On August 13, 2026, cybersecurity firm VECERT Analyzer issued a preventive alert about a distributed denial-of-service (DDoS) campaign targeting Uruguay's state infrastructure. The attack, claimed by the pro-Palestinian hacker group Hider Nex under #OpUruguay, has not been officially confirmed but could disrupt key government websites, including Parliament and the Judiciary.

In a world where digital borders are as critical as physical ones, Uruguay has become the latest target of a politically motivated cyber offensive. On August 13, 2026, the cyber intelligence platform VECERT Analyzer raised a preventive alert about a massive DDoS (Distributed Denial of Service) attack aimed at the country's state infrastructure. The attack was claimed by an actor known as Hider Nex, linked to pro-Palestinian cyberactivist groups, through official Telegram channels.

This alert, shared on VECERT's official X (formerly Twitter) account, indicates the operation is part of #OpUruguay and has a geopolitical activist motive. While the attack's status is listed as unconfirmed, centralized monitoring detected a Layer 7 volumetric / HTTP Flood campaign against several Uruguayan government portals.

Targeted Government Websites

According to the VECERT report, the specific targets include:

  • Portal Único del Estado Uruguayo (Uruguay's Single State Portal)
  • Parlamento de Uruguay (Parliament)
  • Poder Judicial de Uruguay (Judiciary)
  • Tribunal de Cuentas (TCR) (Court of Accounts)
  • Tribunal de lo Contencioso Administrativo (TCA) (Administrative Litigation Court)
  • Banco de Previsión Social (BPS) (Social Welfare Bank)

The report mentions that Check-Host verification links show supposed interruptions and anomalous traffic, with SSL/HTTP 403 errors and connection drops on the affected infrastructure.

Preventive Technical Recommendations

VECERT also published a series of recommendations to mitigate the impact:

  • Activation of DDoS protection rules on WAF/CDN services (Cloudflare, Incapsula, Akamai) that protect the .gub.uy domain.
  • Temporary geographic blocking of traffic from ASNs or regions not critical to Uruguayan public administration.
  • Endpoint monitoring and log analysis on load balancers and reverse proxies (NGINX) to identify botnet signatures and recurring IP addresses.

Context and Background

DDoS attacks work by overwhelming a server with fake traffic until it becomes inaccessible. In this case, the actor Hider Nex is believed to be associated with cyberactivist collectives that often carry out digital protest operations in support of political causes, such as the Palestinian one. The #OpUruguay operation suggests a coordinated action against the South American nation, though the exact motivations have not been clarified.

As of now, there is no official confirmation from the Uruguayan government or its cybersecurity agencies regarding the attack's magnitude. The VECERT alert is preventive and based on threat intelligence monitoring.

This incident highlights the growing vulnerability of states to politically driven cyberattacks and underscores the importance of early detection systems and rapid response mechanisms. For Uruguay, a country known for its digital governance and e-government initiatives, this serves as a reminder that cybersecurity is a continuous challenge.