Latin America's public bodies keep appearing on leak sites

Ransomware crews spent the past month posting a steady trickle of Latin American public institutions to their extortion sites: a provincial tax agency in Argentina, two municipal governments, and a set of universities. The absolute numbers are small, but the pattern stands out against the rest of the world.

Of the 68 leak-site claims IntelFusions recorded against South American organizations in the 30 days to 8 August 2026, nine named a government body or an educational institution. That is roughly one in seven. Across the other 914 claims we logged worldwide in the same window, 40 did, or about one in twenty-three.

Who has been listed

Those follow the claim in late July when Qilin put the Argentine Army on its leak site.

Not one crew's campaign

This is not a single gang working one region. Twenty-two different crews were behind those 68 South American claims, from established operations such as Qilin, LockBit and INC Ransom to leak sites that only appeared this year. Public institutions there are being picked up broadly, not by one operator with a local specialty.

Read these claims carefully

Every figure above comes from posts written by the extortionists themselves. A listing is a claim, not a confirmed breach: crews inflate, recycle and sometimes invent victims, and the posts say nothing about how the attackers got in. The sector labels are our own classification of the named organization, not the gang's. Leak-site data also measures what criminals choose to publish rather than where attacks actually happen, and our corpus is heavily weighted toward the United States, which is part of why a regional skew this size is worth flagging. The underlying posts sit on Tor hidden services, which IntelFusions does not link.

Why public bodies are exposed

Municipal governments, provincial agencies and universities hold exactly the data extortion works on: civil and tax records, payroll, student files and health information. They also tend to run lean IT teams on public budgets, and when their systems go down the disruption is immediately visible to residents, which is the pressure the crews are counting on. We reported earlier this month that ransomware at Brazilian schools was traced to stolen logins rather than any exotic technique, which is the shape most of these intrusions take.

What defenders should do

Nothing in these listings identifies an entry point, so the guidance is the unglamorous baseline rather than anything targeted:

Country context and historical incident data for the country named most often here are on our Brazil profile, which currently carries a High targeting level in our data.

This briefing is provided by IntelFusions for informational and defensive purposes only. It summarizes extortion claims published by ransomware leak sites. Those claims are made by the attackers, are unverified, and may be false, exaggerated, or recycled from earlier breaches. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions