< Back to situations

We’ll email you as it develops, and you can follow the whole thread from day one.

[SITUATION] · [ACTIVE]

32 clusters · 140 sources · 88 days · First seen · Last updated

Categories: TECHNOLOGY · CRIME · BUSINESS · HEALTH · POLITICS

AI‑enhanced ransomware surge and policy response

Entities: Nicole Filippetti · Brazil · Fortinet · Grupo Linka · RansomHouse

Overview

AI‑driven ransomware campaigns now combine rapid credential theft, AI‑generated phishing, and encryption within minutes. Sophos (July 2026) reports 79 % of incidents start with compromised identities, and Proofpoint finds 65 % of victims say AI boosted attack success.

In Q2 2026 global ransomware incidents rose 3 % to 2,229 attacks, with Qilin, The Gentlemen, DragonForce and Akira accounting for a third of activity. A new “agentic ransomware” variant embeds autonomous AI agents that reconnoitre, adapt to defenses and encrypt without external C2.

Latin America remains a hotspot. Brazil led the region in 2025 with 17.8 % year‑on‑year growth; Mexico recorded a 38 % rise and a 90 % jump in AI use, averaging $1.35 million in recovery costs per breach and 70 % of ransom demands above $1 million. Six‑in‑ten Mexican firms cease operations within six months. FortiGuard logged 843.3 billion attack attempts across Latin America in 2025, Brazil the most affected, followed by Mexico and Colombia.

Human error drives 67 % of successful breaches, while a shortage of over 77,000 qualified cybersecurity professionals hampers response; only 27 % of Mexican companies have specialised protection services.

Defensive tactics are also evolving. AI‑enhanced tools now automate threat detection, patching and attack prediction. Pay‑per‑use models in Spain are democratizing next‑generation firewalls, and insurers pair cyber‑insurance with AI risk assessments. Experts warn that AI‑accelerated vulnerability discovery may make patch‑management the next bottleneck.

Policy moves include the UK drafting a ban on ransomware payments by public‑sector bodies and Brazil’s Army Intelligence Centre flagging an AI‑enabled strategic threat. SMEs are urged to adopt zero‑trust, MFA and offline immutable backups as ransomware becomes increasingly identity‑driven.

Claims

What the coverage asserts, and how well corroborated each claim is across sources.

Timeline

  1. 1 day ago

    [TECHNOLOGY] 10 sources
    ESET reports surge in ransomware attacks across Latin America

    AI boosts both cyber defenses and ransomware attacks; ESET reports 52.7% of Latin American firms saw attempts and a 16.5% rise in ransomware in early 2026, while pay‑per‑use security models spread in Spain.

  2. 4 days ago

    [TECHNOLOGY] 5 sources
    Mexico sees 38% rise in ransomware attacks on businesses, AI use up 90%

    Ransomware attacks on Mexican firms rose 38% last year, AI‑driven attacks up 90%; average recovery cost $1.35 million, 70% of ransoms exceed $1 million, amid a shortage of 77,000 security experts.

  3. 6 days ago

    [CRIME] 10 sources
    Ransomware attacks surge with AI-driven threats, Brazil hit hardest

    AI‑driven agentic ransomware is rising, with attacks up 3% globally in Q2 2026 and 17.8% in Brazil, where hypervisor and backup targets dominate; phishing remains the main entry vector.

  4. 10 days ago

    [TECHNOLOGY] 9 sources
    Proofpoint AI‑Era Ransomware Report Shows AI Boosts Attack Success

    AI is boosting ransomware success (65% of attacks) and accelerating cyber‑crime, while firms ramp up AI defenses amid a 77% rise in AI‑driven fraud.

  5. 12 days ago

    [TECHNOLOGY] 2 sources
    Ransomware up 23% globally as Brazil's army warns of combined cyber‑AI threats

    Ransomware attacks rose 23% in June 2026, targeting corporate access points, as Brazil's army reports cyber‑AI threats now form a unified strategic challenge.

  6. 13 days ago

    [CRIME] 13 sources
    Ransomware attacks surge as compromised identities and AI tools fuel new threats

    Compromised credentials now drive 79% of ransomware attacks, AI‑enhanced groups like BlackMamba target hospitals, and governments move to ban ransom payments.

  7. 15 days ago

    [TECHNOLOGY] 2 sources
    Small Business Cybersecurity Guides Focus on Simple, Low-Cost Measures

    Guides urge small businesses to adopt simple, low‑cost cybersecurity steps—employee training, MFA, password managers—while avoiding pricey, unnecessary tools and noting insurance won’t prevent attacks.

