Panama faces a cyber threat landscape that reveals significant exposure to targeted attacks against organizations and systems. The country accounts for 2.96% of threats detected in forums, leaks, and the Dark Web in Latin America, despite representing approximately 0.7% of the regional population.
Oydia's October 2025 analysis places Panama's relative risk factor at 4.2 times: more than four times the attack volume projected from its population size.
Malware, ransomware, and phishing among the top threats
In 2024, Panama recorded 4 billion cyberattack attempts. Mastercard's Cyber Insights Report Panama identifies malware at 32%, ransomware at 23%, supply chain attacks at 19%, and phishing at 13% among the country's most frequent threats.
The landscape also includes incidents recorded in Panama and elsewhere in the region.
Recent figures show a new surge
Panama recorded 4.8 billion cyberattack attempts in 2025, 20% more than the previous year. By the end of the first half of 2026, the figure had already reached 1.9 billion. Over the last three years, phishing has consolidated its position as one of the primary attack vectors.
Cyberattacks are increasing across Latin America
Panama's data fits into a broader regional trend. During the first quarter of 2025, cyberattacks in Latin America increased by 108% year over year. The region averaged 2,640 attacks per organization each week, compared with 1,925 globally.
In the first half of 2025, Latin American organizations experienced an average of 2,716 weekly attacks, 39% above the global average of 1,955. At the same time, ransomware has expanded beyond encryption to include data-leak extortion.
Email remains among the most frequent attack vectors: 62% of malicious files are delivered through this channel, primarily through phishing and malware. The attack surface also includes vulnerabilities in applications, operating systems, and services; supply chain attacks; insecure configurations; weak policies; and monitoring limitations. People are also part of this surface through phishing, scams, and identity impersonation.
New forms of impersonation
Deepfakes—AI-generated content capable of simulating real human faces, voices, and gestures—have joined this landscape. This technology can be used for identity impersonation, fraud, or manipulation.
Measures to address this threat include identity verification through secondary channels, employee training to recognize deepfake indicators, and clear internal policies for sensitive operations.
Preparedness as part of the strategy
As threats evolve, a cybersecurity strategy must connect four pillars:
Essential measures include multi-factor authentication for critical services, backups with restoration testing, EDR or anti-malware solutions, updated IT assets, and a formal security hardening process.
For small and medium-sized enterprises, measures can be expanded to include:
- Access policies and data governance.
- Network segmentation and centralized monitoring.
- Phishing simulations and vendor reviews.
- Security testing and vulnerability management.
- Formal incident response plans.
“Our people are the first firewall.”
The evolution of cyber threats means prevention, detection, response, and recovery must be managed as one strategy. Preparedness starts with understanding exposure.
Assess your level of exposure
Ten questions, five minutes, and immediate results to identify potential security improvements for your organization.
Start assessmentSources and methodology
- Oydia regional exposure analysis, October 2025.
- Mastercard Cyber Insights Report Panama, 2024 figures.
- FortiGuard Labs 2025 and H1 2026 figures, as reported by Panamá América.
- Check Point Research, Global Cyber Attack Report Q1 2025.
- Check Point Research, Latin America 2025 Mid-Year Cyber Snapshot.
