CiberLATAMbywhalemate

Brazil Open Finance and Deepfake Fraud

Evertec shows how Open Finance, Pix and facial biometrics are creating new fraud paths in Brazil, and how banks and regulators are responding.

Whalemate Labs · AI-assisted researchAug 3, 202638 min read

Evertec Trends put a structural shift in Brazilian financial fraud at the center of its latest analysis. The rise of e-commerce, Pix instant payments, Open Finance and embedded finance has improved efficiency, but it has also multiplied the points of contact criminals now exploit. The new attack profile blends social engineering, credential theft, account opening in third-party names, synthetic identity fraud, deepfakes designed to defeat facial biometrics, fake boletos, QR code tampering and abuse of user consent inside flows that appear legitimate.

The evidence collected in the research shows the problem is no longer marginal. Brazil recorded more than 9 million signs of financial fraud in the first half of 2026, with mobile phones as the main channel, Pix present in 85% of cases and close to 40% of events tied to social engineering scams. At the same time, sector studies and media reports point to a defense ecosystem that is moving faster, with banks adding multimodal biometrics, liveness detection, behavioral analytics and AI to spot anomalies, while the Central Bank strengthens its regulatory architecture with compulsory rejection of suspicious transactions, tougher penalties and controls over Pix keys and shell accounts.

Brazil has also become a regional laboratory for the fraud economy. Open Finance is already operating at the scale of tens of billions of API calls per month, and attackers are exploiting that expanded surface by hijacking sessions, simulating consent and using leaked real data to gain credibility. Deepfakes are no longer rare either. The ANPD said Brazil accounted for 39% of Latin American deepfake cases in 2025, and attacks using fake images, voices and identities rose 126% year over year. Data from the Federal Police, banks and specialized media points in the same direction, financial fraud in Brazil has become more professional, more automated and more dependent on generative AI.

The result is an environment where manual prevention is no longer enough. The technical response now goes beyond blocking transactions and includes CPF and CNPJ verification, two-factor authentication, stronger biometric validation, negative lists, remote validation controls against biometric injection and verifiable consent policies. This report organizes that picture, cross-references the regulatory and operational milestones and separates confirmed facts from claims attributed to unofficial sources, to show how financial fraud in Brazil moved from isolated channels to the infrastructure of the market itself.

Executive Summary

Evertec Trends described a fundamental shift in Brazilian financial fraud. The growth of e-commerce, card payments, card-not-present purchases, Pix, boletos and Open Finance created more touchpoints and, with them, more opportunities for criminal groups to exploit technological weaknesses, social engineering, identity theft and compromised credentials. This is not a single vector, but a fraud economy that is more diversified, more automated and less dependent on one attack platform.

The most sensitive part of the finding is that organized crime no longer has to force the infrastructure every time. According to the consolidated material, attackers in Brazil increasingly get victims to authorize the fraudulent operation themselves. That makes classic detection harder, because many legacy defenses relied on signs of a non-consensual transaction. If the user approves it, even under deception, the operation blends into a legitimate flow.

Open Finance is the structural factor. Operating at the scale of tens of billions of API calls each month and living alongside Pix and embedded finance as shared market infrastructure, it widens the exposure surface. Exame and Serasa note that the user authorizes data sharing under regulatory oversight and with legal backing, but they also warn that every new touchpoint increases exposure. CNN Brasil adds another risk, the secondary sale of data collected by ecosystem third parties, an issue the Central Bank is studying with a view to tighter rules. In other words, the trust model depends on much stricter technical and contractual controls than those required by a simple consent screen.

The biometric front has also changed. Evertec, Exame, Diário do Nordeste, Metro1, CNN Brasil, IT Section and Itaú Unibanco all point to deepfakes and manipulated selfies becoming part of the attacker toolkit. The target is no longer just passwords. Criminals try to bypass liveness checks, facial recognition, document validation and account opening using photos, audio and video generated or altered by AI. The material includes fake account openings, fraudulent loan applications, fake call center scams and one specific injection technique in which the camera flow is interrupted to insert synthetic video into the onboarding process.

The response from Brazil's financial sector is broad and increasingly regulatory. The Central Bank strengthened the anti-fraud framework with compulsory rejection of transactions showing signs of fraud, rules on shell accounts, requirements for the Banking as a Service model and harsher penalties. It also reinforced Pix controls, including transaction challenges inside apps, blocking of involved keys, CPF and CNPJ regularity checks and consistency checks on the name before registering, changing or porting keys. All of that confirms that the Brazilian case is no longer treated as a collection of incidents, but as a systemic governance problem for payments and identity.

