CiberLATAMbywhalemate

LATAM Leads Card Fraud, Stripe Says

Stripe said LATAM’s 2025 card fraud rate was 65% higher than North America’s, with Peru, Colombia, Chile, Argentina and Mexico under pressure.

Whalemate Labs · AI-assisted researchPublished:3 min read

Stripe said Latin America has had the highest card fraud rates among the regions it has tracked since January 2022. In 2025, the regional rate was 65% higher than North America’s, 151% above Asia Pacific and 160% above Europe, the Middle East and Africa.

Stripe said Latin America has had the highest card fraud rates among the regions it has tracked since January 2022. In 2025, the region’s fraud rate was 65% higher than North America’s, 151% above Asia Pacific, and 160% above Europe, the Middle East and Africa.

What do the regional data show?

The clearest signal is the persistence of digital banking and payment fraud across several countries in the region, driven by heavier use of online channels and tighter authentication controls. At the same time, official and industry reports show the problem is not limited to card use. It also includes identity theft, credential theft, malware and investment scams.

In Peru, the Public Ministry recorded 29,118 complaints linked to crimes under Law 30096 between January and July 2026, according to Andina. The same report cited 19,602 cases under Article 8 of that law and 457 complaints of aggravated fraud tied to access or theft of debit or credit card data issued by the financial or banking system. The most common category was computer fraud and identity theft.

What is happening in Colombia, Chile, Argentina and Mexico?

Reports from those countries point to a common pattern, more fraud in digital environments and more responses based on stronger authentication, identity verification and official alerts. In Colombia, 85.1% of fraud tied to stolen data, mobile app credentials and card information is concentrated in digital channels, and those channels account for 78.8% of fraud claims in 2026, according to La República.

That same report said the banking sector has pushed multifactor authentication and biometrics in response. In Chile, coverage of Microsoft Digital Crimes Unit operations identified 5,606 Lumma Stealer victims, 1,636 Fox Tempest victims and 479 linked to RedVDS. Also, since August 2026, banks, fintechs and card issuers must use at least two independent identity factors for critical operations such as electronic transfers, digital customer onboarding and changes to sensitive data, using tools such as passkeys and biometrics.

In Argentina, the Central Bank warned about fake investment campaigns using its name or that of its officials. According to the advisory, scammers impersonate banks, digital wallets or public agencies and ask for national ID numbers, usernames, passwords, verification codes, tokens or one-time passcodes. In Mexico, Condusef said 64 financial institutions had been impersonated online and on social media by fake lenders, with masked calls and AI-generated videos used to defraud users.

What measures are banks and regulators taking?

The responses aim to reduce the value of stolen credentials and make it harder to take over accounts or devices. In Mexico, Condusef and the Association of Banks issued an alert on financial fraud using malware capable of taking control of mobile devices, and recommended stopping suspicious transactions, disconnecting the device, changing passwords from a secure device and contacting the financial institution directly.

In Peru, since July 1, 2025, banks, card issuers and digital wallets must apply at least two independent authentication factors in certain transactions, under SBS Resolution No. 2286-2024. Combined with the region’s fraud data, those measures point to a digital channel that remains at the center of both attacks and defenses.

Sources

View all