CiberLATAMbywhalemate
Intelligence reportAug 11, 202626 min read

Traditional Banking and Insurers, July 2026

July ended with more regulation, persistent digital fraud, and signs of ransomware and phishing affecting banking and insurance across the region.

Traditional Banking and Insurers, July 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are filled automatically with verified, dated facts from within the period. Each one states its source base and counting criterion, so the figures reconcile across modules. They are the recurring month-to-month reading; the later analysis develops the cases without repeating this summary.

Indicator window: 66 dated facts in July 2026 · 5 without confirmed date (excluded from the indicators). Facts from earlier months are used only as comparative context in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Verified Signal Monthly Dashboard July 2026 · Latin America Top threat: Regulation (19 of 63 events). Coverage: 66 dated events in July 2026 · 5 undated conf... VERIFIED FACTS 63 period baseline: all counts measured from below on this total RANSOMWARE / EXTORTION 4 2 encrypted assets confirmed · 2 not classified determinable from the material UNCLASSIFIED INCIDENTS 7 breaches or disruptions without declared threat type FRAUD / PHISHING 8 documented fraud campaigns REGULATION 19 standards, rulings, or penalties UNIQUE CVEs 9 CVE-2026-15409 / CVE-2026-15410
Verified Signal Monthly Dashboard — Base: 63 verified dated events for Latin America.
MONTHLY FIXED MODULE Threat-axis distribution July 2026 · Latin America Each event counts in only one axis, so the total is exactly 63. "Unclassified incidents" is the remainder. Regulation 19 Unclassified 15 Vulnerabilities 10 Fraud 8 Incidents 7 Ransomware 4
Threat-axis distribution — Each event is assigned to a single axis based on its classification; the total reconciles to the 63 events in the period.
MONTHLY FIXED MODULE Sectoral Distribution of Signals July 2026 · Latin America Base: 63 incidents in the period · total 75 because 11 incidents were classified in more than one sector. Other / no sector ident… 23 Financial Services 18 Public Sector / OIV 14 Technology 13 Telecom 5 Healthcare 1 Retail / Consumer 1
Sectoral Distribution of Signals — Heuristic sector classification by victim. One incident may affect more than one sector, so the total may exceed the base.
MONTHLY FIXED MODULE Geographic distribution of signal July 2026 · Latin America Each event is assigned to a single country or to regional coverage, so the total is exactly 63 of 63 events… Regional 23 Colombia 13 Uruguay 11 Peru 7 Paraguay 4 Argentina 3 Brazil 2
Geographic distribution of signal — Verified period events grouped by country or regional coverage; each event is counted once.

Monthly executive summary

July 2026 was dominated by regulation and sustained pressure on digital banking and insurance channels. The leading threat indicator was regulation, with 19 of 63 verified events in the period, while fraud and phishing remained central to the monthly signal. At the same time, the material pointed to extortion incidents, active campaigns affecting organizations across the region, and a significant block of regulatory updates in Colombia, Peru and Brazil.

The clearest reading of the month is that the risk surface stopped concentrating only on the classic technology perimeter and expanded to identity, digital customer interaction and compliance frameworks. In Argentina, the public warning about online scams and the BCRA recommendations pointed to a very specific pattern, requests to install software, links sent through chat and credential theft. In Colombia, the combination of a new law on identity theft, a regulatory proposal on open finance and operational notices to the market made clear the intensity of the regulatory agenda around authentication, data handling and incident reporting.

The operational front also showed a negative signal. Kaspersky reported a cyberattack campaign against Latin America, with direct mention of entities in Colombia, and described a ransomware variant in which attackers encrypted systems with BitLocker and then printed ransom notes on corporate printers. The material does not allow a single interpretation for all cases, because in two of them the source does not specify whether encryption occurred and in two others it does confirm it. Even so, the signal is enough to show that extortion remained active and was using less conventional tactics.

Fraud made the period especially noisy. La Nación reported that virtual scams now generate more than 200 complaints per month, a figure that helps frame the pressure on banks and insurers serving retail customers. That was accompanied by Banco de Bogotá's notices about the transfer of 267.000 Itaú customers, an environment especially sensitive to phishing and impersonation, and by the fact that 73% of Latin American companies suffered phishing over the last year, with the banking sector among the most affected according to ESET.