  8. 19 days ago

    [TECHNOLOGY] 2 sources
    Corporate Backup Strategies to Counter Ransomware and Wiper Attacks

    Studies reveal most firms lack proper backup safeguards against ransomware and wiper attacks; only a minority isolate and test backups, prompting calls for immutable storage, strict isolation, and comprehensive

  9. 20 days ago

    [BUSINESS] 7 sources
    Small businesses face growing cyber‑insurance and backup challenges

    Small firms are urged to adopt immutable backups as insurers tighten requirements; cyber spending now rivals rent, with many still lacking proper insurance and confidence in data protection.

  10. 26 days ago

    [TECHNOLOGY] 7 sources
    AI Agent ‘JadePuffer’ Executes First Fully Autonomous Ransomware Attack

    Researchers report JadePuffer, the first ransomware run entirely by an AI agent, which exploited a Langflow flaw, auto‑adapted during the attack, and was set up by a human operator.

  11. 28 days ago

    [TECHNOLOGY] 28 sources
    JadePuffer AI Agent Executes First Fully Autonomous Ransomware Attack

    Sysdig reports JadePuffer, an autonomous AI agent, carried out a full ransomware attack via a Langflow bug, encrypting 1,342 records and adapting in 31 seconds, marking the first documented agentic ransomware.

  12. about 1 month ago

    [TECHNOLOGY] 5 sources
    AI Agent JadePuffer Executes First Fully Autonomous Ransomware Attack

    Sysdig reports JadePuffer, the first fully autonomous AI‑driven ransomware, exploiting Langflow (CVE‑2025‑3248) and Nacos vulnerabilities to encrypt data and demand Bitcoin, highlighting a new threat model for

  13. about 1 month ago

    [TECHNOLOGY] 2 sources
    AI logistics sector sees governance framework rollout and surge in cargo thefts

    NMFTA released a free AI governance framework for logistics, while U.S. police busted a multi‑state theft ring stealing $1.3 M of AI data‑center equipment.

  14. about 1 month ago

    [TECHNOLOGY] 3 sources
    Ransomware Threats Escalate, Targeting Global Financial Systems

    Ransomware in 2026 uses AI to target executives, adds triple extortion and attacks IoT, disrupting payment rails, banking platforms and trading systems, threatening global financial stability.

  15. about 1 month ago

    [TECHNOLOGY] 2 sources
    SonicWall warns healthcare cyberattacks stay high despite overall decline in 2026

    SonicWall’s 2026 Healthcare Protect Brief shows cyber‑attacks on hospitals declined only 17 %, far less than other sectors, driven by exposed remote‑desktop tools, IoT devices and legacy VPNs; ten ransomware —

  16. about 1 month ago

    [TECHNOLOGY] 5 sources
    Ransomware Defense Shifts Toward Resilience and Identity‑Based Protection

    Ransomware guidance urges healthcare and Canadian organisations to adopt cyber‑resilience, focusing on identity‑based security as attackers develop tools to disable EDR defenses.

  17. about 1 month ago

    [TECHNOLOGY] 3 sources
    Ransomware attacks surge 48% globally in May 2026

    May 2026 saw a 48 % global rise in ransomware attacks to 698 incidents, with major growth in Asia and heightened targeting of Android devices and private users.

  18. about 2 months ago

    [TECHNOLOGY] 2 sources
    AI‑driven ransomware threats push firms toward immutable backup solutions

    IT leaders fear AI‑driven ransomware, but many lack immutable backups; CyberSense wins award for AI‑based ransomware recovery platform that verifies backup integrity.

  19. about 2 months ago

    [TECHNOLOGY] 2 sources
    AI-Driven Healthcare Ransomware Risks and FBI Cyber Range Highlight Expanding Cyber Threats

    Agentic AI in healthcare heightens ransomware risks, while the FBI's new Alabama cyber range simulates attacks across homes, hospitals and infrastructure, highlighting expanding cyber threats.

  20. about 2 months ago

    [CRIME] 2 sources
    Ransomware Surge Driven by AI and Healthcare Data Threatens Global Cybersecurity

    Ransomware activity hit record levels in Q1 2026, boosted by AI‑generated phishing and deep‑fakes, while stolen healthcare data fuels a lucrative underground market, raising global cyber risk.