The scale of the evidence matches that picture. Agência Brasil reported more than 9 million signs of fraud in the first half of 2026, with 78% of cases tied to mobile phones and 85% involving Pix. Quod attributes about 40% to social engineering. ANPD said Brazil accounted for 39% of Latin America's deepfake cases in 2025. Sector studies by Fenasbac, GASA, Febraban and Serasa point to multimillion-real losses and a rising victim count. The picture that emerges is clear, the line between banking fraud, digital identity and cyber abuse has almost disappeared.

Milestones timeline in Brazil2025Bank MasterliquidatedMay 2026New rulesICP-Brasil2026-07-06BC tightens Pixaccess2026-07-18Over 9M fraud2026-08-02Deepfakes up830%
Milestones timeline in Brazil — From tighter regulation to deepfake cases and fraud involving Pix and Open Finance.

Context and Background

Evertec Trends framed the discussion as a structural change in Brazil's financial system. The expansion of electronic payment methods improved financial inclusion and transaction efficiency, but it also increased exposure to fraud. The growth of e-commerce, in-person card payments, online card-not-present purchases, Pix, boletos and Open Finance opened new attack surfaces for actors who combine technical weaknesses with psychological manipulation.

The most important part of the context is that Brazil's financial infrastructure has become shared. Evertec argues that Open Finance, Pix and embedded finance stopped being isolated initiatives and now function as a common layer of the market. That has a direct consequence for fraud. If data moves between multiple participants, if payments are embedded invisibly in the customer journey and if compliance processes depend less on manual control, attackers no longer need to break one system. They only need to exploit a weak point in the consent, authentication or validation chain.

Exame explains that Open Finance allows users to authorize the sharing of financial data between institutions under Central Bank supervision. Serasa adds that this sharing has legal backing and can only happen with the data subject's consent and for a specific purpose, in line with Brazil's LGPD data protection law. The problem is not the regulatory principle itself, but the number of touchpoints that multiply and can be used by attackers to build convincing approaches with real data.

CNN Brasil added another regulatory warning, saying the Central Bank is studying stricter rules to curb the resale of data collected by companies that participate in the Open Finance ecosystem. The concern matches the risk of secondary use of shared information. Once data circulates, exposure is no longer limited to the originating bank and instead depends on the entire chain of participants, vendors and processors.

At the same time, identity has stopped being purely documentary. IT Section reported that Instruction No. 36 from the National Institute of Information Technology reworked the requirements for ICP-Brasil digital certificates, adding official documents, biometrics, public database queries, negative lists, an electronic dossier with audit trail and anti-deepfake and anti-biometric-injection mechanisms for remote validation. The underlying message is clear, isolated document authentication is no longer enough in environments where visual impersonation and synthetic fraud are part of the criminal playbook.

In terms of volume, the data is also blunt. Agência Brasil reported more than 9 million signs of fraud in the first half of 2026, with the mobile phone as the main attack channel. Quod, cited by R7, said Pix appeared in 85% of cases and social engineering accounted for about 40%. Added to that are studies by Fenasbac and GASA, which estimate more than 24 million Brazilians were victims of scams via Pix and boletos between July 2024 and June 2025, with losses close to R$ 29 billion.

Regional coverage of the reportAxis: evidence volume in the research, not total criminal incidence.BrazilHighest coverageColombiaMedium coverageMexicoMedium coverage
Regional coverage of the report — Brazil accounts for the core of the evidence; Colombia and Mexico provide the comparative contrast.

Key Facts Table

Date Fact Source Confidence
2026-07-06 Open Finance, Pix and embedded finance are described as shared financial infrastructure, operating at the scale of tens of billions of API calls per month. Evertec Trends Confirmed
2026-07-06 The Central Bank is studying restrictions on Pix access for fintechs and banks with weak cyber security. O Globo Confirmed
2026-07-09 Exame warns that Open Finance increases exposure because it creates more touchpoints with customer data. Exame Confirmed
2026-07-09 CNN Brasil flags regulatory concern over the secondary sale of data obtained through Open Finance. CNN Brasil Confirmed
2026-07-10 CSMV reports that Resolution BCB No. 501/25 requires compulsory rejection of transactions with a well-founded suspicion of fraud. CSMV Confirmed
2026-07-14 Federal Police report a case in Montes Claros, Minas Gerais, involving a GOV.BR account takeover, account opening and fraudulent loan. Polícia Federal Confirmed
2026-07-16 Federal Police and Gaeco in Bahia act against a group suspected of bank fraud and money laundering. Polícia Federal Confirmed
2026-07-18 Agência Brasil reports more than 9 million signs of fraud in six months, with 78% involving mobile phones and 85% involving Pix. Agência Brasil Confirmed
2026-07-18 Quod attributes about 40% of cases to social engineering. R7 / Quod Confirmed
2026-07-20 Febraban warns about the selfie scam and abuse of facial recognition. Metro1 Confirmed
2026-07-22 Federal Police investigate fraud with fake documents in Paraná and digital identity hijacking in Santa Clarores. Polícia Federal Confirmed
2026-07-23 BC Protege+ allows users to register a free restriction on opening new accounts. BoanotíciaBrasil Confirmed
2026-07-24 The Central Bank tightens Pix security and penalties, while Itaú warns about deepfakes and impersonation. Banco Central, Itaú Unibanco Confirmed
2026-07-27 Evertec publishes the technical report on the new attack profile in Brazil. Evertec Trends Confirmed
2026-07-27 Diário do Nordeste describes deepfakes used to simulate real biometrics and open fake accounts. Diário do Nordeste Confirmed
2026-07-28 IT Section reports new requirements against deepfakes and biometric injection in digital certificates. IT Section Confirmed
2026-07-29 ANPD says Brazil accounted for 39% of Latin America's deepfake cases in 2025. Valor Econômico Confirmed
2026-07-31 FICCO in Alagoas investigates fraud and embezzlement in Caixa social benefit accounts. Polícia Federal Confirmed
2026-08-02 Exame reports that 42.5% of financial fraud recorded in 2025 involved AI and that deepfake use grew 830% between 2024 and 2025. Exame Confirmed

Operation Timeline

Date Event Actor / Vector Verified Source
2025-11 Liquidation of Bank Master for serious regulatory violations. Structured bank fraud, with criminal networks and militias Insight Crime
2026-05 Identification requirements for ICP-Brasil digital certificates are revised with anti-deepfake mechanisms. Document validation and biometrics IT Section
2026-07-06 The Central Bank discusses restricting Pix access for participants with weak cyber security. Systemic risk in instant payments O Globo
2026-07-06 Evertec describes Open Finance, Pix and embedded finance as shared infrastructure. Attack surface through APIs and consent Evertec Trends
2026-07-10 CSMV details the new anti-fraud framework, including compulsory rejection of suspicious transactions. Operational and sanctions rules CSMV
2026-07-14 Federal Police investigate electronic bank fraud involving a hijacked GOV.BR account and fraudulent loan. Digital identity takeover Polícia Federal
2026-07-16 Federal Police and Gaeco in Bahia act against a network that opened fake accounts and laundered money. Fake documentation and account opening Polícia Federal
2026-07-18 More than 9 million signs of fraud are reported in six months. Mobile, Pix and social engineering Agência Brasil, Quod
2026-07-20 Febraban warns about the selfie scam and the use of selfies to authorize operations. Abused facial recognition Metro1
2026-07-23 BC Protege+ becomes part of preventive account-opening controls. Voluntary restriction by the holder BoanotíciaBrasil
2026-07-24 Itaú warns about deepfakes, fake call centers and emotional manipulation, while the Central Bank tightens Pix. AI-enabled social engineering Itaú Unibanco, Banco Central
2026-07-27 Evertec publishes the base technical report for this investigation. New attack profile in Brazil Evertec Trends
2026-07-27 Diário do Nordeste documents deepfakes used to simulate real biometrics and open fake accounts. Fraudulent onboarding Diário do Nordeste
2026-07-29 ANPD reports that Brazil accounted for 39% of regional deepfakes in 2025. Generative AI applied to fraud Valor Econômico
2026-07-31 FICCO in Alagoas investigates fraud in Caixa social benefit accounts. Systemic diversion of benefits Polícia Federal
2026-08-02 Exame estimates that 42.5% of financial fraud in 2025 already involved AI. Deepfakes and liveness checks Exame

Attack Chain and TTPs

The pattern seen in the material is consistent with a modular attack chain. The first step is usually initial access through social engineering, phishing, smishing, vishing or in-person approaches. In Brazil, Exame warns that many Open Finance scams use real data such as name, CPF, address and purchase history to make consent requests more believable. The opening phase is not meant to force a complex technical intrusion, but to get a user action, a code, an approval or a session opening.

Then comes the stage of impersonation or abuse of valid accounts. MITRE defines the Valid Accounts technique as the use of compromised legitimate credentials to access systems. In the Brazilian corpus, that translates into account takeover, digital identity hijacking, access to GOV.BR, credential reuse and opening financial products in the victim's name. The operation can continue with contact changes, diversion of authenticators, Pix key portability or opening mule accounts to move the money.

The second major block is biometric control evasion. Diário do Nordeste, Metro1, CNN Brasil, Itaú Unibanco and IT Section describe deepfakes, manipulated selfies, synthetic videos and injection techniques used to bypass liveness checks and facial recognition. The goal is not just to look real, but to produce a signal that the automated system will accept. Correio 24 Horas even reported a case in Bahia where photos of elderly faces were used to defeat facial recognition in banking apps and take out loans.

At this point, MITRE's Masquerading technique fits well. The attacker uses false identities and appearances to evade defenses. The forgery can be documentary, biometric or contextual. Several reports also mention combinations of photo, audio and video, suggesting campaigns that combine credentials, audiovisual impersonation and onboarding manipulation.

The third block is monetization. Transfers through Pix appear, along with fraudulent loans, movements into third-party accounts, account draining and the use of fake boletos. Agência Brasil and Quod's research shows that Pix was the dominant channel. The Operação Infiltrados case, with about R$ 45 million diverted, and the arrest of an employee suspected of diverting about R$ 2 million, illustrate that monetization can rely both on automated channels and on internal abuse.

Persistence is usually completed through laundering and fragmentation. Evertec describes criminal organizations with divided functions across social engineering, malware, money laundering, mule accounts, document forgery and data trafficking. That matters because it explains why the attacks no longer look like isolated acts, but like specialized services. The Fraud as a Service model lowers the barrier to entry for smaller groups and professionalizes the operation.

Observed attack chainInitial accessphishingsmishing, vishingSpoofingcredentialsvalid accountsBiometricsdeepfakelivenessMonetizationPixLoansCorpus evidence shows attacks that combine induced consent, deepfakes, and rapid money movement.
Observed attack chain — Induced consent, biometric spoofing, and monetization through instant payments or credit.
MITRE TTP Description Source
TA0001 Initial Access Initial access through phishing, smishing, vishing or approaches aimed at obtaining consent or credentials. MITRE, Exame, Semana, Pulzo
T1078 Valid Accounts Use of compromised legitimate accounts to operate in banking, Pix or Open Finance. MITRE, Polícia Federal, R7
T1036 Masquerading Use of fake identities, deepfakes and impersonation to evade controls. MITRE, CNN Brasil, Diário do Nordeste, IT Section
Operational persistence Division of labor among social engineering, laundering, forgery and mule accounts. Evertec Trends
Biometric evasion Manipulated selfies, videos, liveness checks and proof-of-life flows. Diário do Nordeste, Metro1, IT Section, Correio 24 Horas
Exfiltration and monetization Fund transfers through Pix, fraudulent loans and third-party accounts. Agência Brasil, Polícia Federal, O Globo

Regional Impact

Regional Overview

The Brazilian case matters for the rest of Latin America because it combines three elements that do not always appear together. First, highly integrated payments and data infrastructure, with Open Finance, Pix and interconnected fintechs. Second, growing use of generative AI for identity fraud, deepfakes and impersonation. Third, a regulatory response that moves quickly, but still depends on banks, vendors and authorities coordinating technical controls in real time.

The link between identity and fraud is no longer purely documentary. The reports cited show that the industry has started treating facial biometrics, liveness checks and digital consent as attack surfaces. At the same time, organized crime works with access to leaked data, targeted social engineering and session hijacking. That combination repeats, with variations, in several countries across the region, although Brazil contains the deepest body of material collected.

Brazil

Brazil is the center of the report. Evertec Trends, Exame, Agência Brasil, Quod, CNN Brasil, Serasa, O Globo, IT Section, Itaú Unibanco, Metro1, Diário do Nordeste, the Federal Police, the Central Bank and ANPD all point to a consistent picture. Fraud has moved from card misuse and boletos toward an environment where attackers exploit Open Finance, Pix, digital identity and facial biometrics.