Financial cybersecurity was also shaped by the debate over minimum resilience. Susep published a guide of recommendations for supervised entities, Peru tightened the duty to report incidents within 24 hours and to notify customers within up to 10 business days, and Colombia's SFC opened comments to update open finance rules with risk management policies, information security and incident reporting. The regional pattern is consistent, more documentation requirements, more traceability and more pressure for entities to prove controls and response times.

Regional overview for the month

July’s regional signal was elevated. Not because a single large intrusion dominated the agenda, but because of an accumulation of verified events combining fraud, extortion, regulation and technical exposure. In traditional banking and insurance, that usually points to a more complex risk environment than a month driven by a single vector, because the problem is spread across remote access, identity management, outsourcing, cloud services and communication with affected users.

Latin America continued to show a pattern that had already appeared in earlier vendor and agency reports, even though this report has no month-over-month baseline. The region remains attractive to cybercrime because of the expansion of digital services and virtual wallets, with Check Point Research telemetry placing Latin America at 2.803 weekly attacks and 5% year-over-year growth. That figure reflects attempts and automated blocks, not confirmed-impact incidents, but it helps explain the exposure backdrop facing banks, insurers and fintechs.

The month’s qualitative risk is high. That assessment rests on three verifiable conditions in the source material: first, the number of confirmed events tied to regulation, fraud and operational security; second, the presence of active campaigns and ransomware using uncommon extortion techniques; third, the volume of references to phishing, impersonation and online scams with direct impact on customers and business processes. This is not an alarmist reading, but a synthesis consistent with the density and severity of the recorded events.

TIMELINE Verified events for the period 1/7 Susepannounceda 1/7 In Bogotá, Julyof 1/7 The same notefrom 1/7 TheSuperintendencyof Finance 1/7 A note from Last 1/7 TheframeworkBaaSfrom
Timeline of verified events, July 2026 — Confirmed milestones within July 2026. Events from prior months are excluded from the timeline and used only as context.

The region also showed a convergence between public policy and market cybersecurity. Colombia moved forward on open finance and protection against identity impersonation; Peru tightened incident reporting and notification; Brazil published a guidance manual for supervised entities and, according to press coverage, considered restricting Pix access for institutions with cyber weaknesses. These are different responses, but they converge on the same idea, regulatory tolerance for security failures is shrinking and the cost of noncompliance is moving into the business more quickly.

For banking and insurance, the month sent a cross-cutting signal on the importance of governance. Technical controls alone are not enough if there are no clear procedures for reporting, escalation, third-party relationships, business continuity and communication with customers. That requirement appears explicitly in Peru’s rules and in Susep’s manual, and also implicitly in the logic behind Colombia’s new open finance rules.

Period indicators

Indicator Value
Verified facts in the period 63
Time window for the indicators 66 dated facts in July 2026 · 5 with unconfirmed date (excluded from the indicators)
Unclassified incidents (breaches or outages) 7
Cases with ransomware or extortion as the primary focus 4
Confirmed encryption of assets 2
Cases with undetermined classification based on the material 2
Documented fraud or phishing cases 8
Documented regulatory moves 19
Critical CVEs mentioned 9
Sectors with at least one documented fact 6
Main threat of the month Regulation (19 of 63 facts)
Facts with direct source confirmation 97%
Aggregated telemetry figures excluded from volume 3 (aggregated attempts or blocks: not incidents with confirmed impact)

Relevant Incidents

StrikeShark campaign and its reach into the region

Kaspersky detected a cyberattack campaign called StrikeShark that targeted organizations in Latin America, including entities in Colombia. The material does not identify a specific financial victim, but it places the region within the reach of an active operation involving malware payloads and malicious distribution through PDFs and fake installers, according to Infobae México coverage. For banking and insurance, the key point is less the campaign name than the entry method, because decoy files and fake installers tend to fit well in environments where vendors, work attachments, and validation documents circulate.

