Regional research places Brazil at roughly 30% of identified ransomware victims in Latin America, Mexico at approximately 14% and Argentina at about 13%, with RansomHub and LockBit among the most active operations.
The Distribution Tracks Economic Size
Brazil, Mexico and Argentina are the region’s largest economies. A victim distribution matching economic ranking is what you would expect if targeting were essentially opportunistic — more organisations, more internet-facing estates, more victims.
That is a mildly reassuring finding. It suggests the region is not being singled out so much as included, which is the same reading the corpus applied to country counts at 25-1206.
LockBit Appearing Here Is Worth Noting
The corpus filed at 25-0908 that LockBit resurfaced with a new release in September 2025, eighteen months after Operation Cronos seized its infrastructure and named its leadership.
Finding the brand among the most active operations in a region is consistent with that file’s conclusion: the name survived a disruption designed to destroy it, because in a market where reputation is the scarce asset a recognised brand retains value even after being demonstrably compromised.
"Identified Victims" Means Leak-Site Listings
The usual caution applies with extra force outside the US and UK. A listing is an advertisement, per 25-1230, and organisations that pay before publication are generally never listed.
In jurisdictions without mandatory disclosure, leak-site listings are close to the only visible record — which means the regional picture is assembled almost entirely from what attackers chose to publish. Graded medium accordingly.
Built on published regional research, listed below. Victim shares derive from leak-site identification and are subject to the limitations at 25-1230. Corrections: corrections@forensicpost.com.