CiberLATAMbywhalemate
Intelligence report

Traditional Banking and Insurers, August 2026

August saw 125 verified banking and insurance events in LATAM, with fraud the leading threat, plus more regulation and several scam-related rulings.

Sep 1, 202631 min read
Traditional Banking and Insurers, August 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are completed automatically with the verified facts dated within the period. Each one states its basis and counting criterion, so the figures reconcile across modules. They are the recurring month-to-month reading; the later analysis develops the cases without repeating this summary.

Indicator window: 125 dated facts in August 2026. Facts from earlier months are used only as comparative context in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Monthly Verified Signal Dashboard August 2026 · Latin America Leading threat: Fraud (44 of 125 incidents). Coverage: 125 dated incidents in August 2026 VERIFIED INCIDENTS 125 period baseline: all counts measured from below against this total RANSOMWARE / EXTORTION 4 2 asset encryption confirmed · 2 not classified cannot be determined from the material UNCLASSIFIED INCIDENTS 13 breaches or outages without declared threat type FRAUD / PHISHING 44 documented fraud campaigns documented REGULATION 25 rules, resolutions, or sanctions UNIQUE CVEs 0 none in the material reviewed (does not imply absence in the region)
Monthly Verified Signal Dashboard — Base: 125 verified dated incidents for Latin America.
FIXED MONTHLY MODULE Threat Axis Distribution August 2026 · Latin America Each event is counted in just one axis, so the total is exactly 125. "Unclassified incidents" is the remainder. Fraud 44 Unclassified 39 Regulation 25 Incidents 13 Ransomware 4
Threat Axis Distribution — Each event is assigned to a single axis based on its classification; the total reconciles with the 125 events in the period.
MONTHLY FIXED MODULE Sector breakdown of signal August 2026 · Latin America Base: 125 events in the period · total 201 because 58 events are classified in more than one sector. Financial Services 92 Public sector / OIV 47 Retail / consumer 22 Other / unidentified sector 18 Telecom 16 Technology 3 Health 2 Energy 1
Sector breakdown of signal — Heuristic sector classification by victim sector. One event can affect more than one sector, so the total may exceed the base.
MONTHLY FIXED MODULE Geographic distribution of coverage August 2026 · Latin America Each incident is assigned to just one country or to regional coverage, so the total is exactly 125 out of 125 incidents … Paraguay 23 Argentina 21 Chile 17 Bolivia 15 Brazil 15 Colombia 12 Peru 11 USA 11
Geographic distribution of coverage — Verified incidents from the period grouped by country or regional coverage; each incident is counted once.

Executive Summary for the Month

August 2026 closed with 125 verified incidents involving traditional banking and insurers in Latin America, a jump from July and a clear shift in the risk mix. Fraud and phishing led the agenda with 44 cases, while regulatory actions added 25 developments and unclassified incidents reached 13. The material points to a region that is more exposed to customer-targeted deception and, at the same time, more active in regulatory and legal responses.

The month’s strongest signal was the sophistication of digital fraud. In Argentina, Bolivia, Brazil, Chile, Colombia, Paraguay, and Peru, campaigns and cases emerged tied to card cloning, fake banking call centers, deepfakes, SIM swapping, fake QR-based loans, WhatsApp impersonation, and urgency-based phone scams. At the same time, several courts began to consolidate standards of strict liability for banks and third parties, especially when unusual transactions were not detected or a digital scheme was not stopped in time.

The other major block in the period was regulatory. There were BCRA updates in Argentina, new security rules for Pix and Drex in Brazil, regulatory progress in Chile under Law 21.663 and its implementing decree, SIN adjustments in Bolivia with two-factor authentication, and draft measures from Colombia’s Financial Superintendency related to borrower relief and disaster claims. Taken together, regulators are pushing harder controls in digital banking, authentication, and incident reporting.

No critical CVEs were mentioned in the material analyzed, which does not mean the region lacked severe vulnerabilities. There were relevant operational and security incidents, including Pix instability in Brazil and the data incident involving Pix keys at Pefisa, as well as an operation against electronic fraud that would have affected Banco do Brasil and Federal Police actions tied to banking fraud and money laundering. On ransomware, the month remained contained: four cases where extortion or ransomware was the primary focus, two with confirmed encryption and two where the source did not specify the technical impact.

