Get alerts on this situation
We’ll email you as it develops, and you can follow the whole thread from day one.
Unsubscribe anytime.
[SITUATION] · [ACTIVE]
32 clusters · 140 sources · 88 days · First seen · Last updated
Categories: TECHNOLOGY · CRIME · BUSINESS · HEALTH · POLITICS
AI‑enhanced ransomware surge and policy response
Entities: Nicole Filippetti · Brazil · Fortinet · Grupo Linka · RansomHouse
Overview
AI‑driven ransomware campaigns now combine rapid credential theft, AI‑generated phishing, and encryption within minutes. Sophos (July 2026) reports 79 % of incidents start with compromised identities, and Proofpoint finds 65 % of victims say AI boosted attack success.
In Q2 2026 global ransomware incidents rose 3 % to 2,229 attacks, with Qilin, The Gentlemen, DragonForce and Akira accounting for a third of activity. A new “agentic ransomware” variant embeds autonomous AI agents that reconnoitre, adapt to defenses and encrypt without external C2.
Latin America remains a hotspot. Brazil led the region in 2025 with 17.8 % year‑on‑year growth; Mexico recorded a 38 % rise and a 90 % jump in AI use, averaging $1.35 million in recovery costs per breach and 70 % of ransom demands above $1 million. Six‑in‑ten Mexican firms cease operations within six months. FortiGuard logged 843.3 billion attack attempts across Latin America in 2025, Brazil the most affected, followed by Mexico and Colombia.
Human error drives 67 % of successful breaches, while a shortage of over 77,000 qualified cybersecurity professionals hampers response; only 27 % of Mexican companies have specialised protection services.
Defensive tactics are also evolving. AI‑enhanced tools now automate threat detection, patching and attack prediction. Pay‑per‑use models in Spain are democratizing next‑generation firewalls, and insurers pair cyber‑insurance with AI risk assessments. Experts warn that AI‑accelerated vulnerability discovery may make patch‑management the next bottleneck.
Policy moves include the UK drafting a ban on ransomware payments by public‑sector bodies and Brazil’s Army Intelligence Centre flagging an AI‑enabled strategic threat. SMEs are urged to adopt zero‑trust, MFA and offline immutable backups as ransomware becomes increasingly identity‑driven.
Claims
What the coverage asserts, and how well corroborated each claim is across sources.
- [○ 1 SOURCE] Agentic ransomware embeds AI agents that autonomously perform reconnaissance and encrypt critical data without external C2 servers. (d5c1a2ec-c259-493f-919e-b97455418c0e)
- [○ 1 SOURCE] Hackers used an autonomous AI agent to spy on Thailand’s Ministry of Finance. (97c2dbbb-eb49-4aa4-9905-668c9007d32b)
- [○ 1 SOURCE] Global ransomware attacks increased 3% in Q2 2026, totaling 2,229 incidents. (3702141e-12f0-484f-a894-a5561477f843)
- [○ 1 SOURCE] The Qilin ransomware group recorded 301 victims in Q2 2026, the highest among ransomware groups. (3702141e-12f0-484f-a894-a5561477f843)
- [○ 1 SOURCE] Ransomware attacks grew 17.8% worldwide in 2025, with Brazil ranking ninth globally and leading Latin America. (8e8a146e-3822-4172-a344-de40c8f1ce56)
- [○ 1 SOURCE] In Brazil, 93% of ransomware attacks targeted backup infrastructures, and groups also focused on hypervisor platforms such as VMware ESXi and Microsoft Hyper‑V. (8e8a146e-3822-4172-a344-de40c8f1ce56)
- [○ 1 SOURCE] Phishing was the primary initial‑access technique in over half of Cisco Talos IR engagements in Q2 2026. (921f5e6e-fc39-4677-a9f8-3e34b47fe20a)
- [○ 1 SOURCE] A QR‑code phishing campaign targeting Australian organisations used compromised Microsoft 365 accounts to harvest credentials throughout Q2 2026. (921f5e6e-fc39-4677-a9f8-3e34b47fe20a)
Timeline
-
1 day ago
[TECHNOLOGY] 10 sourcesESET reports surge in ransomware attacks across Latin AmericaAI boosts both cyber defenses and ransomware attacks; ESET reports 52.7% of Latin American firms saw attempts and a 16.5% rise in ransomware in early 2026, while pay‑per‑use security models spread in Spain.
-
4 days ago
[TECHNOLOGY] 5 sourcesMexico sees 38% rise in ransomware attacks on businesses, AI use up 90%Ransomware attacks on Mexican firms rose 38% last year, AI‑driven attacks up 90%; average recovery cost $1.35 million, 70% of ransoms exceed $1 million, amid a shortage of 77,000 security experts.
-
6 days ago
[CRIME] 10 sourcesRansomware attacks surge with AI-driven threats, Brazil hit hardestAI‑driven agentic ransomware is rising, with attacks up 3% globally in Q2 2026 and 17.8% in Brazil, where hypervisor and backup targets dominate; phishing remains the main entry vector.
