Traditional Banking and Insurers, August 2026
August saw 125 verified banking and insurance events in LATAM, with fraud the leading threat, plus more regulation and several scam-related rulings.
Key findings
- Fraud and phishing were the month’s dominant threat, with 44 events and broad regional reach.
- Judicial pressure on banks increased, especially in Argentina, over SIM swapping, phishing, and account draining.
- Chile, Brazil, and Bolivia drove major regulatory changes in authentication, incident reporting, and payment methods.
- Brazil combined an operational incident, data exposure, and police operations, with focus on Pix and electronic fraud.
- No critical CVEs were recorded in the analyzed material, but there were incidents and exposures with operational and legal impact.
- Ransomware remained present, though it was not the main story in the vertical during August.
- The most urgent security response for the sector is to strengthen identity, transaction monitoring, and customer support.
Monthly reference modules
These modules are completed automatically with the verified facts dated within the period. Each one states its basis and counting criterion, so the figures reconcile across modules. They are the recurring month-to-month reading; the later analysis develops the cases without repeating this summary.
Indicator window: 125 dated facts in August 2026. Facts from earlier months are used only as comparative context in the analysis, never as volume for this period.
Executive Summary for the Month
August 2026 closed with 125 verified incidents involving traditional banking and insurers in Latin America, a jump from July and a clear shift in the risk mix. Fraud and phishing led the agenda with 44 cases, while regulatory actions added 25 developments and unclassified incidents reached 13. The material points to a region that is more exposed to customer-targeted deception and, at the same time, more active in regulatory and legal responses.
The month’s strongest signal was the sophistication of digital fraud. In Argentina, Bolivia, Brazil, Chile, Colombia, Paraguay, and Peru, campaigns and cases emerged tied to card cloning, fake banking call centers, deepfakes, SIM swapping, fake QR-based loans, WhatsApp impersonation, and urgency-based phone scams. At the same time, several courts began to consolidate standards of strict liability for banks and third parties, especially when unusual transactions were not detected or a digital scheme was not stopped in time.
The other major block in the period was regulatory. There were BCRA updates in Argentina, new security rules for Pix and Drex in Brazil, regulatory progress in Chile under Law 21.663 and its implementing decree, SIN adjustments in Bolivia with two-factor authentication, and draft measures from Colombia’s Financial Superintendency related to borrower relief and disaster claims. Taken together, regulators are pushing harder controls in digital banking, authentication, and incident reporting.
No critical CVEs were mentioned in the material analyzed, which does not mean the region lacked severe vulnerabilities. There were relevant operational and security incidents, including Pix instability in Brazil and the data incident involving Pix keys at Pefisa, as well as an operation against electronic fraud that would have affected Banco do Brasil and Federal Police actions tied to banking fraud and money laundering. On ransomware, the month remained contained: four cases where extortion or ransomware was the primary focus, two with confirmed encryption and two where the source did not specify the technical impact.
The scale of the regional picture makes August a high-risk month for the sector. Not because there was an extraordinary volume of sophisticated intrusions, but because customer-facing fraud grew sharply, legal pressure on banks and telecom companies increased, and regulatory responses accelerated in several countries. Defense is no longer decided only at the perimeter or in monitoring, but in authentication, identity validation, smart friction, and evidentiary traceability.
Regional snapshot for the month
August’s regional signal was elevated and uneven. The volume of 125 verified incidents, along with 44 fraud or phishing episodes and 25 regulatory changes, points to a landscape where the most profitable attack surface remained the end user, but with rising costs for banks, insurers, and financial infrastructure players now facing more litigation, more reporting demands, and more pressure to prove due diligence.
Risk was not concentrated in a single country. Argentina contributed a heavy density of scams, public alerts, and court rulings. Brazil concentrated police operations, regulatory adjustments, a Pix incident, and a data exposure case at Pefisa. Chile posted a mix of digital fraud data, a new cybersecurity law, and interagency coordination against transnational financial fraud. Bolivia moved to tighten authentication and formalize complaints over fake loans. Paraguay and Peru added multiple account-draining and bank impersonation schemes. Colombia stood out more for regulation and disaster response, but it also saw financial deception campaigns.
The risk picture for traditional banking and insurers is high for two reasons. First, fraud is no longer episodic or isolated, but a steady stream of multichannel deception that mixes phone calls, messaging, social media, and legitimate apps. Second, institutional response is shifting toward stricter security and accountability standards, which raises the cost of failing to detect, report, or document reasonable controls. In that context, the month showed not only attacks, but also a reset in the standard expected by judges and regulators.