The scale of the regional picture makes August a high-risk month for the sector. Not because there was an extraordinary volume of sophisticated intrusions, but because customer-facing fraud grew sharply, legal pressure on banks and telecom companies increased, and regulatory responses accelerated in several countries. Defense is no longer decided only at the perimeter or in monitoring, but in authentication, identity validation, smart friction, and evidentiary traceability.

Regional snapshot for the month

August’s regional signal was elevated and uneven. The volume of 125 verified incidents, along with 44 fraud or phishing episodes and 25 regulatory changes, points to a landscape where the most profitable attack surface remained the end user, but with rising costs for banks, insurers, and financial infrastructure players now facing more litigation, more reporting demands, and more pressure to prove due diligence.

Risk was not concentrated in a single country. Argentina contributed a heavy density of scams, public alerts, and court rulings. Brazil concentrated police operations, regulatory adjustments, a Pix incident, and a data exposure case at Pefisa. Chile posted a mix of digital fraud data, a new cybersecurity law, and interagency coordination against transnational financial fraud. Bolivia moved to tighten authentication and formalize complaints over fake loans. Paraguay and Peru added multiple account-draining and bank impersonation schemes. Colombia stood out more for regulation and disaster response, but it also saw financial deception campaigns.

The risk picture for traditional banking and insurers is high for two reasons. First, fraud is no longer episodic or isolated, but a steady stream of multichannel deception that mixes phone calls, messaging, social media, and legitimate apps. Second, institutional response is shifting toward stricter security and accountability standards, which raises the cost of failing to detect, report, or document reasonable controls. In that context, the month showed not only attacks, but also a reset in the standard expected by judges and regulators.

TIMELINE Verified events during the period 1/8 Aspecializedlegalstudy 2/8 A legalpublicationspecialized 2/8 The MinistryPublicProsecutor 2/8 Anotherpublicationlegal 2/8 The Standard ofCharacter 2/8 Thestandardsforsecurity
Verified Timeline of Events, August 2026 — Confirmed milestones within August 2026. Events from earlier months are outside the timeline and are used only as context.

Period indicators

Indicator August 2026 Previous month Change
Verified facts for the period (base for all indicators) 125 63 +62
Indicator time window 125 facts dated August 2026 63 facts dated July 2026 N/A
Unclassified incidents (breaches or disruptions) 13 7 +6
Cases with ransomware or extortion as the primary focus 4 4 unchanged
Ransomware breakdown by impact type, asset encryption confirmed 2 2 unchanged
Ransomware breakdown by impact type, impact not determinable from the material 2 2 unchanged
Documented fraud or phishing cases 44 8 +36
Documented regulatory moves 25 19 +6
Critical CVEs mentioned 0, none in the material analyzed, this does not imply absence in the region N/A N/A
Sectors with at least one documented fact 7 6 +1
Dominant threat of the month Fraud, 44 of 125 facts Regulation, 19 of 63 facts shift in focus
Facts with direct source confirmation 92% N/A N/A

The period base remains the same across all indicators, 125 verified facts dated August 2026. The sectors are not exclusive, so one fact can affect banking, telecom, payments and, in some cases, insurance or compliance. The 0 critical CVEs figure should be read as an absence in the material analyzed, not as an absence of critical vulnerabilities exploited in the region.

Relevant incidents

Pix, an operational outage with no confirmed attack

Brazil's most visible episode was the Pix instability on August 23, which disrupted transactions during the morning and was resolved that same day. According to the Central Bank, there were no signs of a cyberattack, fund diversion, or exposure of banking information. The case was classified as an operational disruption, not a confirmed intrusion.

Its analytical value lies in the context. Pix was already under pressure from new security rules, the regulator's push to strengthen controls, and the recent exposure of Pix key data at Pefisa. In other words, even without evidence of an attack, Brazil's most sensitive payment rail ended up at the center of a trust and resilience agenda that does not allow too many failures in a row.