The StrikeShark signal is also useful for reading the regional threat picture. This was not an abstract threat, but a campaign concrete enough to be attributed by a vendor and covered across several countries. That kind of activity calls for reviewing controls over email, attachment sandboxing, blocking unauthorized executables, and detection rules for documents that try to invoke external installers. In traditional banking, where operational trust in documents and third-party workflows remains high, that pattern can spread internally if it overlaps with exchanges between risk, legal, and operations teams.

Ransomware with BitLocker and corporate printers

Kaspersky reported ransomware attacks in Colombia and Mexico in which attackers used Microsoft BitLocker to encrypt systems and then printed ransom notes from compromised corporate printers. The source said the cases were investigated between May and June 2026, and that they exploited weak configurations and other infrastructure vulnerabilities. The value of the material lies in two points, first, it confirms asset encryption in two cases, second, it shows an extortion tactic that relies on an under-monitored office resource, the printer, to make the attacker’s message visible inside the organization.

In the financial sector, this type of incident deserves attention because it blurs the classic split between endpoint and print environment. Many organizations still manage printers as support assets rather than exposure nodes, when in practice they can be used to reveal the attacker’s presence, distribute ransom notes, and create internal pressure. In addition, if initial access was enabled by configuration errors, the incident is not limited to encryption, it also exposes a broader technical hygiene debt, incomplete inventory, excessive permissions, insufficient segmentation, and weak monitoring of peripheral services.

Ransomware and extortion with incomplete classification

The month’s material also recorded two ransomware or extortion cases whose exact nature could not be determined precisely. The source places them within the same attack family, but does not specify whether there was encryption, prior exfiltration, or only a claim posted on a leak site. That difference is critical for any CISO, because operational, legal, and communications handling changes a great deal depending on the case. A machine encrypted with service disruption is not the same as a threat to publish data without immediate operational impact.

The editorial, and operational, recommendation is not to force a single interpretation when the material does not allow it. For this report, those two incidents are counted within the ransomware or extortion indicator, but the inability to classify them precisely means they must be treated cautiously. In a real crisis room, that caution translates into validating logs, confirming the scope of access, reviewing possible exfiltration, and separating extortion pressure from confirmed unavailability.

Massive online scams with frequent complaints

La Nación reported that online scams now generate more than 200 complaints per month and detailed basic prevention measures for cyberfraud, such as not sharing passwords or verification codes and enabling two-factor authentication. The figure does not describe a specific intrusion at a particular institution, but it does signal sustained criminal demand across financial channels. For banks and insurers, that translates into more support tickets, more reimbursement cases to review, more first-party fraud, and greater pressure on customer service teams.

What matters here is not only the number, but its structural nature. When complaints remain above 200 per month, the problem stops being an isolated event and becomes a continuous flow of low- and medium-complexity incidents that consume response capacity. This usually hits customer service and fraud prevention first, and security teams later. That is why the link between the call center, fraud, the SOC, and legal teams stops being secondary and becomes central to containment.

Customer migration and fraud window at Banco de Bogotá

Banco de Bogotá warned about scam attempts by phone calls, SMS, and fake emails in the context of the transfer of 267,000 Itaú customers to Banco de Bogotá between July 31 and August 1, 2026. According to the coverage, neither Itaú nor the bank asks for access keys, verification codes, tokens, or confidential information by phone, SMS, WhatsApp, email, or social media. The timing matters, since a large customer migration always opens an ideal window for social engineering, because it combines uncertainty, urgency, and changes in the authentication experience.

In traditional banking, this kind of transition has two angles. The first is reputational, because any fraud tied to the process can be interpreted by customers as a bank failure. The second is technical, because the migration concentrates large volumes of communications that attackers can imitate. Effective defense depends not only on preventive messaging, but also on reinforcing the authenticity of notifications, narrowing interaction channels, and raising fraud controls throughout the transfer window.

Active Threats and Campaigns

Ransomware and Extortion

The strongest evidence this month in this category is Kaspersky's case involving Colombia and Mexico, with confirmed encryption through BitLocker and printed ransom notes left on corporate machines. That pattern confirms extortion with real operational impact, because encrypting assets takes systems offline and disrupts business continuity. The use of corporate printers as a pressure channel points to offensive maturity, not because the mechanism is sophisticated on its own, but because it exploits overlooked assets to magnify damage.