Period indicators
| Indicator | August 2026 | Previous month | Change |
|---|---|---|---|
| Verified facts for the period (base for all indicators) | 125 | 63 | +62 |
| Indicator time window | 125 facts dated August 2026 | 63 facts dated July 2026 | N/A |
| Unclassified incidents (breaches or disruptions) | 13 | 7 | +6 |
| Cases with ransomware or extortion as the primary focus | 4 | 4 | unchanged |
| Ransomware breakdown by impact type, asset encryption confirmed | 2 | 2 | unchanged |
| Ransomware breakdown by impact type, impact not determinable from the material | 2 | 2 | unchanged |
| Documented fraud or phishing cases | 44 | 8 | +36 |
| Documented regulatory moves | 25 | 19 | +6 |
| Critical CVEs mentioned | 0, none in the material analyzed, this does not imply absence in the region | N/A | N/A |
| Sectors with at least one documented fact | 7 | 6 | +1 |
| Dominant threat of the month | Fraud, 44 of 125 facts | Regulation, 19 of 63 facts | shift in focus |
| Facts with direct source confirmation | 92% | N/A | N/A |
The period base remains the same across all indicators, 125 verified facts dated August 2026. The sectors are not exclusive, so one fact can affect banking, telecom, payments and, in some cases, insurance or compliance. The 0 critical CVEs figure should be read as an absence in the material analyzed, not as an absence of critical vulnerabilities exploited in the region.
Relevant incidents
Pix, an operational outage with no confirmed attack
Brazil's most visible episode was the Pix instability on August 23, which disrupted transactions during the morning and was resolved that same day. According to the Central Bank, there were no signs of a cyberattack, fund diversion, or exposure of banking information. The case was classified as an operational disruption, not a confirmed intrusion.
Its analytical value lies in the context. Pix was already under pressure from new security rules, the regulator's push to strengthen controls, and the recent exposure of Pix key data at Pefisa. In other words, even without evidence of an attack, Brazil's most sensitive payment rail ended up at the center of a trust and resilience agenda that does not allow too many failures in a row.
The Central Bank's public response was immediate and consistent across three separate reports, with a single message: the service was normalized, there was no impact on balances or keys, and the attack hypothesis was ruled out. For banks and acquirers, this leaves a concrete operational lesson, contingency communications must be fast, consistent, and backed by technical traceability, because the reputational cost of an ambiguous outage can be almost as high as that of an intrusion.
Exposure of 28.203 Pix keys at Pefisa
Brazil's Central Bank reported a security incident tied to Pefisa, involving exposure of personal data linked to 28.203 Pix keys. The affected information was registration data only, with no password, balances, financial transactions, or other data protected by bank secrecy. The incident does not appear to be a broad intrusion into core infrastructure, but rather a limited exposure of customer data.
The nature of the leaked material matters. Even without credentials or transaction data, the volume is enough to fuel targeted fraud campaigns, impersonation, and financial pretexting. In a regional environment where fraud increasingly relies on plausible identity data, a database containing name, CPF, institution, branch, account, and key creation date may be enough to improve the precision of social engineering.
Specialized coverage also linked the episode to the new security rules in the Pix ecosystem and to the regulator's interest in raising barriers against fraud. That does not turn the leak into a systemic attack, but it does signal that data governance at entities connected to the payment system remains a sensitive front. For a bank CISO, the case is a reminder that partial exposures also require containment, notification, and post-incident monitoring.
Operação Rastro and electronic fraud against Banco do Brasil
The São Paulo Civil Police launched Operação Rastro against an organization suspected of electronic fraud that reportedly caused losses of approximately R$ 50 million to Banco do Brasil. The source describes the misuse of access credentials belonging to two employees of the institution, along with warrants in several states and multiple suspects. The operation is framed as a theft-by-electronic-fraud scheme, with a direct banking component.
Although the material does not provide a full technical chain, it does leave two solid points. First, abuse of internal credentials was the vector mentioned. Second, the case had interstate reach and led to search and seizure measures targeting equipment and documents. That puts the spotlight on privileged identity controls, segregation of duties, and monitoring of sensitive access in large-scale banking environments.
The case is only indirectly relevant for insurers, but it illustrates a dynamic that does cross the financial vertical, the exploitation of legitimate or stolen access to move money, evade alerts, and escalate fraud. In this kind of scenario, the problem does not end at the technical perimeter. Internal investigations, coordination with law enforcement, and the ability to show when and how the anomaly was detected also come into play.
Fake bank call center fraud in Brazil
On August 11, G1 described the spread of the fake bank call center scam, in which criminals pose as bank employees and call victims to push them into sharing data or authorizing transactions. The pattern is classic, but the report places it as a still-active and highly effective method, powered by fear, urgency, and institutional impersonation.
The tactic works because it mixes social engineering with procedures that look like real customer service. The attacker gains credibility by mentioning recent transactions, preventive blocks, or supposed security checks. In that context, the recommendation to hang up and contact the bank through official channels is not just preventive, it is also an operational containment measure that banks should build into the customer experience.
The value of the case is not its originality, but its persistence. When a method remains active in August and coexists with newer ones, such as deepfakes or messaging-based impersonation, financial sector defenses have to assume fraud quickly adapts to the least resistant channel. Customer service and anti-fraud teams end up sharing the same battleground.
Deepfakes and Central Bank impersonation in Argentina
In Argentina, the Central Bank again warned about scams using fake videos created with artificial intelligence to impersonate officials and steal banking data. This month's material shows the institutional message and several reports that expand on it, criminals are also distributing manipulated videos, emails, WhatsApp messages, and SMS, promoting nonexistent investments and requesting payments in dollars or sensitive data.
The significance of the case lies in the maturity of the tactic. This is not just about forging an audiovisual piece, but about building a multichannel campaign that combines urgency, authority, and the promise of returns. The cited material insists that the BCRA does not offer financial services to the public or request payments through those channels, and that the only reliable validation is through the agency's official channels.