The Central Bank's public response was immediate and consistent across three separate reports, with a single message: the service was normalized, there was no impact on balances or keys, and the attack hypothesis was ruled out. For banks and acquirers, this leaves a concrete operational lesson, contingency communications must be fast, consistent, and backed by technical traceability, because the reputational cost of an ambiguous outage can be almost as high as that of an intrusion.

Exposure of 28.203 Pix keys at Pefisa

Brazil's Central Bank reported a security incident tied to Pefisa, involving exposure of personal data linked to 28.203 Pix keys. The affected information was registration data only, with no password, balances, financial transactions, or other data protected by bank secrecy. The incident does not appear to be a broad intrusion into core infrastructure, but rather a limited exposure of customer data.

The nature of the leaked material matters. Even without credentials or transaction data, the volume is enough to fuel targeted fraud campaigns, impersonation, and financial pretexting. In a regional environment where fraud increasingly relies on plausible identity data, a database containing name, CPF, institution, branch, account, and key creation date may be enough to improve the precision of social engineering.

Specialized coverage also linked the episode to the new security rules in the Pix ecosystem and to the regulator's interest in raising barriers against fraud. That does not turn the leak into a systemic attack, but it does signal that data governance at entities connected to the payment system remains a sensitive front. For a bank CISO, the case is a reminder that partial exposures also require containment, notification, and post-incident monitoring.

Operação Rastro and electronic fraud against Banco do Brasil

The São Paulo Civil Police launched Operação Rastro against an organization suspected of electronic fraud that reportedly caused losses of approximately R$ 50 million to Banco do Brasil. The source describes the misuse of access credentials belonging to two employees of the institution, along with warrants in several states and multiple suspects. The operation is framed as a theft-by-electronic-fraud scheme, with a direct banking component.

Although the material does not provide a full technical chain, it does leave two solid points. First, abuse of internal credentials was the vector mentioned. Second, the case had interstate reach and led to search and seizure measures targeting equipment and documents. That puts the spotlight on privileged identity controls, segregation of duties, and monitoring of sensitive access in large-scale banking environments.

The case is only indirectly relevant for insurers, but it illustrates a dynamic that does cross the financial vertical, the exploitation of legitimate or stolen access to move money, evade alerts, and escalate fraud. In this kind of scenario, the problem does not end at the technical perimeter. Internal investigations, coordination with law enforcement, and the ability to show when and how the anomaly was detected also come into play.

Fake bank call center fraud in Brazil

On August 11, G1 described the spread of the fake bank call center scam, in which criminals pose as bank employees and call victims to push them into sharing data or authorizing transactions. The pattern is classic, but the report places it as a still-active and highly effective method, powered by fear, urgency, and institutional impersonation.

The tactic works because it mixes social engineering with procedures that look like real customer service. The attacker gains credibility by mentioning recent transactions, preventive blocks, or supposed security checks. In that context, the recommendation to hang up and contact the bank through official channels is not just preventive, it is also an operational containment measure that banks should build into the customer experience.

The value of the case is not its originality, but its persistence. When a method remains active in August and coexists with newer ones, such as deepfakes or messaging-based impersonation, financial sector defenses have to assume fraud quickly adapts to the least resistant channel. Customer service and anti-fraud teams end up sharing the same battleground.

Deepfakes and Central Bank impersonation in Argentina

In Argentina, the Central Bank again warned about scams using fake videos created with artificial intelligence to impersonate officials and steal banking data. This month's material shows the institutional message and several reports that expand on it, criminals are also distributing manipulated videos, emails, WhatsApp messages, and SMS, promoting nonexistent investments and requesting payments in dollars or sensitive data.

The significance of the case lies in the maturity of the tactic. This is not just about forging an audiovisual piece, but about building a multichannel campaign that combines urgency, authority, and the promise of returns. The cited material insists that the BCRA does not offer financial services to the public or request payments through those channels, and that the only reliable validation is through the agency's official channels.

