CiberLATAMbywhalemate

Latin America: AI in one in five cyberattacks

IBM said AI aided one in five cyberattacks in Latin America, with deepfakes and AI-powered malware among the main uses.

Whalemate Labs · AI-assisted researchPublished:2 min read

One in five cyberattacks in Latin America over the past year was aided by artificial intelligence, according to an IBM study cited in regional press. The use was concentrated in identity impersonation through deepfakes and malware enhanced by AI models.

One in five cyberattacks in Latin America over the past year was aided by artificial intelligence, according to an IBM study cited in regional press. Available coverage points to two main uses, identity impersonation through deepfakes and malware generated or enhanced with AI models.

How is AI being used in these attacks?

AI is being used mainly to imitate voices and faces for fraud, and to strengthen malware with generative capabilities, according to the regional coverage cited. In attacks that impersonate identities, the technique is meant to make fake messages, audio, or video more convincing.

The same set of sources also included a local example and a regulatory warning. Argentina's eltrece reported the circulation of AI-generated videos and audio that imitated the voice and face of public figures, including Marcos Galperín, to promote supposed investments. That report also said audiovisual phishing would be more common in Argentina and could have nearly tripled in recent years, although that comparison was not backed by a visible primary source in the results.

What regulatory issue is emerging in Argentina?

Argentina sits in a regulatory gray area when generative models are used with sensitive data, especially genomic data, according to a regional analysis published in Turing Magazine. That work says Argentina, Chile, and Colombia have data protection laws and biosafety rules, but the intersection between those frameworks and generative AI remains unresolved.

The local regulatory debate also includes the state's response to drafting AI rules. Coverage by iProfesional said the Agency for Access to Public Information created a specific program to analyze and regulate AI, with a focus on transparency, bias, and data protection, and that during 2026 the state formally incorporated the development of regulatory frameworks for strategic technologies.

What operational warnings came out of the AI discussion?

Cyber.ar 26 warned about uncontrolled use of generative platforms, known as shadow AI, and about the risk that employees share personal data, internal documents, or source code without measuring the consequences. The proposed response included usage policies, information classification, and data loss prevention controls.

That assessment fits a scenario in which AI is no longer seen only as a productivity tool, but also as a vector for fraud, leaks, and attack automation. The available sources do not identify a new verifiable local case of generative phishing or deepfakes in Argentina, but they do show that both the regulatory and operational fronts are already open.

Sources

View all