New Microsoft data shows a highly uneven regional threat landscape, while ransomware continues rising sharply.
Redmond, United States
A new Microsoft cybersecurity report shows that the United States remains by far the most frequently observed target of state-linked cyber activity in the Americas, while countries including Brazil, Canada, Chile, Colombia, Mexico and Peru also appear prominently in the regional picture.
The Microsoft Digital Defense Report 2026 analyzed activity detected between July 2025 and June 2026. During that period, the United States recorded 531 observed state-linked cyber events, vastly more than any other country in the hemisphere. Brazil followed with 27, while Canada registered 26.
The numbers then fall sharply. Chile, Colombia and Mexico each recorded nine observed events, while Peru registered seven, Ecuador five, Argentina four and the Dominican Republic three.
Those figures should not be interpreted as a direct ranking of which countries are least secure. The volume of detected activity depends on many factors, including the size of the digital economy, the number of strategic targets, cloud usage, geopolitical relevance and the visibility available to Microsoft’s security systems.
The report also highlights ransomware as a separate and growing problem. In the United States, recorded ransomware incidents increased from 724 in the previous reporting period to 1,087, a rise of roughly 50 percent. Canada saw an even steeper proportional increase, from 98 to 172 cases.
Latin American countries face a different mix of exposure. Governments, banks, telecommunications providers, energy companies and public institutions increasingly depend on interconnected digital infrastructure, while many organizations still operate with uneven cybersecurity maturity and legacy systems.
Artificial intelligence is adding another layer to the threat environment. Cybercriminals and state-linked groups can now use AI tools to accelerate reconnaissance, generate convincing phishing content, automate parts of malware development and scale attacks more quickly than before.
Credential theft remains particularly dangerous because compromising a single account can provide access to broader corporate or government systems. The report also warns that newly discovered vulnerabilities can sometimes be exploited within less than 24 hours, reducing the time available for organizations to install patches and close security gaps.
For countries such as Mexico, Colombia and Peru, the figures are a reminder that cybersecurity is increasingly part of national security rather than simply an IT problem. Financial systems, government databases, logistics networks, energy infrastructure and communications can all become strategic targets.
The regional pattern also reveals a broader reality. Cyber activity does not follow borders in the same way traditional conflict does. A malicious campaign can be launched from one continent, routed through another and affect institutions thousands of kilometers away within minutes.
In the digital security race, the most important question is no longer whether a country will be targeted, but how quickly it can detect, contain and recover from the attack.