high. At the same time, there was a two-hour disruption in the BGP control plane, a major Movistar outage caused by fiber damage, and a regulatory warning about a possible service cutoff affecting tens of thousands of fixed internet users in the dispute between TV Azteca and ATP. The country showed a mix of cyberincident, physical infrastructure fragility, and contractual tension over the last mile.
Mexico closed the month with another availability pattern: outages on gob.mx, widespread internet failures reported by users of several companies, and a case attributed to Telmex involving cable theft in Ecatepec that affected thousands of users according to the local source. There was no consistent attribution to cyberattack in those events, but they did expose how dependent digital services are on connectivity and the physical operation of the network. Taken together, August showed that in telecommunications, risk does not come only from intrusion, it also comes from espionage campaigns, extortion, edge failures, fiber cuts, and disputes that can turn into real outages.
Regional overview of the month
August's regional picture was one of elevated risk for the vertical, with confirmed incidents that had impact, ransomware and espionage campaigns, and several outages whose cause was never publicly attributed. This was not a region dominated by a single vector. The month exposed a broader attack surface, with operators, ministries, retail internet providers, government portals, and the network control plane all under pressure at once.
The dominant signal was the mix of persistence and ambiguity. Persistence, because the cases were not isolated or limited to one country. Ambiguity, because much of the material remained incompletely classified, whether because of a lack of corporate confirmation, claims limited to leak sites, or connectivity events where the technical cause was not publicly closed out. That combination complicates operational response, since security teams have to work with hypotheses of espionage, extortion, and physical availability without being able to fully separate each layer.
In terms of severity, the main weight was not in the raw number of headlines but in the quality of the impact. A ransomware attack that degrades public services, an espionage alert involving carriers, a BGP disruption, and a possible loss of connectivity for tens of thousands of users are different in nature, but they all strike the same point, trust in service continuity. For telecoms and ISPs, that continuity is part of the product, not an accessory feature.
The country-by-country differences were also clear. Chile moved into criminal investigation and cyberespionage territory. Brazil combined high-profile attacks on the sector with ransomware claims involving communications actors. Colombia showed the highest density of events with public impact on digital services and connectivity. Mexico, by contrast, exposed the fragility of access infrastructure, with platform outages and failures reported by users of several operators. Taken as a whole, the region did not show a single closed regional campaign, but several overlapping fronts.
Period indicators
The table below reproduces exactly the indicators provided for August 2026, along with their base and time window. Read it as verified facts from the period, not as aggregated telemetry or activity from prior months used only for comparison.
| Indicator | August 2026 | Previous month | Change |
|---|---|---|---|
| Verified facts from the period, base for all indicators | 122 | 67 | +55 |
| Time window for the indicators | 123 facts dated in August 2026, 5 from previous months (comparative frame, not monthly volume) | ||
| Unclassified incidents, breaches, or disruptions | 45 | 17 | +28 |
| Cases with ransomware or extortion as the primary focus | 17 | 15 | +2 |
| Ransomware breakdown, confirmed asset encryption | 1 | ||
| Ransomware breakdown, exfiltration without encryption, simple extortion | 1 | ||
| Ransomware breakdown, leak site mention only | 4 | ||
| Ransomware breakdown, classification could not be determined from the material | 11 | ||
| Documented fraud or phishing cases | 1 | 2 | -1 |
| Documented regulatory developments | 5 | 0 | +5 |
| Critical CVEs mentioned | 0, none in the material analyzed, which does not imply absence in the region | ||
| Sectors with at least one documented event | 7 | 5 | +2 |
| Predominant threat of the month | Unclassified, 47 of 122 facts | Unclassified, 20 of 67 facts | |
| Facts with direct source confirmation | 80% | ||
| Aggregated telemetry figures excluded from the volume | 1, aggregated attempts or blocks, not incidents with confirmed impact |
Relevant incidents
Most of the month’s analytical value comes from the cases that did have operational impact, partial confirmation, or regulatory consequences. In August, there was no single pattern, but rather a mix of espionage, ransomware, connectivity outages, and service disputes affecting carriers, ISPs, and access-related platforms.
Chile, investigation into Lilac Typhoon against Entel, Movistar, and Telmex
Chile was home to one of the month’s most sensitive signals, because the event was not a simple service outage but an investigation into possible cyberespionage against the country’s main telecommunications companies. The Metropolitan North Central Prosecutor’s Office and the PDI were working from a U.S. intelligence alert linking the activity to Lilac Typhoon, also identified as DEV-0234 by one source, and to possible use of ShadowPad.