That has a direct impact on banks and insurers because the fraud uses highly trusted brands to feed campaigns that end in account drain and credential theft. It also creates an operational need, training customer service teams to identify when a query is actually part of a scam that started outside the bank, not just a one-off complaint.
SIM swapping and account drain in Argentina
The Junín Civil and Commercial Court of Appeals confirmed a ruling against Movistar and Banco Galicia in a SIM swapping case that ended with a customer's account being drained. The report describes an almost instant transfer of funds, joint liability, and a rebuke to the bank for failing to detect the unusual nature of the transactions. Another legal report detailed that the ruling included direct damages, moral damages, and a civil fine.
The case matters because it makes the bridge between telecom and banking clear. The unauthorized duplication of the SIM was not just the step before the fraud, it was the mechanism that allowed control of the victim's digital identity. When that happens, the bank is exposed not only by the loss, but also by its ability to prove transaction monitoring and management of anomalous events.
The takeaway for the sector is familiar, but in August it became more visible. Mobile-factor security can no longer be treated as an external layer. For home banking, wallets, and SMS authentication, the risk of number or line hijacking translates into direct losses and litigation that can end in substantial compensation and additional sanctions.
Fake QR loans in Bolivia
Bolivia's Central Bank filed criminal complaints against alleged scammers who used its name and image to offer fake loans through social media and messaging apps, asking for deposits via QR codes. The institution clarified that it does not offer loans or manage investments for private individuals and warned that there were signs of similar cases in other parts of the country.
This fraud format combines two advantages for the criminal, an attractive financial promise and a payment method that is fast, visible, and difficult to reverse. The use of QR codes gives it an appearance of formality and lowers the victim's perception of risk. In addition, the BCB's own warning about possible reach beyond Cochabamba broadens the geographic reading of the case.
This type of campaign affects banking, payments, and eventually non-bank financial products competing for digital users. For security teams, the case underlines the need to monitor brand impersonation, register fake accounts and channels, and speed up reporting and takedown processes. In fraud like this, response speed matters as much as detection.
Cyberfraud in Buenos Aires and a steady complaint curve
The Public Prosecutor's Office of the City of Buenos Aires reported around 1.300 cyberfraud complaints in the first half of 2026, with an average of more than 200 per month. August's material ties that volume to phishing, social media scams, and digital financial operations, as well as abuse of trust involving older adults to obtain cards or make unauthorized purchases.
This is not an isolated incident, but a volume gauge for the Argentine market. The figure helps explain why so many reports this month revolve around account drain, impersonation, and banking fraud. It also shows that the problem is not limited to one bank, because most cases operate through user habits, social channels, and reused credentials.
For the sector, this context explains the density of court rulings and public warnings. When the complaint flow is that high, banks are forced to improve detection, traceability, and customer response. If they do not, each new scam stops being an isolated event and becomes part of a series of similar claims that erode trust and raise legal exposure.
Electronic banking fraud and money laundering in Brazil
Brazil's Federal Police opened Operação Klonen to investigate electronic banking fraud, money laundering, and asset concealment. The official communication places the case within a plot against financial institutions, without naming a specific victim from the sector, but clearly marking the banking axis of the investigation.
Its relevance for the monthly analysis lies in the overlap between fraud and laundering. When stolen money moves quickly through concealment structures, the response cannot stop at blocking access or reporting the initial scam. It requires much tighter coordination between anti-fraud teams, AML compliance, and authorities. That link appeared several times in August, especially in Brazil and Bolivia.
The case also fits the month's broader trend, instead of focusing on a single intrusion technique, criminal groups are combining impersonation, electronic fraud, and fund routing. For the financial sector, that means watching not only the entry point, but also the downstream circuit used to disperse, withdraw, and convert stolen funds.
Active threats and campaigns
Ransomware and extortion
August reporting recorded four cases with ransomware or extortion as the primary focus. In two of them, asset encryption was confirmed. In the other two, the source did not allow a determination of whether there was encryption or only extortion with a threat to publish data. There was no single dominant campaign, only scattered references to groups and claims, with the clearest impact showing up in economic pressure rather than prolonged disruption of banking services.
For banks and insurers, this category was quieter than fraud, but no less important. The absence of a major confirmed encryption case in the vertical does not mean lower exposure. What the month shows is that ransomware remained present as a coercion tool and that the regional financial ecosystem continued to face extortion, even if the material analyzed did not always provide enough technical detail to classify each incident precisely.
Fraud and phishing
Fraud was the leading threat of the month, with 44 documented incidents. The repeated use of phishing campaigns, fake banks, deepfakes, SIM swapping, impersonation by phone, messaging, and QR codes confirms that the most profitable vector remained social engineering supported by trusted channels. There was no single dominant technique, but a mix of tactics adapted to the country, the channel, and the victim profile.
The regional pattern is consistent. In Argentina, BCRA notices, court cases, and interviews about fake websites overlapped. In Brazil, operational instability, fake call center fraud, Pix data exposure, and police operations were added to the mix. Bolivia focused on authentication and complaints about fake loans. Chile, Paraguay, and Peru also showed a broad range of impersonation and account-draining schemes. The common threat was the exploitation of credentials, identity, and urgency.