That has a direct impact on banks and insurers because the fraud uses highly trusted brands to feed campaigns that end in account drain and credential theft. It also creates an operational need, training customer service teams to identify when a query is actually part of a scam that started outside the bank, not just a one-off complaint.

SIM swapping and account drain in Argentina

The Junín Civil and Commercial Court of Appeals confirmed a ruling against Movistar and Banco Galicia in a SIM swapping case that ended with a customer's account being drained. The report describes an almost instant transfer of funds, joint liability, and a rebuke to the bank for failing to detect the unusual nature of the transactions. Another legal report detailed that the ruling included direct damages, moral damages, and a civil fine.

The case matters because it makes the bridge between telecom and banking clear. The unauthorized duplication of the SIM was not just the step before the fraud, it was the mechanism that allowed control of the victim's digital identity. When that happens, the bank is exposed not only by the loss, but also by its ability to prove transaction monitoring and management of anomalous events.

The takeaway for the sector is familiar, but in August it became more visible. Mobile-factor security can no longer be treated as an external layer. For home banking, wallets, and SMS authentication, the risk of number or line hijacking translates into direct losses and litigation that can end in substantial compensation and additional sanctions.

Fake QR loans in Bolivia

Bolivia's Central Bank filed criminal complaints against alleged scammers who used its name and image to offer fake loans through social media and messaging apps, asking for deposits via QR codes. The institution clarified that it does not offer loans or manage investments for private individuals and warned that there were signs of similar cases in other parts of the country.

This fraud format combines two advantages for the criminal, an attractive financial promise and a payment method that is fast, visible, and difficult to reverse. The use of QR codes gives it an appearance of formality and lowers the victim's perception of risk. In addition, the BCB's own warning about possible reach beyond Cochabamba broadens the geographic reading of the case.

This type of campaign affects banking, payments, and eventually non-bank financial products competing for digital users. For security teams, the case underlines the need to monitor brand impersonation, register fake accounts and channels, and speed up reporting and takedown processes. In fraud like this, response speed matters as much as detection.

Cyberfraud in Buenos Aires and a steady complaint curve

The Public Prosecutor's Office of the City of Buenos Aires reported around 1.300 cyberfraud complaints in the first half of 2026, with an average of more than 200 per month. August's material ties that volume to phishing, social media scams, and digital financial operations, as well as abuse of trust involving older adults to obtain cards or make unauthorized purchases.

This is not an isolated incident, but a volume gauge for the Argentine market. The figure helps explain why so many reports this month revolve around account drain, impersonation, and banking fraud. It also shows that the problem is not limited to one bank, because most cases operate through user habits, social channels, and reused credentials.

For the sector, this context explains the density of court rulings and public warnings. When the complaint flow is that high, banks are forced to improve detection, traceability, and customer response. If they do not, each new scam stops being an isolated event and becomes part of a series of similar claims that erode trust and raise legal exposure.

Electronic banking fraud and money laundering in Brazil

Brazil's Federal Police opened Operação Klonen to investigate electronic banking fraud, money laundering, and asset concealment. The official communication places the case within a plot against financial institutions, without naming a specific victim from the sector, but clearly marking the banking axis of the investigation.

Its relevance for the monthly analysis lies in the overlap between fraud and laundering. When stolen money moves quickly through concealment structures, the response cannot stop at blocking access or reporting the initial scam. It requires much tighter coordination between anti-fraud teams, AML compliance, and authorities. That link appeared several times in August, especially in Brazil and Bolivia.

The case also fits the month's broader trend, instead of focusing on a single intrusion technique, criminal groups are combining impersonation, electronic fraud, and fund routing. For the financial sector, that means watching not only the entry point, but also the downstream circuit used to disperse, withdraw, and convert stolen funds.

Active threats and campaigns

Ransomware and extortion

August reporting recorded four cases with ransomware or extortion as the primary focus. In two of them, asset encryption was confirmed. In the other two, the source did not allow a determination of whether there was encryption or only extortion with a threat to publish data. There was no single dominant campaign, only scattered references to groups and claims, with the clearest impact showing up in economic pressure rather than prolonged disruption of banking services.