The scale data is striking. More than 9 million signs of fraud in the first half of 2026, 78% via mobile phones, 85% involving Pix and about 40% stemming from social engineering. On top of that, Fenasbac and GASA estimate more than 24 million victims of Pix and boleto scams between July 2024 and June 2025, nearly R$ 29 billion in losses and a 43% increase in Pix-related losses compared with 2023. ANPD, for its part, said Brazil accounted for 39% of Latin America's deepfake cases in 2025 and saw a 126% year-over-year increase in attacks using fake images, voices and identities.

The operational picture reflects that scale. The material includes fraud in Caixa social benefit accounts, fake account openings, fraudulent loans, diversions in beneficiary accounts, internal abuse by bank employees and a major historical fraud case, Bank Master, which Insight Crime links to criminal networks and militias. The combined reading is that Brazilian financial fraud is no longer dependent only on the classic digital perimeter and has moved into the trust chain that supports the payments system.

Colombia

Colombia appears in the material with a more visible regulatory and preventive agenda. Law 2573 of 2026, according to El País, suspends collections and temporarily removes negative credit reports for identity theft starting in November 2026. The Financial Superintendency created a dedicated space to guide the public on phishing, smishing, vishing, identity theft and friendly fraud, with recommendations to report immediately, deactivate products and file complaints with police and prosecutors.

The practical risk, however, is already showing signs similar to Brazil's. TintaTIC describes more than 218,000 complaints for identity theft and highlights the opening of digital accounts with stolen data and the creation of altered records. Semana warns about email, voice and video deepfakes that imitate banks or trusted people. Pulzo warned about smishing tied to the launch of Bre-B, with fake messages asking for passwords, codes and even biometrics. BBVA Colombia, meanwhile, recommends enabling biometric authentication and checking suspicious notifications through the official app.

The case block is also strong. El Espacio Digital reported a fake bank adviser in Bogotá who extracted data for credit card fraud. La FM described a digital wallet scam that uses stolen identities and transfers "by mistake" to load debt onto the victim. Creditolab and Juan Antonio Matiz collect response steps such as reporting to prosecutors, contacting the bank, blocking cards, reviewing credit reports and acting on possible SIM swapping. Overall, the country shows a mix of regulatory controls, user education and warning signals against impersonation and onboarding fraud.

Mexico

Mexico shows a parallel technical pattern, though with less regulatory detail in the material. Condusef reported 43,871 complaints for attempted financial fraud in the first half of 2026, a 16.7% year-over-year increase, and 118,287 total reports, up 11.3% from a year earlier. Shufti Pro says the country faces account takeover, SPEI payment manipulation, social engineering and cartel-linked laundering. That points to convergence between financial fraud and organized cybercrime.

Juan Guevara, cited by Imagen Radio, described an injection attack technique in account-opening processes through mobile apps. The attacker interrupts the camera and replaces the feed with a fake AI-generated video to fool the selfie or video system. The same corpus mentions a sharp increase in digital account-opening fraud and account takeover, although those percentages are attributed by the sources and should not be treated as an official consolidated series in this report.

Banorte responded with a dual-security strategy based on verifying phone lines with telecoms and behavioral biometrics that analyze geolocation, device use and other patterns. Xataka México adds that CNBV approved changes allowing identification with official documents, fingerprints and facial recognition, especially for level 3 and 4 accounts, and that cash deposits or withdrawals above 140,000 pesos must be supported by biometrics. MITRE fits the Mexican picture well, because the material reflects initial access by social engineering, use of compromised valid accounts and masquerading through deepfakes or synthetic identities.

Technical Indicators

No classic technical IOCs were published in the consolidated material, such as hashes, IPs, domains, malicious URLs or malware artifacts. The corpus does provide operational and contextual indicators that help profile the campaigns.

