IBOV 185,147.15 ▼ 0.02% IPSA 11,315.26 ▼ 1.14% IPC MEX 64,866.61 ▼ 0.87% MERVAL 3,041,993 ▼ 0.23% COLCAP 2,556.17 ▲ 0.46% BVL PERÚ 59,789.81 ▼ 0.24% USD/BRL5.13▼ 0.03% USD/MXN16.91▲ 0.20% USD/CLP932.88▼ 0.18% USD/COP3,115▼ 0.46% USD/PEN3.36▲ 0.14% USD/ARS1,510▲ 0.08% USD/UYU40.24— 0.00% USD/PYG5,947— 0.00% USD/BOB12.40— 0.00% USD/DOP59.00— 0.00% USD/CRC448.67— 0.00% USD/GTQ7.63— 0.00% USD/HNL26.84— 0.00% USD/NIO36.62— 0.00% USD/VES811.71▲ 0.66% USD/PAB1.00— 0.00% USD/BZD2.00— 0.00% USD/JMD 157.28 — 0.00% USD/TTD6.71— 0.00% EUR/BRL5.96▲ 0.18% BRENT 88.88 ▼ 0.03% WTI 83.11 ▼ 0.11% IRON ORE 161.91 — — COPPER 6.61 ▲ 0.03% GOLD 4,461 ▲ 1.78% SILVER 65.59 ▲ 1.26% SOY 1,184 ▲ 3.20% CORN 480.50 ▲ 10.02% WHEAT 655.00 ▲ 3.93% COFFEE 317.25 ▼ 5.51% SUGAR 16.43 ▼ 1.79% ORANGE JUICE 138.55 ▼ 0.47% COTTON 85.03 ▲ 2.33% COCOA 5,719 ▲ 3.18% BEEF 223.60 ▼ 3.93% CATTLE 339.10 ▼ 3.16% LITHIUM 75.20 ▲ 1.47% PETR4 41.64 ▼ 0.05% VALE3 72.97 ▲ 0.83% ITUB4 38.60 ▼ 1.03% BBDC4 16.85 ▲ 0.36% ABEV3 14.89 ▼ 0.80% BBAS3 19.37 ▲ 0.47% B3SA3 14.26 ▼ 0.21% WEGE3 47.59 ▲ 0.49% PRIO3 59.14 ▼ 0.19% SUZB3 41.33 ▲ 2.35% RENT3 34.68 ▼ 0.09% AZZA3 15.89 ▼ 2.63% CSAN3 3.22 ▼ 1.83% RAIZ4 0.25 — 0.00% PCAR3 2.75 ▼ 0.36% GMAT3 3.65 ▼ 1.08% PSSA3 48.13 ▼ 0.54% CVCB3 1.33 ▼ 2.92% POSI3 3.36 ▲ 2.44% SLCE3 13.34 ▲ 0.30% NATU3 8.14 ▼ 0.73% IBOV 185,147.15 ▼ 0.02% IPSA 11,315.26 ▼ 1.14% IPC MEX 64,866.61 ▼ 0.87% MERVAL 3,041,993 ▼ 0.23% COLCAP 2,556.17 ▲ 0.46% BVL PERÚ 59,789.81 ▼ 0.24% USD/BRL 5.16 ▲ 0.01% USD/MXN 17.06 ▼ 0.24% USD/CLP 913.98 ▲ 0.04% USD/COP 3,140 ▲ 0.03% USD/PEN 3.36 ▼ 0.66% USD/ARS 1,493 ▲ 0.10% USD/UYU 40.27 ▲ 1.24% USD/PYG 5,939 ▲ 1.68% USD/BOB 11.64 ▼ 0.76% USD/DOP 58.34 ▲ 1.25% USD/CRC 445.92 ▲ 0.89% USD/GTQ 7.62 ▲ 2.21% USD/HNL 26.79 ▲ 1.57% USD/NIO 36.62 ▲ 0.69% USD/VES 762.44 ▼ 0.13% USD/PAB 1.00 — 0.00% USD/BZD 2.00 — 0.00% USD/JMD 157.28 — 0.00% USD/TTD 6.70 ▲ 0.61% EUR/BRL 5.95 ▲ 1.01% BRENT 88.88 ▼ 0.03% WTI 83.11 ▼ 0.11% IRON ORE 161.91 — — COPPER 6.61 ▲ 0.03% GOLD 4,461 ▲ 1.78% SILVER 65.59 ▲ 1.26% SOY 1,184 ▲ 3.20% CORN 480.50 ▲ 10.02% WHEAT 655.00 ▲ 3.93% COFFEE 317.25 ▼ 5.51% SUGAR 16.43 ▼ 1.79% ORANGE JUICE 138.55 ▼ 0.47% COTTON 85.03 ▲ 2.33% COCOA 5,719 ▲ 3.18% BEEF 223.60 ▼ 3.93% CATTLE 339.10 ▼ 3.16% LITHIUM 75.20 ▲ 1.47% PETR4 41.64 ▼ 0.05% VALE3 72.97 ▲ 0.83% ITUB4 38.60 ▼ 1.03% BBDC4 16.85 ▲ 0.36% ABEV3 14.89 ▼ 0.80% BBAS3 19.37 ▲ 0.47% B3SA3 14.26 ▼ 0.21% WEGE3 47.59 ▲ 0.49% PRIO3 59.14 ▼ 0.19% SUZB3 41.33 ▲ 2.35% RENT3 34.68 ▼ 0.09% AZZA3 15.89 ▼ 2.63% CSAN3 3.22 ▼ 1.83% RAIZ4 0.25 — 0.00% PCAR3 2.75 ▼ 0.36% GMAT3 3.65 ▼ 1.08% PSSA3 48.13 ▼ 0.54% CVCB3 1.33 ▼ 2.92% POSI3 3.36 ▲ 2.44% SLCE3 13.34 ▲ 0.30% NATU3 8.14 ▼ 0.73%
since 2009
Monday, September 7, 2026

Latin America Markets

Gunra Ransomware Hits Three Uruguayan Firms in Three Months

By · September 7, 2026 · 4 min read

Daily Brief

The morning intel from across Latin America. Free.

