# Latin American Cybercriminals Target Government Agencies, Exposing Millions of Citizen Records
## A Regional Crime Wave Without Borders: Latin American Threat Groups Shift from Ransomware to Pure Data Extortion
Cybercriminals operating across Latin and South America have declared open season on government agencies, stealing and monetizing sensitive citizen data at unprecedented scale. The public-administration sector has become the region's most-breached industry, as organized threat groups exploit vulnerabilities and shift tactics away from traditional ransomware toward high-volume data theft and extortion operations.
The latest incident—a purported leak exposing 5.8 million records of Uruguayan citizens—signals an alarming trend that security researchers say reflects a maturing, regionally-focused cybercriminal ecosystem. Unlike global ransomware cartels, these actors possess deep knowledge of local governance structures, regulatory environments, and political sensitivities, making them particularly effective at targeting what matters most: the personal data of entire populations.
## The Threat: A Continental Breach Wave
In mid-May 2026, a threat group calling itself La Pampa Leaks claimed responsibility for compromising Uruguay's government-sponsored identity service, which is managed by state telecommunications provider Antel. According to breach claims, the attackers accessed millions of identity records and have begun monetizing the data through citizen-data lookup services—essentially selling access to personal information on criminal marketplaces.
But Uruguay is far from alone:
The scope and scale of these incidents underscore a fundamental shift in the threat landscape: government agencies, once viewed as high-risk targets due to their security posture, are increasingly seen as high-value targets due to the citizen data they hold.
## Background and Context: A Maturing Regional Threat Ecosystem
Cybersecurity researchers have long focused on nation-state APT groups and global ransomware cartels. The rise of sophisticated Latin American cybercriminal syndicates demands a recalibration of that focus.
According to Fabio Assolini, lead security researcher at Kaspersky's Global Research and Analysis Team (GReAT), these threat actors are distinctly different from their global counterparts:
> "Unlike global cartels that cast a wide net, these actors intimately understand the regional geopolitical landscape. They have their own playbooks and are moving away from traditional operational models."
Several factors have enabled this ecosystem to flourish:
| Factor | Description |
|--------|-------------|
| Regulatory Gaps | Many government agencies in the region operate with legacy infrastructure and outdated security controls |
| Regional Knowledge | Local threat actors understand governance structures, budget cycles, and decision-making processes that global actors miss |
| Data Monetization | Identity data, government employee records, and health information command premium prices on criminal marketplaces |
| Low Consequences | Law enforcement cooperation across borders remains inconsistent, reducing accountability |
| Geopolitical Sensitivity | Governments may be reluctant to publicly disclose breaches for political reasons |
The COVID-19 pandemic accelerated this trend by forcing rapid digitalization of government services without corresponding security investments—a pattern that crime groups have systematically exploited.
## Technical Details: Evolution from Ransomware to Pure Extortion
Perhaps most significantly, Latin American threat groups are abandoning the traditional ransomware playbook in favor of a simpler, lower-risk model: pure data exfiltration followed by extortion.
### Traditional Ransomware Model
### New "Pure Extortion" Model
This tactical shift reflects operational sophistication. Assolini explains: "Moving away from traditional operational models, these groups are pivoting to 'pure extortion' attacks, bypassing the encryption phase entirely to focus solely on high-volume data exfiltration."
Key technical indicators of these attacks include:
The Uruguay incident in particular suggests attackers exploited Antel's identity management infrastructure—a critical system that, when compromised, yields massive citizen datasets immediately.
## Implications: Who Is at Risk and What Is at Stake
### Immediate Risks
Government Employees and Citizens: Personal identification data—including national ID numbers, addresses, family information—enables identity theft, fraud, and targeted phishing campaigns. Citizens in affected countries face years of potential fraud and criminal targeting.
Public Service Continuity: When health ministries, tax agencies, and social services are compromised, government operations themselves become hostage to criminals. Payment or non-disclosure becomes an operational decision, not just a security one.
Cross-Border Spillover: Data stolen from government agencies in one country can be weaponized against diaspora communities, dual-nationals, and business interests in neighboring nations.
### Systemic Risks
## Recommendations: What Organizations Should Do Now
### For Government Agencies
1. Immediate Network Segmentation: Isolate identity management systems, health records, and citizen data from general administrative networks
2. Credential Audit: Conduct comprehensive reviews of privileged account access and deactivate unused credentials
3. Extended Detection and Response (XDR): Deploy monitoring for data exfiltration patterns, not just encryption activity
4. Incident Response Preparation: Develop protocols for data breach disclosure that account for political considerations while prioritizing transparency
5. Regional Information Sharing: Join LATAM-specific threat intelligence communities to share indicators with peer agencies
### For Private Organizations
### For Individuals
---
## HackWire Analysis
The shift from ransomware to pure data extortion reveals a troubling truth: encryption is no longer necessary to weaponize stolen data. Latin American threat groups have discovered that the threat of disclosure is often sufficient to extract payment—and when it isn't, the data itself has market value. This model is harder to defend against because it leaves no ransomware signature, no threatening note, no encryption timeline to trigger incident response. Organizations must detect and stop attackers *before* they exfiltrate data, not after.
What's particularly concerning is the regional focus. These aren't indiscriminate campaigns; they're methodical, targeted operations by groups with deep knowledge of government operations and political vulnerabilities. The Uruguayan incident's targeting of an identity provider suggests attackers are studying and prioritizing high-impact systems. The Colombian health ministry's 23 million attacks in March alone suggest sustained, organized pressure—not random scanning.
The industry should expect this model to spread globally. Once threat actors prove that data exfiltration alone creates sufficient pressure, and that disclosure threats are often more valuable than ransom demands, the incentive to continue with ransomware encryption diminishes. Organizations in every region should assume their defenders are one step behind the actual threat activity. The time to detect these actors is measured in weeks, not days—and many organizations lack the visibility to achieve that.
For defenders: assume your network is being passively scanned by organized groups right now. The Uruguayan and Mexican incidents suggest these operations take months to plan. Your window to detect and evict them before mass exfiltration occurs is narrow. — *HackWire Editorial*
---
## Related Coverage