The other cases in this category do not make it possible to determine whether there was encryption or only a claim of responsibility. For a monthly report, that difference matters. From a defensive standpoint, a financial organization should assume extortion can begin before encryption, continue with exfiltration, and end in disruption. The sequence is not always linear, but it does require a review of segmentation, privileged credentials, restore capability, and monitoring of printing and remote administration services.

Fraud and Phishing

Digital fraud was one of the most consistent signals in the period. ESET's report, cited by Infobae, places phishing as the most common vector in Latin America, affecting 73% of the organizations surveyed. The same coverage notes that social engineering remains one of the most effective methods for obtaining credentials or installing malware. That finding fits the rest of the material, from the BCRA's guidance on chat links to Banco de Bogotá's warnings about fake calls, SMS messages, and emails.

At the same time, ACIS cited Asobancaria figures showing more than 218,000 fraud complaints in digital channels in the first half of 2025 in Colombia, which helps frame the scale of scams affecting the financial system. Even though that figure comes from a different period, it is still a useful qualitative benchmark for the magnitude of the problem in the country. In Peru, the SBS warned about loan apps that use extortion tactics to collect payments, a mix of fraud, psychological pressure, and abuse of personal data that usually sits outside the traditional banking perimeter but directly affects consumers of financial services.

APT and Targeted Intrusion

The month's material did not include a classic APT campaign attributed to a group with a specific financial target and confirmed persistence against banking or insurance. The closest signal is StrikeShark, which is presented as an active campaign against organizations in the region, but the material provided is not enough to classify it precisely as an APT in the strict sense. In a rigorous editorial analysis, that should not be forced.

What does stand out is a convergence of offensive interest in the financial sector because of the value of its data, the urgency of its processes, and its dependence on third parties. That appears in the phishing reports, in the discussion of open finance, and in concerns about platforms with cybersecurity weaknesses that could face restrictions, according to coverage of Pix in Brazil. The vector may not be APT in doctrinal terms, but the sustained pressure on identity, integrations, and authorizations is clear.

Critical vulnerabilities

CVE Software Exploitation Source
CVE-2026-25089 Fortinet FortiSandbox Active exploitation, command injection, included in KEV by CISA F5 Labs
CVE-2026-39808 Fortinet FortiSandbox Active exploitation, command injection, included in KEV by CISA F5 Labs
CVE-2026-58644 Microsoft SharePoint Active exploitation, insecure deserialization, included in KEV by CISA F5 Labs
CVE-2026-15409 SonicWall SMA1000 Active exploitation, included in KEV by CISA Quasa
CVE-2026-15410 SonicWall SMA1000 Active exploitation, included in KEV by CISA Quasa
CVE-2026-48908 JoomShaper SP Page Builder Active exploitation, dangerous file upload, included in KEV by CISA The Hacker News
CVE-2026-48282 Adobe ColdFusion Active exploitation, path traversal, included in KEV by CISA The Hacker News
CVE-2026-56290 Joomlack Page Builder Active exploitation, improper access control, included in KEV by CISA The Hacker News
CVE-2026-55255 Langflow Active exploitation, IDOR, included in KEV by CISA The Hacker News

The nine critical vulnerabilities mentioned in the source are not explicitly tied to a Latin American financial incident this month, but they are part of the technical backdrop that banking and insurance teams need to treat as relevant. When CISA adds a flaw to KEV because it is being actively exploited, the operational response in a regional financial institution should be immediate, inventory, external exposure, patch prioritization, and a review of detection rules. That is especially important for perimeter products, collaboration tools, and web components exposed to customers or integrators.

In July, CISA’s weekly bulletin for the week of July 20, 2026, also summarized vulnerability updates for the period. The source does not expand on every detail in the material available, but its inclusion alone reinforces the need to keep patch management aligned with internet exposure. In banking and insurance, vulnerabilities under active exploitation should not be treated as a general infrastructure issue, but as a direct factor in continuity and fraud, because many intrusions begin with a jump from a poorly patched public surface.

