Find notable cyber news and cases, enriched with sources, timelines, and signals.

Latin American organizations face a sustained weekly cyberattack surge

Target Trend
First reported
Last updated
Happening score
H score 19
1 unique sources, 2 articles

Summary

Hide ▲

Latin American organizations are seeing a 53% year-over-year rise in weekly cyberattacks, and the region has become the most heavily targeted on the planet. The trend matters because it combines higher attack volume with a delivery mix that favors email phishing and high-pressure targeting of healthcare and financial services.

Related Happenings

The Gentlemen affiliate-driven RaaS expansion and enterprise scale-up

Threat Actor Meta
First: 21.04.2026 17:00 Last: 21.04.2026 17:00 Sources 1

About this happening: **The Gentlemen ransomware gang** is using a **legitimate vulnerable driver** to defeat enterprise defenses, weaponizing **ThrottleStop.sys** as **ThrottleBlood.sys** to kill **AV...

UK organizations saw blocked cyber-attacks rise 36% YoY in February 2026

Target Trend
First: 11.03.2026 12:30 Last: 11.03.2026 12:30 Sources 1

About this happening: **UK organizations** faced **1504 blocked cyber-attacks per organization per week** in **February 2026**, a **36% YoY increase** that signals a worsening threat environment. That...

Middle East retaliatory hacktivist DDoS campaign

Campaign
First: 04.03.2026 19:21 Last: 04.03.2026 19:21 Sources 1

About this happening: A **retaliatory hacktivist DDoS campaign** has surged across the **Middle East**, creating broad disruption risk for **government** and **public-infrastructure** targets. Research...

Europol-coordinated Tycoon2FA takedown

Law Enforcement
First: 04.03.2026 19:01 Last: 04.03.2026 19:01 Sources 1

About this happening: **Europol** coordinated a law-enforcement operation that **seized 330 domains** tied to **Tycoon2FA**, disrupting a **phishing-as-a-service** platform used for **credential theft*...

Latest development: 23.03.2026 23:52

CrowdStrike observed Tycoon2FA return to pre-disruption activity levels within days after the March 4, 2026 Europol-led takedown, with daily campaign volumes on March 4 and March 5, 2026 falling to 25% of pre-disruption levels before rebounding to early 2026 levels. The phishing-as-a-service platform continued using largely unchanged TTPs against Microsoft 365 and Gmail accounts and remained active in malicious email campaigns, BEC, email thread hijacking, cloud account takeovers, and malicious SharePoint links.

Middle East hacktivist surge targets government, banking, aviation and telecom sectors

Target Trend
First: 02.03.2026 17:00 Last: 02.03.2026 17:00 Sources 1

About this happening: **More than 150 hacktivist incidents** were recorded between **February 28 and March 1, 2026**, marking a sharp surge in **Middle East** targeting that raised spillover risk for o...

Timeline

  1. 05.03.2026 16:00 3 articles · 2mo ago

    Check Point flags Latin America as the most targeted region

    Technical Analysis Update

    In March 2026, Check Point reported that Latin American organizations were facing about 3,100 cyber threats per week, after a 53% year-over-year rise in regional attacks that made the region the most heavily targeted on the planet. The same analysis said malicious-file delivery in Latin America was dominated by email rather than the web, and that phishing, infostealers, banking malware, botnets, healthcare targeting, and financial services targeting were especially prominent across the region.

    Show sources