Latin America sees bank fraud tied to deepfakes
Banks and users in Latin America face impersonation, deepfakes and caller ID spoofing, with fraud attempts and official alerts.
Digital bank fraud in Latin America is shifting toward more sophisticated impersonation, with caller ID spoofing, deepfakes, synthetic identities and attempts to bypass biometrics or MFA. Cases and alerts gathered in Central America, Mexico, Chile, Peru, Brazil and other markets show a chain that runs from credential theft to fund movement through mule accounts.
Banks, regulators and media in several Latin American countries, and beyond the region, are reporting a rise in impersonation fraud that blends fake calls, deepfakes, synthetic identities and biometric bypass techniques. In Central America, BioCatch described a chain that starts with the exposure or theft of personal data, then moves to credential compromise, account takeover or authorized payment scams, and ends with fund movement through mule-account networks.
Which techniques are gaining ground?
The tactics most often appearing in coverage are caller ID spoofing, bank support impersonation, deepfakes and synthetic identities, along with attempts to hijack sessions or exhaust MFA controls. In Mexico, a report from Cinecassette explained that caller ID spoofing falsifies the visible number to make the call appear to come from a trusted institution, and can include requests for confidential data, SMS codes or tokens, as well as transfers "to protect" funds.
The same logic appears in technical analysis from NHIMG on account takeover in financial services, where the attacker poses as bank support or fraud staff, often using caller ID spoofing or fake emails, to get approval for data changes or transfers. Trusona, citing FBI IC3 data, said that in 2025 account takeovers through impersonation of financial institution support generated about 4,700 complaints and $359.7 million in losses, while business email compromise reached $3.05 billion.
What do the region's cases show?
Regional coverage shows that these tactics are already affecting multiple markets and victim profiles. Bloomberg Línea reported, citing Experian, that 71% of people surveyed in Colombia, Mexico, Chile, Peru and Panama received at least one fraud attempt over the past year, and that 82% believe these incidents have increased, according to the source's note.
In Peru, Infobae described recent threats to banks including biometric bypass, deepfakes, synthetic identities and account takeover, which can include session hijacking or MFA fatigue. That said, it was journalistic coverage and not an official confirmation. In Mexico, the Secretariat of Security and Citizen Protection reported a campaign that used manipulated images and videos with artificial intelligence of the president, the security secretary and the governor of Banco de México to promote fake investments, with 12 individuals and one company linked to the scheme and more than $2 million frozen.
Chile also appears as a case of more elaborate social engineering. The Clinic detailed a phone-based banking scam in which the RUT becomes the entry key, with attackers posing as the bank's fraud team and using sales scripts to persuade customers to hand over data or authorize transactions. Revista Emprende added that Chile's central bank warned about misuse of its name, image and officials in fraud schemes that include AI-generated videos used for impersonation.
How are banks and associations responding?
The response is moving toward out-of-band verification and official channels. The Portuguese Banking Association warned about fraudulent calls made in its name, said caller ID spoofing was used in some cases to falsify the association's main number, and stressed that any inquiry must be verified through official channels. BNP Paribas, meanwhile, told customers to confirm the identity of the supposed employee through a push notification in the GOmobile app and to compare the caller's details with those shown in the application.
In Brazil, a Febraban executive warned about an "epidemic" of social-engineering fraud attempts and recommended checking any suspicious situation only through official bank channels, such as the number printed on the card or the bank's website, even when additional biometrics are requested by SMS or app. In El Salvador, La Prensa Gráfica reported on a banking and cybersecurity agenda that discussed the use of AI for real-time fraud and AML detection, in a response line more focused on automating defense.
What do reports say about biometrics and deepfakes?
The reports agree that traditional biometrics is no longer enough on its own against audiovisual impersonation. An analysis cited by MSN México said that 72% of surveyed organizations detected an increase in digital injection attacks using deepfakes, reinforcing the growth of AI-based biometric evasion. In Brazil, O Globo described how so-called "deepfakes caseiros" are being used to try to bypass banking apps and liveness checks in order to access withdrawals, loans or purchases.
Coverage also shows wider use in other contexts. A report from Inkl on Latin American families sending remittances described calls and video calls using false identities generated by AI to pressure people into urgent transfers, and recommended family code words, official remittance or banking apps and two-factor authentication. At the same time, a report on deepfake fraud in Mexico said cyber authorities and the Financial Intelligence Unit coordinated an investigation and froze more than $2 million.
What regional scope emerges from this coverage?
What emerges is not an isolated case, but a convergence of tactics that crosses banking, payments and remittances. Central America is dealing with the classic sequence of data theft, account takeover and laundering through mule accounts, while Mexico, Chile, Peru and Brazil show local variants of impersonation using AI, fake calls and attacks on end users. The picture left by these reports is one of digital fraud leaning more heavily on advanced social engineering and impersonation tools that are now reaching authentication processes and everyday interactions with banks.
Sources
- Los fraudes y estafas con IA más recurrentes en México, Colombia, Chile, Perú y Panamábloomberglinea.com· Bloomberg Línea
- ¿Cómo la IA está blindando el dinero de los chilenos frente al fraude?revistaemprende.cl· Revista Emprende
- Associação Portuguesa de Bancos alerta para chamadas fraudulentas em seu nomertp.pt· RTP
- AI Deepfake Scams Are Draining the Remittances Latino Families Send Home — Here's How to Fight Backinkl.com· Inkl
- El panorama del fraude en Centroaméricabiocatch.com· BioCatch
- Cómo el RUT se convierte en la puerta de entrada a una estafa bancaria que se masifica en Chiletheclinic.cl· The Clinic
- La nueva trampa que vacía cuentas bancarias en México: así te roban en menos de 80 segundosinfobae.com· Infobae México
- Fraude con deepfakes aumenta y empresas enfrentan nuevas amenazas de IAmsn.com· MSN México
- Identidades sintéticas y técnicas de fatiga: contraseñas ya no frenan el fraude digital y bancos en Perú encienden las alertasinfobae.com· Infobae Perú
- Vivemos uma epidemia de tentativas de golpes com engenharia social, diz diretor da Febrabanyoutube.com· Globo / Febraban
- Expertos abordan los nuevos desafíos de la IA y la ciberseguridad para la bancalaprensagrafica.com· La Prensa GráficaUnverified URL
- 'Deepfake caseiro' dispara e vira nova ameaça de golpes e fraudes financeirasoglobo.globo.com· O Globo
- Account takeover fraud in financial services needs stronger call verificationnhimg.org· NHIMG
- Llamadas que aparentan ser del banco: así opera el fraude del caller ID spoofing en Méxicocinecassette.com· Cinecassette
- Deepfakes de IA en México: congelan más de 2 millones de dólaresmayacomunicacion.com.mx· Maya Comunicación
- Call center impersonation and wire approvals: what controls still failnhimg.org· NHIMG
- Pilny komunikat BNP Paribas. Bank zwrócił się do klientówrmf.fm· RMF FM



