CiberLATAMbywhalemate
Intelligence report

Bolivia Cybersecurity Update, September 2026

Bolivia saw entity attacks, banking fraud, and an intense regulatory agenda, with a focus on banking and personal data.

Oct 1, 202619 min read
Bolivia Cybersecurity Update, September 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are completed automatically with verified facts dated within the period. Each one states its basis and counting criterion, so the figures reconcile across modules. They are the recurring month-by-month reading, and the analysis that follows develops the cases without repeating this summary.

Indicator window: 84 dated facts in September 2026. Facts from earlier months are used only as comparative context in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Verified signal monthly dashboard September 2026 · Bolivia Top threat: Unclassified (32 of 79 incidents). Coverage: 84 dated incidents in September 2026 VERIFIED INCIDENTS 79 period base: all counts measured from below on this total RANSOMWARE / EXTORTION 3 3 unable to determine classification with the material UNCLASSIFIED INCIDENTS 12 breaches or outages without threat type declared FRAUD / PHISHING 10 documented fraud campaigns documented REGULATION 14 standards, resolutions, or sanctions UNIQUE CVEs 0 none in the analyzed material (does not imply absence in the region)
Verified signal monthly dashboard — Base: 79 verified dated incidents in Bolivia.
MONTHLY FIXED MODULE Distribution by threat axis September 2026 · Bolivia Each event is counted under only one axis, so the total is exactly 79. "Unclassified incidents" is the remainder. Unclassified 32 Regulation 14 Incidents 12 Fraud 10 Vulnerabilities 8 Ransomware 3
Distribution by threat axis — Each event is assigned to a single axis based on its classification; the total reconciles with the 79 events in the period.
FIXED MONTHLY MODULE Sectoral Distribution of Signals September 2026 · Bolivia Base: 79 incidents in the period · total 93 because 12 incidents are classified in more than one sector. Other / no identifiable sector… 31 Public sector / OIV 18 Financial Services 17 Telecom 12 Technology 8 Energy 3 Retail / Consumer 2 Education 2
Sectoral Distribution of Signals — Heuristic classification by victim sector. One incident may affect more than one sector, so the total may exceed the base.
MONTHLY FIXED MODULE Critical Infrastructure in Bolivia September 2026 · Bolivia 6 of 79 facts from the period touch critical infrastructure. One fact may appear in more than one category. Public sector / government 18 Energy / utilities 1 Telecom / connectivity 7
Critical Infrastructure in Bolivia — Verified facts about public sector, utilities, and essential services

Monthly Executive Summary for Bolivia

September in Bolivia pointed to two clear pressures, concrete incidents affecting entities and users, with the National Chamber of Industries, Banco Unión, and retail banking at the center, and an active regulatory agenda around ASFI, the UIF, the IMF, and new sector registries. The month closed with medium-high operational risk, driven by fraud, institutional account compromise, and structural weaknesses in data and oversight.

The most sensitive case in the period was the intervention at ANH and the review of the B-SISA system, where nine vulnerabilities were documented and linked to fuel diversion and control failures. That episode showed that digital problems were not limited to the financial perimeter, and also affected critical state systems with operational and internal control consequences. At the same time, the National Chamber of Industries reported the takeover of its official Facebook account, and different media outlets documented phishing campaigns, impersonation, and AI-driven scams.

Bolivia's banking sector remained under sustained pressure. La Razón reported, using Fortinet data, 111 million cyberattack attempts in the first half of 2026 against national IP addresses, with the financial sector among the main targets. That does not mean confirmed incidents, but it does provide context for the multilayered defenses, stronger authentication, and customer education described by local banks. The month also left two highly visible fraud cases, one using Banco Unión's name and another involving a fake website that emptied a retiree's account.

On the regulatory front, Bolivia moved forward on supervision and compliance frameworks, although several pieces are still being developed. There were decrees and new registries for financial and real estate entities, references to ASFI's stronger role under the agreement with the IMF, and multiple reports on a future framework for virtual assets. The country also still lacks a general personal data protection law, a gap that worsens exposure for customers and users to leaks or improper handling of information.

National outlook for the month in Bolivia

Bolivia saw a mix of isolated incidents, user fraud, and an active regulatory push in September, with an overall medium-high risk trend driven by volume, sector diversity, and the weight of the financial and government systems involved. There was no confirmed ransomware wave or critical CVEs reported in the material reviewed, but there were several events with operational, reputational, or compliance impact.

The regional picture helps explain the month’s climate. Different sources placed Latin America as a heavily targeted ransomware zone and described banks and payment systems as facing growing pressure, while Bolivia also appeared in notes on cryptoasset frameworks and anti-money laundering prevention. Locally, public discussion centered on digital security, data protection, financial oversight, and the modernization of public and private infrastructure.

Bolivia, September 2026CNIattack onFacebookANH and B-SISA 9critical flawsBanco Uniónfraudbrand-relatedIMF and ASFIplus supervisionSENAPIblockchainand traceabilitySep 1Sep 10Sep 9Sep 16-18Sep 30
September 2026, cybersecurity milestones in Bolivia — A concise timeline of the month’s most relevant events, focused on incidents, fraud, and regulation.

The dominant signal was not uniform. In banking and digital fraud, phishing campaigns, brand impersonation, and scams using QR codes or artificial intelligence carried the most weight. In the state sector, the most serious finding was at the ANH, because it exposed logic and control weaknesses in a sensitive operating system. On the regulatory side, the agenda moved forward, but several elements still lacked final rules, a single authority, or defined deadlines.

Bolivia period indicators

Indicator September 2026 value Prior month comparison
Verified events in the period (base for all indicators) 79 59, +20
Time window for the indicators 84 events dated September 2026 same declared window
Unclassified incidents (breaches or outages) 12 11, +1
Cases with ransomware or extortion as the primary focus 3 11, -8
Ransomware breakdown by impact type: Cannot be determined from the material 3 same criterion, no comparable data
Documented fraud or phishing cases 10 2, +8
Documented regulatory moves 14 6, +8
Critical CVEs mentioned 0, none in the analyzed material no comparable data for the previous month
Sectors with at least one documented event 8 4, +4
Predominant threat of the month Unclassified (32 of 79 events) Unclassified (29 of 59 events)
Events with direct source confirmation 84% n/a
Aggregated telemetry figures excluded from the total 5 (aggregated attempts or blocks, not incidents with confirmed impact) n/a
Sectors with documented incidentsBolivia, September 2026Banking and financehighest densityState and OIVANH, SERECIFraudphishing, QR, AIRegulationASFI, UIF, FMITelecomTigo outages
Sectors with signals in Bolivia, September 2026 — Qualitative breakdown of the sectors with documented incidents in the period, without adding telemetry or unconfirmed signals.

Relevant incidents in Bolivia

ANH and B-SISA, vulnerabilities in a critical fuel system

The intervention at the National Hydrocarbons Agency exposed the month’s most serious finding outside the financial sector. The report cited by Opinión detailed nine vulnerabilities in the B-SISA system, including backdoors, license plate manipulation, weak controls, and password exposure in the code. The result was operational and tied to state control, not just technical.

The chain of events also included later corrections. Reports from Opinión, La Patria and Surtidores LATAM indicated that the compromised system was replaced nationwide, a security patch was applied, and operations were coordinated with SEGIP to curb fuel diversion. The material does not describe data exfiltration, but rather a serious failure of control and integrity in a supply system.

National Chamber of Industries, takeover of an institutional account

The National Chamber of Industries said its official Facebook page was the target of a cyberattack and was temporarily taken offline while it regained control. The official notice said the compromise resulted from the unauthorized takeover of administrator credentials, which allowed attackers to change settings and publish unrelated content.

The case falls under institutional account compromise, with limited reputational and operational impact, but it remains relevant to the attack surface of trade groups and business chambers. The response included enabling multifactor authentication, reviewing devices, and coordinating with Meta and authorities. For the report, this case counts as a verified incident, not telemetry.

Banco Unión and fraudulent use of its name to attract deposits

Bolivia Verifica documented a scam in which third parties used Banco Unión's name to offer loans and request advance deposits to private accounts. The bank issued a denial and clarified that it does not request upfront payments or confidential banking data through those channels.

The case fits brand impersonation fraud, with a classic social engineering component. There was no evidence in the analyzed material of a compromise of the bank's infrastructure, but there was abuse of institutional identity to mislead potential victims. This type of operation continues to appear repeatedly in the country.

Tigo, service outages and user complaints

El Diario reported ongoing mobile voice and fixed and mobile internet outages affecting Tigo in several areas of La Paz and Santa Cruz. The available material describes interruptions and continuity problems, but does not attribute the incident to a data breach or threat actor activity.

For that reason, the case is classified as a service disruption without further attribution. The text provides no evidence linking it to IMEI extraction, information leakage, or ransomware. In a monthly report, this kind of case matters because it shifts the focus from confidentiality to availability, even without a confirmed cyber cause.

Leak attributed to SERECI in cybercrime channels

The material included references to a supposed leak of the SERECI database, detected in cybercrime channels and picked up by a threat intelligence platform. The content suggests large-scale exposure of personal and biometric data, but the month’s supporting material does not allow the alert to be elevated to an independently confirmed operational incident.

For editorial integrity, this point remains an externally attributed signal, not a verified incident with confirmed impact. Even so, it serves as useful background for tracking the country, especially given the sensitivity of civil registry data and the local gap in data protection.

Active threats and campaigns in Bolivia

Ransomware and extortion

The month did not produce a clear picture of ransomware with verified impact in Bolivia. There were three cases or mentions within the broader ransomware or extortion category, but the available material did not allow a determination of whether the impact involved encryption, exfiltration without encryption, or only an appearance on a leak site. For that reason, the classification remains undetermined.

At the regional level, RedTigerIT identified Latin America as the most targeted area for ransomware and said Bolivia is on operators' radar. That view provides context, but it does not replace confirmed local incidents. In Bolivia's case, the month leaned more toward fraud, brand abuse, and control failures than toward verifiable encryption-based extortion.

Fraud and phishing

The main operational driver was fraud. There were campaigns and cases tied to the use of Banco Unión's name, fake bank pages, bogus ChatGPT subscriptions, and QR code scams. In several of those incidents, the attacker sought to steal credentials, induce transfers, or capture card data.

El Diario's coverage of scams created with artificial intelligence also showed the qualitative shift in deception: cloned voices, urgent messages, suspicious links, and institutional branding used to build trust. ASFI issued recommendations so users can verify official channels and stop the attack before handing over data. The dominant pattern was social, not technical.

APT, bots, and coordinated manipulation

The material did not include solid attribution to a state APT or a named persistent group. What did appear was coordinated manipulation of public conversation, with references to bots, fake accounts, and automated amplification around Bolivian media outlets or pages. It points to disinformation and digital pressure, closer to informal hacktivism or platform manipulation than to a classic advanced intrusion.

The available evidence here is stronger as an environment-level phenomenon than as a traditional security incident. Even so, it matters because it affects reputation, information continuity, and the response capacity of organizations that rely on social networks to communicate.

Critical vulnerabilities with impact in Bolivia

CVE Software Exploitation Source
None mentioned N/A No critical CVEs were recorded in the September 2026 material analyzed Period materials

The critical CVE indicator was zero. That does not mean there were no exploited vulnerabilities in the region, or no serious flaws in Bolivia. In fact, the ANH and B-SISA case showed relevant technical and logical weaknesses, but they were not reported under a CVE identifier in the material reviewed.

Regulation and compliance in Bolivia

September was a heavy month for regulation, with 14 documented moves. The most visible package centered on the agreement with the IMF and the role ASFI would play in financial supervision, stress testing, asset evaluation, and prudential strengthening. The prevailing reading is that oversight of the financial system is tightening, not easing.

There were also decrees and registrations with sector-specific impact. Supreme Decree 5693 aimed to strengthen the solvency of financial entities and assign ASFI registration, supervision, and control functions over certain certificates. Renapsi was also created for real estate services, with a focus on transparency, legality, and user protection. In both cases, the logic was to expand traceability and formality.

The crypto agenda followed a different track, still in the stage of commitments rather than final rules. Several reports said Bolivia committed to the IMF to develop a robust framework to regulate and supervise virtual assets, with a focus on money laundering, improper capital outflows, and oversight of operators. The reporting was consistent on one point: there is still no law or active regulation that fully closes that design.

A structural gap also remains. Bolivia still has no general personal data protection law, no specialized administrative authority, and no unified sanctions regime. The Constitutional Court said the privacy protection action exists as an individual judicial remedy, but that does not replace a compliance framework. For sectors that handle financial data, the lack of a framework remains a significant risk.

Most affected sectors in Bolivia

Banking drew the heaviest signal density, both in the volume of attack attempts and in the number of fraud cases and regulatory references. There was no operational collapse, but there was persistent pressure, with phishing campaigns, brand impersonation, the use of AI for deception, and strengthened defenses by several institutions. Traditional banks responded with technology and awareness efforts.

The public sector was also exposed, though in different ways. The ANH showed a structural weakness in a critical fuel system, while SERECI appeared in an alert about an unconfirmed leak. In both cases, the underlying issue was the same, high-value systems with weaknesses in control, traceability, or credential protection.

Industry and business associations saw smaller-scale incidents, but they were useful for reading the attack surface. The case involving the National Chamber of Industries showed account compromise and the need for a digital crisis protocol. The same pattern appears in organizations that are not necessarily part of the financial core, but do manage reputation, information, and communication channels that can be taken over or degraded.

In telecommunications, Tigo provided an availability signal. There was no evidence of a confirmed intrusion, but there were complaints about outages in several parts of the country. At the same time, the material showed that Bolivia remains an environment where digital fraud crosses sectors, from banking and consumer services to identity services and messaging channels.

Compared with the previous month, September saw more verified incidents, more fraud and more regulation, but less confirmed ransomware. Ransomware or extortion as the primary focus fell from 11 to 3, while fraud and phishing rose from 2 to 10. That shift suggests immediate pressure on users and brands weighed more heavily than encryption as the main attack method.