Type Value Source
TTP Social engineering used to induce consent Evertec Trends, Agência Brasil, Exame
TTP Pix present in 85% of cases Agência Brasil, Quod
TTP Mobile phone as the main channel, 78% of records Agência Brasil, Quod
TTP Deepfakes used to bypass facial biometrics and proof of life Exame, Diário do Nordeste, CNN Brasil, IT Section
TTP Injection attack in app-based onboarding Imagen Radio
TTP Compulsory rejection of transactions with a well-founded suspicion CSMV
Preventive control BC Protege+ to stop unauthorized account openings BoanotíciaBrasil
Preventive control CPF and CNPJ verification and name consistency for Pix keys CSMV
Preventive control Multimodal biometrics and 3D liveness CNN Brasil, ClickPetroleo e Gás / Exame
TTP MatrixTA0001Initial AccessPhishing, smishing, vishing, induced consentT1078Valid AccountsCompromised accounts, account takeover, GOV.BRT1036MasqueradingDeepfakes, manipulated selfies, synthetic identity
TTP Matrix — MITRE helps organize financial fraud as identity becomes the first attack layer.

Analysis for Security Teams

The main operational lesson is that defense can no longer depend on one layer. In Brazil, attackers combine induced consent, credential compromise, biometric manipulation and fast monetization through Pix or credit. That forces detection to move from the isolated event to the full sequence of behavior.

For anti-fraud teams, the first focus should be the consent flow. If Open Finance relies on valid user authorizations, telemetry must detect deviations in the onboarding experience, session hijacking, sudden device changes, unusual hours, abnormal network origin and the reuse of leaked real data to trigger requests. The material suggests that many attacks go undetected because the operation looks authorized. The quality of consent matters, not just its existence.

The second focus is biometrics. Selfie, video and proof-of-life flows need controls against injection, deepfakes and document manipulation. IT Section says remote validation already requires specific mechanisms against deepfake and biometric injection. Practically, identity validation should not depend only on a frontal image, but on multimodal biometrics, liveness signals, comparison with trusted databases and contextual analysis. CNN Brasil and ClickPetroleo e Gás / Exame cite multimodal biometrics and 3D liveness as the response needed to keep a synthetic face from passing as real.

The third focus is instant payments. The Central Bank has already tightened rules, but the attacker's ability to move money quickly remains the core risk. That is why prior verification of CPF and CNPJ, account holder name and transaction behavior should be integrated before enabling Pix keys, porting keys or accepting transfers to accounts under suspected fraud. Resolution BCB No. 501/25 and related rules show the regulator pushing detection to the point before or immediately after authorization, not just to the later chargeback stage.

The fourth focus is organized fraud. Evertec describes a structure with specialists split by function. That means defenses have to treat the problem as a criminal supply chain. It is not enough to block the deceived user. Teams also need to identify mule-account networks, reused devices, affiliation patterns across accounts, repeated use of synthetic identities, recycled passwords and coordinated funnel behavior. The objective is to break the scale economics of fraud, not just respond case by case.

At a prioritization level, teams should treat three scenarios as high priority. First, remote onboarding with selfie or video. Second, consent authorization or Pix key approval from new devices or hijacked sessions. Third, loan requests or account openings using leaked real data and signs of social engineering. In those cases, added friction such as step-up challenges, second-channel verification, manual review or temporary suspension appears justified by the risk level shown in the material.

It also makes sense to link fraud and cyber security more closely. MITRE helps organize the analysis. Initial Access covers entry through phishing or smishing. Valid Accounts explains the use of compromised legitimate credentials. Masquerading reflects deepfakes and visual impersonation. Applied to banking fraud, that taxonomy gives anti-fraud, SOC, IAM, risk and compliance teams a shared language.

Material Limitations

The material does not include exploitable technical indicators of criminal infrastructure, such as IPs, hashes, domains or malware samples. It also does not contain one end-to-end case with the full chain confirmed from initial access to monetization. What is available is a strong combination of technical, regulatory, judicial and journalistic reporting that makes it possible to reconstruct patterns, but not to attribute a single unified campaign with certainty.

Several figures are attributed by the sources themselves rather than by primary documents accessible in the corpus. That applies to some percentages reported by media outlets on deepfake growth, account takeover or digital account opening. This report preserves that uncertainty where needed.

The geographic coverage is uneven. Brazil contains most of the verifiable material and therefore structures the main analysis. Colombia and Mexico provide enough facts for a comparative reading. Argentina, Chile, Paraguay, Bolivia, Peru, the United States and Uruguay did not contribute additional verifiable facts within the consolidated research, so they are not developed as separate subsections.

Corpus limitationsNo classic IOCsMany figures come from secondary sourcesBrazil holds most of the evidence; other countries have partial coverage
Corpus limitations — The material helps map patterns, but does not provide technical artifacts of criminal infrastructure.

Sources

View all