-
10 days ago
[TECHNOLOGY] 9 sourcesProofpoint AI‑Era Ransomware Report Shows AI Boosts Attack SuccessAI is boosting ransomware success (65% of attacks) and accelerating cyber‑crime, while firms ramp up AI defenses amid a 77% rise in AI‑driven fraud.
-
12 days ago
[TECHNOLOGY] 2 sourcesRansomware up 23% globally as Brazil's army warns of combined cyber‑AI threatsRansomware attacks rose 23% in June 2026, targeting corporate access points, as Brazil's army reports cyber‑AI threats now form a unified strategic challenge.
-
13 days ago
[CRIME] 13 sourcesRansomware attacks surge as compromised identities and AI tools fuel new threatsCompromised credentials now drive 79% of ransomware attacks, AI‑enhanced groups like BlackMamba target hospitals, and governments move to ban ransom payments.
-
15 days ago
[TECHNOLOGY] 2 sourcesSmall Business Cybersecurity Guides Focus on Simple, Low-Cost MeasuresGuides urge small businesses to adopt simple, low‑cost cybersecurity steps—employee training, MFA, password managers—while avoiding pricey, unnecessary tools and noting insurance won’t prevent attacks.
-
19 days ago
[TECHNOLOGY] 2 sourcesCorporate Backup Strategies to Counter Ransomware and Wiper AttacksStudies reveal most firms lack proper backup safeguards against ransomware and wiper attacks; only a minority isolate and test backups, prompting calls for immutable storage, strict isolation, and comprehensive
-
20 days ago
[BUSINESS] 7 sourcesSmall businesses face growing cyber‑insurance and backup challengesSmall firms are urged to adopt immutable backups as insurers tighten requirements; cyber spending now rivals rent, with many still lacking proper insurance and confidence in data protection.
-
26 days ago
[TECHNOLOGY] 7 sourcesAI Agent ‘JadePuffer’ Executes First Fully Autonomous Ransomware AttackResearchers report JadePuffer, the first ransomware run entirely by an AI agent, which exploited a Langflow flaw, auto‑adapted during the attack, and was set up by a human operator.
-
28 days ago
[TECHNOLOGY] 28 sourcesJadePuffer AI Agent Executes First Fully Autonomous Ransomware AttackSysdig reports JadePuffer, an autonomous AI agent, carried out a full ransomware attack via a Langflow bug, encrypting 1,342 records and adapting in 31 seconds, marking the first documented agentic ransomware.
-
about 1 month ago
[TECHNOLOGY] 5 sourcesAI Agent JadePuffer Executes First Fully Autonomous Ransomware AttackSysdig reports JadePuffer, the first fully autonomous AI‑driven ransomware, exploiting Langflow (CVE‑2025‑3248) and Nacos vulnerabilities to encrypt data and demand Bitcoin, highlighting a new threat model for
-
about 1 month ago
[TECHNOLOGY] 2 sourcesAI logistics sector sees governance framework rollout and surge in cargo theftsNMFTA released a free AI governance framework for logistics, while U.S. police busted a multi‑state theft ring stealing $1.3 M of AI data‑center equipment.
-
about 1 month ago
[TECHNOLOGY] 3 sourcesRansomware Threats Escalate, Targeting Global Financial SystemsRansomware in 2026 uses AI to target executives, adds triple extortion and attacks IoT, disrupting payment rails, banking platforms and trading systems, threatening global financial stability.
-
about 1 month ago
[TECHNOLOGY] 2 sourcesSonicWall warns healthcare cyberattacks stay high despite overall decline in 2026SonicWall’s 2026 Healthcare Protect Brief shows cyber‑attacks on hospitals declined only 17 %, far less than other sectors, driven by exposed remote‑desktop tools, IoT devices and legacy VPNs; ten ransomware —
-
about 1 month ago
[TECHNOLOGY] 5 sourcesRansomware Defense Shifts Toward Resilience and Identity‑Based ProtectionRansomware guidance urges healthcare and Canadian organisations to adopt cyber‑resilience, focusing on identity‑based security as attackers develop tools to disable EDR defenses.
-
about 1 month ago
[TECHNOLOGY] 3 sourcesRansomware attacks surge 48% globally in May 2026May 2026 saw a 48 % global rise in ransomware attacks to 698 incidents, with major growth in Asia and heightened targeting of Android devices and private users.
-
about 2 months ago
[TECHNOLOGY] 2 sourcesAI‑driven ransomware threats push firms toward immutable backup solutionsIT leaders fear AI‑driven ransomware, but many lack immutable backups; CyberSense wins award for AI‑based ransomware recovery platform that verifies backup integrity.
