Uruguay — Cyber Threat Profile
CERTuy logged 42,768 cybersecurity incidents in Uruguay during 2025, close to triple the 14,264 recorded in 2024, though only 0.17% were rated high or very-high severity, down from 0.48% the prior year. In October 2025, the ransomware group Crypto24 listed Banco Hipotecario del Uruguay on its leak site, claiming to have exfiltrated over 700GB of customer financial records. CERTuy, operating under AGESIC, coordinates national incident response and publishes these annual incident statistics, but Uruguay's expanding digital financial services remain exposed to internationally active ransomware crews.Threat actors targeting Uruguay
- Gunra Ransomware · 3 incident(s)
- LockBit Ransomware · 2 incident(s)
- Qilin Ransomware · 2 incident(s)
- Akira Ransomware · 1 incident(s)
- Deadlock Ransomware · 1 incident(s)
- Global Ransomware · 1 incident(s)
- Payload Ransomware · 1 incident(s)
- RansomHouse Ransomware · 1 incident(s)
Most targeted sectors
Recent claimed incidents
Read the full analysis on IntelFusions