Coverage agreed that the investigation is aimed at determining whether there was access to information, not a breach that has already been confirmed. The Rio Times, BioBioChile, 24Horas, Cooperativa, T13, Emol, RevistaSeguridad.cl, and Security-Chu described a scenario involving network reconnaissance, metadata extraction, and persistence, with an emphasis on espionage rather than immediate disruption. That distinction changes the risk reading, because the operational objective would be preparatory, quiet, and long term.
There was also a relevant timeline. Radio Cooperativa reported that suspicious activity may have been present since September 2024 in infrastructure associated with Movistar and since April 2025 in equipment linked to Entel and Telmex. The same material says compromised devices were used as an obfuscation layer, a detail that fits a distributed operation model that is hard to attribute. Although the exact date and scope remain under investigation, the case puts carriers at the center of a discussion about network security, endpoint visibility, and lateral traffic monitoring.
From an operational standpoint, the Chilean case leaves two lessons. The first is that telecommunications companies can be direct espionage targets because of the value of their metadata, internal routes, and potential access to communications. The second is that the absence of a confirmed breach does not remove the risk, because the actor may have remained inside the network for months without triggering a visible event. That requires reviewing historical telemetry, segmentation, remote access, and the cleanup of administration tools.
Brazil, Grupo Rái and LockBit 5.0’s leak site
The Grupo Rái case was one of the main ransomware mentions in Brazil’s telecom and communications ecosystem. Dexpose.io and GalaxyWarden said LockBit 5.0 claimed to have attacked the company and that the domain rai.com.br was listed on its leak site in early August. Darkfield/Orizon One recorded it as a data breach, but the available material does not clarify the volume or type of information exposed.
Here it is worth separating the taxonomy carefully. The sources support the existence of a leak site claim and, in one of them, a signal of data publication. They do not allow us to say with the same confidence whether the actor encrypted assets, only exfiltrated information, or whether the impact was limited to the public mention of the case. That is why the event’s classification in the report depends on caution, not on additional inference.
The significance for the sector is not only the specific victim but also the type of actor involved. LockBit 5.0 continues its classic double-extortion logic, with publication threats, demands for contact, and public exposure of domains. For a communications conglomerate, reputational damage can be as sensitive as loss of availability, because it affects business relationships, corporate customer trust, and possible regulatory scrutiny. The fact that the company had not publicly acknowledged the incident at the time of coverage keeps the case in unconfirmed territory, but that does not make it irrelevant.
Brazil, Intranet Gov Brasil and The Gentlemen’s claim
The other relevant Brazilian case was Intranet Gov Brasil, linked to the intranet.gov.br domain and claimed by The Gentlemen. BreachSense recorded it as a claimed victim, Ransomware.live listed it with an estimated attack date, and GalaxyWarden said the domain was added to a leak site as a supposed compromise of the internal network and the digital portal used by the federal government. However, none of the sources provided evidence of a confirmed leak.
The difference from the Grupo Rái case is that here the affected target is closer to government digital infrastructure than to a purely private communications company. Even so, for this report the value lies in the actor’s behavior and in the kind of exposure a digital services platform can face when it serves as an access portal for citizens and businesses. The material also makes clear that Serpro and Dataprev had not issued an incident notice at the time of coverage.
This kind of claim has an additional problem, the asymmetry between exposure and verification. A leak site can create the perception of compromise without there yet being enough public evidence of access, encryption, or exfiltration. For telecom and ISP teams, that matters because the actor’s pressure can spill over to associated providers, integrators, or digital identity platforms connected to exposed services.
Colombia, ransomware against the Ministry of Justice and degradation of public services
Colombia had the month’s clearest ransomware case with confirmed impact in August. On August 2, the Ministry of Justice acknowledged that it had been the victim of a ransomware attack that affected part of its technological infrastructure and degraded several digital services. The agency itself said it activated containment protocols, isolated compromised systems, and coordinated the response with MinTIC and COLCERT.
The importance of this case for telecom and connectivity is not direct in operator terms, but it is in terms of the state digital ecosystem’s dependence on access networks and services. The incident affected services linked to drug enforcement and judicial processes, that is, sensitive functions that depend on connected and available infrastructure. White Hunters also indicated that some files were encrypted, but that no evidence of information theft had been found at the time of the acting minister’s statement.