Regulation and compliance

July was, above all, a regulatory month. The most visible case was Colombia, where the Superintendency of Finance published for comment Draft External Circular 10 of 2026, with a deadline of August 10, to update the rules for the open finance system in line with Decree 368 of 2026. The draft says supervised entities that already operate schemes or use cases under External Circular 004 of 2024 will have until April 7, 2027 to adapt to the new instructions. The publication also organizes the new chapter into three sections, general provisions, data handling and the participant directory.

That structure matters. In practice, mandatory open finance increases the weight of data governance, granular authorization and participant traceability. For traditional banks and insurers that interact with third-party ecosystems, the threat is no longer just credential theft, it is the correct management of who can access which data, under what legal basis and with what reporting mechanisms. The SFC reinforced that shift with a circular letter dated July 27 and with an institutional bulletin from MinHacienda that welcomed the decree formalizing the mandatory open finance framework.

Also in Colombia, Congress enacted Statutory Law 2573 of 2026, aimed at strengthening protection for victims of identity fraud used to obtain loans, financial products or services. The law requires entities to prove the mechanisms used to verify identity before approving a transaction. For the financial sector, that is a clear signal, the evidentiary standard for authentication is no longer informal and becomes part of legal risk, not just fraud risk.

Regulation and complianceBrazilSusep HandbookColombiaOpen bankingPeru24-hour reportData handling, incidents, continuity, and third parties were the recurring themes.Regulatory pressure is affecting traditional banking, insurers, and payment schemes.
July regulatory flow — Simple map of the month’s main regulatory pieces in Colombia, Peru, and Brazil.

Brazil added another important piece. Susep published a Cybersecurity Guidance Manual for supervised entities, in an advisory capacity, to support implementation of the minimum requirements already set out in current regulations. The manual applies to insurers, local reinsurers, open supplementary pension entities, capitalization companies, insurance cooperatives and mutual asset protection operations administrators, and includes guidance on governance, risk management, data protection, business continuity, incidents, outsourcing and cloud. It is based on CNSP Resolutions 416/2021, 491/2026 and 492/2026, and on Susep Circulars 638/2021 and 700/2024.

Coverage of Pix in Brazil added a sign of potentially tougher oversight. Folha de S.Paulo reported that the Central Bank is weighing restrictions on Pix access for institutions with cybersecurity weaknesses, with possible limits on hours, days or amounts, or even a ban on registering new Pix keys. The report describes it as a measure under study, not an approved rule, but it still points to a stricter regulatory threshold for vulnerable institutions. For banks, that kind of approach can become a strong reputational pressure point because it affects access to a mass payment infrastructure.

Peru rounded out the strongest compliance block. The SBS issued Resolution SBS 01741-2026, which requires public reporting of any cybersecurity incident within 24 hours of becoming aware of the event. The same rule sets a deadline of up to 10 business days for entities to notify affected users of the incident and the corrective actions taken. Another report added that some provisions on incident reporting and digital contracting take effect 360 days after publication, while human support applies from July 3, 2026. At the same time, the SBS warned about loan apps that use extortionate collection tactics, a message that links cybersecurity, consumer protection and the control of abusive practices.

The regional regulatory block is completed by the BaaS front in Peru. The SBS requires policies and procedures approved by the board, with prior evaluation of recipients, periodic monitoring, risk management, exit criteria and reporting and escalation mechanisms. It also expressly identifies credit, operational, cybersecurity and anti-money laundering/terrorist financing risks, and requires an updated list of recipients reported every six months and published on the entity's website. For compliance teams, this means mapping not only critical providers, but also recipients and third parties with the ability to change the risk surface.

Countries and most affected subsegments

Colombia

Colombia was likely the country with the highest density of regulatory and operational developments during the month. The SFC concentrated several publications on open finance, Congress advanced Law 2573 of 2026 on identity theft, and Banco de Bogotá issued specific warnings about fraud attempts during the transition of Itaú customers. Added to that were references to more than 3,000 weekly cyberattacks on Colombian companies according to Infobae, and Colombia’s mention in the StrikeShark campaign and in ransomware cases involving BitLocker and printed notes.

