Ransomware crews turn on Chile after months of quiet

Chilean companies are showing up on ransomware leak sites at a pace the country has not seen all year. IntelFusions incident data records 10 extortion claims against organizations in Chile over the last 21 days, against 6 in the entire 90 days before that. The crews driving the increase are not the ones that normally work the country.

The clearest shift belongs to The Gentlemen, the crew that overtook Qilin in July as the most active extortion brand on the leak sites. It has named 8 Chilean victims in its entire history, and 7 of those landed in the last 30 days. Its first was in March. Qilin, which has posted more Chilean victims over time than any other group, managed 3 in the same window.

Chile is now a top-five country for one crew

Across the 135 claims The Gentlemen posted worldwide in the last 30 days, Chile ranks fourth by victim count, behind the United States with 42, India with 9 and Italy with 9, and ahead of Germany, Spain, France and Canada. For an economy of about 20 million people that is well out of proportion to its size, and well out of proportion to where the crew was pointing in the spring. The organizations named are mid-market industrial, manufacturing and technology firms, most with no public profile outside Chile.

The rest of the region moved with it

South America was the only continent where leak-site claims rose this week. The region logged 20 claims in seven days against a weekly average of roughly 13 over the preceding four weeks, while North America fell to 101 from about 117 and Europe to 55 from about 68. Ten different crews were active in South America over those seven days, so this is not one group's spree. Argentina and Brazil carried a comparable share, extending a pattern of Latin American targets we reported earlier this month in our coverage of the region's public bodies.

Why a claim count is not a breach count

These are unverified extortion claims the gangs publish themselves, on their own sites, to pressure victims into paying. None of the Chilean organizations named has publicly confirmed an intrusion, and crews have been caught recycling and inventing entries. Posting is also bursty: The Gentlemen listed three Chilean names on 26 August and two more on 23 August, so part of any weekly rise is a batch uploaded at once rather than steady new activity. The defensible reading is that Chilean organizations are appearing in more crews' publication queues than before, not that ten Chilean companies were confirmed encrypted this month.

Where a Chilean defender should look first

The leak-site posts say nothing about how anyone got in, and we will not guess. What is documented is the crew's tooling: Kaspersky researchers have described The Gentlemen equipping affiliates with a custom backdoor and quiet network reconnaissance, and the group has separately been seen handing affiliates purpose-built tools for switching off endpoint protection. Defenses that assume the endpoint agent will still be running when the encryptor executes are the ones that fail against this crew. Offline, tested backups and tight control of remote access and administrative credentials matter more than any single indicator.

Chile's national CSIRT coordinates incident response and runs sectoral CERTs across energy, transport and finance under the country's 2023 to 2028 national cybersecurity policy. Organizations that find themselves named on a leak site should report through that channel rather than negotiating quietly, if only so the next Chilean company on the list learns something from it.

This briefing is provided by IntelFusions for informational and defensive purposes only. It summarizes extortion claims published by ransomware leak sites. Those claims are made by the attackers, are unverified, and may be false, exaggerated, or recycled from earlier breaches. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions