CiberLATAMbywhalemate
Intelligence report

Neobanks, FinTech, and PSPs, August 2026

Fraud, payment failures, and two extortion cases defined August in LATAM; Chile and Brazil showed the sharpest signal.

Sep 1, 202627 min read
Neobanks, FinTech, and PSPs, August 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are completed automatically using verified dated facts within the period. Each one states its basis and counting criterion, so the figures reconcile across modules. They are the recurring month-to-month reading, and the later analysis develops the cases without repeating this summary.

Indicator window: 83 dated facts in August 2026. Facts from earlier months are used only as comparative context in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Verified signal monthly dashboard August 2026 · Latin America Top threat: Fraud (25 of 83 incidents). Coverage: 83 incidents dated in August 2026 VERIFIED INCIDENTS 83 period baseline: all counts measured from below against this total RANSOMWARE / EXTORTION 2 2 encrypted assets confirmed UNCLASSIFIED INCIDENTS 19 breaches or outages without declared threat type FRAUD / PHISHING 25 documented fraud campaigns documented REGULATION 4 rules, rulings, or sanctions UNIQUE CVEs 1 CVE-2026-72898
Verified signal monthly dashboard — Base: 83 verified incidents dated within the period for Latin America.
MONTHLY FIXED MODULE Threat axis distribution August 2026 · Latin America Each case counts in just one axis, so the total is exactly 83. "Unclassified incidents" is the remainder. Fraud 25 Unclassified 20 Incidents 19 Vulnerabilities 13 Regulation 4 Ransomware 2
Threat axis distribution — Each case is assigned to one axis based on its classification; the total reconciles to the 83 cases in the period.
FIXED MONTHLY MODULE Sectoral distribution of alerts August 2026 · Latin America Base: 83 incidents in the period · total 129 because 33 incidents fall into more than one sector. Finance 60 Public sector / OIV 18 Technology 17 Other / unspecified sect… 14 Retail / consumer 10 Telecom 4 Education 4 Energy 2
Sectoral distribution of alerts — Heuristic sector breakdown by victim. One incident may affect more than one sector, so the total can exceed the base.
FIXED MONTHLY MODULE Geographic distribution of signal August 2026 · Latin America Each incident is assigned to one country or to regional coverage, so the total is exactly 83 out of 83 incidents of… Regional 22 Argentina 16 Chile 15 USA 15 Brazil 13 Peru 2
Geographic distribution of signal — Verified incidents in the period grouped by country or regional coverage; each incident is counted once.

Monthly executive summary

August 2026 sent a mixed but tougher signal for neobanks, FinTechs, and payment processors in Latin America: 83 verified events, 19 unclassified incidents, 25 documented fraud or phishing cases, and two extortion or ransomware events as the primary focus. The month’s picture shows more operational pressure from fraud than from vulnerabilities, with Chile and Brazil as the main hotspots and an electronic payments case in Argentina that exposed control failures across the collection chain.

The month’s most visible event was the processing error involving TelePASE and Mercado Pago on the Riccheri Highway, where, for several hours on August 14, debits of up to $155.802 were recorded for a crossing whose usual cost was about $1.548,82. Coverage agrees that there was no cyberattack, but rather a pricing and processing issue. Even so, the case exposed a sensitive operational weakness for any PSP: insufficient validation between capture, calculation, settlement, and dispute handling.

At the same time, Brazil concentrated the month’s most complex signal through several police operations and cases of digital financial fraud. Operação Pane Seca, Operação Ouroboros, and Operação Klonen point to everything from intrusions into financial institution systems to combined schemes involving electronic fraud, money laundering, and the use of cards, transit accounts, and virtual asset platforms. The attempt to divert R$ 350 million from TAG, Stone’s acquirer, was blocked in time, but it exposed a sector-wide weak point in acquiring infrastructure and in antifraud coordination among actors.

Chile provided the clearest regulatory and quantitative risk signal of the period. The Central Bank of Chile reported that complaints of fraud involving digital payment methods reached US$98 million in the first half of 2026, equivalent to about 0,06% of transacted value, with a steady increase since the second half of 2024 and a marked persistence in debit cards. The official reading pushes the issue away from being treated as an isolated anomaly and toward a structural trend of fraud against everyday payment instruments.

