Traditional Banking and Insurers, September 2026
Fraud, impersonation, and new rules shaped September in LATAM banking and insurance, with focus on Argentina, Brazil, Colombia, Mexico
Key findings
- Fraud was the dominant threat of the month, accounting for 37 of 83 verified incidents in banking and insurance across Latin America.
- Argentina, Peru, and Colombia concentrated the most relevant regulatory activity, with a focus on anti-fraud, incident reporting, and digital identity.
- Brazil led the most sophisticated operational signal, with deepfakes, facial biometrics, and direct injection techniques at the center of fraud.
- Mexico continued to show high pressure from banking fraud on mobile devices and claims over unauthorized charges or transfers.
- There were no cases of ransomware or extortion classified as the primary focus in the September material analyzed.
- No critical CVEs were recorded in the month’s corpus, which does not imply a lack of exploited vulnerabilities in the region.
Monthly reference modules
These modules are populated automatically with verified, dated facts from the period. Each one states its source basis and counting criterion so the figures reconcile across modules. They are the recurring month-to-month read, while the later analysis develops the cases without repeating this summary.
Indicator window: 83 dated facts in September 2026. Facts from earlier months are used only as comparative context in the analysis, never as volume for this period.
Monthly executive summary
September was dominated by digital fraud in traditional banking and insurers across Latin America, with 83 verified incidents in the period, 37 tied to fraud or phishing, 8 uncategorized incidents, and 7 regulatory moves. The month combined tighter supervisory responses, alerts on social engineering and biometrics, and greater police coordination against schemes that are already affecting financial institutions and insurance systems in several countries.
The regulatory front was especially visible in Argentina, Peru, and Colombia. The BCRA launched its anti-fraud framework on September 1 through Comunicación A 8471 and also said that, starting that same month, it would make public information available to administrators of instant transfers to improve fraud monitoring. In Peru, the SBS proposed a single procedure for reporting operational incidents that applies to companies in the financial, insurance, and pension systems. In Colombia, the SIC opened a public consultation on identity verification and personal data processing, with direct impact on financial and credit products.
Operational pressure came mainly from banking fraud, identity theft, and attacks on mobile devices. In Mexico, CONDUSEF and banks warned about malware capable of capturing passwords, intercepting verification codes, and taking control of the phone, while reports of claims for unauthorized charges or transfers kept rising. In Brazil, the discussion focused on deepfakes, virtual cameras, and automated account opening, with coverage describing estimated losses and growing attack sophistication. The primary source and the coverage converge on the risk shifting to authentication and digital onboarding.
The insurance sector appeared with lower volume, but with its own risk signals. In Colombia, the Superintendencia Financiera identified risks tied to cybersecurity, fraud, data quality, third-party dependence, and operational continuity in the insurance environment. In Brazil, the growth of cyber insurance and the debate over deepfakes show that insurers are already absorbing part of the demand for coverage against incidents that affect financial infrastructure and digital identity channels.
There were no ransomware or extortion cases classified as the primary focus in September's material, and no critical CVEs were mentioned in the corpus analyzed. That does not mean exploited vulnerabilities were absent in the region, only that they were not recorded in this report's source material. The operational reading of the month is clear, the dominant problem was not encryption, but fraud in its various forms, AI-enabled impersonation, and the regulatory response to organize detection, reporting, and prevention.
Regional overview of the month
The region ended September with a medium-high risk level for traditional banking and insurers, not because of destructive intrusion, but because of the volume of verifiable incidents tied to fraud, impersonation, and tighter regulation. The amount of activity is enough to keep pressure on identity controls, authentication, digital channels, and reporting processes, although there are no signs of primary ransomware or a single regional campaign that has displaced the rest of the threat landscape.
Latin America showed a fairly clear split. Argentina advanced anti-fraud regulation for financial institutions and payment providers. Brazil concentrated the highest volume of operational reporting on fraud, deepfakes, biometrics, and police action. Colombia combined regulatory consultation with an insurance focus. Mexico continued to show a high baseline of banking fraud, especially on mobile devices. Paraguay had a more political and institutional month, with requests for reports on alleged cyberfraud and preventive warnings from the central bank. Peru, meanwhile, shifted the conversation toward standardized incident reporting and the criminal statistics for computer fraud and identity theft.
The month’s severity is not measured by system destruction, but by the friction that digital scams, impersonation, and identity fraud create in day-to-day operations. Exposure cuts across the board because it affects customer onboarding, validation, instant transfers, claims handling, document authenticity checks, and oversight. In several reports, facial biometrics appeared as a necessary but insufficient control, especially when attackers can inject synthetic content or reuse a real-time validation.
Against that backdrop, the risk reading for banking and insurance is medium-high. It is medium because the material does not show mass encryption, widespread service outages, or dominant ransomware. It is high because fraud remains the main threat, because there is evidence of greater professionalization, and because regulators and supervisors are treating the problem as an operational risk rather than a simple case of user abuse.
Period indicators
| Indicator | September 2026 value | Previous month comparison |
|---|---|---|
| Verified events in the period (base of all indicators) | 83 | 125, -42 |
| Time window for the indicators | 83 events dated in September 2026 | 125 events dated in August 2026 |
| Unclassified incidents (breaches or disruptions) | 8 | 13, -5 |
| Cases with ransomware or extortion as the primary focus | 0 | 4, -4 |
| Ransomware breakdown by impact type | No classifiable ransomware cases in the period | No comparable data from the previous month |
| Documented fraud or phishing cases | 37 | 44, -7 |
| Documented regulatory actions | 7 | 25, -18 |
| Critical CVEs mentioned | 0, none in the material analyzed, this does not imply absence in the region | No comparable data from the previous month |
| Sectors with at least one documented event | 6 | 7, -1 |
| Main threat of the month | Fraud (37 of 83 events) | Fraud (44 of 125 events) |
| Events with direct source confirmation | 89% | No comparable data from the previous month |
The table shows two notable changes from August. First, the total number of verified events fell from 125 to 83, pointing to a month with less information density but not necessarily lower exposure. Second, regulatory activity dropped from 25 to 7 events, while fraud remained the dominant theme. That shift matters because it suggests the month was not about regulatory expansion, but about implementation, consultation, and preventive communication.
Relevant Incidents
BCRA and Communication A 8471 in Argentina
The strongest response in traditional banking this month came from Argentina's Central Bank, which began rolling out its formal fraud risk management framework for financial institutions and payment service providers in September. The process started on September 1 with Communication A 8471, which brought internal and external fraud into the operational risk framework and set requirements for structures, policies, accountable roles, and risk appetite.
The significance of the case lies not only in the rule itself, but in how it repositions fraud within the control model. The text requires identifying risks tied to products, services, processes, and digital channels, which forces institutions to look beyond a single transaction. It also pushes them to stop treating fraud as a business or customer service issue and place it under a formal risk management function.
On September 3, the BCRA added another relevant element when it said it would make public information available to immediate transfer administrators to strengthen fraud analysis and monitoring. That introduces a risk profiling logic that does not stop at the bank, but also reaches administrators and payment providers. The move is consistent with supervision that wants to anticipate behavior and patterns, not just record losses after the fact.
Coverage cited by El Cronista added that the new provisions would take effect for financial institutions on December 1, 2026, and that some payment service providers would have staggered implementation through September 2027. That difference in deadlines suggests a phased transition, designed to absorb the operating costs of compliance without slowing the adoption of controls.
AI Fraud and Mobile Devices in Mexico
Mexico remained one of the region's main barometers for banking fraud. Between January and July 2026, CONDUSEF recorded 42,791 complaints from bank customers over unrecognized charges or transfers, a figure that helps show the pressure on digital channels even if it is not limited to September. At the same time, banks and regulators issued specific alerts about malware installed on mobile phones and about fraud attempts using social engineering.
The month's reporting sequence is clear. La Jornada warned on September 10 that the malware could capture passwords, intercept verification codes, or take control of the device. On September 11, Expansión explained that if compromise was suspected, users should stop the transaction, disconnect the device from the internet, and contact the financial institution through official channels. On September 12, El Debate broadened the picture with the overlay technique, where fake screens are layered over legitimate banking apps.
The key signal is not only that fraud exists, but that the attack is moving onto the user's device and combining different layers of abuse. The phone stops being a passive tool and becomes the control point where credentials, codes, and sessions are intercepted. For banks and insurers with high mobile adoption, that means reviewing authentication flows, device risk signals, and the ability to stop anomalous transactions without overblocking legitimate customers.
On September 17, DPL News reported that CONDUSEF received 42,791 complaints for unrecognized charges or transfers between January and July. That figure, while cumulative and not strictly monthly, shows the problem is not marginal. In addition, Crónica's coverage of Banco Azteca said fraud complaints fell between January and May 2024 compared with the same period in 2026, suggesting some institutions are already adjusting their response, although that comparison should be treated cautiously because of the attribution data available.
