Brazil debuted in 3rd place globally in ransomware. June 2026. According to Ransomware.live, there were 23 attacks in one month, behind only the United States (199) and Germany (49). The first time Brazil entered the Top 10 since Ransomware.live started publishing data. We watched the curve climb throughout 2026 and the signal is clear: this is not a one-off spike — it is a structural symptom.
The group behind the jump: The Gentlemen
The group behind the jump is called The Gentlemen. According to Ransomware.live, it emerged in mid-2025 as a split from Qilin. In one year, it went from zero to 580 victims in 77 countries. In Q2 2026, it led the global ranking of ransomware groups.
The method is what sets it apart. According to the operation's documentation, the group maintains a curated database of 14,700 pre-compromised FortiGate devices. The exploitation uses CVE-2024-55591, an authentication bypass with CVSS 9.8. When they want to attack a company, they pick an already-compromised FortiGate from the list and enter with super-administrator access. No initial phishing, no brute force — the door was already open.
According to Ransomware.live, Brazil is the 4th most targeted country by The Gentlemen, with 19 confirmed victims in Q1 2026. The concentration of vulnerable FortiGate in Brazilian infrastructure is the reason.
The cost: Pix, BMP, and BTG Pactual
Reported cases in the Brazilian payments ecosystem show the scale. C&M Software, July 2025: access to the Pix payment system, estimated loss over 1 billion reais. BMP alone lost 541 million reais. BTG Pactual, March 2026: 100 million reais stolen via Pix, operations temporarily suspended.
We do not present these cases as ransomware incidents specifically — they are payment system compromises via Pix, related to the broader financial threat ecosystem. But the pattern is the same: unauthorized access, long dwell time, late detection.
According to IBM Cost of a Data Breach 2025, the average data breach cost in Brazil is 7.19 million reais. According to Sophos State of Ransomware 2025, 73% of Brazilian companies have been ransomware victims. Brazil is no longer a secondary target — it is one of the top three.
FortiBleed and CTIR Gov Recommendation 12/2026
According to CTIR Gov, Recommendation 12/2026 issued on June 24 points to 39 Brazilian domains affected and 309 compromised credentials. The FortiBleed campaign exposed 73,932 FortiGate devices globally. Brazil in 11th place with 1,737 devices.
The correlation with The Gentlemen's jump is direct. The group chooses targets where there is vulnerable FortiGate. Brazil has vulnerable FortiGate. The math is simple — and the result shows up in the ranking.
What Tech86 implements
We implement five layers of defense that cover exactly The Gentlemen's kill chain:
- Behavioral EDR with automated response — isolates the host in seconds when encryption behavior is detected. It does not wait for signatures, it watches behavior.
- SOC 24/7 with MDR — according to IBM Cost of a Data Breach 2025, the average dwell time in Brazil is 241 days. The SOC shortens this to hours by correlating alerts that get lost in the noise.
- Annual pentest (mandatory) — BACEN Resolução 5.274 requires it. The pentest finds the breach before the criminal. CVE-2024-55591 should have been found internally.
- Awareness with phishing simulation — most attacks start with human error. Phishing is the number one ransomware vector.
- WAF with Virtual Patching — closes the front door while the official patch does not arrive. Critical for CVE-2024-55591, where Fortinet's patch cycle may lag.
Conclusion
Brazil entered the ranking because of vulnerable FortiGate and 241 days of dwell time. Attackers choose easy targets. Brazil is easy. While the global detection average drops, Brazil's remains at 241 days — eight months of window for the attacker to map, exfiltrate, and position the ransomware. We help companies close that window before The Gentlemen picks the next FortiGate from the list.