The final week of the month added a different kind of incident in the regional crypto-finance ecosystem, although with a global architecture. Avici, a neobank built on Solana, and its issuing partner Rain reported a vulnerability in card contracts that allowed user funds to be drained and forced full reimbursements. The technical source describes an authorization flaw in an older version of card contracts, now patched, confirming that risk does not always come from a perimeter intrusion, but also from contract logic and version management.

TIMELINE Verified events for the period 5/8 Coverageeconomicnational 5/8 The fifth Reportof 5/8 The Central Bankof 6/8 In the publicpresentation 6/8 Sector coveragepoints to 6/8 Mediaspecializedinretail
Verified timeline of events, August 2026 — Milestones with confirmed dates within August 2026. Events from earlier months are excluded from the timeline and used only as context.

Regional outlook for the month

August’s regional picture is one of elevated risk, not because of a single catastrophic breach, but because of the mix of volume, attack vectors, and repeated failures in the payments layer. The month brought transaction fraud, processing errors, possible data exposure incidents, extortion threats tied to leaking data, and a breach in card crypto infrastructure, with direct impact on users, banks, processors, and payment systems.

Fraud was the dominant signal, accounting for 25 of 83 verified incidents. That does not mean the rest of the month was less serious. It means the available material was concentrated in diversion attempts, scams, alerts, and anti-fraud operations. Operationally, that distribution fits a more mature payments ecosystem, one that is more exposed and more closely monitored, where prevented losses and blocked cases are already part of daily risk.

Chile provided statistical evidence of persistence. The Central Bank itself said fraud involving digital payment methods has increased since 2024 and that in the first half of 2026 it rose across almost all instruments, except ATM withdrawals. The most sensitive part of that pattern is that debit cards show the most persistent behavior, shifting the discussion from isolated theft to account control, merchant validation, and real-time transaction monitoring.

Brazil added another layer, institutional response capacity. The Federal Police announced operations that dismantled groups dedicated to attacks on financial institution systems, electronic banking fraud, and money laundering. The relevant point for the sector is not just criminal enforcement, but the range of schemes, from extortion demanding 10 bitcoins to avoid leaking data, to attempts to reroute receivables and the use of crypto structures to hide funds.

Argentina, through the Riccheri incident, showed a different operational risk. There was no intrusion and no malware, but there was a pricing failure that directly affected users of a wallet integrated with an electronic toll system. For PSPs and wallets, the message is clear: billing integrity, limit controls, and reversibility should be treated with the same seriousness as authentication and fraud prevention.

Period indicators

The month is based on 83 verified facts dated August 2026, and all other indicators are calculated exclusively from that time window. The snapshot does not mix telemetry with incidents, and the shift from July shows a move away from vulnerabilities toward fraud and processing failures.

Indicator August 2026 July 2026 Change
Verified facts in the period (base for all indicators) 83 66 +17
Time window for the indicators 83 facts dated August 2026 66 facts dated July 2026 N/A
Unclassified incidents (breaches or outages) 19 3 +16
Cases with ransomware or extortion as the primary focus 2 1 +1
Ransomware breakdown by impact type, confirmed asset encryption 2 1 +1
Documented fraud or phishing cases 25 0 +25
Documented regulatory moves 4 3 +1
Critical CVEs mentioned 1 15 -14
Sectors with at least one documented fact 7 6 +1
Dominant threat of the month Fraud (25 of 83 facts) Vulnerabilities (40 of 66 facts) Shift in focus
Facts with direct source confirmation 94% N/A N/A

The 19 unclassified incidents merit separate attention. In this kind of report, that category does not mean lower severity. It means the source material was not specific enough to classify the technical nature or impact. For a CISO, that matters because an unclassified breach can hide anything from a service outage to data exposure or an ongoing extortion attempt.

