
Chile, Mexico and Colombia tighten controls
New privacy, AML and open finance rules advance in Chile, Mexico and Colombia, with different deadlines, sanctions and technical standards.

New privacy, AML and open finance rules advance in Chile, Mexico and Colombia, with different deadlines, sanctions and technical standards.

The BCRP approved rules for acquiring and fund collection. It requires segregated funds, transparency, and takes effect Jan. 1, 2027.

ESET links FamousSparrow to a SparroWocky campaign against Latin American governments, with eight territories and 90% of targets in the region.

Brazil set a PSAV authorization deadline and added COAF reporting for crypto transfers of $10,000 or more, with controls starting in 2026.

ESET links a regional spying campaign to FamousSparrow and its new SparroWocky backdoor, with Peru among the targets.

Chile, Mexico, Brazil and others are speeding up new data, fraud, cybersecurity and virtual asset rules through 2028.

Kaspersky found 90 Brazilian stores infected with malware that replaces Pix QR codes and Pix Copia e Cola at checkout.

Law 7593/2025 and RG 47/2026 expand data and crypto controls in Paraguay, adding obligations, sanctions, and proportionality debates.

Unit 42 tracked two AI-assisted intrusion clusters in Mexico, Ecuador and Brazil, using NextChat, Claude

Unit 42 found two AI-linked clusters targeting governments, water, and banks in Mexico, Ecuador, and Brazil since February 2026.

Brazil tightened PSAV rules on licensing, capital, audit and a 24-hour hold for higher-risk crypto transfers.

Chile’s Law 21,719 takes effect Dec. 1, 2026, creating a new agency, stronger rights, fines up to 20,000 UTM, and GDPR-like rules.

Brazil updated the Pix DICT manual with deeper tracing, an 80-day response window, and new MED 2.0 adjustments.

The Gentlemen grew into a double-extortion RaaS in 2026, targeting LATAM with Fortinet, RDP, and attacks in Colombia, Peru

Brazil’s ANPD opened a probe into Discord over child safety risks and ordered Go Live and similar live video features suspended.

Water attacks in the U.S. affected at least 12 states. New York is funding 153 systems as Latin America exposes energy gaps.

Mexico has nearly 200 state-level AI proposals, but no federal general law or corporate cybersecurity framework yet.

Evertec shows how Open Finance, Pix and facial biometrics are creating new fraud paths in Brazil, and how banks and regulators are responding.

OpenAI confirmed a sandbox escape during an internal test that hit Hugging Face and exposed credentials across four external services.

CVE-2024-24919 exposed Check Point gateways to credential theft and was used in ransomware and APT campaigns, with regional relevance for Brazil.

Brazil’s BCB 580/2026 brings virtual asset service providers into the prudential regime, with capital rules and a transition through 2028.

The Gentlemen listed Mercado Libre on its leak site in July 2026. Exfiltration signs emerged, but no public proof of operational impact.

ColCERT says ORB3/CHARLIE is used for espionage against telecom and critical infrastructure in South America, with 16 nodes

Latin America accounts for 48.3% of AI-driven synthetic identity fraud. Banks and fintechs face weaker remote onboarding controls.

Between May and June 2026, multiple trackers and intelligence reports linked Qilin to active ransomware campaigns that escalated around a critical Check

Chile faced 8.8 billion cyberattack attempts in 2025, and between January and June 2026