For banks and insurers, this category was quieter than fraud, but no less important. The absence of a major confirmed encryption case in the vertical does not mean lower exposure. What the month shows is that ransomware remained present as a coercion tool and that the regional financial ecosystem continued to face extortion, even if the material analyzed did not always provide enough technical detail to classify each incident precisely.

Fraud and phishing

Fraud was the leading threat of the month, with 44 documented incidents. The repeated use of phishing campaigns, fake banks, deepfakes, SIM swapping, impersonation by phone, messaging, and QR codes confirms that the most profitable vector remained social engineering supported by trusted channels. There was no single dominant technique, but a mix of tactics adapted to the country, the channel, and the victim profile.

The regional pattern is consistent. In Argentina, BCRA notices, court cases, and interviews about fake websites overlapped. In Brazil, operational instability, fake call center fraud, Pix data exposure, and police operations were added to the mix. Bolivia focused on authentication and complaints about fake loans. Chile, Paraguay, and Peru also showed a broad range of impersonation and account-draining schemes. The common threat was the exploitation of credentials, identity, and urgency.

APT and targeted intrusion

The period's material does not show a clearly attributed APT campaign in the traditional banking and insurance axis. There are incidents involving fraud with internal credentials, police operations for unauthorized access, and cases of data exposure that could support later intrusion, but the available sources do not provide enough basis to describe a sustained advanced campaign against banks or insurers with solid technical attribution.

That does not reduce the risk profile, because the month left signs of preparation and tactical evolution. The combination of exposed data, abused legitimate access, and vulnerable mobile channels creates a favorable environment for focused intrusion. Even so, with the material available, the dominant category for the vertical remains fraud, not attributed advanced intrusion.

Critical vulnerabilities

No critical CVEs were recorded in the material analyzed for August 2026. That does not mean there were no critical vulnerabilities exploited in the region, only that none appeared in the sources provided for this report. The focus for the month was fraud, authentication, data exposure, and compliance, not software exploitation identified by CVE.

CVE Software Exploitation Source
No critical CVEs were recorded in the material analyzed N/A N/A N/A

Regulation and compliance

Regulation was a major theme in August, and not just because of volume. The month recorded 25 documented regulatory moves, with notable changes in Argentina, Bolivia, Brazil, Chile, Colombia, and Peru. The common thread was clear, more authentication, more reporting, tighter third-party oversight, and faster response capabilities for incidents or fraud with financial impact.

Argentina and the BCRA

In Argentina, the BCRA published Communication A 8438 and another rule in the Official Gazette, as part of a package of regulatory communications for financial institutions. The source material does not spell out the full content, but it places the measures within the broader update of the system’s rules. That alone signals regulatory continuity in a month dominated by bank fraud and litigation.

Argentina’s regulatory agenda moved alongside a wave of warnings about deepfake scams, phishing, and account draining. That overlap matters because judicial pressure and regulatory pressure often rise together. When courts begin to support strict liability or contributory fault, regulators usually raise expectations for monitoring, authentication, and incident management. August showed both fronts at once.

Bolivia and two-factor authentication

Bolivia made visible progress on digital security. The SIN rolled out two-factor authentication for its Virtual Office and framed it within global cybersecurity standards. It also set up support channels for issues tied to the new model, which suggests awareness of the operational friction that an authentication change can create. The BCB, meanwhile, warned about fake QR-based loans and clarified that it does not offer loans or investments to the public.

The overlap between authentication and fraud is significant. The country is not only trying to harden controls, it is also trying to support users who could be locked out or confused by the security upgrade. For banking and insurance, that transition is useful because it points to a regional framework where MFA and user support move together.

Brazil, Pix, and crypto

Brazil added a dense regulatory agenda. The Central Bank was cited in coverage about new security rules for Pix and Drex, and about a real-time alert system for threats tied to crypto assets, in partnership with Hypernative. Some of those pieces come from corporate or market sources, so they should be read as signals of regulatory and technical direction, not as a confirmed final product promise.

