Latin American Cybercriminals Hoover Up Government Data
Recent investigations reveal a surge in cybercriminal activity targeting government agencies across Latin America, primarily driven by groups like La Pampa Leaks and the Chronus Group. These actors are stealing and monetizing citizen data, with the public-administration sector being the most-breached region in the past year. The attacks are characterized by a shift towards pure extortion tactics and the reuse of historical data, highlighting a complex threat landscape influenced by geopolitical factors and regional regulations.
A series of data breaches, including the La Pampa Leaks incident targeting Uruguay's government-sponsored identity service and the Chronus Group's attack on 25 Mexican government agencies, demonstrate a growing trend of cybercriminals focusing on government institutions in Latin America. These groups, often operating independently, are leveraging stolen citizen data for monetization, primarily through lookup services. Fabio Assolini of Kaspersky's GReAT notes that unlike global cartels, these regional actors possess a deep understanding of the local geopolitical landscape, utilizing 'pure extortion' attacks to bypass encryption and prioritize high-volume data exfiltration. The attacks are further complicated by the region's political instability and economic challenges, making government systems attractive targets for hacktivists and state-aligned actors. Notably, Peru, Mexico, and Brazil have also experienced significant data breaches, placing them among the most targeted nations globally. The use of recycled data and fabricated breach claims by groups like Bashe (APT73) adds another layer of deception to the threat landscape.