The drop in critical CVEs from 15 to 1 should not be read as a structural improvement. In August, the material included only one critical CVE mentioned, but that does not mean the region stopped facing relevant vulnerabilities. It simply means the month’s source set was dominated by fraud, law enforcement actions, and processing failures, not by technical disclosures of software exploitation.

Relevant incidents

This month is best explained through specific cases rather than a single narrative. The main ones were the mass TelePASE and Mercado Pago failure in Buenos Aires, a series of anti-financial-fraud operations in Brazil, the Central Bank of Chile’s warning about persistent digital fraud, and the breach in the Avici and Rain crypto card ecosystem.

TelePASE and Mercado Pago failure on Riccheri

The Riccheri Highway incident was August’s most visible case in mass-use electronic payments. Between 10:00 a.m. and 6:00 p.m. on August 14, users who paid with TelePASE linked to Mercado Pago were charged up to $155,802 for a crossing that normally cost $1,548.82. The source agrees that the concessionaire Corresur acknowledged a processing error and that refunds were underway.

The most delicate part of the case is that there were no signs of a cyberattack. Coverage by Infobae, La Nación, La Gaceta, Mejor Informado, Mosca and other outlets describes a problem in the electronic billing calculation or integration, not a malicious intrusion. That does not reduce its relevance for the sector, because a processing error of this magnitude is an operational failure with a direct impact on trust, reconciliation and customer support.

Mosca adds a key detail, between the vehicle crossing record and the money leaving the account, there was no control that stopped a charge one hundred times above the tariff. That point matters for PSPs and wallets, because it points to missing limits and anti-fraud validations inside the collection chain, not at the network edge or the user-facing interface.

The formal complaint path was also documented. Alerta Tránsito details that the user first had to complain to Corresur or through TelePASE and, if the claim was rejected, escalate it to the Dirección Nacional de Vialidad. That route matters because it turns a technical failure into an institutional compensation process, something many payment operators underestimate until the problem is already on social media and in the press.

Attempted R$ 350 million fraud against TAG, Stone

Brazil produced the month’s highest nominal-volume case in acquiring and receivables registration. TAG, controlled by Stone, detected an attempted fraud worth nearly R$ 350 million in card payments and said there was no financial impact or customer data exposure. The case was blocked after an external alert and cooperation among registrars and players in the payments ecosystem.

The importance of the episode lies in the vector. According to Valor Econômico coverage, the attackers registered in TAG’s network as ecosystem participants and sought to alter the ownership of receivables from large corporations, redirecting payment flows to accounts they controlled. It is a more sophisticated fraud pattern than basic phishing because it targets settlement infrastructure and trust between actors in the chain.

The statement reproduced by economic media shows an orderly sector response, security protocols were activated, access was interrupted, cooperation with other systems was tightened, the attempt was blocked and neutralized, and the competent authorities were notified. Febraban and ABBC also issued alerts to their members, and all related operations were blocked.

Valor International’s reference to a financial institution in the ecosystem, such as Rede, helps explain the value of third-party anti-fraud monitoring. Early detection of a suspicious destination account was a decisive piece in stopping the scheme. That reinforces a practical lesson: detection does not always start with the flow originator, but with the network of counterparties that sees crossed anomalies.

Operação Pane Seca and the economic scale of financial fraud in Brazil

Brazil’s Federal Police reported dismantling a group responsible for intrusions into the systems of financial institutions, with estimated losses of R$ 227 million. The case broadens the month’s map because it was not just an isolated theft, but an organization with the ability to materially affect banking and payments infrastructure.

The operational value of the statement lies in the word "intrusions." Unlike the blocked attempt against TAG, here the signal is illicit access to financial institution systems, a point where the PSP sector converges with traditional banking, authentication, insider fraud and incident management. For LATAM, this type of case often indicates hybrid attack chains, where social engineering, credential abuse or integration weaknesses matter more than any single tool.

The reading alongside the German case attributed to a payment provider is also important. Help Net Security reported that German and Brazilian authorities attribute the incident to the exploitation of a vulnerability in the booking process of a German payment services provider, caused by a faulty update. That description shows that risk does not stop at geography, and that Brazilian actors can become linked to attacks on international payments infrastructure.

