AI-Driven Ransomware Campaign Targets Latin American Enterprises
Article Content
- •AI coding assistants are being weaponized in ransomware attacks across Latin America.
- •Over two dozen organizations have been affected, with significant data theft reported.
- •QRishing activity in Mexico accounts for nearly 70% of incidents in Latin America.
A ransomware affiliate known as Azazel has utilized an AI coding assistant to conduct attacks within enterprise networks, affecting over two dozen organizations across six countries, including Mexico. The campaign, linked to the Gentlemen ransomware group, involved the use of stolen development credentials and remote command execution, leading to significant data theft. Reports indicate that AI-assisted ransomware has reached Mexico, with a notable increase in QRishing activities, where nearly 70% of such incidents in Latin America originated. The attacks have impacted various sectors, including logistics, insurance, and pharmaceuticals. Additionally, South Korean authorities are investigating similar attacks against financial institutions, where AI agents exploited vulnerabilities, resulting in data breaches affecting 68,000 individuals. The growing trend of AI-assisted cyber threats highlights the need for organizations to bolster their defenses against increasingly sophisticated attacks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Gentlemen in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What organizations are affected?
How is AI being used in these attacks?
What should organizations do to defend against this threat?
Continue Reading
Veradigm Data Breach Exposes Patient Information via Vendor Compromise Veradigm, a healthcare technology company, reported a data breach involving a third-party vendor's systems, where hackers accessed personal data, including Social Security numbers, of some patients. The breach was disclosed in an 8-K filing with the SEC on September 8, 2026. The unauthorized party obtained credentials…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…