Kaseya and other breach summaries placed the attack in a time window very close to the ColCERT alert, which reiterated that ransomware risk in Colombia remained high. That context does not prove causality, but it does show continuity between technical warnings and the incident materializing. In sectors such as telecom or ISP, the lesson is that the days leading up to a transition or sensitive institutional event tend to concentrate greater operational and reputational pressure.
Colombia, BGP disruption and physical damage at Movistar
August also brought a BGP control-plane disruption in Colombia lasting about two hours. Telecom Observer reported a measurable drop in the median prefix count, with a maximum severity calculated at 770 and no significant concurrent degradation in IPv4 reach or traffic. The cause was not publicly attributed, so the event remains a network disruption without a closed official explanation.
At the same time, Movistar explained a major outage in its fixed and mobile services due to damage to fiber infrastructure in different parts of the country. Infobae Colombia, El Tiempo, and other outlets reported intermittent internet, television, and mobile phone service in several cities, and that technical teams were working in the field to restore operations. The Ministry of ICT later said network recovery was above 85% in most networks, but without a breakdown by operator or territory.
The analytical value of both events together lies in the coexistence of layers. One shows a routing or control-plane failure with no attributed cause. The other shows a physical fiber problem with public impact. For a vertical CISO, the combination requires looking at redundancy, route diversity, BGP monitoring, NOC-SOC correlation, and the ability to distinguish between a cyber incident and infrastructure degradation. The boundary between the two may seem obvious in the operations room, but to the end user both end up looking like a service outage.
Colombia, risk for small ISPs over the TV Azteca and ATP dispute
Colombia’s CRC warned that a contractual dispute between TV Azteca and ATP could leave about 57,000 fixed internet users in 261 municipalities without service. The available information clarifies that there was no confirmation of an actual outage at the time of the warning, but it did identify 245 small ISPs involved and 419 potentially affected sites. It also noted that the ecosystem was rural and small-scale.
Although this was not a confirmed cyberattack, the case belongs in the sector because it shows how a commercial dispute between intermediaries can translate into operational risk for the last mile. In markets with highly fragmented ISPs, a contractual or technical dependency on a wholesaler can create a massive failure surface without any intrusion. For continuity teams, this counts as critical connectivity risk and third-party dependency.
The CRC warning is useful because it adds a regulatory layer to resilience. It is not enough for the core network to be secure or for the SOC to have monitoring. If hundreds of small providers depend on a few contracts for access, the potential interruption becomes systemic. In August, that risk was documented with concrete numbers and with a prudent regulatory clarification, the lack of confirmation of an actual cut.
Mexico, gob.mx outage and massive internet failures
Mexico contributed several availability incidents, all relevant to telecom and ISP operations even if not all were confirmed cyberattacks. On August 19, gob.mx went offline for about two hours, and the ATDT said it was a connectivity cut, with an initial recovery estimate of about 25 minutes. Infobae México, N+, Diario de México, and Ejé Central agreed that the authority framed the event as an infrastructure failure, not a confirmed security incident.
That same day, users from different companies reported a massive internet failure affecting Totalplay, Izzi, and Telmex, among others. Coverage from N+ and La Crónica made clear that these were user reports and that there was no consistent official position from the companies on the causes. The number of affected providers suggests a problem that may be in upstream, backbone, or network coordination, but the material does not allow a more precise attribution.
The Izzi case, cited by La Crónica based on Downdetector, added another layer of instability perception. And El Independiente’s report on a cable theft in Ecatepec, which left more than thirty thousand users without service according to the source, shows that in Mexico connectivity continuity can break down because of both technical causes and physical infrastructure damage. For a reader in the sector, the message is direct, the risk surface includes commercial, technical, and physical security layers.
Active Threats and Campaigns
The month’s picture shows three major threat families, ransomware and extortion, espionage, and availability disruption. In Latin American telecom and ISP environments, none appeared in pure form. The campaigns were mixed with leak site claims, ongoing investigations, and connectivity failures with no closed attribution.
Ransomware and Extortion
The month closed with 17 cases where ransomware or extortion was the primary focus, but the internal taxonomy is fragmented and distinct impacts should not be merged. There was one case with confirmed encryption, Colombia’s Ministry of Justice. There was another with exfiltration without encryption, also in Colombia, where the official statement said no evidence of theft had been found at the time of the information cutoff, although an independent monitoring source acknowledged file encryption. And there were several leak site claims, where the verifiable impact did not go beyond the public mention of the victim.