  21. about 2 months ago

    [HEALTH] 2 sources
    Healthcare data breaches spur cybercrime market and push stronger vendor security rules

    Health‑ISAC urges tighter third‑party governance as TrendAI shows a global cybercrime market exploiting stolen patient data, with ransomware and vendor compromises driving multimillion‑dollar losses.

  22. about 2 months ago

    [CRIME] 2 sources
    Healthcare data emerges as top cybercrime commodity

    TrendAI finds stolen health records now drive a mature cybercrime market, with ransomware sales making up 36% of activity and vendors serving as supply‑chain multipliers.

  23. 2 months ago

    [CRIME] 4 sources
    AI‑driven cargo theft surge hits Canada and US supply chains

    AI data‑centre demand fuels a surge in high‑value cargo theft in Canada and the US, with losses up 60% to $725 million and criminals using AI for phishing and fake documents.

  24. 3 months ago

    [POLITICS] 2 sources
    U.S. House Appropriations Approves $4M for Cargo Theft Task Forces

    U.S. House Appropriations earmarks $4 M for task forces to fight rising cargo theft, praised by the American Trucking Associations.

  25. 3 months ago

    [TECHNOLOGY] 2 sources
    Indiana K‑12 schools face surge in cyberattacks, prompting stronger data‑security measures

    Indiana K‑12 schools report a sharp rise in cyberattacks, prompting costly fixes and a push for stronger data‑security practices.

  26. 3 months ago

    [TECHNOLOGY] 2 sources
    SK Shield reports South Korean SMEs take average 106 days to respond to cyber attacks

    SK Shield says South Korean SMEs need 106 days on average to detect and start responding to cyber attacks, with ransomware and data theft most common.

  27. 3 months ago

    [CRIME] 2 sources
    Canada sees digital fraud loss median CAD $1,301 as attempts outpace global average

    Canada's digital fraud attempts exceed the global average, with a median loss of CAD $1,301, mainly from stolen cards.

  28. 3 months ago

    [POLITICS] 2 sources
    U.S. House approves cargo theft prevention bill (CORCA)

    U.S. House passes the Combating Organized Retail Crime Act to strengthen federal response to cargo theft, now headed to Senate.

  29. 3 months ago

    [TECHNOLOGY] 2 sources
    Nigeria's NITDA alerts to AI-driven 'DeepLoad' malware targeting banks and government agencies

    Nigeria's NITDA warns that AI‑driven 'DeepLoad' malware is stealing banking credentials and data from banks, agencies and citizens.

  30. 3 months ago

    [CRIME] 9 sources
    FBI warns of $725 M surge in cyber‑enabled cargo theft

    FBI alerts that cyber‑enabled cargo theft losses hit $725 M in US/Canada, urging logistics firms to tighten verification and security.

  31. 3 months ago

    [TECHNOLOGY] 3 sources
    Cybercrime Surge Threatens African Enterprises and Global Small Businesses

    Cybercrime now makes up over 30% of crimes in parts of Africa, prompting calls for stronger institutional defenses and basic security steps for businesses.

  32. 3 months ago

    [TECHNOLOGY] 2 sources
    India faces 505 cyber threats per minute as credential theft spikes, report says

    India logged 265 million cyber detections (505 per minute) in 2025, with credential theft surging against IT firms, report warns.

Sources

24x7mag.com · 4sysops.com · abcmoney.co.uk · affinitymsp.com.au · aktiencheck · analyticsinsight.net · australianmanufacturing.com.au · avantionline.it · b2b-cyber-security.de · bankofalbuquerque.com · bhaskarlive.in · bhconsulting.ie · bitmat.it · bleepingcomputer.com · bookclubz.com · borncity.com · brasil247.com · bright.nl · businessdiary.com.ph · businessnewsthisweek.com · businesstechweekly.com · byline.network · calibre800.com · capminds.com · channelinsider.com · cioafrica.co · countryrebel.com · cryptobriefing.com · culturalpolicy.com · cyberscoop.com · cybersecuritynews.es · dailyguardian.ae · diario21.com.mx · diarioeldia.uy · dicpas.es · digitaljournal.com · digitalmarketreports.com · divebuddies.net · dmarketforces.com · ebizlatam.com · elheraldodesaltillo.mx · ensegundos.do · enterprisesecuritytech.com · expresscomputer.in · fighthistory.com · finance.technews.tw · flagthis.com · gamesite.zoznam.sk

This summary has been updated 1 time: see revision history