Pular para o conteúdo principal
Close
Security

Brazil in 3rd Place Globally in Ransomware: The Gentlemen, FortiGate and 241 Days of Dwell Time

Gabriel Ferraresi· CEO | Tech86July 18, 20263 min
securityransomwarethe-gentlemenfortigatecve-2024-55591edrsocmdrpixbacen

Brazil debuted in 3rd place globally in ransomware. June 2026. According to Ransomware.live, there were 23 attacks in one month, behind only the United States (199) and Germany (49). The first time Brazil entered the Top 10 since Ransomware.live started publishing data. We watched the curve climb throughout 2026 and the signal is clear: this is not a one-off spike — it is a structural symptom.

The group behind the jump: The Gentlemen

The group behind the jump is called The Gentlemen. According to Ransomware.live, it emerged in mid-2025 as a split from Qilin. In one year, it went from zero to 580 victims in 77 countries. In Q2 2026, it led the global ranking of ransomware groups.

The method is what sets it apart. According to the operation's documentation, the group maintains a curated database of 14,700 pre-compromised FortiGate devices. The exploitation uses CVE-2024-55591, an authentication bypass with CVSS 9.8. When they want to attack a company, they pick an already-compromised FortiGate from the list and enter with super-administrator access. No initial phishing, no brute force — the door was already open.

According to Ransomware.live, Brazil is the 4th most targeted country by The Gentlemen, with 19 confirmed victims in Q1 2026. The concentration of vulnerable FortiGate in Brazilian infrastructure is the reason.

The cost: Pix, BMP, and BTG Pactual

Reported cases in the Brazilian payments ecosystem show the scale. C&M Software, July 2025: access to the Pix payment system, estimated loss over 1 billion reais. BMP alone lost 541 million reais. BTG Pactual, March 2026: 100 million reais stolen via Pix, operations temporarily suspended.

We do not present these cases as ransomware incidents specifically — they are payment system compromises via Pix, related to the broader financial threat ecosystem. But the pattern is the same: unauthorized access, long dwell time, late detection.

According to IBM Cost of a Data Breach 2025, the average data breach cost in Brazil is 7.19 million reais. According to Sophos State of Ransomware 2025, 73% of Brazilian companies have been ransomware victims. Brazil is no longer a secondary target — it is one of the top three.

FortiBleed and CTIR Gov Recommendation 12/2026

According to CTIR Gov, Recommendation 12/2026 issued on June 24 points to 39 Brazilian domains affected and 309 compromised credentials. The FortiBleed campaign exposed 73,932 FortiGate devices globally. Brazil in 11th place with 1,737 devices.

The correlation with The Gentlemen's jump is direct. The group chooses targets where there is vulnerable FortiGate. Brazil has vulnerable FortiGate. The math is simple — and the result shows up in the ranking.

What Tech86 implements

We implement five layers of defense that cover exactly The Gentlemen's kill chain:

  1. Behavioral EDR with automated response — isolates the host in seconds when encryption behavior is detected. It does not wait for signatures, it watches behavior.
  2. SOC 24/7 with MDR — according to IBM Cost of a Data Breach 2025, the average dwell time in Brazil is 241 days. The SOC shortens this to hours by correlating alerts that get lost in the noise.
  3. Annual pentest (mandatory) — BACEN Resolução 5.274 requires it. The pentest finds the breach before the criminal. CVE-2024-55591 should have been found internally.
  4. Awareness with phishing simulation — most attacks start with human error. Phishing is the number one ransomware vector.
  5. WAF with Virtual Patching — closes the front door while the official patch does not arrive. Critical for CVE-2024-55591, where Fortinet's patch cycle may lag.

Conclusion

Brazil entered the ranking because of vulnerable FortiGate and 241 days of dwell time. Attackers choose easy targets. Brazil is easy. While the global detection average drops, Brazil's remains at 241 days — eight months of window for the attacker to map, exfiltrate, and position the ransomware. We help companies close that window before The Gentlemen picks the next FortiGate from the list.

blog.cta_consulting_title

blog.cta_consulting_subtitle

Ransomware Defense and MDR

Frequently Asked Questions

According to Ransomware.live, Brazil recorded 23 attacks in one month, behind only the United States (199) and Germany (49). It was the first time Brazil entered the Top 10 since Ransomware.live started publishing data. The concentration of vulnerable FortiGate devices in Brazilian infrastructure is the structural reason.

According to Ransomware.live, The Gentlemen emerged in mid-2025 as a split from Qilin. In one year, they went from zero to 580 victims in 77 countries and led the global ranking of ransomware groups in Q2 2026. The method: 14,700 pre-compromised FortiGate devices, exploiting CVE-2024-55591 (authentication bypass with CVSS 9.8). The group maintains a curated database of already-breached Fortinet firewalls and enters with super-administrator access.

CVE-2024-55591 is an authentication bypass in FortiGate firewalls with CVSS 9.8. It allows an attacker to enter with super-administrator access without valid credentials. The Gentlemen maintains a curated database of 14,700 FortiGate devices already compromised via this vulnerability. When they want to attack a company, they pick a FortiGate from the list and enter directly.

According to IBM Cost of a Data Breach 2025, the average data breach cost in Brazil is 7.19 million reais. Reported cases in the Pix ecosystem include C&M Software (over 1 billion reais in estimated losses, with BMP alone losing 541 million reais) and BTG Pactual (100 million reais stolen via Pix in March 2026). According to Sophos State of Ransomware 2025, 73% of Brazilian companies have been ransomware victims.

Dwell time is the time an attacker remains inside the network before being detected. According to IBM Cost of a Data Breach 2025, the average dwell time in Brazil is 241 days. In 241 days, the attacker maps the network, exfiltrates data, moves laterally, and positions the ransomware. Without a 24/7 SOC with MDR, the company discovers the attack when encryption is already finished — too late.

Blog — Get in Touch

Have a question about our articles or services? Our team is ready to help.

Schedule a Meeting

Book a time slot.

Schedule Now

Email

Send us a message.

[email protected]

WhatsApp

Quick conversation.

Address

Avenida Paulista, 1636 - São Paulo - SP - 01310-200

Tech86 Specialist

Online now

Hello! How can we help scale your business today?

Tech86 Engineering

We Value Your Privacy

We use cookies and similar technologies to optimize your experience, analyze site traffic, and personalize content. By clicking "Accept All", you agree to the use of all cookies. Read our Privacy Policy.