Deepfakes and Identity Fraud in Brazil
Brazil concentrated the most advanced operational debate. Coverage on September 15 and 16 described the use of deepfakes, virtual cameras, emulation, SDK modification, and direct injection techniques to automate account openings and bypass facial biometrics. The critical point is that the attacker no longer needs to show a manipulated image in front of the camera, since synthetic content can be injected into the application itself or into the server.
The information from VU cited by IPNews and TI Inside, with attributions that the reports themselves marked as indirect, pointed to an 830% increase in deepfake-related scams and estimated losses of R$1.8 billion between July 2025 and April 2026. Those figures should be read cautiously because the available excerpt does not link to the full primary report, but they do illustrate the market's narrative about a very rapid rise in AI-assisted fraud.
Beyond the numbers, the technical problem is concrete. InfoMoney said facial biometrics has become a technology used by banks, fintechs, and digital platforms, while palm vein biometrics is starting to be discussed as an alternative. Portal Contábeis also noted that Brazilian regulation does not require a specific biometric technology, but rather controls capable of verifying identity and authenticity. That leaves institutions facing a result obligation, not a method obligation.
On September 28, Correio Braziliense added a useful detail, saying the Central Bank recorded 43 incidents in the first five months of 2026, 34 of them fraud cases, and that Brazilian rules include intelligence, traceability, penetration testing, and access controls. Although that statistic is not limited to September, it reinforces the idea that the main risk in Brazil lies in process manipulation, not infrastructure outages.
Paraguay, the Financial System Under Institutional Pressure
Paraguay did not show a high volume of technical incidents, but it did see a month of institutional tension around the financial system. On September 10, the Senate approved information requests to the Central Bank of Paraguay about financial institutions, including background on controls, sanctions, and proceedings tied to alleged cyberfraud against Banco Itaú Paraguay. The sequence of later meetings between authorities, private banks, and President Santiago Peña shows the issue escalated to the political level.
That matters because it resets expectations about the regulator's strength and the system's response. ABC Color reported that banking associations were demanding clarity on the BCP's controls and technical response, while Última Hora said Central Bank and Banking Superintendency teams began preparing a rigorous reply to parliamentary questions. The mix of information requests, meetings, and public demands for technical autonomy is not an operational incident, but it is a signal of pressure on sector governance.
At the same time, the BCP issued preventive guidance on digital channels. La Nación Paraguay reported on September 24 that the agency urged caution with urgent data requests and calls about account blocks, and reminded users of common risks such as fraud, identity theft, credential theft, and unauthorized access. The reading is consistent with the rest of the region, where social engineering prevention occupies as much space as technical defense.
Peru and the Standardization of Operational Reporting
Peru closed September with a regulatory move that affects both banking and insurance. The SBS authorized publication of a draft rule to replace separate reports for significant operational disruptions and significant cybersecurity incidents with a single operational incident report, applicable to financial, insurance, and pension system companies.
The proposal matters for two reasons. First, it takes an integrated view of incidents, no longer artificially splitting availability, cybersecurity, and continuity. Second, it sets different initial reporting deadlines, up to two hours for companies with market concentration and up to five hours for banks, finance companies, municipal savings and loan institutions, and rural savings and loan institutions. That forces faster detection, classification, and internal escalation.
Coverage from Agencia Andina added that the draft sought a single, standardized process, open for comments until October 16. PQS and Infobae Perú filled in the picture with details on intermediate and final deadlines. For the insurance sector, the point is especially important because the proposal explicitly includes it, which is not always the case in reporting rules centered on banking.
In addition, the Public Prosecutor's Office reported 457 complaints of aggravated fraud linked to the theft or access of debit or credit card data issued by the financial or banking system. Although the statistic is also cumulative and not exclusive to September, it helps explain why reporting standardization appears as a necessary response rather than just an administrative one.
Colombia: Digital Identity and Insurance Risk
Colombia combined two vectors of interest for this report. On one side, the Superintendence of Industry and Commerce opened a public consultation on identity validation mechanisms and the secure handling of personal data, with a focus on obligations for entities offering financial or credit products. On the other side, the Financial Superintendency identified cybersecurity, fraud, data quality, third-party dependence, analytical models, and operational continuity as risks in the insurance sector.
The SIC consultation matters because it places digital identity at the center of the regulatory debate. OlarteMoure said it expressly included technologies such as biometrics, along with effectiveness, reliability, and technical standards. The SIC itself said the consultation would remain open until September 25. That suggests the regulator wants technical input before setting stricter identity validation criteria.
On the insurance side, La FM reported on September 30 that the Financial Superintendency saw cybersecurity and fraud risks among the sector's main concerns, alongside data quality and third parties. The point is consistent with the rest of the month, because insurers appear not so much as victims of a specific breach, but as operators whose business increasingly depends on data, modeling, and outsourced ecosystems.