APT and targeted intrusion
The period's material does not show a clearly attributed APT campaign in the traditional banking and insurance axis. There are incidents involving fraud with internal credentials, police operations for unauthorized access, and cases of data exposure that could support later intrusion, but the available sources do not provide enough basis to describe a sustained advanced campaign against banks or insurers with solid technical attribution.
That does not reduce the risk profile, because the month left signs of preparation and tactical evolution. The combination of exposed data, abused legitimate access, and vulnerable mobile channels creates a favorable environment for focused intrusion. Even so, with the material available, the dominant category for the vertical remains fraud, not attributed advanced intrusion.
Critical vulnerabilities
No critical CVEs were recorded in the material analyzed for August 2026. That does not mean there were no critical vulnerabilities exploited in the region, only that none appeared in the sources provided for this report. The focus for the month was fraud, authentication, data exposure, and compliance, not software exploitation identified by CVE.
| CVE | Software | Exploitation | Source |
|---|---|---|---|
| No critical CVEs were recorded in the material analyzed | N/A | N/A | N/A |
Regulation and compliance
Regulation was a major theme in August, and not just because of volume. The month recorded 25 documented regulatory moves, with notable changes in Argentina, Bolivia, Brazil, Chile, Colombia, and Peru. The common thread was clear, more authentication, more reporting, tighter third-party oversight, and faster response capabilities for incidents or fraud with financial impact.
Argentina and the BCRA
In Argentina, the BCRA published Communication A 8438 and another rule in the Official Gazette, as part of a package of regulatory communications for financial institutions. The source material does not spell out the full content, but it places the measures within the broader update of the system’s rules. That alone signals regulatory continuity in a month dominated by bank fraud and litigation.
Argentina’s regulatory agenda moved alongside a wave of warnings about deepfake scams, phishing, and account draining. That overlap matters because judicial pressure and regulatory pressure often rise together. When courts begin to support strict liability or contributory fault, regulators usually raise expectations for monitoring, authentication, and incident management. August showed both fronts at once.
Bolivia and two-factor authentication
Bolivia made visible progress on digital security. The SIN rolled out two-factor authentication for its Virtual Office and framed it within global cybersecurity standards. It also set up support channels for issues tied to the new model, which suggests awareness of the operational friction that an authentication change can create. The BCB, meanwhile, warned about fake QR-based loans and clarified that it does not offer loans or investments to the public.
The overlap between authentication and fraud is significant. The country is not only trying to harden controls, it is also trying to support users who could be locked out or confused by the security upgrade. For banking and insurance, that transition is useful because it points to a regional framework where MFA and user support move together.
Brazil, Pix, and crypto
Brazil added a dense regulatory agenda. The Central Bank was cited in coverage about new security rules for Pix and Drex, and about a real-time alert system for threats tied to crypto assets, in partnership with Hypernative. Some of those pieces come from corporate or market sources, so they should be read as signals of regulatory and technical direction, not as a confirmed final product promise.
The regulatory logic is still consistent. Brazil’s regulator is acknowledging blind spots, expanding coverage over the crypto market, and tightening controls on mass payment rails. That combination matters for the banking sector because it points to a higher standard for transaction monitoring, fraud prevention, and operational resilience. The Pix incident on August 23, even though it was not an attack, reinforced that agenda further.
Chile and the new cybersecurity law
Chile was one of the most regulation-heavy countries of the month. Law 21.663 and Decree 295 set reporting obligations at three hours, updates at 24 or 72 hours depending on criticality, an action plan within seven days, and a final report within 15 days. ANCI acts as a receiving authority alongside the National CSIRT, and fines for noncompliance can escalate depending on the organization’s category.
The material also shows that companies classified as PSE and OIV are speeding up monitoring and response projects. For banks and insurers, this is critical because compliance is no longer about having a document. It is about reporting quickly, with evidence, and with the ability to reconstruct the incident sequence. Chile is setting a maturity benchmark that will likely influence other markets in the region.
Colombia, disaster relief, and financial claims
Colombia’s Financial Superintendence published draft measures and relief steps for borrowers and policyholders affected by the earthquake, along with instructions to soften the impact of the disaster situation on financial consumers. The focus is not a cyberattack, but it does center on service continuity, claims handling, and regulatory response in an extreme situation.
For insurers, this block is especially relevant because it connects claims, credit, and customer service. When the regulator prioritizes expedited complaints mechanisms or relief measures, internal operations must be able to sustain short response times, case traceability, and consistent documentation. August delivered that signal alongside the fraud agenda, showing that regional financial compliance has become broader and more tactical.
Peru and tougher fines
In Peru, the material included SBS resolutions and coverage about new fines for banks, AFPs, and insurers. Although the listed sources do not detail the full scope of each resolution here, they do confirm a move toward tougher sanctions and a more severe supervisory environment. That fits with the rise of fraud through calls, messages, voice impersonation, and fake receipts.
The link between regulation and threat is direct. When a regulator tightens fines and supervision, the sector has to show that it understands operational risk and fraud as one chain of control. In August, Peru made that tension especially clear, especially in the digital payments and consumer banking ecosystem.