The regulatory logic is still consistent. Brazil’s regulator is acknowledging blind spots, expanding coverage over the crypto market, and tightening controls on mass payment rails. That combination matters for the banking sector because it points to a higher standard for transaction monitoring, fraud prevention, and operational resilience. The Pix incident on August 23, even though it was not an attack, reinforced that agenda further.

Chile and the new cybersecurity law

Chile was one of the most regulation-heavy countries of the month. Law 21.663 and Decree 295 set reporting obligations at three hours, updates at 24 or 72 hours depending on criticality, an action plan within seven days, and a final report within 15 days. ANCI acts as a receiving authority alongside the National CSIRT, and fines for noncompliance can escalate depending on the organization’s category.

The material also shows that companies classified as PSE and OIV are speeding up monitoring and response projects. For banks and insurers, this is critical because compliance is no longer about having a document. It is about reporting quickly, with evidence, and with the ability to reconstruct the incident sequence. Chile is setting a maturity benchmark that will likely influence other markets in the region.

Colombia, disaster relief, and financial claims

Colombia’s Financial Superintendence published draft measures and relief steps for borrowers and policyholders affected by the earthquake, along with instructions to soften the impact of the disaster situation on financial consumers. The focus is not a cyberattack, but it does center on service continuity, claims handling, and regulatory response in an extreme situation.

For insurers, this block is especially relevant because it connects claims, credit, and customer service. When the regulator prioritizes expedited complaints mechanisms or relief measures, internal operations must be able to sustain short response times, case traceability, and consistent documentation. August delivered that signal alongside the fraud agenda, showing that regional financial compliance has become broader and more tactical.

Peru and tougher fines

In Peru, the material included SBS resolutions and coverage about new fines for banks, AFPs, and insurers. Although the listed sources do not detail the full scope of each resolution here, they do confirm a move toward tougher sanctions and a more severe supervisory environment. That fits with the rise of fraud through calls, messages, voice impersonation, and fake receipts.

The link between regulation and threat is direct. When a regulator tightens fines and supervision, the sector has to show that it understands operational risk and fraud as one chain of control. In August, Peru made that tension especially clear, especially in the digital payments and consumer banking ecosystem.

Regulatory developments by countryArgentinaBoliviaBrazilChileColombiaBCRATwo-factor authenticationPix and cryptoLaw 21.663Relief and insurance
Regulatory Pressure Comparison — Documented regulatory developments in August 2026 materials.

Countries and most affected subsegments

Argentina

Argentina was one of the month’s densest hotspots, both for fraud volume and for judicial and regulatory response. The material brings together BCRA alerts on deepfakes, phishing cases, SIM swapping rulings, X-based scams, and court decisions that assign strict liability or shared fault between bank and customer. It also adds growing reports of cyberfraud complaints in CABA.

By subsegment, the most repeated impact hit retail banking, home banking, wallets, and credit cards. Coverage of card cloning with fraudulent online purchases shows that classic fraud is still alive, even as it coexists with more modern techniques. The Argentine cases also put the evidentiary burden in the spotlight, with each ruling seeming to demand more from banks to prove they monitored activity and reacted in time.

Brazil

Brazil concentrated operational incidents, data exposures, police operations, and security updates tied to Pix and crypto. Pix instability, the Pefisa incident, Operação Rastro, Operação Klonen, and the crypto alert plan made for a month of heavy pressure on the financial system and its payment flows. It is no surprise that the Central Bank appeared in so many reports.

The most strained subsegment was payments and digital banking, followed by compliance and financial crime. The coexistence of electronic banking fraud, money laundering, and on-chain monitoring suggests the country is pushing for tighter integration between antifraud controls, AML, and technology supervision. For insurers, the direct volume impact is lower, but the exposure matters because of business continuity and the use of shared digital channels.

Chile

Chile combined strong regulation with expanding digital fraud. The Central Bank reported nearly US$98 million in unknown transactions or transactions reported as fraudulent during the first half of 2026, while the country advanced in implementing the Cybersecurity Framework Law and a national table against transnational financial fraud. That dual pressure, monetary loss and legal demands, captures Chile’s month well.