Brazil: Police Operations Against Electronic Fraud and Benefit Fraud
Brazil also delivered concrete criminal and police enforcement actions. On September 23, the Ministry of Justice and Public Security said Ciberlab had supported three Civil Police operations against groups under investigation for electronic fraud, virtual scams, and money laundering in Ceará, Rio Grande do Sul, and Pará. That same day, another official communication described Operation Fake Card, a case of benefit card fraud involving 52 municipalities across ten federal states and an investigated flow of R$437.8 million.
The scale of Fake Card helps show that regional fraud is not limited to classic digital banking. It also touches payment schemes, benefits, public administration, and merchants. From a risk perspective for financial institutions and insurers, that matters because the payments ecosystem and money flows are shared, and because anti-fraud controls have to look at usage patterns, merchant networks, and beneficiaries, not just individual accounts.
On September 24, the Ministry reiterated Ciberlab's support for three operations in different states, reinforcing the idea of sustained police pressure on electronic fraud schemes. September did not center on ransomware or extortion here, but it did show a strong concentration of actions against fraud affecting the financial infrastructure and the channels through which money moves.
Active Threats and Campaigns
Fraud and Phishing
Fraud was by far the dominant threat in September. The 37 verified incidents tied to fraud or phishing point to a broad and varied attack surface, ranging from bank impersonation scams and banking malware to fake lenders, deepfake attacks, and benefits fraud. The spread of cases suggests there was no single regional campaign, but several abuse families that share social engineering, identity manipulation, and credential theft techniques.
In Argentina, Bolivia, and Paraguay, fraud often centered on brand impersonation and deceptive offers of loans or services. In Mexico, the main vector was mobile devices, fake apps, and malware aimed at unauthorized transactions. In Brazil, fraud became more technical and automated, with an emphasis on facial biometrics, virtual cameras, and synthetic content. In Peru and Colombia, fraud also showed up in the way regulators are reorganizing their reporting rules and identity validation requirements.
One common thread ran through almost all of the month’s cases. The attacker tries to close the gap between the legitimate user and control of the process. Stealing a password is no longer enough. The attacker has to intercept the second factor, spoof a biometric check, trick the help desk, force an immediate transfer, or insert a fake document into customer onboarding. That shift makes several controls designed for less adaptive threats obsolete.
Ransomware and Extortion
No cases of ransomware or extortion were recorded as the primary focus in September’s material. There were also no verifiable descriptions of asset encryption, simple extortion through exfiltration, or isolated mentions in leak sites that would allow the impact to be classified precisely. The absence of this category in the corpus should not be read as the absence of ransomware in the region, but as the absence of confirmed cases in the material reviewed.
That absence matters because it changes the priority picture. In months with ransomware, the discussion usually centers on downtime, recovery, and negotiation. In September, the focus was instead on fraud prevention, identity authentication, and the ability to report operational incidents in time. For banking and insurance, that means the dominant risk was not paralysis, but the fraudulent takeover of accounts, sessions, and decisions.
APT and Targeted Intrusion
September’s material did not support an APT or targeted intrusion campaign with enough precision for this vertical. There were references to attacks against payment systems and to organizations in the financial, retail, and e-commerce sectors in Brazil, but the available source did not confirm a traditional bank or an insurer as a separate affected entity. For that reason, this report does not elevate that material to a consolidated APT campaign.
The cautious reading is that the threat environment does include actors capable of using AI and automation to speed up intrusions, but this month’s material was not enough to isolate a classic espionage or persistence campaign aimed specifically at banking or insurance. The dominant pressure remains fraud, not prolonged stealth intrusion.
Critical Vulnerabilities
No critical CVEs were recorded in the September 2026 material reviewed. That does not mean critical vulnerabilities were absent from the region, only that they were not mentioned in the verified sources for the month.
| CVE | Software | Exploitation | Source |
|---|---|---|---|
| No critical CVEs were recorded in the material reviewed | Not applicable | Not applicable | Not applicable |
Regulation and compliance
The month’s regulatory agenda was intense, though less crowded than August. In Argentina, Communication A 8471 from the BCRA formalized fraud risk management for financial institutions and payment providers, with requirements covering structures, policies, the designation of responsible officers, and risk appetite definitions. The rule’s significance is that it makes fraud an explicit component of operational risk and links it to products, services, and digital channels.
The same country also saw another key move, because the BCRA announced that starting in September 2026 it would make public information available to administrators of instant transfers to strengthen fraud analysis and monitoring. That points to a better reading of risk profiles and a more intensive use of data for prevention. For compliance teams, the message is that prevention is not limited to post-event monitoring, but extends into customer onboarding and periodic review logic.
In Bolivia, the government approved Supreme Decree 5693, which relaxes rules applicable to financial intermediation entities to protect their solvency, and it also reported on a decree that assigned registration, reporting, supervision, control, and follow-up duties for certain certificates to ASFI. Added to that is the commitment, under a program backed by the IMF, to develop a regulatory and supervisory framework for virtual assets to reduce the risk of illicit capital outflows and protect financial resilience.
In Colombia, the SIC opened a public consultation on identity validation and personal data processing, while the Superintendence of Finance reminded the market that its controlled experimentation space, LaArenera, is used to identify risks and generate evidence to strengthen supervision and regulation. The thread is clear, the regulator wants greater capacity to validate identity technologies and to understand how financial innovation affects risk.
In Peru, the SBS proposed a single procedure for reporting operational incidents, with initial, interim, and final reports. The consultation matters for banks, insurers, and pension funds because it unifies criteria that were previously split by incident type. For compliance and crisis management teams, that means reorganizing internal manuals, escalation flows, and responsibilities across operations, technology, risk, and legal.
In Paraguay, the regulatory debate was shaped by the Senate’s request for information from the BCP on financial entities, cybersecurity controls, and alleged cyberfraud. Although it is not a new rule, it is a compliance event in the broader sense because it increases public scrutiny of the supervisor and forces the system to explain its response capacity. At the same time, the central bank issued digital security recommendations for the use of electronic channels.
Countries and most affected subsegments
Brazil
Brazil had the highest concentration of events tied to fraud, biometrics, deepfakes, and police actions. The most affected subsegment was digital banking and onboarding, followed by payments and benefit schemes. Insurance also emerged through cyber insurance and analysis of risks linked to advanced fraud. The mix of regulatory, operational, and law enforcement coverage makes Brazil the region’s main laboratory for the month.
Brazil’s events show a market where identity is at the center of the conflict. Deepfakes, virtual cameras, voice cloning, and direct injection techniques are all aimed at breaking trust in facial biometrics as the only barrier. At the same time, the state response is taking shape through tighter controls, more traceability, and coordinated investigations. That two-sided dynamic gives the country a central place on September’s map.
Argentina
Argentina stood out for the clarity of its rules and for the treatment of fraud as an operational risk. Traditional banking and payment providers were brought under an implementation framework that begins with Communication A 8471 and is tied to public information sharing by the BCRA to monitor instant transfers. The most affected subsegment is payments and transfers, where the speed of transactions and the level of digitization increase exposure.
The country did not record a long list of incidents, but it did show a concrete regulatory response that is likely to shape the wider market. The fact that risk analysis extends to products, services, processes, and digital channels forces banks and PSPs to review control models, not just isolated cases. For the sector, Argentina ends the month as a case of regulatory maturity.
Mexico
Mexico showed a heavy fraud burden linked to mobile devices, fake apps, and social engineering attacks. CONDUSEF and the ABM urged caution against malware capable of capturing credentials and taking control of devices, and the number of complaints over unrecognized charges or transfers remained high. The most sensitive subsegment is consumer banking and its mobile channel.
Mexico matters not because of a single incident, but because the problem persists and the attack surface is varied. The coverage points to an ecosystem where fraud relies on malware installation, app impersonation, and abuse of user trust. That makes preventive education and device monitoring central to control.
Colombia
Colombia stood out for the interaction between digital identity regulation and insurance-sector concerns. The SIC opened a public consultation affecting financial and credit entities, while the Financial Superintendency focused on cybersecurity, fraud, and third parties in insurance. The affected subsegment is twofold, on one side identity validation in financial services, on the other risk management in insurers.
The key issue in Colombia is that the debate is not only about attacks, but also about how identity is verified and what standards should govern that verification. That could affect onboarding, account recovery, remote signing, and access to policies or credit products. The regulatory discussion is, in itself, part of the risk surface.
Paraguay
Paraguay saw a month of institutional pressure on the financial system, with requests for reports on alleged cyber fraud and high-level meetings between authorities and banks. The most exposed subsegment is traditional banking, especially entities under scrutiny for controls and response. Although there was no confirmed major technical incident, the political and reputational burden was high.
That was compounded by preventive warnings from the BCP about requests for data and urgent calls tied to account blocks. The message matches the regional trend, fraud does not always arrive as a visible intrusion, but as an abuse of trust and urgency. Paraguay therefore appears as a country where the governance of the system came under review.
Peru
Peru combined high criminal statistics with a regulatory proposal that directly affects banks, insurers, and pension systems. The most relevant subsegment is operational incident reporting, because the SBS wants to unify and speed up notification of significant events. In addition, complaints of computer fraud and identity theft continue to show a sustained pattern of abuse against users and entities.
The proposed reform matters because it aligns the supervisor’s response with the operational reality of incidents that can no longer be classified simply. For insurers and banks, the change requires early detection, documentation, and escalation capabilities. Peru did not close the month with a single major incident, but it did with a more demanding regulatory architecture.
Trends and signals to watch
The first signal to watch is the drop in total volume from August, from 125 to 83 incidents, without that meaning the risk has eased. Fraud remained the main threat, with 37 documented incidents, only seven fewer than the previous month. In other words, the number of reports fell, but the center of gravity of the risk for banking and insurance did not change.
The second signal is the sharp decline in regulatory moves, from 25 in August to 7 in September. That decline does not reflect a lack of interest, but a shift from drafting to implementation and public consultation. In Argentina and Peru in particular, new rules or rules under consultation suggest that October and November could show more internal adaptation work than policy announcements.
The third signal is the advance of identity-based threats. Deepfakes, facial biometrics, virtual cameras, voice cloning and masked calls appear across different countries in different terms, but with the same logic, breaking authentication controls. What matters is not only that these techniques exist, but that they are already entering banks’ perimeter and, by extension, the processes insurers use to verify customers and claims.
The fourth signal is that several regulators are already treating fraud as an operational risk, not as a one-off abuse. That changes expectations for reporting, traceability, governance and timelines. The contrast with August is also useful: the previous month saw more incidents and more regulation, but September sharpened the narrative around fraud as the main vector and the need to standardize incident reporting.
Security team recommendations
Banks and insurers should treat September as a month for tightening identity controls, not as a routine awareness period. The immediate priority is to review the full authentication journey, from customer onboarding to recurring transactions, because the fraud observed is not limited to initial access. It moves through transfers, biometric checks, and credential recovery.
Risk signals from the device and the channel also need to be strengthened. Cases in Mexico show that a compromised mobile phone remains a central entry point. That means integrating mobile endpoint telemetry, overlay detection, app integrity checks, behavioral verification, and dynamic friction for high-risk transactions. If the channel cannot tell a legitimate user from a manipulated environment, losses can occur even when the password is correct.
Multimodal authentication standards also need to be raised. Evidence from Brazil indicates that facial biometrics alone are no longer enough when deepfakes, direct injection, or reused validations are in play. Teams should combine face recognition with contextual signals, transaction risk, cross-checks, and anti-abuse controls on device changes, remote onboarding, and unusual activity. The recommendation is not to abandon biometrics, but to stop treating them as sufficient proof.
Fraud and compliance teams should also review their notification and escalation timelines. Peru’s SBS and Argentina’s BCRA are pushing for faster, more structured reporting, which in practice requires ready-to-use playbooks, clear owners, and evidence collected from the start of the event. If an organization takes too long to classify an incident, it will also take too long to contain it and report it to the regulator.
For the insurance business, the lesson is similar, but with a different emphasis. Third-party risk, data quality, and operational continuity need closer review, because those were precisely the risks flagged by Colombia’s Superintendencia Financiera. Insurers that depend on analytics models, bank integrations, or digital document workflows need to test what happens when identity fails, when a provider goes down, or when fraud undermines the validity of a record.
Finally, threat intelligence should focus on fraud, not just malware. The month showed a convergence of social engineering, impersonation, automation, and trust manipulation. Security teams should monitor fake financial campaigns, brand abuse, spoofed calls, account opening attempts, and fraud paths tied to benefits, payments, and instant transfers.
Frequently Asked Questions
What regulatory changes crossed banking and insurance this month?
Argentina, Peru, and Colombia accounted for the most relevant changes for both sectors. Argentina's BCRA formalized anti-fraud measures for financial entities and payment providers, Peru's SBS proposed a single report for operational incidents across banking, insurance, and pensions, and Colombia's SIC opened a consultation on identity validation and personal data.
Which fraud technique was most exposed by facial biometrics?
Brazil showed that the main problem is no longer only fake photos or videos, but direct injection, virtual cameras, and reused validations. That overlaps with the facial biometrics discussed by InfoMoney and with the imposter scheme described by Agencia Brasil, where the goal is to bypass the entire identity process.
How does incident reporting change for financial institutions and insurers?
In Peru, the SBS proposed replacing separate reports with a single operational incident report, with initial deadlines of up to two hours for certain companies and up to five hours for banks and other entities. That brings continuity, cybersecurity, and operations into one reporting flow.
What is the link between digital fraud and banking supervision in Paraguay?
Paraguay showed that fraud did not remain only a technical issue. The Senate requested reports from the BCP on controls, sanctions, and alleged cyberfraud, while the central bank responded with recommendations for operating through digital channels. The debate combined reputation, controls, and the supervisor's institutional capacity.
What should an insurer's CISO watch besides banking fraud?
They should watch data quality, third-party dependence, and operational continuity. That combination appears in the Superintendencia Financiera de Colombia's assessment for the insurance sector and connects with identity risk, onboarding, and the use of analytical models. This is not only about attacks, but also about failures that undermine trust in information.
Material limitations
This report was built exclusively from the verified facts provided for September 2026 and from the sources listed as citable. No facts from other months were used for the period count, although the explicit comparison with the previous month was incorporated according to the indicators already provided.
The time window for the indicators is the one stated in the report base, 83 facts dated in September 2026. When accumulated figures from January to July or from other periods are cited, they are included only as descriptive context, not as the monthly volume. Figures from other windows were not added to the September period.
A zero indicator, particularly for critical CVEs, means none were recorded in the material analyzed, not that no critical vulnerabilities exploited in the region exist. The same applies to the ransomware and extortion line, which had no typifiable cases in this month’s corpus.
Aggregated telemetry for attempts or blocks was also left out of the analysis base because no methodologically consolidated figures were provided to turn them into incidents. Consumer social networks and sponsored posts were excluded as well, because they do not appear among the sources authorized for citation.
Sources
- Gestión del riesgo de fraude: el nuevo desafío para las organizaciones financierasEl Cronista
- El BCRA profundiza la estrategia de prevención del fraudeBanco Central de la República Argentina
- Comunicación A 8471Boletín Oficial de la República Argentina
- El Banco Central de Argentina establece nuevos requisitos para la gestión del riesgo de fraude para las entidades financieras y proveedores de servicios de pagosAllende & Brea
- Bolivia to tighten crypto oversight as part of IMF backed reformsCrypto.news
- Estafadores utilizan el nombre de Banco Unión para ofrecer créditos y solicitar depósitos a cuentas particularesBolivia Verifica
- Paz emite decreto para flexibilizar reglas a entidades financieras y resguardar solvenciaLa Opinión
- Ciberseguro enfrenta deepfakeValor Econômico
- Bancos em estado de alerta com aumento de invasõesCorreio Braziliense
- Ciberlab apoia polícias civis em operações contra fraudes eletrônicas em três estadosMinistério da Justiça e Segurança Pública
- Após era da facial, biometria das veias da mão é a nova aposta da cibersegurançaInfoMoney
- Golpes com deepfake crescem 830% no Brasil, diz VUIPNews
- Golpes com deepfake disparam 830% no Brasil e já respondem por 1 em cada 15 fraudes do paísTI Inside
- Deepfake pode transformar biometria facial em uma falsa sensação de segurança nos bancosPortal Contábeis
- Golpe do sósia usa tecnologia para tentar burlar biometriaAgência Brasil
- Golpe do sósia usa tecnologia para tentar enganar biometria facialTV Sim Brasil
- Sedigi defende integração entre setores para prevenir fraudes digitaisMinistério da Justiça e Segurança Pública
- Sistemas mais complexos acentuam riscos cibernéticosValor Econômico
- Fraudes financeiras cibernéticas estão mais sofisticadas, alerta BCCNN Brasil
- Grupo hacker mira sistemas de pagamentos no Brasil e usa IA para acelerar ataques, mostra GoogleValor Econômico
- Superfinanciera recibió 469 quejas contra aseguradoras tras el terremoto: estas son las principales razonesLa FM
- Abren consulta sobre protección de datos por validación de identidadOlarteMoure
- ¿Cómo verificar su identidad digital en Colombia sin caer en fraudes?Noticias RCN
- Colombia: SIC Opens Consultation on Identity Verification SystemsBaker McKenzie
- Publicación sobre consulta pública de validación de identidad y protección de datos personalesSuperintendencia de Industria y Comercio
- La experimentación controlada fortalece la supervisión de la innovación financieraSuperintendencia Financiera de Colombia
- Condusef registra 64 instituciones suplantadas por falsas financieras que utilizan llamadas enmascaradas y videos con inteligencia artificial para defraudar a usuariosEl Imparcial
- México | Apps falsas y brechas de ciberseguridad levantan alerta nacional contra fraudesDPL News
- En México, apps falsas y brechas de ciberseguridad levantan alerta nacional contra fraudesBrújula Digital
- ¿Tu celular está lento o muestra ventanas raras? Estas son las señales de malware bancarioExpansión
- Alerta de CONDUSEF: delincuentes buscan controlar tu celular para cometer fraude bancarioEl Debate
- Fraude bancario: alertan autoridades por malware que roba datos del celularExpansión
- Exhortan bancos y Condusef a tomar precauciones ante fraudesLa Jornada
- Brecha digital y fraudes: los retos de los adultos mayores en el sistema financiero mexicanoEl Economista
- Que el fraude no te sorprendaCONDUSEF
- BCP da claves para operar con medios digitalesÚltima Hora
- BCP insta a desconfiar de pedidos de datos y llamados urgentes por bloqueo de cuentaLa Nación Paraguay
- ¿Qué esperan los gremios del BCP ante los cuestionamientos al sistema financiero?ABC Color
- Peña, BCP y bancos rompen el hermetismo tras pedido de informes del SenadoÚltima Hora
- Asoban insistió en la "autonomía técnica" del BCP durante la reunión con Peña en Mburuvicha RógaLa Política Online Paraguay
- Reunión de Peña y BCP con bancos: ¿qué revelaron los participantes?ABC Color
- Senado solicita informes al BCP acerca de entidades financierasLa Nación Paraguay
- Aprueban pedido de informe sobre fraudes cibernéticos en banco ItaúLa Tribuna Paraguay
- Repositorio de normas legales: setiembre 2026La Cámara - Cámara de Comercio de Lima
- Fraude informático y suplantación de identidad son los ciberdelitos más denunciadosAgencia Andina
- Fraude informático lidera los ciberdelitos en PerúAgencia Andina
- SBS plantea procedimiento único para reportar incidentes operacionalesPQS
- SBS busca que bancos informen en máximo dos horas sobre caídas de sistema y otros incidentesInfobae Perú
- Entidades supervisadas: SBS propone nuevos lineamientos para reportar incidentes operacionalesEl Peruano
- SBS propone procedimiento único para reportar incidentes operacionalesAgencia Andina
- Ciberlab apoia polícias civis em operações contra fraudes eletrônicas em três estadosMinistério da Justiça e Segurança Pública do Brasil
- Polícia de SC apreende R$ 8,7 milhões em criptomoedasSpaceMoney
- Operação Fake Card investiga fraude em cartões de benefícios e movimentação de R$ 437,8 milhõesMinistério da Justiça e Segurança Pública do Brasil
- Cuidado con estas llamadas: Superfinanciera no ofrece créditos ni tarjetasSemana
- PF prende grupo por desvio de R$ 45 milhões da CaixaG1
- Bancos en Colombia deberán asumir fraudes con tarjetas si incumplen esta norma de seguridadNoticias RCN
- Golpes digitais: veja como identificar fraudes e saiba o que fazerAgência SP
- Polícia de SC desarticula quadrilha e apreende R$ 8,7 milhões em criptomoedas de hackersLivecoins
- Operação ClickFix desarticula grupo cibercriminoso e apreende mais de R$ 8,7 milhões em criptoativosMinistério da Justiça e Segurança Pública do Brasil
- Proyecto de Circular Externa 15 - 2026Superintendencia Financiera de Colombia
- ¡ALERTA, NO SE DEJE ENGAÑAR! La Superintendencia Financiera NO ofrece tarjetas de crédito, créditos o cualquier otro producto o servicio financieroSuperintendencia Financiera de Colombia
- Superfinanciera advirtió sobre llamadas falsas para ofrecer créditos en nombre de la entidadLa República
- PF combate esquema de desvio de cartões bancáriosPolícia Federal do Brasil
- Proyecto de Circular Externa 14 - 2026Superintendencia Financiera de Colombia
- Cyberattacks hit Latin America's energy sector hardestBNamericas
- La paradoja de la ciberseguridad en UY (de la preocupación a la resiliencia)InfoNegocios
- Organizaciones públicas y privadas fortalecen la cooperación para el intercambio de inteligencia de amenazasCentro Nacional de Respuesta a Incidentes de Seguridad Informática (CERTuy)
- Se multiplican en Uruguay denuncias por fraude y estafas digitalesPrensa Latina
- De 2.000 a 30.000 denuncias: el ciberdelito crece, se profesionaliza y desafía a la Justiciala diaria
- Nueva estafa en la modalidad de suplantación de identidadMinisterio del Interior de Uruguay
- Mónica Ferrero dijo que Gilberto Rodríguez, “en tres semanas, avanzó más que el anterior fiscal en los tres años que estuvo”la diaria