That last category includes Grupo Rái and Intranet Gov Brasil, plus another eleven cases whose classification could not be determined from the available material. For security practice, that means extortion risk remains high, but the most useful data point is not the broad label, it is the level of evidence for encryption, leakage, or simple publication. A leak site does not automatically mean unavailability, and unavailability alone does not prove exfiltration.
The main operational signal is that ransomware remained a cross-cutting threat, but with very uneven impacts. In telecom and connectivity, that requires differentiated response plans. If there is encryption, the priority is recovery and forensic preservation. If there is exfiltration, the priority is legal containment, notification, and monitoring for later abuse. If there is only a leak site mention, the priority is validation, persistence hunting, and preventing reputational escalation.
Fraud and Phishing
The month’s material recorded just one documented case of fraud or phishing, and it does not belong to the core telecom and ISP vertical, but to the broader regional environment. That low presence should not be read as a lack of fraud pressure on operators. It more likely suggests that, in August, the public narrative was dominated by intrusion, extortion, and availability, not impersonation campaigns.
From an operational standpoint, that does not reduce the risk around identity abuse, SIM swap, or support fraud. It simply shows that the material analyzed did not present enough volume to turn it into a central trend in the report. As a priority signal, telecom teams should keep protecting support channels, credential reset flows, user portals, and authentication workflows, even if the period’s evidence was concentrated elsewhere.
APT and Cyberespionage
The most sensitive APT front was in Chile. The association of Lilac Typhoon with cyberespionage activity in Entel, Movistar, and Telmex networks, along with the reference to ShadowPad and the need for forensic analysis and remote access hardening, points to a campaign closer to persistence than to a visible strike. The sources do not confirm mass exfiltration, but they do describe a pattern consistent with espionage infrastructure.
The strategic relevance of that signal is high because a carrier concentrates metadata, routing information, technical inventory, and potential visibility into third-party services. If an actor manages to move inside that environment, the value of the access goes far beyond file theft. It can enable communications tracking, pivoting to providers, observation of remote administration, and preparation for future actions. For that reason, the Chile case should be read through both network resilience and national security lenses.
Critical vulnerabilities
No critical CVEs were recorded in the August 2026 material reviewed. That does not mean the region was free of critical vulnerabilities, only that the coverage reviewed did not provide explicit CVE identifiers for this period. As a result, the month’s technical focus was more on campaigns, disruptions, and claims than on documented exploitation of specific flaws by number.
| CVE | Software | Exploitation | Source |
|---|---|---|---|
| No critical CVEs were recorded in the material reviewed | N/A | N/A | Period material |
Regulation and Compliance
August brought five documented regulatory moves, and all of them point in one way or another to pressure on continuity, investigations, or interagency coordination. They do not form a single regulatory agenda, but they do show telecom, connectivity, and digital services moving closer to the state response.
In Colombia, the CRC framed the interruption risk for 57,000 fixed internet users tied to small ISPs in a contractual dispute between TV Azteca and ATP. The regulatory issue here is not a sanction or a formal cybersecurity proceeding, but an institutional acknowledgment that a commercial dependency can turn a retail access network into a mass service problem. That puts supplier concentration and contractual resilience under scrutiny.
Also in Colombia, the Attorney General's Office stepped in over electric infrastructure security in Tolima after an attack, although without attributing it to cyberattacks. The case is not telecom in the strict sense, but it matters for the sector because connectivity services depend on power, backbone networks, and the physical environment. When the state adds this kind of alert to its radar, the message for carriers and ISPs is that resilience no longer stops at the logical perimeter.
The third regulatory front was the institutional response to the ransomware attack on Colombia's Ministry of Justice. Coordination with COLCERT, MinTIC, Microsoft’s DART team, and IDB partners showed a broader response model than that of a stand-alone unit. For connectivity operators and security teams, that suggests rising expectations for cooperation among the public sector, response teams, and technology vendors in high-impact incidents.
Countries and most affected subsegments
The geographic distribution in August was uneven. Some countries saw multiple events of different kinds, while others had one or two tightly concentrated incidents. Overall, Colombia, Chile, Brazil and Mexico stood out as the most visible nodes in the month’s telecom and connectivity provider signal.
Colombia
Colombia had the highest visible operational density in the month. The ransomware attack on the Ministry of Justice, the high alert from ColCERT, the BGP disruption, the major Movistar outage, and the CRC warning about interruption risk for small ISPs all converged there. That accumulation shows that the country not only suffered incidents, but also saw broad regulatory and media attention on continuity and resilience.