-
about 2 months ago
[TECHNOLOGY] 2 sourcesAI-Driven Healthcare Ransomware Risks and FBI Cyber Range Highlight Expanding Cyber ThreatsAgentic AI in healthcare heightens ransomware risks, while the FBI's new Alabama cyber range simulates attacks across homes, hospitals and infrastructure, highlighting expanding cyber threats.
-
about 2 months ago
[CRIME] 2 sourcesRansomware Surge Driven by AI and Healthcare Data Threatens Global CybersecurityRansomware activity hit record levels in Q1 2026, boosted by AI‑generated phishing and deep‑fakes, while stolen healthcare data fuels a lucrative underground market, raising global cyber risk.
-
about 2 months ago
[HEALTH] 2 sourcesHealthcare data breaches spur cybercrime market and push stronger vendor security rulesHealth‑ISAC urges tighter third‑party governance as TrendAI shows a global cybercrime market exploiting stolen patient data, with ransomware and vendor compromises driving multimillion‑dollar losses.
-
about 2 months ago
[CRIME] 2 sourcesHealthcare data emerges as top cybercrime commodityTrendAI finds stolen health records now drive a mature cybercrime market, with ransomware sales making up 36% of activity and vendors serving as supply‑chain multipliers.
-
2 months ago
[CRIME] 4 sourcesAI‑driven cargo theft surge hits Canada and US supply chainsAI data‑centre demand fuels a surge in high‑value cargo theft in Canada and the US, with losses up 60% to $725 million and criminals using AI for phishing and fake documents.
-
3 months ago
[POLITICS] 2 sourcesU.S. House Appropriations Approves $4M for Cargo Theft Task ForcesU.S. House Appropriations earmarks $4 M for task forces to fight rising cargo theft, praised by the American Trucking Associations.
-
3 months ago
[TECHNOLOGY] 2 sourcesIndiana K‑12 schools face surge in cyberattacks, prompting stronger data‑security measuresIndiana K‑12 schools report a sharp rise in cyberattacks, prompting costly fixes and a push for stronger data‑security practices.
-
3 months ago
[TECHNOLOGY] 2 sourcesSK Shield reports South Korean SMEs take average 106 days to respond to cyber attacksSK Shield says South Korean SMEs need 106 days on average to detect and start responding to cyber attacks, with ransomware and data theft most common.
-
3 months ago
[CRIME] 2 sourcesCanada sees digital fraud loss median CAD $1,301 as attempts outpace global averageCanada's digital fraud attempts exceed the global average, with a median loss of CAD $1,301, mainly from stolen cards.
-
3 months ago
[POLITICS] 2 sourcesU.S. House approves cargo theft prevention bill (CORCA)U.S. House passes the Combating Organized Retail Crime Act to strengthen federal response to cargo theft, now headed to Senate.
-
3 months ago
[TECHNOLOGY] 2 sourcesNigeria's NITDA alerts to AI-driven 'DeepLoad' malware targeting banks and government agenciesNigeria's NITDA warns that AI‑driven 'DeepLoad' malware is stealing banking credentials and data from banks, agencies and citizens.
-
3 months ago
[CRIME] 9 sourcesFBI warns of $725 M surge in cyber‑enabled cargo theftFBI alerts that cyber‑enabled cargo theft losses hit $725 M in US/Canada, urging logistics firms to tighten verification and security.
-
3 months ago
[TECHNOLOGY] 3 sourcesCybercrime Surge Threatens African Enterprises and Global Small BusinessesCybercrime now makes up over 30% of crimes in parts of Africa, prompting calls for stronger institutional defenses and basic security steps for businesses.
-
3 months ago
[TECHNOLOGY] 2 sourcesIndia faces 505 cyber threats per minute as credential theft spikes, report saysIndia logged 265 million cyber detections (505 per minute) in 2025, with credential theft surging against IT firms, report warns.
Sources
24x7mag.com · 4sysops.com · abcmoney.co.uk · affinitymsp.com.au · aktiencheck · analyticsinsight.net · australianmanufacturing.com.au · avantionline.it · b2b-cyber-security.de · bankofalbuquerque.com · bhaskarlive.in · bhconsulting.ie · bitmat.it · bleepingcomputer.com · bookclubz.com · borncity.com · brasil247.com · bright.nl · businessdiary.com.ph · businessnewsthisweek.com · businesstechweekly.com · byline.network · calibre800.com · capminds.com · channelinsider.com · cioafrica.co · countryrebel.com · cryptobriefing.com · culturalpolicy.com · cyberscoop.com · cybersecuritynews.es · dailyguardian.ae · diario21.com.mx · diarioeldia.uy · dicpas.es · digitaljournal.com · digitalmarketreports.com · divebuddies.net · dmarketforces.com · ebizlatam.com · elheraldodesaltillo.mx · ensegundos.do · enterprisesecuritytech.com · expresscomputer.in · fighthistory.com · finance.technews.tw · flagthis.com · gamesite.zoznam.sk
This summary has been updated 1 time: see revision history