CiberLATAMbywhalemate

Colombia, Argentina tighten digital fraud controls

Colombia logged more than 39,000 digital fraud complaints in six months, while Argentina added new controls on transfers and flagged accounts.

Whalemate Labs · AI-assisted researchPublished:3 min read

Colombia accumulated more than 39,000 digital fraud complaints in six months and, according to reports cited by local media, 80% of bank fraud claims in 2024 came through the internet. Argentina also moved to new Central Bank controls on transfers, suspicious accounts and claims over unrecognized transactions.

Colombia and Argentina have moved in recent days to confront digital fraud on several fronts. In Colombia, Asobancaria reported more than 39,000 digital fraud complaints in the most recent first half of the year. A report cited by local media said 80% of fraud cases reported by users to banks in 2024 happened online. In Argentina, the Central Bank introduced a risk-profile system to identify accounts tied to fraudulent schemes and illegal gambling, along with a new free online complaint channel.

What do the Colombia numbers show?

The reports point to a high level of activity concentrated in digital channels. According to Radar Tecnológico, the amount claimed in digital fraud cases in the country reached $679,000 million, and the Asobancaria figure, cited by La Gran Noticia in a public warning from Banco de Bogotá, put digital fraud complaints at more than 39,000 in the most recent first half of the year.

The same report cited by Radar Tecnológico said that during 2024, 80% of fraud cases reported by users to banks happened over the internet. Colombia's Cybersecurity Emergency Response Group, ColCERT, also published a trend report showing that fraud accounted for 79.83% of the digital security incidents it handled over the past two years.

In that ColCERT report, phishing and unauthorized use of email appeared as recurring methods. The mix of bank complaints, handled incidents and deception techniques shows that digital financial fraud remains one of the main burdens for the system and for users.

What changed in Argentina?

The Central Bank of the Argentine Republic rolled out the risk-profile system to strengthen oversight of digital transfers and detect accounts linked to fraud and illegal gambling. The framework covers unrecognized transactions through online banking, banking apps and digital wallets.

According to the BCRA's official notice, users must first file a complaint with the financial institution and, if the response is unsatisfactory, submit a free online filing with the Central Bank as a second step. The bank also said that starting in September it will provide administrators of instant transfers with additional public information to improve analysis and monitoring tools.

The measure comes as, according to iProfesional, an annual digital security report tied to the local market said 43% of Argentine users suffered some kind of hack or online scam. That same coverage noted a rising trend in prior years, at 31% in 2024 and 33% in 2025.

What techniques keep repeating in the region?

Recent reporting points to a fairly stable pattern: impersonation, urgency and contact channels that appear legitimate. In Peru, an analysis of digital fraud described scams designed to get users to authorize a transaction, using urgent messages and unverified channels. In Argentina, another report detailed phone and WhatsApp scams aimed at stealing home banking and virtual wallet credentials, including tokens and verification codes.

At the same time, Palo Alto Networks Unit 42 published an analysis of campaigns targeting organizations in Latin America, including a financial campaign in Brazil. The research described a cluster aimed at the financial services sector with job-offer-themed phishing, compromise of vulnerable web servers, customized remote access trojans and a Go-based SOCKS5 proxy with file names suggesting the use of AI tools.

Cloud Security Alliance expanded that context by saying the CL-CRI-1163 campaign focused on Brazilian financial institutions using résumé and job-offer lures, combining phishing with AI-augmented intrusions and tunneling tools to keep access to payment and digital banking systems.

Also in Brazil, CybersecBrazil reported that Breeze Comet has compromised companies in the financial, retail and e-commerce sectors since 2024, exploiting payment systems and banking software to carry out hundreds of fraudulent Pix transactions. The case adds a concrete operational dimension to the regional impact of these campaigns on payment rails.

Sources

View all