Countries and most affected subsegments
Argentina
Argentina was one of the month’s densest hotspots, both for fraud volume and for judicial and regulatory response. The material brings together BCRA alerts on deepfakes, phishing cases, SIM swapping rulings, X-based scams, and court decisions that assign strict liability or shared fault between bank and customer. It also adds growing reports of cyberfraud complaints in CABA.
By subsegment, the most repeated impact hit retail banking, home banking, wallets, and credit cards. Coverage of card cloning with fraudulent online purchases shows that classic fraud is still alive, even as it coexists with more modern techniques. The Argentine cases also put the evidentiary burden in the spotlight, with each ruling seeming to demand more from banks to prove they monitored activity and reacted in time.
Brazil
Brazil concentrated operational incidents, data exposures, police operations, and security updates tied to Pix and crypto. Pix instability, the Pefisa incident, Operação Rastro, Operação Klonen, and the crypto alert plan made for a month of heavy pressure on the financial system and its payment flows. It is no surprise that the Central Bank appeared in so many reports.
The most strained subsegment was payments and digital banking, followed by compliance and financial crime. The coexistence of electronic banking fraud, money laundering, and on-chain monitoring suggests the country is pushing for tighter integration between antifraud controls, AML, and technology supervision. For insurers, the direct volume impact is lower, but the exposure matters because of business continuity and the use of shared digital channels.
Chile
Chile combined strong regulation with expanding digital fraud. The Central Bank reported nearly US$98 million in unknown transactions or transactions reported as fraudulent during the first half of 2026, while the country advanced in implementing the Cybersecurity Framework Law and a national table against transnational financial fraud. That dual pressure, monetary loss and legal demands, captures Chile’s month well.
In subsegments, banks and payment systems were the most exposed, but the regulatory impact reaches all essential service providers and operators of vital importance. The removal of coordinate cards at several banks and the shift toward stronger authentication methods also point to a structural change in the financial user experience.
Bolivia
Bolivia showed a more focused agenda around authentication, fraud reporting, and institutional strengthening. SIN activated two-factor authentication, the BCB reported false QR-based loans, and the UIF appeared close to leaving the FATF gray list after correcting deficiencies. The strengthening of CSIRT Bolivia was also reported as part of a broader strategy.
The most visible subsegment was digital tax services, but the takeaway extends to the financial system as a whole. The push for stronger authentication and sector-specific response structures points to a region where banking will have to live with more formal reporting and support models. Bolivia did not have the highest number of incidents, but several carried high structural value.
Paraguay
Paraguay maintained a steady flow of emptied accounts, theft complaints, and prevention alerts. The material mentions specific victims, a lawmaker reporting a cyberattack, malware suspicions, and bank prevention notes. While the documented volume is lower than in Argentina or Brazil, the repetition of incidents shows meaningful exposure in the retail segment.
The most affected subsegment was personal checking and bank accounts, with heavy social engineering and credential theft. The variety of media outlets reporting the same pattern indicates that the issue has become part of the country’s everyday financial security coverage.
Peru
Peru showed a mix of consumer banking fraud, attacks through calls and messages, and regulatory pressure on banks, pension funds, and insurers. The appearance of voice spoofing, fake receipts, and synthetic identities in August coverage suggests a technical escalation in social engineering. It is a troubling sign because it combines automation with the exploitation of personal trust.
The insurance subsegment appears less because of its own incidents and more because of the regulatory and compliance environment. The mention of tougher fines and the context of fraud directed at end customers means the insurance sector must strengthen validation, document fraud controls, and payment oversight. The common vector remains identity, not just infrastructure.
Colombia
Colombia was not the country with the highest volume of banking cyber incidents, but it was an important regulatory hub. The Financial Superintendence published measures linked to natural disasters, loans, and insurance, and opened draft circular letters and relief measures for affected parties. The signal here is operational resilience and supervisory response rather than intrusion or mass banking fraud in the material analyzed.
The most exposed subsegment is insurance, because of the nature of the relief and claims measures. For banks, the lesson is that compliance and consumer service will face tighter regulation even outside cyberincident scenarios. That requires business continuity, mass service handling, and documentary evidence to be built into the same operating framework.
Trends and signals to watch
The comparison with July shows a sharp shift in pace and focus. Verified incidents rose from 63 to 125, fraud or phishing from 8 to 44, and regulatory moves from 19 to 25. The main signal is not just higher activity, but a shift from a regulatory-heavy agenda to one dominated by fraud, with greater visible impact on customers and higher legal costs for financial institutions.
The ransomware count held steady at four cases in both months, suggesting the threat remained present without becoming the vertical's main story. Fraud, by contrast, expanded much more sharply and spread across more countries and subsegments. That should push teams to prioritize tactical awareness campaigns, stronger authentication, and detection of unusual transfers, rather than reading August as a month centered on destructive malware.
The nature of legal risk also changed. The Argentine rulings and the mix of reports, fines, and rules in Chile show that judges and regulators are less willing to accept generic explanations. If a bank cannot prove monitoring, alerting, blocking, or timely response, the cost is no longer only reputational. It is also judicial, administrative, and in some cases, directly financial.