The most exposed subsegment was retail connectivity and public digital services dependent on network infrastructure. No single campaign against telecom was observed, but there were multiple signs of fragility at different layers. For an operator or internet provider, that suggests readiness should include links, fiber, BGP, ransomware response in support systems, and management of contractual dependence on wholesalers.
Chile
Chile was the center of the telecommunications espionage front. The Entel, Movistar and Telmex case, with a judicial investigation and technical references to ShadowPad, made it one of the month’s most sensitive stories. The country’s relevance in the report is not tied to a service outage, but to the potential depth of access and the institutional impact of the alert.
The most affected subsegment was large phone and internet carriers. The sources did not confirm a data breach, but they made clear that the actor’s interest may have been in the network and its persistence mechanisms. For Chile, August showed that the telecom attack surface can become a target for foreign intelligence and that reputational damage begins before any public leak.
Brazil
Brazil combined two types of signal. One was an attack or claim involving Grupo Rái, a company linked to the communications sector. The other was the highest volume of cyberattacks against the telecommunications sector in the telemetry cited by local media, with 2,927 attacks in the period analyzed by Check Point, a figure that should be read as telemetry, not confirmed incidents.
The subsegment here is twofold, communications companies and cybersecurity services for corporate customers offered by operators. Vivo’s launch of the new Agêntico SOC for corporate clients is not an incident, but it does show how carriers are expanding into managed defense services. That commercial move reflects real market demand, but it should not be confused with a monthly risk measure.
Mexico
Mexico was dominated by availability incidents. The outages affecting gob.mx, the failures at multiple ISPs and the Telmex case involving cable theft point to an ecosystem where last-mile connectivity and physical infrastructure remain weak points. The material did not contain a confirmed cyberattack against a Mexican carrier with the same relevance as the Chilean or Colombian cases.
The most visible subsegment was end users and online public services dependent on third-party connectivity. That leaves a useful signal for the sector, operational resilience for portals and digital services should be designed with the assumption that the network layer can also fail for reasons outside the system itself. For telecom companies and ISPs, that means reviewing redundancy, link monitoring and commercial response times.
Trends and signals to watch
The comparison with the previous month shows a sharp jump in verified incidents, from 67 to 122. Unclassified incidents also rose sharply, from 17 to 45. That suggests August saw more activity, but also more noise or more material that sources have not yet closed out. That combination deserves attention, because more incidents do not always mean more clarity. Sometimes they mean more exposure without a final attribution.
The increase in ransomware or extortion cases, from 15 to 17, is not explosive in absolute terms. It does, however, reinforce the persistence of that threat as one of the main risks for the vertical. What changed is the variety of how it appeared. In August there was confirmed encryption, unresolved exfiltration, and several mentions on leak sites. That fragmentation makes tactical reading harder, but it reflects more accurately how extortion campaigns operate today.
The regulatory movement, which went from 0 to 5, is perhaps the most underestimated signal of the month. When regulators, ministries, and oversight bodies begin to intervene on continuity, outage risk, or response coordination, the effect on telecoms and ISPs goes beyond the individual incident. Expectations rise for traceability, notification, and technical support before the public.
It is also worth looking at the gap between the dominant threat and total volume. In July, the picture was already unclassified, but on a smaller base. In August, unclassified reached 47 of 122 incidents. That suggests that journalists and monitoring sources are still tracking many events where the impact is clear but the classification is not yet closed. For security teams, the practical signal is straightforward, do not wait for the perfect label to begin containment, investigation, and documentation.
Security recommendations for telecom and ISP teams
Telecom and ISP teams in Latin America should treat August as a stress test, not as an isolated anomaly. The mix of espionage, ransomware, physical disruption and contractual risk means security has to be layered, not limited to detection tools.
First, review remote access and persistence in network environments. The Chile case points to espionage infrastructure with possible ShadowPad use and long-term presence. That requires an inventory of remotely managed systems, a review of edge configurations, credential rotation, MFA validation where applicable, and auditing of lateral movement across corporate and operational networks.
Second, clearly separate operational continuity from forensic classification. When connectivity drops, as in Mexico or in Movistar's outage in Colombia, the team must quickly determine whether the event is physical, backbone-related, routing-related, or a cybersecurity incident. That distinction is not cosmetic, it affects internal escalation, customer communications, and any eventual notification obligation.
