CiberLATAMbywhalemate

BCRA Tightens Controls on Instant Transfers

Argentina’s central bank will use public data to build per-person fraud risk scores for instant transfers.

Whalemate Labs · AI-assisted researchPublished:2 min read

The Central Bank of the Argentine Republic will tighten controls on instant transfers and use public data to build per-person fraud risk profiles. The framework also aims to detect unusual patterns and flows linked to illegal gambling, according to cited coverage.

The Central Bank of the Argentine Republic will tighten controls on instant transfers and use public information to build a per-person fraud risk profile. The move, confirmed by the BCRA itself, is part of a framework that, according to cited coverage, will also help identify unusual patterns and flows tied to illegal gambling.

What did the BCRA confirm?

The BCRA confirmed that it will strengthen its fraud prevention strategy and that instant transfer operators will use public data to build a fraud risk score for each person. The information was published by the central bank on its official site on September 3, 2026.

That confirmation came after coverage from LmNeuquen, which reported that the agency would tighten controls on instant transfers in Argentina. State-of.biz added that the new framework would allow operators to detect unusual patterns and flows linked to illegal gambling.

What is the scope of the new score?

According to an independent legal and technical analysis of Communication A 8473, the fraud risk score will be a required input for onboarding new customers and for transaction monitoring in instant transfers. That gives the framework a concrete operational use within admission and follow-up processes.

Bruchou & Funes de Rioja also noted that the profiling is part of a stricter control framework for this type of transfer. The technical note does not change the measure, but it does help place it as a mandatory tool within banking operations tied to instant payments.

How does it connect to regional criminal activity?

The BCRA move comes as active phishing and backdoor campaigns target organizations across Latin America, including banks and financial services. ANY.RUN reported that one such campaign uses lures such as fake tax documents and DocuSign-style notices, and seeks persistent remote access to compromised systems.

That analysis observed a four-stage infection chain and attributed the activity with medium confidence to tradecraft consistent with Silver Fox or Winos4.0, while noting that attribution has not been confirmed. The company also said the campaign’s stated goal is to obtain persistent remote access, which raises pressure on financial institutions in the region.

In Honduras, La Prensa Honduras also reported an alleged network of six cyber scammers that used phishing to enter a victim’s online banking and carry out 17 transfers totaling more than L586,000 in 41 minutes, according to the investigation cited by the outlet. The case shows how quickly these operations can move once they gain access to an account.

Sources

View all