The Colombian pattern is clear, public debate is moving between consumer protection, data regulation, financial supervision and real operational risk. For traditional banking, the most sensitive point is authentication and identity verification. For insurers, the reading is no less significant, because any expansion of open finance or data sharing tends to affect underwriting, customer service and claims handling as well, especially when third-party integrations are involved.

Peru

Peru saw a month of tighter rules and direct warnings to users and institutions. The SBS set a 24-hour deadline for public incident reporting and up to 10 business days to notify users, while other provisions on incident communication and digital contracting were phased in over time. The authority also warned about loan apps using extortion tactics to collect payments. In BaaS, the focus on directories, prior assessment of recipients and periodic monitoring reinforces the idea that the digital financial ecosystem must be far more documented.

Although the Peruvian material does not show a major point breach in banking or insurance, it does create a strong institutional signal. The underlying issue is that the regulator is pushing the market to treat cybersecurity as a reportable and auditable process, not just as technology. That forces institutions to consolidate evidence, detection times, notification criteria and coordination with legal and customer service teams.

Brazil

Brazil delivered the clearest signal for the insurance sector. The Susep manual matters because of its scope and implementation language, since it translates cybersecurity principles into a concrete list of topics for supervised entities, governance, risk, data, continuity, incidents, outsourcing and cloud. The other Brazilian front, the possible tightening of Pix access for vulnerable institutions, points to payment infrastructure and the relationship between security and business enablement.

The most exposed subsegment here is insurers and mutual property protection entities, followed by any institution that depends on instant payments or Pix key integrations. In both cases, the signal is the same, cyber weakness can bring immediate regulatory and commercial consequences.

Argentina

Argentina concentrated public discussion on virtual fraud. La Nación reported more than 200 monthly complaints for virtual scams, and the BCRA reinforced preventive recommendations, especially against requests to install software and links received through chat. That combination is useful because it shows the interaction between the monetary authority, mainstream media and real fraud behavior affecting bank accounts.

For traditional banking, the main exposure is customer interaction, identity validation and support for social engineering incidents. For insurers, the problem appears through similar channels, impersonation, requests to update data, fake claims and manipulation of contact channels. The material does not point to a major Argentina-specific sector breach, but it does show a persistent base of retail fraud risk.

Paraguay

Paraguay provided context on sector maturity and regional exposure, although with fewer directly incident-related developments for traditional banking or insurers. ASOBAN announced its convention with a focus on cybersecurity, data protection and technological innovation, and another report covered new investment strategies in banking in the context of that convention. La Tribuna also mentioned virtual asset regulation and the obligation to report transactions above 1,000 dollars.

That material suggests the country is actively discussing how to shield financial and fintech sectors from digital risk. It is not a crisis snapshot, but it is a picture of institutional preparation. From a regional perspective, Paraguay stands out as a market where the cybersecurity conversation still coexists with innovation and investment, which makes it harder to separate business from control.

There is no comparable baseline from the previous month in the archived format, so it would not be appropriate to invent a quantitative change from June. Even so, July leaves several repeated signals worth watching closely. The first is the persistence of social engineering fraud. The BCRA, Banco de Bogotá, La Nación and ESET point to the same problem, the user remains the preferred entry point and identity remains the most attacked asset.

The second signal is the maturation of the regulatory front. Colombia, Peru and Brazil moved rules or guidance with a direct impact on security, incident reporting and third-party governance. That suggests compliance is no longer a post-incident function, but part of the security architecture. In particular, Peru's short reporting deadlines and Colombia's open finance framework suggest security teams will need much tighter coordination with legal, risk and customer support.

The third signal is the diversification of extortion. Ransomware with BitLocker and printed notes on corporate printers points to a more creative use of internal infrastructure, and the existence of two cases with incomplete classification is a reminder that extortion can arrive with different levels of evidence. For banking and insurance, this means detection cannot stop at endpoints and backups, it also needs monitoring of printing, privileged credentials and administrative task traceability.

The fourth signal is that the third-party attack surface keeps expanding. References to open finance, BaaS, mass customer transfers and measures on Pix show that sector security is increasingly dependent on external relationships. In that model, risk is no longer controlled by perimeter alone, but by contracts, APIs, participant onboarding and shared continuity testing.

