CiberLATAMbywhalemate

Latin America sees AI-driven fraud surge

Deepfakes, phishing and identity theft powered by AI are rising in Mexico, Paraguay and across the region.

Whalemate Labs · AI-assisted researchPublished:4 min read

Artificial intelligence is now part of fraud and impersonation schemes across Latin America, with concrete signs in Mexico, Paraguay and regional companies. At the same time, Argentina, Chile and other industry players are starting to adjust defensive and regulatory responses to the same phenomenon.

Artificial intelligence is already being used to scale fraud, phishing, identity theft and extortion across Latin America, with recent reports from Mexico, Paraguay, Venezuela and the regional business sector. At the same time, defensive and regulatory responses are beginning to emerge in Argentina, Chile and some companies, while agencies and specialists warn about the use of deepfakes and automation in attacks.

How is AI being used in fraud?

AI is appearing in phishing schemes, identity theft, fake websites, manipulated video calls and deception campaigns aimed at users and employees. In Mexico, one column said deepfakes have become a real threat and that their use grew 700 percent, according to the Secretariat of Security and Citizen Protection. The same publication attributed to Delta Protect the figure that 21 percent of cyberattacks in the country now use artificial intelligence.

The Mexican case was not isolated. Sumsub’s Identity Fraud Report 2025 2026 said the country recorded a 484% increase in the use of deepfakes and related attacks, with identity theft through video calls and synthetic content becoming more sophisticated in corporate environments. Mexico’s Condusef also publicly warned that criminal groups are using artificial intelligence and deepfake videos to impersonate banks and financial institutions and seek sensitive data and money transfers.

What patterns do regional reports detect?

Different surveys show that AI is already built into criminal operations and that its use extends across more than one fraud method. An investigative note published in Venezuela said Mexican criminal organizations are incorporating digital tools, including AI, to strengthen logistics, extortion, surveillance and recruitment. The same investigation identified romance scams and identity theft through artificially generated content as forms tied to criminal use of AI.

The institutional response proposed in that investigation rests on four fronts, regulatory updates, stronger police and judicial capabilities, regional cooperation and rights protection. In Paraguay, specialist Miguel Ángel Gaspar said AI is already present in roughly 80% of phishing, identity theft, banking fraud and cyberharassment cases. According to that same report, the technology is being used to gather information, generate fake websites or apps, and improve the attack vector.

Sector surveys also reflect that expansion. A survey of executives and operators in sports betting and online casinos in Latin America found that 57% of companies suffered attacks involving deepfakes or generative AI over the past year, with attempted fraud, identity theft and manipulation of remote verification processes. A financial column citing the same survey added that 57% of participants already identify fraud linked to deepfakes or generative AI, that synthetic identity represents 48% of the cases analyzed in the region, and that AI-powered injection attacks reach 46%.

Another analysis of deepfake fraud in companies said 72% of the organizations consulted detected an increase in attacks through digital injection with deepfakes, along with more AI-falsified documents and social engineering schemes aimed at employees and customers.

What defensive and regulatory signals are emerging?

The response to the problem combines technical controls, regulatory changes and internal company rules. In Chile, one report said artificial intelligence can also be used as a defensive tool by analyzing access patterns, unusual transactions or atypical behavior. The same publication recommended multifactor authentication, access controls, double verification for sensitive operations and simple ways to report suspicious messages.

In Argentina, an opinion piece said Decree 941/2025 created the National Cybersecurity Center and assigned it detection, defense, response and recovery functions for incidents. Another legal analysis by Amnesty International on the country said Decree of Necessity and Urgency 941/2025 amended the National Intelligence Law to expand the use of AI-based surveillance systems, and questioned that those changes were made by decree, warning about the risks of algorithmic surveillance for social control.

Mexico is also appearing on the corporate front. An opinion article said AI and its associated risks have already entered companies and recommended clear rules on what data can be uploaded into AI tools, visibility into the tools employees use and a financial plan to respond to an incident. In the same vein, the ESET Security Report 2026 for Latin America said 56.3% of surveyed security professionals consider AI-driven threat automation the main risk tied to this technology, while 19.6% identify deepfakes specifically as the main risk, a figure that rises to 24.2% in IT and technology organizations.

What do the numbers say about the scale of the problem?

The available figures show rapid growth that varies by country, channel and sector. In Mexico, beyond the 700 percent increase cited by one column, the industry source quoted by Expansión reported a 484% jump in deepfakes and related attacks. The Standard CIO added that, according to industry data, Chile recorded a 148% rise in identity fraud rates and a 57% increase in malware activity since the last quarter of 2025.

That same coverage said attempts to take over accounts in Colombia rose 188%, driven by a 77% increase in deepfake use, while in Argentina the use of this technology for fraud increased 66%. Globally, more than 81% of AI fraud cases detected in 2025 involved deepfakes, according to the same article.

On channels, the coverage added that phishing accounted for 49% of harmful content blocked globally in 2025, that 70% of mobile phishing happens via SMS and that scams through that channel grew 40% year over year. The picture painted by these sources is consistent: AI is no longer a future threat, but an operational layer now embedded in digital fraud affecting companies, users and agencies across the region.

Sources

View all