Operação Ouroboros and electronic fraud with money laundering

In Rondônia, the Força Integrada de Combate ao Crime Organizado investigated and dismantled a criminal organization that carried out electronic fraud against financial institutions and laundered the proceeds. The significance of this case is not only the fraud itself, but the coupling between digital fraud and laundering, a combination that often complicates attribution and fund recovery.

The Federal Police’s official note describes a financial circuit that does not end with theft, but with the conversion and concealment of assets. For neobanks, PSPs and fintechs, that chain means fraud must be treated as an AML risk, not as an isolated account fraud incident. If a fraudulently originated transaction can move through transit accounts, companies or virtual assets, reaction time becomes critical.

Operação Klonen and the combined use of payments and cryptoassets

Operação Klonen added a second layer of complexity. The Federal Police said the group under investigation hid funds obtained through payment cards issued without the beneficiaries’ consent, transit accounts, companies, payment institutions and virtual asset platforms. That mix of payment methods and cryptoassets shows an adaptive laundering infrastructure.

The most useful point for a sector reading is that the concealment chain brings regulated and semi-regulated actors together at the same time. That makes oversight harder because the fraud is not observed on a single platform. It spreads across issuers, acquirers, fintechs, pass-through accounts and crypto intermediaries, which requires signal correlation rather than isolated alerts.

Kambista breach and possible data exposure

Peruvian fintech Kambista notified users about a security incident in its cloud infrastructure that may have exposed sensitive data. The company said it found no evidence of extraction or leakage at the time of notification, and iupana stressed that the decision was preventive.

This case falls into the untitled incident category for the period, because the material does not confirm exfiltration or detail a full technical vector. Even so, for a digital exchange, the mere act of notifying a possible exposure already marks a significant risk threshold in trust, compliance and user support. The regional relevance lies in cloud use as a shared risk surface.

Avici and Rain, vulnerability in card contracts on Solana

The final block of the month was the most technical in the crypto-finance ecosystem. Avici, a Solana-based neobank, suffered a breach on August 28 that drained funds from users linked to its crypto cards. Estimates range from around 600,000 dollars to just over 1 million, depending on the source, and full reimbursements to affected users were confirmed.

The explanation that best consolidates the material is Rain’s. The card infrastructure provider attributed the incident to an authorization vulnerability in an older version of its card contracts, which has now been updated across all programs. FinanceFeeds and other technical outlets point to a faulty authorization flow and obsolete contracts still deployed, reinforcing that the failure was logical and contractual, not a classic perimeter intrusion.

Tria reported 636 affected users for a total of 431,945 dollars in card balances, while Avici reported 1,685 users with about 500,859.22 dollars in balances to be compensated. CoinDesk raised the total drained amount to approximately 1.1 million dollars and recorded a drop of up to 49% in the AVICI token. The common point is clear: a single infrastructure provider can concentrate risk across multiple programs, and a late or incomplete patch has systemic effects.

Active Threats and Campaigns

In August, the region was not dominated by a classic ransomware campaign against fintechs, but by an ecosystem of fraud, extortion, and abuse of payment infrastructure. That distinction matters because it changes which controls should be prioritized: authentication and authorization, processing integrity, counterparty monitoring, and coordinated response with payment networks and regulators.

Ransomware and Extortion

There were two cases where ransomware or extortion was the main focus, and in both the available material makes the financial pressure component clear. The first was the Brazilian Federal Police investigation into a group that breached the system of a financial institution and demanded 10 bitcoins not to disclose sensitive data. Coverage by Correio Braziliense adds that the demand was equivalent to approximately R$ 328 mil.

The source does describe a classic extortion case, with a threat to leak information and payment in cryptoassets. The material does not provide enough detail to say whether assets were encrypted, so it should be described as extortion with a disclosure threat, not as confirmed ransomware with encryption. That nuance avoids conflating legal impact with operational impact.

The second case linked to economic pressure or damage was the exposure in the crypto ecosystem of Avici and Rain cards, but it does not fit the same category. In that case, the vector was an authorization vulnerability in card contracts, not extortion. Recovery came through refunds and patches, not negotiation with attackers.