The regulatory footprint also grew, from 6 to 14 documented moves. That is not a cosmetic figure. It indicates that authorities and institutions tied to the financial system are responding with more rules, more oversight, and more registration requirements. The previous month already showed signs of adjustment, but September consolidated them, especially at ASFI, UIF, FMI, and sector registries.

By sector, the jump from 4 to 8 sectors with documented events suggests broader thematic spread, not necessarily uniformly higher severity. The list included banking, industry, hydrocarbons, telecommunications, media, crypto, data protection, and real estate services. That breadth means risk has to be viewed as an ecosystem issue, not just a problem concentrated in one flagship sector.

The absence of critical CVEs in the month’s material should not be read as technical calm. The B-SISA case shows that a critical operation can fail because of business logic, weak authentication, unsafe manual controls, or exposed credentials, without any published CVE being involved.

Recommendations for security teams in Bolivia

First, banks and fintech firms need to tighten identity validation and session-abandonment flows, because most of September’s damage came from phishing, impersonation, and brand abuse. MFA, biometrics, anti-fraud limits, anomaly monitoring, and out-of-band verification should be tied to customer education campaigns that do not rely only on static materials.

Second, organizations that manage social media accounts or public channels need stricter access recovery plans and credential rotation. The case of the Cámara Nacional de Industrias shows that a compromised institutional account can become a vector for disinformation or reputational loss within hours.

Third, the public sector and critical infrastructure operators need to review their control logic, not just their perimeter. The ANH and B-SISA incident highlighted backdoors, exposed passwords, weak validation, and unsafe manual controls. That requires business auditing, segregation of duties, and privilege review.

Fourth, legal and compliance teams should prepare for the new regulatory cycle. With ASFI, UIF, FMI, Renapsi, and the future virtual assets framework advancing at different speeds, institutions will face more demands for traceability, reporting, and documentation. The absence of a data law does not reduce the pressure, it shifts it toward litigation, reputation, and self-regulation.

Fifth, any entity that processes payments, customer data, or identities must assume that AI-enabled fraud is already part of the local threat landscape. Telling users to "check the sender" is not enough. Organizations need stronger communication filters, domain protection, and warnings about fake pages, voice clones, and messages with artificial urgency.

Frequently Asked Questions

What changed more between September and the previous month in Bolivia, fraud or ransomware?

Fraud and phishing rose more than ransomware in September. Fraud or phishing cases increased from 2 to 10, while ransomware or extortion cases fell from 11 to 3. The comparison appears in the indicator table and in the Active Threats and Campaigns in Bolivia section.

Which incident created the highest operational risk for Bolivia's critical infrastructure?

The intervention at ANH and the discovery of nine vulnerabilities in B-SISA was the most serious case for critical infrastructure. It affected fuel control, system integrity, and operational traceability. The technical breakdown is in Relevant Incidents in Bolivia and Critical Vulnerabilities with Impact in Bolivia.

Was there evidence of a confirmed mass data breach in September?

The material shows signals and claims, but no solid operational confirmation of a mass breach verified by a primary source. It includes mentions of SERECI and rumors on cybercrime channels, along with the absence of a data law that makes oversight difficult. See Material Limitations and Regulation and Compliance in Bolivia.

What role did ASFI play in the month, and why does it matter for cybersecurity?

ASFI appeared as a reinforced supervisor of the financial system under the IMF agreement and new measures for financial entities. This matters because banks face more digital fraud, more control requirements, and greater compliance pressure. The details are in Regulation and Compliance in Bolivia and Most Affected Sectors in Bolivia.

Were any critical CVEs exploited in Bolivia during September?

No. The critical CVE indicator was zero in the material analyzed. That does not mean vulnerabilities do not exist in the region, only that no critical CVEs appeared in this corpus. The ANH case shows that severe impact can occur without a CVE published in the report.

Material limitations

The report was built exclusively from the material provided for September 2026 and the specified 84 dated events in that month. The indicators reproduce the declared base in the input and do not add aggregated telemetry as if it were incident data, because those 5 records correspond to automated attempts or blocks, not confirmed impacts.

A zero value, especially for critical CVEs, means there were no verifiable mentions in the material analyzed for this month. It does not mean there are no critical vulnerabilities in Bolivia or in the region. Likewise, several ransomware events were left as undetermined classification because the material did not specify whether there was encryption, exfiltration, or only a mention on a leak site.

Items without a confirmed date were also excluded from the count. The sources excluded from the core analysis were consumer social networks, sponsored posts, promotional content, and material not included in the list of approved sources. When a claim came from a source with uncertain attribution, it was treated as contextual signal and not as a fully corroborated fact.

Sources