CiberLATAMbywhalemate

Chile warns banks on vishing scams

Banks and authorities in Chile are warning about vishing, a phone scam used to steal credentials. Fraud law and case law have tightened the rules.

Whalemate Labs · AI-assisted researchPublished:Updated 3 min read

Banks in Chile have issued an alert over rising vishing cases, where criminals call users posing as executives, technical support staff, or even police officers to steal passwords and transfer codes.

Update September 3, 2026: This article now includes the legal reinforcement brought by Law 21,673, approved in May 2024, and the Supreme Court ruling that requires continuous monitoring to stop bank fraud. It also adds recent SERNAC data on complaints, response rates, and vishing’s share of scam attempts.

Banks in Chile have issued an alert over the rise in vishing, a scam in which criminals call users posing as executives, technical support staff, or even police officers to steal passwords and transfer codes.

What banks are warning about

The warning, reported by El Mostrador, focuses on calls where the supposed operator tries to get the victim to hand over sensitive data or approve transactions while staying on the line. Under security rules, no bank in Chile may ask by phone for secret keys, transfer passwords, card coordinate codes, or confirmation of transactions in the mobile app while the customer is speaking to the alleged representative.

The fraud works by exploiting the trust generated by what sounds like a legitimate call and pushing the user to hand over information in real time, enough to empty accounts or authorize the unauthorized use of financial instruments. Digital banking educational material in Chile says about 28% of credit card fraud victims reported being affected through vishing, a share that shows how heavily this tactic factors into payment fraud.

What changed with Law 21,673

Law 21,673, known as the Fraud Law, was approved in May 2024 and strengthened Chile’s protections against bank fraud by clarifying procedures and responsibilities for banks and customers. In practical terms, consumers filing a fraud claim must submit a sworn statement and a criminal complaint to qualify for reimbursement of funds.

That tougher evidentiary burden has gone hand in hand with figures showing limited recovery. According to SERNAC data cited in sector analyses, Chilean banks’ favorable response rate to fraud claims is about 7%, a gap that contrasts with the obligation to keep 24/7 blocking channels available.

What recent complaints show

SERNAC logged 19,834 complaints for financial fraud in Chile during 2024, up 109% from 2023, according to sector analyses based on its statistics. That jump confirms a sharp rise in fraud tied to digital channels, including phishing and vishing.

Sector analyses citing SERNAC studies and the University of Chile also indicate that about 28% of Chileans have been targeted by vishing attempts and that close to one in four spam calls to Chilean numbers involves scam attempts or fraudulent activity. A meaningful share of those calls targets banking products.

What victims should do

In the same official context, authorities reiterated that victims should immediately contact the bank’s 24/7 emergency channels to block payment methods, formally notify the financial institution, and then file a complaint with Carabineros or the PDI. Consumer guidance on banking in Chile adds that the applicable rules set a 30-business-day deadline to file a formal claim with the bank over unauthorized transactions.

That minimum reporting and criminal-investigation path is completed with a complaint to the PDI, Carabineros, or the Fiscalía in fraud cases stemming from phishing or vishing. Chile’s Library of Congress, meanwhile, maintains a legal guide on theft and fraud involving cards and financial instruments, which says institutions must report every six months the number of affected users, the amounts involved, and response times.

What did the Supreme Court say

A Chilean Supreme Court ruling on June 25, 2024, Rol 38.128-2023, cemented case law requiring banks to have continuous monitoring systems capable of identifying, assessing, and blocking suspicious transactions as quickly as possible. That decision strengthens the technical security duty that goes along with the obligations in the Fraud Law.

The combination of bank alerts, service rules, evidentiary requirements, and case law leaves Chile with a stricter framework against vishing, but also a clear gap between the number of complaints and the actual return of funds. The focus remains on stopping the scam before the victim hands over credentials or authorizes a transaction from their own device.

Sources

View all