In subsegments, banks and payment systems were the most exposed, but the regulatory impact reaches all essential service providers and operators of vital importance. The removal of coordinate cards at several banks and the shift toward stronger authentication methods also point to a structural change in the financial user experience.

Bolivia

Bolivia showed a more focused agenda around authentication, fraud reporting, and institutional strengthening. SIN activated two-factor authentication, the BCB reported false QR-based loans, and the UIF appeared close to leaving the FATF gray list after correcting deficiencies. The strengthening of CSIRT Bolivia was also reported as part of a broader strategy.

The most visible subsegment was digital tax services, but the takeaway extends to the financial system as a whole. The push for stronger authentication and sector-specific response structures points to a region where banking will have to live with more formal reporting and support models. Bolivia did not have the highest number of incidents, but several carried high structural value.

Paraguay

Paraguay maintained a steady flow of emptied accounts, theft complaints, and prevention alerts. The material mentions specific victims, a lawmaker reporting a cyberattack, malware suspicions, and bank prevention notes. While the documented volume is lower than in Argentina or Brazil, the repetition of incidents shows meaningful exposure in the retail segment.

The most affected subsegment was personal checking and bank accounts, with heavy social engineering and credential theft. The variety of media outlets reporting the same pattern indicates that the issue has become part of the country’s everyday financial security coverage.

Peru

Peru showed a mix of consumer banking fraud, attacks through calls and messages, and regulatory pressure on banks, pension funds, and insurers. The appearance of voice spoofing, fake receipts, and synthetic identities in August coverage suggests a technical escalation in social engineering. It is a troubling sign because it combines automation with the exploitation of personal trust.

The insurance subsegment appears less because of its own incidents and more because of the regulatory and compliance environment. The mention of tougher fines and the context of fraud directed at end customers means the insurance sector must strengthen validation, document fraud controls, and payment oversight. The common vector remains identity, not just infrastructure.

Colombia

Colombia was not the country with the highest volume of banking cyber incidents, but it was an important regulatory hub. The Financial Superintendence published measures linked to natural disasters, loans, and insurance, and opened draft circular letters and relief measures for affected parties. The signal here is operational resilience and supervisory response rather than intrusion or mass banking fraud in the material analyzed.

The most exposed subsegment is insurance, because of the nature of the relief and claims measures. For banks, the lesson is that compliance and consumer service will face tighter regulation even outside cyberincident scenarios. That requires business continuity, mass service handling, and documentary evidence to be built into the same operating framework.

The comparison with July shows a sharp shift in pace and focus. Verified incidents rose from 63 to 125, fraud or phishing from 8 to 44, and regulatory moves from 19 to 25. The main signal is not just higher activity, but a shift from a regulatory-heavy agenda to one dominated by fraud, with greater visible impact on customers and higher legal costs for financial institutions.

The ransomware count held steady at four cases in both months, suggesting the threat remained present without becoming the vertical's main story. Fraud, by contrast, expanded much more sharply and spread across more countries and subsegments. That should push teams to prioritize tactical awareness campaigns, stronger authentication, and detection of unusual transfers, rather than reading August as a month centered on destructive malware.

The nature of legal risk also changed. The Argentine rulings and the mix of reports, fines, and rules in Chile show that judges and regulators are less willing to accept generic explanations. If a bank cannot prove monitoring, alerting, blocking, or timely response, the cost is no longer only reputational. It is also judicial, administrative, and in some cases, directly financial.

Recommendations for security teams

Security teams at banks and insurers should treat this month as a signal to tighten identity controls and fraud response, not just infrastructure defenses. The immediate priority is to review authentication flows, support channels, transaction monitoring, anomaly detection rules, and customer service guidance for impersonation by phone, SMS, messaging apps, and video.

First, defenses against SIM swapping, session theft, and mobile identity hijacking should be strengthened. Cases in Argentina show that a compromised phone number can be enough to drain accounts or speed up transfers. That means adding risk signals for device changes, new payee setup, SIM replacements, and urgent transactions to newly opened accounts.

