We use cookies to optimize your experience, analyze traffic, and personalize ads. Please choose whether you accept our use of non-essential cookies. Read More
Brazil is not only one of the most attacked countries in the world, it is increasingly becoming a real-time laboratory for how industrialized cybercrime operates. In the first half of 2026, systems belonging to companies, institutions, and individuals in Brazil were targeted by 249.3 billion attempted attacks and malicious cyber activities, according to data published by Correio Braziliense based on the Global Threat Landscape report produced by Fortinet.
The report from the Contábeis portal confirms the same number, pointing out that the survey was presented during the Fortinet Cybersecurity Summit Brazil 2026. The InterGATE reinforces the seriousness of the data by highlighting that the volume recorded between January and July 2026 already exceeds the total recorded in the entire year of 2025, a clear sign of acceleration.
And this “2025 total” is also impressive: according to the IT Forum, based on the FortiGuard Labs Global Threat Landscape 2026 report, Brazil accounted for 753.8 billion attempted attacks throughout 2025. TI Inside details this scenario and goes further, showing the regional dimension of the problem: the country was the target of more than 753.8 billion attempted cyberattacks in 2025 alone, concentrating 84% of all attacks recorded in Latin America, which places Brazil among the seven most attacked countries in the world.
If the current trend continues, 2026 should solidify Brazil not only as a regional leader, but as one of the most strategic targets of global cybercrime. And this changes how every Brazilian company, not just large corporations, needs to think about digital security.
Fortinet's surveys use the Cyber Kill Chain, a framework that maps each stage of an attack, from initial reconnaissance to the final action on the target. According to Contábeis, the highlight of the research is the 44% growth in active scans compared to the entire year of 2025, totaling 9 billion in the first six months of 2026 alone, a method used by cybercriminals to monitor vulnerabilities before an actual attack.
Regarding the end of 2025, the IT Forum details that the country registered 743 billion denial-of-service (DDoS) attempts, a 119% increase compared to the previous year, in addition to 35,000 ransomware incidents. The Bahia Econômica portal, publishing the full Fortinet release, adds other relevant factors: 1.4 billion brute-force attacks, a 70% increase compared to 2024, and 3.6 billion vulnerability exploitation attempts, plus 5 billion active scans in the reconnaissance phase alone. According to this survey, Brazil concentrated 187.5 million malware distribution activities in 2025, a 535% increase compared to 2024, and 89 million botnet-related actions.
Read also: Ransomware in Brazil: attacks hit record high in 2026
The most relevant data point for 2026 is not just the volume, but the speed and sophistication of the attacks. According to a report by IT Forum, in 2026 there will be an additional 79% increase and a shift towards the theft of more comprehensive datasets, enabled by agentic AI.
The Inforchannelalso drew attention to this factor when reporting on the 2025 report: the availability of crime kits as a service, such as WormGPT, FraudGPT, and BruteForceAI, contributed to a 389% increase compared to the previous year. This shows how generative AI tools and autonomous agents are being used by criminal groups to automate reconnaissance, customize social engineering attacks, and scale operations that previously required entire teams, reducing the cost and time needed to launch industrial-scale campaigns.
The same survey, according to Inforchannel, points to a structural change in the origin of cloud incidents: throughout 2025, the majority of confirmed cloud incidents originated from stolen, exposed, or misused credentials, and not from direct exploitation of the infrastructure. In other words, the weakest link is no longer just technology, but human identity, access, and behavior.
According to information gathered by TI Inside in another report on the subject, the three sectors most targeted by cybercriminals in Brazil in 2025 were manufacturing, business services, and retail, while Bahia Econômica registered seasonal peaks in other segments: October was the most targeted month, with 198 billion attempted attacks received in that period alone, with government, education, and energy services as the main targets, along with instabilities in cloud services that affected the daily use of the population.
An executive from Fortinet, quoted by TI Inside, sums up the background to this growth well: Brazil has seen significant progress in malware distribution and a substantial increase in denial-of-service attacks, movements directly linked to the acceleration of the country's digitalization, especially in critical services such as banks and e-commerce platforms, and the more dependent companies become on these services, the greater their exposure to cybercrime.
Black Friday fraud: how to protect your operation
Fortinet's numbers are not just market statistics; they are a direct indicator of operational, financial, and reputational risk. A report from the itshow, based on a study by IBEF-PR, reinforces this point: in 2026, cyberattacks will lead the ranking of risks for Brazilian companies, surpassing economic instability and political crises, and a third of national organizations have already recorded losses of at least US$1 million in the last three years.
This repositions cybersecurity: it has ceased to be an exclusive topic for the IT team and has become a matter for boards, business continuity, and regulatory compliance, especially in light of the LGPD (Brazilian General Data Protection Law), which directly holds companies responsible for failures in the protection of personal data.
In practice, the scenario portrayed by these reports exposes three recurring gaps in Brazilian companies:
Faced with a volume of attacks that is growing faster than the manual response capacity of teams, the answer cannot be to buy yet another one-off tool. What these surveys make clear is that effective security stems from governance, centralized visibility, clear access policies, continuous monitoring, and incident response integrated into the business strategy, not separate from it.
This is precisely the principle that guides Skyone's vision of digital security: treating cybersecurity not as an isolated product, but as part of a data and infrastructure governance that accompanies the company from the endpoint to the cloud. This involves 24/7, identity and credential management, incident response, compliance with the LGPD (Brazilian General Data Protection Law), and an intelligence layer that anticipates threats instead of just reacting to them—the same logic of continuous protection that the data disclosed by these sources shows is increasingly necessary.
If your company still treats digital security as an IT project and not as a corporate governance, the 2026 figures are a clear sign that this bill may come due sooner than you think.
Want to understand how to structure governance and digital security in an integrated way for your company? Discover Skyone's perspective on the subject and talk to our experts.
Transform Your Business with Skyone. Request a demo or schedule a call with our experts to discover how Skyone can accelerate your digital strategy.
Have a question? Talk to a specialist and get all your questions about the platform answered.