The fifth signal, more tactical in nature, is the continued presence of actively exploited critical vulnerabilities. The nine CVEs mentioned in the material are not directly tied to the financial sector, but they should still trigger patching priorities in any environment with public exposure or third-party dependencies. The most useful takeaway here is not the total, but the mix, collaboration software, development tools, content management and edge devices keep appearing in active exploitation catalogs.

Security team recommendations

First, strengthen the identity layer. In banks and insurers, phishing and impersonation campaigns show that access control can no longer rely only on passwords and SMS-based second factors. The priority should be phishing-resistant authentication, device enrollment review, contextual risk alerts, and tighter controls on sensitive changes to accounts, beneficiaries, and contact channels.

Second, review customer communication processes. The Banco de Bogotá cases, the BCRA warning, and the virtual scams reported by La Nación show that attackers easily exploit ambiguity across channels. Institutions should standardize messages, reduce communication variability, and clearly publish what they will never ask for by phone, chat, email, or social media. If customers cannot tell the legitimate sender from the fake one, fraud finds room to operate.

Third, expand monitoring beyond the endpoint. The ransomware case involving corporate printers shows that extortion can take hold in assets often treated as secondary. As a result, printers, network devices, admin consoles, and print services need to be inventoried, along with segmentation and least-privilege credentials. Visibility into those assets is often low until an incident happens.

Fourth, prepare more effectively for regulatory response. Peru requires incident notification within 24 hours and user notice within up to 10 business days, Colombia is moving ahead with open finance, and Brazil with guidance for supervised entities. That means organizations need templates, classification criteria, an internal approval path, and predefined points of contact with regulators and consumer teams. An incident without a notification calendar becomes a second incident.

Fifth, review third parties and ecosystems. Peru's BaaS rules and the open finance discussions in Colombia suggest that a significant share of risk will come through integrators, recipients, and ecosystem participants. Institutions should require evidence of controls, segment access by use case, review permission expiration, and establish exit processes for third parties with unusual activity.

Sixth, speed up vulnerability management when active exploitation is involved. The nine CVEs of the month are not an abstract inventory. They are a reminder that internet-exposed solutions, collaboration platforms, and administration software need more aggressive prioritization cycles. In this kind of environment, patching late is the same as leaving open a door the attacker has already seen in the public catalog.

Seventh, strengthen fraud and customer support as a single capability. The month showed that scam reports, social engineering, and customer migrations have an immediate operational impact. Institutions should bring fraud, security, legal, and support together to share signals, speed up reimbursements when appropriate, and contain impersonation campaigns before they turn into reputational crises.

Material limitations

This report was built exclusively from the material provided for July 2026 and from the list of authorized sources. No internet access was used and no external facts were added. Facts without a confirmed date were excluded from the period indicators, although they could be used as qualitative context when the source was clear and the content was useful for interpretation.

The time window for the indicators is the one stated in the material, 66 dated facts in July 2026 and 5 without a confirmed date excluded from the indicators. The indicators are reproduced exactly as provided and should not be reinterpreted as broad regional telemetry. In particular, when an indicator, such as critical CVEs, does not describe a total absence in Latin America but only what was recorded in the material analyzed, that nuance must be preserved. In this case, 9 critical CVEs were mentioned, but if in another period the value were 0, that would mean not recorded in the material, not nonexistent in the region.

It is also necessary to distinguish between incidents with confirmed impact and aggregated telemetry. The Check Point Research figures and the percentages of weekly detections or attacks are automated attempts or blocks, not confirmed intrusions. For that reason, they are not added to incidents or used as direct proof of increased impact. In this report they are mentioned only as context, with an explicit warning about their nature.

Sponsored content, advertorials and consumer materials that were not in the list of available sources were excluded as evidence of trend. Social media and unauthorized posts were also avoided. When a claim comes from a source that presents it with uncertainty, such as coverage of fines in Córdoba or the possible tightening of access to Pix, it was treated as journalistic attribution and not as a settled fact.

Tracking markers

Sources