Second, institutional impersonation needs to be treated as a recurring campaign. Fraud involving fake bank call centers, BCRA deepfakes, and fake QR-based loans shares the same foundation, it exploits trust in a brand and time pressure. The response should not be limited to broad awareness campaigns, but should include short, repeatable, specific messages inside the app, the call center, and complaint channels.

Third, fraud monitoring and AML compliance monitoring need tighter integration. Operação Klonen and the Brazilian electronic fraud case show that stolen money moves fast and is quickly dispersed. If fraud sees the event but AML arrives too late, the damage is already done. Cross-team visibility, along with shared playbooks, reduces that gap.

Fourth, it is key to review operational incident handling and partial data exposure. The Pefisa case shows that a limited leak can fuel later fraud without touching passwords or balances. That requires monitoring abuse of exposed data, accelerating notification to potentially affected users, and adjusting prevention rules in the following months.

Fifth, banks and insurers operating in Chile need to prepare their workflows for the reporting cycle of 3, 24 or 72, 7 and 15 days, depending on criticality and the type of agency. It is not enough to know the obligation exists. Teams need to practice who files, who consolidates evidence, who approves communications, and who maintains technical and legal traceability.

Sixth, customer service should no longer be a peripheral part of fraud response. August made clear that many attacks are resolved, or made worse, at that point. If the customer's first point of contact cannot verify, block, escalate, and document, the defense chain breaks. Real security in this sector starts before the transaction and ends after the complaint.

Frequently Asked Questions

What forces incident reporting to move faster in Chile, Brazil, and Argentina?

Chile is the most prescriptive case in the material, because Law 21.663 and Decree 295 set early warning at three hours, updates at 24 or 72 hours depending on criticality, an action plan within seven days, and a final report within 15. In Argentina and Brazil, there were rules and alerts, but the sources provided did not spell out a cycle this precise.

What type of fraud dominated the month, and which countries showed it most clearly?

Fraud and phishing dominated, with 44 verified incidents. They appeared most clearly in Argentina, Brazil, Bolivia, Chile, Paraguay, and Peru, through deepfakes, fake bank call centers, SIM swapping, fake QR-based loans, impersonation by calls and messages, and account drain.

Was there confirmed ransomware encryption against banks or insurers in the region?

The material recorded four cases with ransomware or extortion as the primary focus, two with confirmed asset encryption and two where the source did not allow the technical impact to be determined. The sources provided do not show clear cases of Latin American banks or insurers with verified encryption as the month’s main event.

Which country showed the most regulatory pressure on digital banking and payments?

Brazil, Chile, and Bolivia concentrated the most visible pressure, though for different reasons. Brazil strengthened Pix and moved forward on crypto alerts, Chile tightened incident reporting with Law 21.663, and Bolivia activated two-factor authentication and complaints over fake loans. If the operational scope over payments is the measure, Brazil and Chile stand out.

What should a bank review first if it wants to reduce exposure to these cases?

First, authentication and detection of identity changes, because several cases this month exploited SIM swapping, phishing, fake calls, and impersonation. Second, monitoring of unusual transactions and new payee registrations. Third, customer service scripts and blocking procedures, because early response was key in the most visible incidents.

Material limitations

This report was prepared exclusively with the material provided for August 2026 and only with facts dated within that month. No internet access or external sources outside the authorized list were used. The indicators reflect the base and time window stated above, and they do not add attempt telemetry or automated blocks, because the material did not provide figures of that kind.

A zero indicator, especially the critical CVE count, means that this data point was not recorded in the August 2026 material analyzed, not that no critical vulnerabilities were exploited in the region. The same applies to any thematic absence: it reflects the available corpus, not the full scope of real-world risk.

Ransomware and extortion were classified cautiously. When the source did not allow a distinction between encryption, exfiltration, or a simple mention on a leak site, that uncertainty was noted in the analysis. Consumer social media and sponsored or commercial posts that are not included in the approved source list were also excluded as evidence.

The indicator window was August 2026. Facts from earlier months, including comparisons with July, were used only for contrast and always with the corresponding month stated explicitly. Sectors are not exclusive, so the same event can affect more than one subsegment of the vertical, especially when it involves a mix of banking, telecom, payments, and compliance.

Sources