Third, harden ransomware response with different playbooks depending on impact. If encryption is involved, the priority is controlled restoration and evidence preservation. If there is a leak-site claim, as in the Brazilian cases, the priority is validation, log review, and monitoring for possible later postings. If there is only extortion with no confirmed encryption, legal and reputational pressure may be the first line of damage.
Fourth, map dependencies on third parties and wholesalers. The CRC Colombia warning about 245 small ISPs potentially affected by a contractual dispute shows that concentration risk does not always come from a malicious actor. Before the problem escalates into a visible outage, it is worth reviewing SLAs, capacity dependencies, backup routes, and communication channels with upstream providers.
Fifth, add monitoring for critical physical infrastructure. Cable theft in Mexico and fiber damage in Colombia are reminders that security in this sector includes physical spans, splices, cable runs and power. For large and small operators alike, that means stronger field monitoring, asset inventory, contractor coordination, and rapid response to last-mile cuts.
Frequently Asked Questions
What type of threat dominated the month across telecom, ISPs, and linked digital services?
The strongest signal was mixed, with ransomware, espionage, and connectivity disruptions all unfolding in the region. Colombia accounted for the confirmed ransomware cases and several continuity incidents, Chile concentrated the cyberespionage front targeting carriers, and Mexico contributed service outages and connectivity failures. The Relevant Incidents section orders those cases by country.
Was there solid evidence of a confirmed mass breach in Chilean carriers?
There was no confirmed mass breach in the material reviewed. The sources on Entel, Movistar and Telmex refer to an investigation into possible cyberespionage, with suspicion of ShadowPad and prolonged access, but no verified list of stolen data and no official confirmation of exfiltration. The Relevant Incidents and Active Threats and Campaigns sections spell out that distinction.
Which ransomware cases had truly verifiable impact?
The strongest case was Colombia's Ministry of Justice, where the agency itself confirmed encryption of part of its infrastructure and degraded services. In Brazil, there were ransomware claims involving Grupo Rái and Intranet Gov Brasil, but the material did not allow the real scope to be closed. The Active Threats and Campaigns section distinguishes encryption, exfiltration, and a leak site.
What should worry a small ISP in the region most after this month?
Third-party dependence and last-mile fragility. The warning from Colombia's CRC showed that a contractual dispute can put tens of thousands of small-provider users at risk, without any cyberattack. On top of that came physical fiber cuts, as in Colombia and Mexico. The Countries and Most Affected Subsegments section cross-references both angles.
Were any critical CVEs exploited in August 2026 for this vertical?
No. The material reviewed did not mention critical CVEs for telecommunications or connectivity providers in August 2026. That does not mean no vulnerabilities were exploited in the region, only that none appeared with a CVE identifier in the sources reviewed. The Critical Vulnerabilities section makes that point explicit.
Material limitations
This report was prepared exclusively from the material provided for August 2026 and from five facts from earlier months used only as comparative context, never as part of the period volume. The time window for the indicators is the one stated at the start, and the basis for all indicators is 122 verified facts from the period.
A 0 indicator, especially for critical CVEs, means it did not appear in the analyzed material, not that there were no critical vulnerabilities in the region. The same applies to any missing mention, the absence of data should not be read as the absence of a fact. In a month with so much incomplete classification, that caution is necessary to avoid overstating the risk.
Promotional sources, commercial press releases, consumer social media posts, and material that was not part of the authorized source list were also excluded from trend construction. Check Point's aggregated telemetry, while useful as exposure context, was not added to the incident volume because it reflects automated attempts or blocks, not intrusions with confirmed impact.
Finally, several facts remained only partially confirmed or without a closed public attribution, especially in leak site cases, connectivity outages, and ransomware claims. When the material does not allow a decision between encryption, exfiltration, or a mere mention on the actor's portal, the report preserves that uncertainty instead of forcing a classification.
