You bought the firewall. You paid for the corporate VPN. You did exactly what any consultant would have recommended five years ago. And yet that same equipment can today be an attacker's way in, not because the concept failed, but because nobody updated it.
That is exactly what a real investigation into critical infrastructure in Latin America just documented. It is worth a close look, because it challenges an assumption almost nobody questions.
What we observed
In mid June 2026, threat intelligence firm CloudSEK published its mapping of a campaign it named Operation Escaneo. The target was critical infrastructure in Mexico, with lesser activity in Ecuador and Portugal, across government, tax authorities, utilities, transport, telecom and banking.
CloudSEK confirmed active beacons from at least five victims, with large scale data theft from several of them.
How we observed it
The campaign came to light because of the attackers' own mistake: they left a staging server exposed online. Researchers found an open directory in early 2026 and, from the artifacts left behind, reconstructed the group's entire toolkit.
What they found is why this case matters for any company in the region, not only the five confirmed victims:
- Entry came almost entirely through the perimeter itself. The group kept tuned exploits for known flaws in Fortinet's SSL VPN and Ivanti Connect Secure, public vulnerabilities with patches available for some time, adapted so they would not crash the target system on exploitation.
- A custom reconnaissance engine called Kimera scanned and triaged targets at high speed, feeding them straight into the exploitation stage. This was not a hand picked, artisanal attack. It was an industrial sweep.
- Persistence was quiet and layered: webshells to hold footholds on web servers, encrypted tunnels disguising traffic as normal HTTP, and a compromised Cisco router fitted with a network level tunnel back to the attacker, invisible to any defense that only watches the host.
- Inside the compromised networks, the result was command execution on SAP and Oracle systems, more than 1.3 million personal records stolen from a single transport provider, a full map of one victim's Active Directory, SSL private keys pulled out live, and SAP service account credentials.
Attribution is held with medium confidence: a collective calling itself "Mexican Mafia" or "Pancho Villa", with prior activity against government and judicial targets in Mexico. CloudSEK is clear that the link is not confirmed.
What it means
Here is the twist compared to what we have discussed before in this space about exposed infrastructure. This is not a company with no protection. This is a company with protection, one that bought the firewall, paid for the VPN, but treated that purchase as a one time event instead of an ongoing responsibility.
And it is not an isolated case. Just last week, the US Cybersecurity and Infrastructure Security Agency (CISA) issued another urgent alert on two more critical, actively exploited Fortinet vulnerabilities, demanding immediate patching across federal agencies. Same vendor, one month later, different flaws. The pattern is not that Fortinet is insecure. It is that any perimeter equipment, from any vendor, is a permanent target that demands permanent upkeep.
The tool you bought to protect yourself only protects you while someone keeps maintaining it after the purchase.
What we still can't conclude
We need to be honest about the limits of what we know. Attribution to "Pancho Villa" is medium confidence, not confirmed. There is no public report confirming whether this same campaign, or another with the same pattern, has touched Panama or Central America. The documented investigation is concentrated in Mexico, with lesser activity in Ecuador and Portugal. Extrapolating directly to our region would go beyond the evidence.
What is solid evidence is the technical pattern itself: an unpatched perimeter as the entry point. That does not depend on attribution or geography.
What decision would make sense
This is not about panic, it is about maintenance. If your company depends on a firewall, corporate VPN, or any network edge equipment:
- Confirm it is on the vendor's latest version. Not "updated a year ago", updated now.
- Ask whoever manages your network whether a patch schedule exists, or whether the equipment was installed and never touched again.
- If nobody in your company can answer those two questions with confidence, that is the finding, before considering any new tool.
That, in essence, is the difference between observing before deciding and assuming you are protected because you bought something once.
What additional evidence we need
We will keep watching this: whether a public report surfaces touching Central America or Panama directly, whether patch adoption improves after CISA's alert, and whether clearer attribution emerges. This space updates on evidence, not on a calendar.
Sources: CloudSEK / Infosecurity Magazine (June 18, 2026); CISA / Infosecurity Magazine (July 17, 2026).
First we see. Then we decide.
At Directsales PTY, we don't assume a security tool is working just because it was installed once. We verify what's actually patched and exposed, then decide with evidence, not assumptions.
Do you know, with certainty, when your firewall or VPN was last patched? Most organizations don't find out until an attacker does.
Want to know if your infrastructure has the same kind of exposure? Schedule a technical conversation with Directsales PTY.