Recommendations for security teams
Security teams at banks and insurers should treat this month as a signal to tighten identity controls and fraud response, not just infrastructure defenses. The immediate priority is to review authentication flows, support channels, transaction monitoring, anomaly detection rules, and customer service guidance for impersonation by phone, SMS, messaging apps, and video.
First, defenses against SIM swapping, session theft, and mobile identity hijacking should be strengthened. Cases in Argentina show that a compromised phone number can be enough to drain accounts or speed up transfers. That means adding risk signals for device changes, new payee setup, SIM replacements, and urgent transactions to newly opened accounts.
Second, institutional impersonation needs to be treated as a recurring campaign. Fraud involving fake bank call centers, BCRA deepfakes, and fake QR-based loans shares the same foundation, it exploits trust in a brand and time pressure. The response should not be limited to broad awareness campaigns, but should include short, repeatable, specific messages inside the app, the call center, and complaint channels.
Third, fraud monitoring and AML compliance monitoring need tighter integration. Operação Klonen and the Brazilian electronic fraud case show that stolen money moves fast and is quickly dispersed. If fraud sees the event but AML arrives too late, the damage is already done. Cross-team visibility, along with shared playbooks, reduces that gap.
Fourth, it is key to review operational incident handling and partial data exposure. The Pefisa case shows that a limited leak can fuel later fraud without touching passwords or balances. That requires monitoring abuse of exposed data, accelerating notification to potentially affected users, and adjusting prevention rules in the following months.
Fifth, banks and insurers operating in Chile need to prepare their workflows for the reporting cycle of 3, 24 or 72, 7 and 15 days, depending on criticality and the type of agency. It is not enough to know the obligation exists. Teams need to practice who files, who consolidates evidence, who approves communications, and who maintains technical and legal traceability.
Sixth, customer service should no longer be a peripheral part of fraud response. August made clear that many attacks are resolved, or made worse, at that point. If the customer's first point of contact cannot verify, block, escalate, and document, the defense chain breaks. Real security in this sector starts before the transaction and ends after the complaint.
Frequently Asked Questions
What forces incident reporting to move faster in Chile, Brazil, and Argentina?
Chile is the most prescriptive case in the material, because Law 21.663 and Decree 295 set early warning at three hours, updates at 24 or 72 hours depending on criticality, an action plan within seven days, and a final report within 15. In Argentina and Brazil, there were rules and alerts, but the sources provided did not spell out a cycle this precise.
What type of fraud dominated the month, and which countries showed it most clearly?
Fraud and phishing dominated, with 44 verified incidents. They appeared most clearly in Argentina, Brazil, Bolivia, Chile, Paraguay, and Peru, through deepfakes, fake bank call centers, SIM swapping, fake QR-based loans, impersonation by calls and messages, and account drain.
Was there confirmed ransomware encryption against banks or insurers in the region?
The material recorded four cases with ransomware or extortion as the primary focus, two with confirmed asset encryption and two where the source did not allow the technical impact to be determined. The sources provided do not show clear cases of Latin American banks or insurers with verified encryption as the month’s main event.
Which country showed the most regulatory pressure on digital banking and payments?
Brazil, Chile, and Bolivia concentrated the most visible pressure, though for different reasons. Brazil strengthened Pix and moved forward on crypto alerts, Chile tightened incident reporting with Law 21.663, and Bolivia activated two-factor authentication and complaints over fake loans. If the operational scope over payments is the measure, Brazil and Chile stand out.
What should a bank review first if it wants to reduce exposure to these cases?
First, authentication and detection of identity changes, because several cases this month exploited SIM swapping, phishing, fake calls, and impersonation. Second, monitoring of unusual transactions and new payee registrations. Third, customer service scripts and blocking procedures, because early response was key in the most visible incidents.
Material limitations
This report was prepared exclusively with the material provided for August 2026 and only with facts dated within that month. No internet access or external sources outside the authorized list were used. The indicators reflect the base and time window stated above, and they do not add attempt telemetry or automated blocks, because the material did not provide figures of that kind.
A zero indicator, especially the critical CVE count, means that this data point was not recorded in the August 2026 material analyzed, not that no critical vulnerabilities were exploited in the region. The same applies to any thematic absence: it reflects the available corpus, not the full scope of real-world risk.
Ransomware and extortion were classified cautiously. When the source did not allow a distinction between encryption, exfiltration, or a simple mention on a leak site, that uncertainty was noted in the analysis. Consumer social media and sponsored or commercial posts that are not included in the approved source list were also excluded as evidence.
The indicator window was August 2026. Facts from earlier months, including comparisons with July, were used only for contrast and always with the corresponding month stated explicitly. Sectors are not exclusive, so the same event can affect more than one subsegment of the vertical, especially when it involves a mix of banking, telecom, payments, and compliance.