Sources
- Vivo amplia proteção digital com novo SOC Agêntico e parceria com Palo AltoTI Inside
- Vivo amplía la protección digital de las empresas con nuevo SOC y alianza con Palo Alto NetworksBNamericas
- Ciberataques crescem 45% no Brasil em julho, aponta pesquisaExame
- Check Point registra alta de 45% nos ciberataques no BrasilIT Section
- Intranet Gov Brasil Data Breach in 2026BreachSense
- Victim: Intranet Gov Brasil - Ransomware.liveRansomware.live
- Intranet Gov Brasil Listed by The Gentlemen Ransomware GroupGalaxyWarden
- LockBit 5.0 Strikes Brazilian Communications Leader Grupo RáiDexpose.io
- rai.com.br data breach — Lockbit5 ransomware leak (2026)Darkfield / Orizon One
- rai.com.br Listed by Lockbit5 Ransomware GroupGalaxyWarden
- Alerta de inteligencia sobre ciberataques a redes de telecomunicaciones en ChileDefrevista
- El silencio que nadie nos explicó y siguen sin explicarnosEl Mostrador
- EEUU alertó ciberataques a empresas chilenas de telecomunicaciones ligados a hackers chinosBioBioChile
- Reportes de inteligencia de Estados Unidos alertan sobre actividad maliciosa y uso de malware en los sistemas de las empresas de telecomunicaciones en ChileRevistaSeguridad.cl
- Chile's Cybersecurity Push: Telecom Espionage ProbeThe Rio Times
- EE.UU. advirtió a Chile sobre la presencia del APT Lilac TyphoonSecurity-Chu
- Diputados piden esclarecer posible ataque informático a empresa de telecomunicacionesCooperativa
- Diputados piden esclarecer eventual ciberespionaje a empresas de telecomunicaciones en ChileEmol
- Diputados califican de “máxima gravedad” presunto ciberespionaje a empresas de telecomunicaciones en ChileT13
- PDI investiga posible espionaje a Entel, Movistar y Telmex tras advertencia de Estados Unidos24horas.cl
- PDI investiga posible espionaje a Entel, Movistar y Telmex tras alerta de EE.UU.24Horas.cl
- "Lilac Typhoon": PDI indaga "posibles ataques informáticos" de un grupo asociado a ChinaRadio Cooperativa
- MinJusticia activa plan integral de recuperación tecnológica luego de vulneración cibernéticaMinisterio de Justicia y del Derecho de Colombia
- La semana en brechas de seguridad 26 de agosto de 2026Kaseya
- Comunicaciones sobre riesgo para usuarios de internet por controversia entre TV Azteca y ATPCRC Colombia
- CRC advierte riesgo de internet para 57.000 usuarios por pelea entre TV Azteca y ATPComisión de Regulación de Comunicaciones (CRC)
- Procuraduría alerta por seguridad de infraestructura eléctrica en Tolima tras atentadoProcuraduría General de la Nación (Colombia)
- Colombia Experiences Border Gateway Protocol DisruptionTelecom Observer
- Movistar explicó falla masiva de internet y TV que afectó varias ciudades de ColombiaInfobae Colombia
- Telecommunications: MinTIC and operators quantify network recoveryEn Colombie
- Ransomware golpea al Ministerio de Justicia de ColombiaWhite Hunters
- Movistar se pronunció tras falla masiva en internet y televisiónEl Tiempo
- Colombia Justice Ministry Hit With Ransomware0dayNews
- Ransomware en el Ministerio de Justicia de ColombiaDataEnforce
- Actualización del comunicado oficial sobre el incidente de ciberseguridadMinisterio de Justicia y del Derecho de Colombia
- MinJusticia confirmó ataque cibernético que afectó parte de su infraestructura tecnológicaNoticias Caracol
- Ransomware Hits Justice Ministry as Colombia Gets New PresidentDark Reading
- Actualización sobre el ataque cibernéticoMinisterio de Justicia y del Derecho de Colombia
- Nuevo Informe de Inteligencia de Amenazas del ColCERTColCERT
- Robo de cable deja sin servicio a 30 mil usuarios en EcatepecEl Independiente
- Una aparente falla menor de conectividad expone profundas vulnerabilidades de ciberseguridad en la infraestructura digital del Gobierno de MéxicoInfobae México
- Falla masiva de Internet Hoy 19 de Agosto 2026: Reportan caída de páginas y apps en MéxicoN+
- ¿Se cayó Izzi? Principales fallas que reportan usuarios hoy, 19 de agostoLa Crónica de Hoy
- Falla Masiva de Internet Hoy 19 de Agosto 2026: Reportan ...N+
- Caos digital: Servicios clave de 'gob.mx' fuera de línea, ¿cuándo volverán?Diario de México