Fraud and Phishing

Fraud was the dominant threat in August and cut across several subsectors. The TAG case involved an attempted diversion of receivables, the Riccheri incident involved operational collection fraud, and Chile provided a persistent statistical signal of rising fraud in digital channels, especially debit and credit cards.

What stood out in August is that much of the fraud did not remain a mere attempt. There were blocked cases, alerts, and referrals to authorities. That means the sector is detecting more, but exposure is also high. The fact that 25 of 83 verified incidents were documented fraud or phishing shows sustained pressure on the transactional layer.

The reading of the Brazilian cases is that fraud no longer depends only on deceiving the end user. It can also mean manipulating trusted relationships between registrars, acquirers, and destination accounts. Chile, by contrast, underscores the persistence of risk in everyday payments and the greater weight of debit cards. These are two sides of the same problem.

APT and Organized Intrusion

The material did not show a classic APT campaign attributed to a persistent group with a regional focus on neobanks or PSPs in Latin America. There are signs of organized intrusion, such as the Brazilian investigation into the attack on a German financial institution, and the cases of intrusions into financial systems in Brazil. But the material is not enough to classify this as an APT campaign in the strict sense.

The absence of a clearly documented APT campaign does not mean there was no sophisticated intrusion. It only means August was dominated by fraud, extortion, processing errors, and contract vulnerabilities, not by solid attribution to a persistent actor. For defensive intelligence, that is also useful signal, the ecosystem is closer to large-scale fraud than to a discreet, long-running offensive operation.

Critical Vulnerabilities

The analyzed material recorded 1 critical CVE mentioned during the period, but it did not identify it by number or with enough technical detail to build an exploitation table. That does not mean critical vulnerabilities were absent in the region, only that the month was dominated by operational incidents, fraud, and financial fraud cases, not technical CVE disclosures.

CVE Software Exploitation Source
Not specified in the material German payment services provider, card contract on Solana, payments-related infrastructure A vulnerability in a booking process caused by a faulty update, and an authorization failure in legacy card contracts, are described. The material does not provide a specific CVE Help Net Security, FinanceFeeds, CoinDesk

The practical lesson from this block is that the critical attack surface in the sector is not limited to traditional software. In August, the clearest vulnerability did not appear as a CVE exploited in a banking app, but as a contract logic problem and a flawed update in the payments and cards layer. That calls for a broader risk inventory beyond software installed on servers.

Regulation and compliance

August brought four documented regulatory moves, and all point in the same direction: more reporting obligations, stricter response requirements, and tighter oversight of payment providers. The region is not seeing any loosening of controls, but a tougher notification and oversight framework.

In Chile, the Central Bank published and explained its 2026 Payment Systems Report, with a focus on digital fraud and the persistent increase since 2024. The official material matters because it does more than describe losses, it pushes for stronger regulatory measures and action by payment service providers. That framing puts the sector under direct scrutiny.

TrendTIC noted that, under Chile’s Cybersecurity Framework Law, public and private institutions designated as Critical Infrastructure Operators or Essential Service Providers must report to the National CSIRT any cyberattack or incident with significant effects. For the payments ecosystem, that means part of the industry now faces more demanding and earlier formal reporting duties.

In Brazil, the official response to fraud and intrusions was also institutionalized. The Federal Police announced operations such as Pane Seca, Ouroboros and Klonen, with coordination of investigations and communication with the relevant authorities. Although these are not regulations in the strict sense, they point to an environment in which financial fraud, money laundering and cyber intrusion are being pursued in a more integrated way.

The TAG case also showed the value of reporting and cooperation among private actors. The company activated protocols, blocked access and notified the authorities, while industry groups alerted their members. In compliance terms, that response matters as much as preventive control, because the operational standard is no longer just to avoid the incident, but to prove traceability and containment.

Countries and subsegments most affected

The month’s geographic distribution was uneven. Argentina, Brazil, Chile, and Peru stood out, each with a different level of detail. At the subsegment level, the most exposed areas were banking and acquiring, payment processors, digital wallets and exchange platforms, and the crypto card ecosystem.

