Cybercriminals Target Critical Infrastructure in Latin America Amid Rising Threats
Cybercriminals are increasingly targeting critical infrastructure in Latin America, including power grids, water systems, and healthcare, posing significant risks to national security.
Executive Takeaway — TL;DR
- Category:
- Critical Infrastructure
- Severity:
- Medium
- Actor Type:
- Cybercriminal
- Geography:
- Latin America
- Confidence:
- Confirmed
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
Introduction
As of March 2026, cybercriminal activities targeting critical infrastructure in Latin America have escalated, posing significant risks to sectors such as power grids, water systems, industrial control systems (ICS), healthcare, and the financial sector. This briefing examines recent trends, notable incidents, and the evolving threat landscape in the region.
Rising Cyberattack Activity
In December 2025, Latin America experienced a 26% year-over-year increase in cyberattacks, with organizations facing an average of 3,065 attacks per week. This surge was primarily driven by ransomware operations and the expanding exposure linked to enterprise adoption of generative AI technologies. (blog.checkpoint.com)
Targeted Sectors
-
Power Grids and Water Systems: Cybercriminals have increasingly targeted critical infrastructure sectors, including energy and water systems. Notably, in January 2026, a significant power outage in Caracas, Venezuela, was suspected to be the result of a cyber-enabled operation, potentially indicating a deliberate attack on the power grid. (axios.com)
-
Industrial Control Systems (ICS): Hacktivist groups have expanded their focus to include ICS attacks, data breaches, and unauthorized access. By September 2025, such attacks accounted for 25% of all hacktivist activities, nearly doubling from the previous quarter. (cyble.com)
-
Healthcare and Financial Sectors: The healthcare and financial sectors have been increasingly targeted by cybercriminals. In Q4 2025, Kaspersky ICS CERT reported that threat actors deployed malware like PhantomVAI Loader in attacks against organizations in sectors including healthcare and finance. (ics-cert.kaspersky.com)
Notable Threat Actors
-
Qilin (Agenda) Ransomware Group: Since January 2025, the Qilin group has affected over 700 victims in 62 countries, primarily targeting organizations in developed markets and high-value industries, including manufacturing, technology, financial services, and healthcare. (ics-cert.kaspersky.com)
-
Hacktivist Groups: Groups like Dark Engine have targeted critical ICS systems to steal sensitive data, demonstrating both strategic breadth and technical depth in their attacks against infrastructure sectors such as energy, food and beverages, and manufacturing. (cyberpress.org)
Regional Challenges
Despite progress in strengthening cybersecurity capacities, Latin America remains exposed to increasingly complex digital threats. A report by the Organization of American States (OAS) and the Inter-American Development Bank (IDB) highlighted structural gaps in resources, talent development, and cross-sector coordination, continuing to expose the region to sophisticated cyber threats. (oas.org)
Conclusion
The medium-level threat posed by cybercriminals targeting critical infrastructure in Latin America necessitates enhanced cybersecurity measures. Organizations must prioritize proactive defense strategies, including regular system updates, employee training, and robust incident response plans, to mitigate the risks associated with these evolving cyber threats.
Highlights:
- Why cyber attacks on critical national infrastructure are such a huge threat, Published on Wednesday, March 18
- Maduro raid had telltale signs of a cyber-enabled blackout, Published on Thursday, January 08
- Canadian government claims hacktivists are attacking water and energy facilities, Published on Friday, October 31
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

CISA and FBI Issue Urgent Warning on Third-Party ICS Risks Following Surge in Critical Infrastructure Attacks

CISA Issues Urgent Warning as Iranian-Linked Actors Target Industrial PLCs in Water Sector

