In a world where digital borders are as critical as physical ones, Uruguay has become the latest target of a politically motivated cyber offensive. On August 13, 2026, the cyber intelligence platform VECERT Analyzer raised a preventive alert about a massive DDoS (Distributed Denial of Service) attack aimed at the country's state infrastructure. The attack was claimed by an actor known as Hider Nex, linked to pro-Palestinian cyberactivist groups, through official Telegram channels.
This alert, shared on VECERT's official X (formerly Twitter) account, indicates the operation is part of #OpUruguay and has a geopolitical activist motive. While the attack's status is listed as unconfirmed, centralized monitoring detected a Layer 7 volumetric / HTTP Flood campaign against several Uruguayan government portals.
Targeted Government Websites
According to the VECERT report, the specific targets include:
- Portal Único del Estado Uruguayo (Uruguay's Single State Portal)
- Parlamento de Uruguay (Parliament)
- Poder Judicial de Uruguay (Judiciary)
- Tribunal de Cuentas (TCR) (Court of Accounts)
- Tribunal de lo Contencioso Administrativo (TCA) (Administrative Litigation Court)
- Banco de Previsión Social (BPS) (Social Welfare Bank)
The report mentions that Check-Host verification links show supposed interruptions and anomalous traffic, with SSL/HTTP 403 errors and connection drops on the affected infrastructure.
Preventive Technical Recommendations
VECERT also published a series of recommendations to mitigate the impact:
- Activation of DDoS protection rules on WAF/CDN services (Cloudflare, Incapsula, Akamai) that protect the .gub.uy domain.
- Temporary geographic blocking of traffic from ASNs or regions not critical to Uruguayan public administration.
- Endpoint monitoring and log analysis on load balancers and reverse proxies (NGINX) to identify botnet signatures and recurring IP addresses.
Context and Background
DDoS attacks work by overwhelming a server with fake traffic until it becomes inaccessible. In this case, the actor Hider Nex is believed to be associated with cyberactivist collectives that often carry out digital protest operations in support of political causes, such as the Palestinian one. The #OpUruguay operation suggests a coordinated action against the South American nation, though the exact motivations have not been clarified.
As of now, there is no official confirmation from the Uruguayan government or its cybersecurity agencies regarding the attack's magnitude. The VECERT alert is preventive and based on threat intelligence monitoring.
This incident highlights the growing vulnerability of states to politically driven cyberattacks and underscores the importance of early detection systems and rapid response mechanisms. For Uruguay, a country known for its digital governance and e-government initiatives, this serves as a reminder that cybersecurity is a continuous challenge.