CiberLATAMbywhalemate

ABIF and Microsoft bolster Chilean banking defenses

ABIF and Microsoft signed an agreement to fight cybercrime and digital fraud in Chile’s banking sector amid rising attacks in the region.

Whalemate Labs · AI-assisted researchPublished:3 min read

ABIF and Microsoft signed an agreement to fight cybercrime and digital fraud in Chile’s banking sector. The move comes amid regional pressure on banks, with 111 million attempted cyberattacks on banking in the first half of 2026, according to a regional publication, and recent hotspots in Mexico and Brazil.

ABIF and Microsoft signed an agreement to fight cybercrime and digital fraud in Chile’s banking sector. The initiative comes as several regional outlets describe a broader rise in attacks against banks and payment systems, with 111 million attempted cyberattacks against banking in the first half of 2026, according to La Razón de Bolivia.

What was signed in Chile?

ABIF and Microsoft agreed to work together against cybercrime and digital fraud in Chile’s banking sector. Microsoft News LATAM published the announcement on Sept. 10, 2026, and said the effort is meant to strengthen the financial system’s response to attacks and fraud schemes affecting banks and customers.

What do the regional alerts show?

Available coverage points to a broad wave of banking fraud and attacks on electronic payments across Latin America. In Bolivia, La Razón reported that financial institutions were among the main targets of cyberattacks in the first half of 2026, and the same publication counted 111 million attempted cyberattacks against banking during that period.

In Mexico, an analysis of digital fraud in digital banking found that 51% of attacks occur during the transaction itself. Another report on digital banking fraud recommended not sharing passwords, PINs, or token codes, and contacting the bank when suspicious activity appears.

What recent cases appeared in Brazil?

In Brazil, Folha de S.Paulo reported a virus that fraudulently alters QR codes, Pix Copia e Cola, and card payments in online stores without leaving a trace. The same report said Kaspersky verified 90 Brazilian e-commerce sites infected by the malware, which replaces the Pix QR code at payment time and redirects money to criminal accounts.

UOL added that the scheme also affects the Pix copy and paste field, so the risk remains even if the customer does not use the camera to scan the code. O Tempo said the scheme was first detected by an independent researcher and later confirmed by Kaspersky, which observed it in 90 online merchants, including optical shops, auto parts stores, fashion retailers, and crowdfunding sites.

What other actors and campaigns were identified?

Fortinet published a technical analysis of Casbaneiro, a banking trojan that uses a multistage infection chain with an HTA downloader, an AutoIt loader, and final injection into a Windows process. ANY.RUN shared a campaign targeting organizations in LATAM with tax and banking lures, delivering a customized HVNC backdoor for persistent access and theft of browser data and keystrokes.

Google Cloud also described BREEZE COMET as a financially motivated actor that specializes in manipulating payment systems and banking software in Brazil to carry out fraudulent transfers. CrowdStrike identified Slim Spider as a new criminal group targeting Brazilian financial institutions and instant payment and crypto systems since at least March 2026.

Sources

View all