Desk live·
ForensicPost
Ransomware/Analysis/File 25-1116

Three Countries Account for Most Latin American Ransomware Victims

Three countries account for well over half of identified ransomware victims in Latin America, with RansomHub and LockBit named as the principal operations.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetLatin American organisations
ActorMultiple
D. Kennedy11 min readConfidence: medium2 sources reviewed

Regional research places Brazil at roughly 30% of identified ransomware victims in Latin America, Mexico at approximately 14% and Argentina at about 13%, with RansomHub and LockBit among the most active operations.

The Distribution Tracks Economic Size

Brazil, Mexico and Argentina are the region’s largest economies. A victim distribution matching economic ranking is what you would expect if targeting were essentially opportunistic — more organisations, more internet-facing estates, more victims.

That is a mildly reassuring finding. It suggests the region is not being singled out so much as included, which is the same reading the corpus applied to country counts at 25-1206.

LockBit Appearing Here Is Worth Noting

The corpus filed at 25-0908 that LockBit resurfaced with a new release in September 2025, eighteen months after Operation Cronos seized its infrastructure and named its leadership.

Finding the brand among the most active operations in a region is consistent with that file’s conclusion: the name survived a disruption designed to destroy it, because in a market where reputation is the scarce asset a recognised brand retains value even after being demonstrably compromised.

"Identified Victims" Means Leak-Site Listings

The usual caution applies with extra force outside the US and UK. A listing is an advertisement, per 25-1230, and organisations that pay before publication are generally never listed.

In jurisdictions without mandatory disclosure, leak-site listings are close to the only visible record — which means the regional picture is assembled almost entirely from what attackers chose to publish. Graded medium accordingly.

This is an analysis file

Built on published regional research, listed below. Victim shares derive from leak-site identification and are subject to the limitations at 25-1230. Corrections: corrections@forensicpost.com.

Sources
  1. Latin America sees sharp rise in ransomware and hacktivist attacks in 2025Industrial Cyber
  2. Deep dive: 2025 LATAM threat landscape reportCrowdStrike
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary