Ransomware crews spent the past month posting a steady trickle of Latin American public institutions to their extortion sites: a provincial tax agency in Argentina, two municipal governments, and a set of universities. The absolute numbers are small, but the pattern stands out against the rest of the world.
Of the 68 leak-site claims IntelFusions recorded against South American organizations in the 30 days to 8 August 2026, nine named a government body or an educational institution. That is roughly one in seven. Across the other 914 claims we logged worldwide in the same window, 40 did, or about one in twenty-three.
Who has been listed
- On 7 August, a crew calling itself L Group posted the web domain of the Administracion Tributaria Provincial, the provincial tax administration for Chaco in northern Argentina, alongside a private university in Rio de Janeiro.
- On 31 July, The Gentlemen listed the Municipal Chamber of Serra, the legislative body of one of the largest cities in Brazil's Espirito Santo state, and the district municipality of San Luis in Lima, Peru.
- Krybit listed the CESMAC University Center in Brazil on 4 August, and Nova listed the Universidad Nacional de Mar del Plata, a large Argentine public university, on 20 July.
Those follow the claim in late July when Qilin put the Argentine Army on its leak site.
Not one crew's campaign
This is not a single gang working one region. Twenty-two different crews were behind those 68 South American claims, from established operations such as Qilin, LockBit and INC Ransom to leak sites that only appeared this year. Public institutions there are being picked up broadly, not by one operator with a local specialty.
Read these claims carefully
Every figure above comes from posts written by the extortionists themselves. A listing is a claim, not a confirmed breach: crews inflate, recycle and sometimes invent victims, and the posts say nothing about how the attackers got in. The sector labels are our own classification of the named organization, not the gang's. Leak-site data also measures what criminals choose to publish rather than where attacks actually happen, and our corpus is heavily weighted toward the United States, which is part of why a regional skew this size is worth flagging. The underlying posts sit on Tor hidden services, which IntelFusions does not link.
Why public bodies are exposed
Municipal governments, provincial agencies and universities hold exactly the data extortion works on: civil and tax records, payroll, student files and health information. They also tend to run lean IT teams on public budgets, and when their systems go down the disruption is immediately visible to residents, which is the pressure the crews are counting on. We reported earlier this month that ransomware at Brazilian schools was traced to stolen logins rather than any exotic technique, which is the shape most of these intrusions take.
What defenders should do
Nothing in these listings identifies an entry point, so the guidance is the unglamorous baseline rather than anything targeted:
- Require multi-factor authentication on every remote access path, including VPN portals, remote desktop and administrative webmail.
- Keep offline, restorable backups of registry, tax, payroll and student systems, and actually test a restore.
- Inventory what is reachable from the internet and take down or gate anything that does not need to be there.
- Report incidents to the national CERT: CERT.br in Brazil, Cert.ar in Argentina, and the Centro Nacional de Seguridad Digital in Peru.
Country context and historical incident data for the country named most often here are on our Brazil profile, which currently carries a High targeting level in our data.
This briefing is provided by IntelFusions for informational and defensive purposes only. It summarizes extortion claims published by ransomware leak sites. Those claims are made by the attackers, are unverified, and may be false, exaggerated, or recycled from earlier breaches. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.