Argentina

Argentina was defined by the Riccheri case, which put the integration of electronic tolls, virtual wallets, and payment reconciliation under scrutiny. The impact was highly visible because the deviation involved amounts hundreds of times higher than expected and because media coverage was extensive. For the PSP subsegment, the episode is a reminder that a calculation failure can have nearly the same reputational effect as a breach.

The complaint process documented by Alerta Tránsito also shows a formal response chain involving the concessionaire, TelePASE, and, ultimately, Vialidad. That sequence is useful for understanding how billing incidents are handled in critical mass-service infrastructure. This was not a cyberattack, but it was a breakdown in transaction integrity.

Brazil

Brazil was the country with the highest concentration of incidents involving financial fraud, extortion, and police investigations. The three clearest threads were the attempted R$ 350 million fraud against TAG, the Pane Seca, Ouroboros, and Klonen operations, and the investigation tied to an attack on a German financial institution with suspected involvement of a Brazilian group.

The subsegment reading is equally clear. Stone, TAG, payment processors, acquiring, banks, and payment ecosystems appear interconnected. On top of that, there are signs of laundering through transit accounts, companies, and virtual asset platforms. Brazil showed a payments-chain problem, not an isolated incident at a single institution.

Chile

Chile contributed fewer specific incidents and a stronger structural signal. The Central Bank of Chile reinforced a narrative of persistent growth in digital fraud, with higher incidence in debit cards and reported losses of US$98 million in the first half of 2026. That affects issuers, acquirers, and payment providers directly.

The sector relevance is twofold. First, fraud rates are rising across nearly all payment instruments. Second, the central bank itself is calling for stronger regulation and controls. In risk terms, Chile appears less as a country with a single incident and more as one where the numbers are already forcing control redesign.

Peru

Peru enters through Kambista, which reported a possible data exposure in its cloud infrastructure. Although data extraction was not confirmed, the decision to notify users in advance reflects compliance sensitivity and reputational management. For a digital exchange fintech, even the possibility of exposure can trigger internal review and communication obligations.

Subsegments

In the electronic wallets and payments segment, TelePASE and Mercado Pago accounted for the most visible failure. In acquiring and receivables processing, TAG was the most serious case. In banking and organized financial fraud, Brazil concentrated several official operations. And in crypto finance, Avici and Rain showed how card infrastructure can affect multiple programs at once.

The comparison with July shows a clear shift in focus. The previous month was dominated by vulnerabilities, with 40 of 66 incidents. In August, the center of gravity moved to fraud, with 25 of 83 incidents. That does not mean the technical surface improved evenly, only that the available material captured more operational incidents, more diversion attempts, and more cases of insufficient validation.

The rise in unclassified incidents, from 3 to 19, is a methodological and operational warning sign. For anyone managing a payments portfolio, it can mean the ecosystem is seeing more events whose true nature was still unclear at the time of publication. In practice, an unclassified incident has to be tracked as a potential breach, outage, or fraud until proven otherwise.

The drop in critical CVEs mentioned, from 15 to 1, also calls for caution. This is not an improvement in regional exposure, but a change in the type of events reported by the sources. August brought less technical vulnerability disclosure and more fraud cases, police operations, and processing problems. The right reading is a shift in attention, not a lower risk profile.

The strongest signal to watch is the combination of fraud and shared infrastructure layers. TAG, TelePASE, and Rain show that risk is not only at the end user level, but in the calculation, authorization, settlement, and contract update chain. That expands the exposure radius to processors, registrars, acquirers, wallets, and issuing partners.

August versus July 2026Illustrative scale of comparable indicators from the monthly report.Fraud 25AugFraud 0JulEvents 83AugEvents 66JulCVEs 1AugCVEs 15Jul
Change in trend versus July — Comparison of the most useful indicators for reading this month’s shift from the previous one.

Security team recommendations

Security teams at neobanks, fintechs, and PSPs should treat August as a month for payment integrity controls, not just intrusion prevention. The available evidence points to prioritizing transaction validation, fraud correlation, third-party monitoring, and response plans that include operational and legal communication.