- Caen páginas del Gobierno de México: ¿qué pasó con gob.mx y qué servicios fueron afectados?Ejé Central
- Corte de conectividad interrumpe los sitios del gobierno de México, según ATDTLa FM Nativa
- ATDT reporta fallas en sitios de gobierno; están temporalmente fuera de servicioSDPnoticias
- Se caen Izzi, Telmex, Totalplay y Megacable hoy 19 de ...Guillermo Ortega
- Mexico Government Websites Down for Two HoursThe Rio Times
- Gobierno de México atribuye caída de su página a corte ...Infobae México
- Sitios web del gobierno federal sufren caída temporalProceso
- Por qué no puedo hacer recargas Telcel: ¿se cayó o suspendieron tu línea?Marca México
- Fallas y caídas de servicio HOY 18 agosto 2026Mediotiempo
- Niega Telcel fallas en vinculación de líneas telefónicasPlano Informativo
- Telcel reporta fallas masivas en datos, recargas y facturaciónRuptura360
- ¿Telcel falla HOY 18 de agosto? Usuarios reportan fallasMilenio
- Falla red Telcel hoy, 17 de agosto: principales errores que reportaron usuariosLa Crónica de Hoy
- Red Telcel falla HOY 17 de agosto 2026: Ciudades afectadas y qué ha dicho la compañía tras la caídaMarca México
- Telmex registra fallas por segundo día consecutivo; usuarios reportan caída este sábadoSDPnoticias
- Falla de Telmex cumple 3 días sin servicio en zonas de la CDMX; usuarios reclaman y exigen respuestasSociedad Noticias
- DDoS Alert: THE GARUDA EYE claims to have targeted the website of Secretaría Nacional de Cultura del ParaguayFalconFeeds.io
- PREVENTIVE ALERT : CONSOLIDATED SUMMARY OF DDOS EVENTS - INCLUDING PARAGUAYVECERT Analyzer
- Qualcomm Issued Security Updates for Multiple Product Vulnerabilities (referencia a difusión por CERT‑PY)Mallory.ai
- PREVENTIVE ALERT: presunto ataque DDoS contra el Ministerio de Relaciones Exteriores de ParaguayVECERT Analyzer (cuenta de threat intelligence en X)
- Alerta DDoS: TheGarudaEye afirma haber atacado el sitio del Ministerio de Relaciones Exteriores de ParaguayFalconFeeds.io
- Qualcomm security advisory (AV26-795)Canadian Centre for Cyber Security
- Alertan sobre estafas con falsas multas de tránsito enviadas por SMS1000Noticias
- UNCONFIRMED activity mentioning entities in 18 countries and dark web postsVECERT Radar
- CYBERCRIME MONITORING SYSTEM: batch of posts on alleged leaks and critical servicesVECERT Radar
- MULTI-COUNTRY PREVENTIVE ALERT: concentration of dark web publications in Latin AmericaVECERT Radar
- No es tu internet: los ciberataques que pueden dejarte sin servicioExpansión México
- El 'ransomware' se dispara un 87 % a nivel global y Latinoamérica se mantiene como la región más atacadaInfobae (agencias)
- VECERT Analyzer: authenticity of samples and databases remains unconfirmedVECERT Radar
- Justicia chilena investiga presuntos ciberataques de hackers chinos a empresas de telecomunicacionesInfobae
- Multiple preventive alert: incidents targeting telecommunications operator databases and other sectors (status UNCONFIRMED)VECERT Radar
- Uno de cada cinco ataques maliciosos son habilitados por IA en América Latina, con un costo promedio de 4.65 millones de dólares para las empresasIBM Latinoamérica
- Cybersecurity in Telecom Industry: Threats and DefenseCloudSEK
- Фахівці T-Mobile фізично перерізали мережевий кабель, щоб зупинити китайських хакерів просто під час зламуВсеЗависло
- T-Mobile отвоевала сети у китайских хакеров Salt TyphoonSecurityLab.ru
- T-Mobile cortó físicamente un cable para expulsar a hackers chinos de su redDiarioBitcoin
- T-Mobile 'chopped a cable' to expel Chinese hackers from its networkTechCrunch
- T-Mobile Sent Four People With Scissors to Stop Chinese HackersYahoo News
- Tras alerta investigan ciberataques a Entel, Movistar y TelmexNIVEL4 Labs
- NewsBites Volume XXVIII – Issue 58SANS Institute
- The Threat of CCP-Controlled Infrastructure in the U.S. Communications BackboneBenton Institute for Broadband & Society
- Chinese Telecom Hack Exposed Data Centers, House Report to SayBloomberg
- Chinese telecom firms kept footholds in US networks despite federal crackdowns, House probe findsNextgov
- Salt Typhoon: What It Is, How It Works & 2026 StatusCorenexis
- T-Mobile Cut Cable to Eject Salt Typhoon HackersCyber Kendra