Sources
- Clonaron mi tarjeta de crédito, hicieron compras online y esto fue lo hice para frenar la estafaTN (Todo Noticias)
- 3 hábitos simples para proteger tu cuenta de banco y billeteras de robos de dinero por phishingiProUP
- Hammurabi online, 24/8/2026Instituto Hammurabi
- Le vaciaron la cuenta en dólares tras una estafa por X y la Justicia repartió culpas entre el banco y el clienteInfobae
- Estafa digital: le robaron casi $20 millones y la Justicia les impuso una dura condena a la compañía telefónica y al bancoInfobae
- La Justicia ratificó un fallo provincial contra un banco por fraude digitalAgencia de Noticias San Luis
- Ciberestafas: ya no se clonan tarjetas pero crecieron las páginas falsasDiario 7 Lagos
- Comunicación “A” 8438/2026Radar Normativo
- Argentine Appeals Court Holds Movistar and Banco Galicia Liable for Ignoring a Biometric ID RulePeople of Internet
- El Banco Central alertó por un nuevo tipo de estafa que vacía cuentas y roba ahorrosiProUP
- Alerta por una nueva estafa virtual: cómo es el engaño que usa la imagen del Banco Central para robar ahorrosInfobae
- Argentine Central Bank Warns of Fraud Using Deepfake ...Scam / security analysis portal
- El BCRA lanzó una alerta urgente por una estafa que usa su imagen para robar datos y dineroEl Economista (Argentina)
- Norma 428601 – BANCO CENTRAL DE LA REPUBLICA ARGENTINA (B.C.R.A.)Banco Central de la República Argentina / Argentina.gob.ar
- Me vaciaron la cuenta: ¿es responsable el banco? La Justicia empieza a dar respuestaPrimera Edición
- SIM swapping: condenan a una telefónica y a un banco por transferencias millonariasDerecho Argentino
- Alarma por el incremento de ciberfraudes: en lo que va del 2026 ingresaron más de 200 denuncias por mesCipolletti Digital
- Estafa con TeamViewer: la Cámara Comercial repartió la responsabilidad 80/20 entre el banco y el clienteNino Legal
- Impuestos aclara que el doble factor de autenticación responde a un estándar global de ciberseguridadAgencia Boliviana de Información (ABI)
- Milenio alerta sobre avance del crimen organizado y “captura institucional” en BoliviaEl Día
- Bolivia está cerca de salir de la lista gris del GAFI, según director de la UIFErbol
- Bolivia está cerca de salir de la lista gris del GAFI, según director de la UIFeju.tv
- Casi 173.000 contribuyentes regularizan deudas mientras el SIN eleva la ciberseguridadeju.tv
- Entel impulsa el fortalecimiento del CSIRT Bolivia frente a amenazas cibernéticasErbol
- BCB denuncia penalmente a presuntos estafadores por falsos créditos con códigos QRRed Uno (Bolivia)
- El doble factor de autenticación responde a un estándar global de ciberseguridadServicio de Impuestos Nacionales (SIN)
- Oruro: Envían a la cárcel a un prófugo acusado de estafa múltipleLa Patria 3.0
- Impuestos refuerza la seguridad digital de los contribuyentes mediante el doble factor de autenticaciónServicio de Impuestos Nacionales (SIN)
- Bolivia KYC, KYB & AML compliance checklistVoveid
- BC: Vazam 28 mil chaves Pix da Pefisa, braço financeiro do grupo PernambucanasConvergência Digital
- Banco Central do Brasil vai lançar sistema de alerta contra ameaças cripto após ataque de US$ 180 milhõesBingX Flash News
- BCB avança em vigilância de corretoras com HypernativeSpaceMoney
- BC prepara sistema de alertas para ameaças envolvendo criptoativosValor Econômico
- Banco Central identifica instabilidade no Pix e descarta ataque cibernéticoTimes Brasil
- Pix tem instabilidade pela manhã e volta ao normal; BC descarta ataqueO Tempo
- BC admite instabilidade no Pix, mas diz que já foi resolvida; razões ainda estão sendo apuradasO Globo
- Banco Central adota novas regras de segurança no Pix para barrar golpesPortal Mais 360
- Banco Central do Brasil advances to contracting HypernativeHypernative
- Operação mira quadrilha por fraude de R$ 50 mi contra empresasCorreio Braziliense
- Polícia Civil faz operação contra quadrilha de furtos eletrônicos que causaram prejuízo de R$ 50 milhões em empresasG1
- PF deflagra operação contra fraudes bancárias eletrônicas e lavagem de dinheiroPolícia Federal do Brasil
- Novas regras do Banco Central, PIX e Drex elevam a cibersegurança financeiraEstado de Minas
- Como golpistas fazem vítimas no golpe da falsa central bancáriaG1 (Globo)
- Autoridades firman convenio que permitirá constituir una Mesa Nacional contra Fraude Financiero TransnacionalEn la Ciudad
- Firman convenio que permitirá constituir una mesa nacional en contra del fraude financiero transnacionalEl América
- Ciberinteligencia: la pieza clave para cumplir con la nueva ley de ciberseguridad en ChilePublimetro Chile
- Interés, temor y celeridad: ¿cómo avanzan las empresas en el cumplimiento de la Ley Marco de Ciberseguridad?Revista Seguridad & Defensa
- Guía completa de la Ley Marco de Ciberseguridad de ChileLey21663.info