By subscribing you agree to our privacy policy. We never share your email.

Uruguay · Cybersecurity

A ransomware group called Gunra has posted three Uruguayan companies on its leak site in less than three months. The victims include an ad agency, a commercial interiors maker, and a law firm.

Key Facts

  • What happened:Gunra ransomware listed three Uruguayan companies on its leak site.
  • Who it hits:Victims: an ad agency, a commercial interiors maker, and a law firm.
  • How big:Gunra claims it stole 40 GB, 30 GB, and 300 GB of data.
  • The catch:The law firm has not confirmed the attack, so its name is withheld.
  • What comes next:Gunra is under FBI watch, according to Uruguayan newspaper El Observador.
Gunra ransomware - computer screen with warning message
Avenida 18 de Julio in Montevideo. Three Uruguayan companies have appeared on the Gunra leak site since June.
One-stop reference
Company Intelligence
Every listed company in Latin America — financials, ownership and structure for 1,450+ companies across 26 exchanges, in one place.
Browse the directory →
RT
Ask Rio Times
Latin American markets, currencies and companies.
Open the full Ask Rio Times →

Gunra ransomware has listed three Uruguayan companies on its leak site in less than three months. The victims include an advertising agency, a commercial interiors maker, and a law firm.

Three Uruguayan Victims in Three Months

Gunra ransomware has posted three Uruguayan companies on its leak site since June 2026. The first victim, an advertising agency, appeared on 12 June 2026.

The second, a company that designs and manufactures commercial interiors, was listed on 30 June 2026. The third, a law firm, was added on 4 September 2026.

Sectors, Not Names, in Initial Report

The first report, from Uruguayan newspaper El Observador, described the victims by sector only. It did not publish the company names.

Threat-intelligence trackers have separately identified the law firm as Blanco & Etcheverry. The firm has not commented on the alleged attack.

What Is Ransomware and Double Extortion?

Ransomware is malicious software that encrypts a victim’s files. Attackers demand payment to unlock them.

Double extortion adds a second threat: attackers steal data before encrypting. They then threaten to publish the stolen data on a public leak site if the victim does not pay.

Gunra’s Claims About Data and Revenue

Gunra’s leak site claims it published 40 GB of files from the advertising agency after non-payment. It also claims it stole 30 GB from the commercial interiors company.

For the law firm, Gunra says it leaked 300 GB of data and estimates the firm’s revenue at US$5 million. These are the group’s own claims, not verified by independent sources.

Gunra Under FBI Watch

El Observador reported on 7 September 2026 that Gunra is under the FBI’s watch. The article described how Gunra operates.

Gunra uses a leak site with a countdown clock to pressure victims. It demands payment and publishes stolen files when victims do not pay.

Uruguay’s Cybersecurity Response

Uruguay’s cybersecurity bodies have not yet issued a public statement about these specific attacks. The government’s national cybersecurity agency, known as CERTuy, has not commented.

Experts advise companies to back up data and train staff to spot phishing emails. They also recommend having a response plan ready.

What Victims Should Do

Companies hit by ransomware should not pay the ransom, experts say. Paying encourages more attacks and does not guarantee data recovery.

Instead, they should report the incident to authorities and seek help from cybersecurity professionals. They should also notify affected customers and partners.

Who Gunra Are

Gunra surfaced in April 2025. The United States FBI and the cybersecurity agency CISA issued a joint advisory on the group on 10 August 2026.

That advisory says Gunra appears to be built on Conti ransomware code leaked in 2022. Conti was one of the largest criminal ransomware operations before it broke up.

Frequently Asked Questions

What is Gunra ransomware?

Gunra is an international ransomware group that uses double extortion. It encrypts files and threatens to leak stolen data if victims do not pay.

Which Uruguayan companies were hit?

Gunra listed an advertising agency, a commercial interiors maker, and a law firm. The law firm is believed to be Blanco & Etcheverry, but it has not confirmed the attack.

How much data was stolen?

Gunra claims it stole 40 GB from the ad agency, 30 GB from the interiors maker, and 300 GB from the law firm. These figures are unverified.

Is the FBI involved?

El Observador reported that Gunra is under FBI watch. However, there is no official confirmation of an FBI investigation.

Sources: El Observador; FBI and CISA joint advisory, 10 August 2026; ransomware.live.

This article was produced by The Rio Times’ automated newsroom system. How we use AI · Report an error

LatAm Markets: Live Signals → — real-time movers, turnover leaders and FX across Latin America.

Read More from The Rio Times

The Rio Times · Power Map
See who really holds power in Latin America
Click to open the Power Map

Rotate for Best Experience

This report is optimized for landscape viewing. Rotate your phone for the full experience.