First, integrity controls should be strengthened across the entire processing chain. The Riccheri case shows that a pricing error can move from capture to final debit without a containment barrier. That requires value limits, exception rules, reconciliation tests, and alerts for unusually large deviations before the charge settles.

Second, third-party dependencies and update contracts should be reviewed. The Avici and Rain incident shows that an old version of a card contract can remain active and become a point of failure. Teams should require version inventories, patch confirmation, anomalous behavior testing, and clear criteria for deactivating legacy programs.

Third, in Brazil and across any acquiring or registration network, counterparty monitoring should be part of the defense. The TAG case indicates that an alert from a third party can stop a large operation. That suggests integrating external signals, suspicious destination lists, cross-checking of accounts, and rapid escalation among ecosystem actors.

Fourth, response procedures should include the regulatory layer from the outset. In Chile, the obligation to report to CSIRT Nacional may apply to critical operators and essential providers. In situations with possible data exposure, such as Kambista, preventive notification and traceability of the internal analysis are as important as forensic review.

Fifth, fraud, extortion, and technical vulnerability should be clearly separated in internal classification. If a team mixes categories, it loses the ability to prioritize. August showed extortion with a threat of leakage, transaction fraud, processing failures, and a card contract vulnerability. Each requires different controls and different escalation paths.

Frequently asked questions

Which country showed the sharpest signal for digital payments in August?

Brazil concentrated the highest density of incidents tied to fraud, extortion, and official investigations, while Chile delivered the most persistent statistical signal on rising digital fraud. Argentina stood out for a mass processing failure at toll booths, and Peru for a possible data exposure at a fintech.

Was the TelePASE case on the Riccheri a cyberattack?

No, the available coverage describes it as a processing and billing error in the integration between TelePASE and Mercado Pago. The case was serious because of the amount debited and the control failure, but the material does not attribute a malicious intrusion. See the relevant incidents section.

What was the month’s predominant threat, and how does it relate to blocked operations?

The predominant threat was fraud, with 25 of 83 verified incidents. That includes blocked attempts, sector alerts, and diverted funds that were stopped, such as the TAG case in Brazil. The mix of detected fraud and thwarted fraud shows defenses are kicking in, but also that pressure remains high.

What does it mean that there were 19 unclassified incidents?

It means the month’s material recorded 19 events as breaches or disruptions, but without enough detail to classify them precisely from a technical standpoint. That does not make them less serious. For security and compliance, an unclassified incident should still be tracked as a potential exposure, disruption, or fraud until confirmed.

Was ransomware confirmed in neobanks or PSPs in the region?

The material records two cases with ransomware or extortion as the primary focus, but the available text does not allow us to confirm ransomware with asset encryption in a regional fintech. In the Brazilian case cited, there was extortion with a threat to leak data and a demand for 10 bitcoins, not verified encryption.

Which subsectors should review their controls first?

Acquiring, payment registration, digital wallets, digital exchanges, and neobanks with card infrastructure or legacy contracts. The month showed failures in electronic billing, attempts to divert receivables, possible data exposure, and a vulnerability in card contracts on Solana.

Material limitations

This report was built exclusively from the facts dated August 2026 provided in the research material. No internet or external material was used, and no sources outside the authorized list were included. The indicator figures reproduce exactly the base and time window reported for the period.

An indicator at 0, or a low value, does not mean there is no risk in the region. In particular, the fact that the critical CVEs mentioned are 1 in August only means that this was the material analyzed for this month, not that there were no critical vulnerabilities exploited in Latin America. The same applies to other categories if the corpus did not capture them.

The indicator window covers 83 facts dated August 2026, and the comparative data correspond to the previous month only as a reference for trend. Facts from earlier months were not counted within the period, although some were used to contextualize trends or explain technical background.

Consumer social networks and unauthorized posts as a primary source, sponsored content, commercial press releases, and any material not included in the list of available sources for citation were excluded from the evidence. Aggregated telemetry of automated attempts or blocks was also excluded, because it does not constitute an incident and cannot be added to the monthly counts.

Sources