- Banco Central advierte aumento de fraudes en pagos digitales: denuncias sumaron US$98 millonesEx-Ante
- Preguntas frecuentes sobre la Ley 21.663Ley21663.info
- Ley 21.663: la Ley Marco de Ciberseguridad de Chile explicadaZynap
- 94% de los clientes de BancoEstado ya no usa tarjeta de coordenadasChócale
- Tarjeta de coordenadas: Quiénes podrán seguir usándola y plazos de los bancosEl Mostrador
- Fin de la tarjeta de coordenadas: el cambio que ya comenzó en Chile y el fraude que sigue poniendo en riesgo tu dineroRadio Futuro
- Alerta por cambio en los bancos: ya cambiaron los requisitos para transferir dineroEl Mostrador
- Proyecto de carta circular - Agosto 31 de 2026Superintendencia Financiera de Colombia
- Superfinanciera anuncia alivios para deudores afectados por el terremoto: estas son las medidas para créditos y segurosInfobae
- Instrucciones para mitigar el impacto de la situación de desastre sobre los consumidores financieros afectadosSuperintendencia Financiera de Colombia
- Colombia's Financial Regulator Proposes Emergency Relief Rules For Earthquake-Affected Borrowers And Insurance ClaimantsFinance Colombia
- Superfinanciera activa 'Quejas exprés' para reclamos financieros relacionados con el sismoMSN / medio colombiano sindicado
- Proyecto de Circular Externa 13 - 2026Superintendencia Financiera de Colombia
- Estafa bancaria: así funciona el engaño en el que delincuentes se hacen pasar por funcionarios del bancoEl Colombiano
- Responder este mensaje de un asistente virtual podría costarle millones de pesos y hacerle perder sus cuentas bancariasSemana
- Alerta por estafa con falsos préstamos bancarios en Bogotá: así operanCityTv
- Evite ser víctima de ciberdelincuentes que usan falsos asistentes virtuales para hurtar datos bancariosBogotá
- En un 80%, los ciberdelincuentes usan la IA para mejorar el vector de ataqueCaaguazú Noticias Digital
- Ciberdelincuentes cambian de estrategia y acechan las cuentas bancariasLa Nación
- Ciberataques bancarios cambian de modalidad y exigen mayor prevenciónLa Nación
- Sin darte cuenta, te vacían la cuentaLa Tribuna
- ¿El banco más inseguro del Paraguay? Itaú acumula denuncias por millonarias estafasDiario Vanguardia
- Allanan vivienda en San Lorenzo por caso de vaciamiento de cuenta de diputadaABC Color
- Alerta por estafas digitales, roban millones desde una página enmascaradaCanal paraguayo (video alojado en YouTube)
- Emprendedora, otra víctima de cibercriminales: le robaron G. 43 millones de su cuentaHoy
- Ciberestafas y vaciamientos de cuentas: víctima relata cómo le robaron G. 25 millonesABC Color
- Cibercrimen: ¿cómo se vulneran las cuentas bancarias y qué puedo hacer para prevenirlo?ABC Color
- Una diputada opositora de Paraguay denuncia haber sido jaqueada y robada por 5.800 dólaresAgencia EFE
- Un venezolano detenido por vaciamiento de cuenta bancaria de Rocío VallejoABC Color
- Diputada Vallejo denuncia cómo le robaron la cuenta bancariaParaguayo Independiente
- Diputada denuncia millonario vaciamiento de su cuenta bancariaYouTube / canal televisivo paraguayo
- 'Remcos', posible responsable del vaciamiento de la cuenta de la diputada VallejoHoy
- Cómo proteger tus cuentas bancarias según la guía del BCPRDN
- Identidades sintéticas y técnicas de fatiga: contraseñas ya no frenan el fraude digital y bancos en Perú encienden las alertasInfobae Perú
- Banco de la Nación alerta a sus clientes por nuevas llamadas y mensajes fraudulentos para robar dineroEl Machete Perú
- Clientes del Banco de la Nación bajo ataque: Estafadores siguen llamándoles para robar su dineroInfobae Perú
- Resolución SBS Nº 02052-2026Actualidad Empresarial
- Denuncian presunto fraude informático por S/1.4 millones en agravio de EsSalud en LambayequeLa República
- Ciberdelitos con inteligencia artificial: Suplantación de voz y comprobantes falsos, el nuevo riesgo en Yape y WhatsAppInfobae Perú
- Resolución SBS Nº 02022-2026Actualidad Empresarial
- SBS fija nuevas multas para bancos, AFP y aseguradorasBaker Tilly Perú
- PNP frustra presunto fraude de más de S/700 000 y detiene a tres personasPolicía Nacional del Perú / YouTube
- US Bank investigates LockBit's claims as ransomware crims set pay-or-leak deadlineThe Register
- LockBit 5.0 targets U.S. Bank, one of the largest banks in the United StatesEscudoDigital
- GlobalSecretGroup Ransomware Escalates Extortion Activity in August 2026BrinzTech
- Hackers targeted US private equity, other firms including Blackstone, CMEReuters
- UBS hit with $125m fine by US FinCENFintech Futures
- The Morning Risk Report: UBS Fined $125 Million Over Alleged AML FailuresThe Wall Street Journal
- UBS fined $125 million by US regulators for money laundering violationsReuters
- FinCEN Assesses Historic $125 Million Penalty Against UBS Financial Services Inc. for Recidivist BSA ViolationsFinCEN
