Neobanks, FinTech and PSPs, July 2026
July brought regulatory pressure in Peru and Brazil, plus 40 vulnerability events and an operational incident at Caixa lotteries.
Key findings
- The dominant signal in July was active exploitation of vulnerabilities, with 40 of 66 verified events in the period.
- Brazil combined operational and regulatory pressure, with an attack on services linked to Caixa and debate over conditioning access to Pix.
- Peru accelerated incident-notification requirements, with 24-hour deadlines to inform users and, in some cases, the public.
- The only case associated with ransomware or extortion could not be classified precisely, because the material only provides a claim attributed to the actor.
- No fraud or phishing cases were documented as incidents in the period, but Peru's SBS warned of a rise in identity theft complaints in an event with no confirmed date.
- Oracle E-Business Suite, Fortinet, SonicWall, SharePoint, and Adobe ColdFusion dominated the technical agenda and are relevant because of their proximity to payment business processes.
- There is no monthly comparative baseline, so the trend reading must be internal to the month itself rather than a change versus June.
Monthly reference modules
These modules are completed automatically with the verified, dated facts within the period. Each one states its basis and counting criterion, so the figures reconcile across modules. They serve as the recurring month-to-month reading; the later analysis develops the cases without repeating this summary.
Indicator window: 66 dated facts in July 2026 · 1 without confirmed date (excluded from the indicators). Facts from earlier months are used only as comparative context in the analysis, never as volume for this period.
Monthly executive summary
July closed with a clear signal for the neobank, FinTech and payment processor segment in Latin America, the most visible risk did not come from a single major data loss event, but from the combination of operational exposure, regulatory pressure and a wave of actively exploited vulnerabilities. In the verified material for the month, the dominant threat was vulnerabilities, with 40 of 66 events, while incidents that were not classified were limited to 3, and there was only one case where the primary focus was ransomware or extortion. The month’s picture is therefore not one of a market dominated by documented mass fraud, but of an environment in which the technical attack surface of third parties and critical platforms continued to strain operational continuity.
The clearest case of operational impact was the attack that affected the system operating Caixa lotteries, with restrictions on transaction limits, suspension of deposits and ticket payments, and a press reference to the diversion of R$ 1 million. For this report, that episode matters less for the amount than for the functional reading, there was a degradation of services that touch payment flows and transaction acceptance, meaning a problem very close to the transactional perimeter shared by PSPs, acquiring and collections environments. Although the coverage does not place the incident within a neobank or fintech proper, it does sit in the same digital payments ecosystem that this segment needs to watch closely.
At the same time, the month was marked by regulatory signals from two major markets. Brazil moved toward the idea of restricting Pix access to banks and fintechs with weak cybersecurity controls, a signal that should not be read as a measure already in force, but as a possible lever for tougher oversight of participants that do not show minimum maturity. Peru, for its part, accelerated the obligation to publicly notify users of cybersecurity incidents, with 24-hour deadlines to report events and an additional requirement to communicate certain outages within ten business days. In compliance terms, July was a month of greater pressure on operational transparency and event traceability.
Information from sector sources and agencies on vulnerabilities showed a repeated pattern, CISA and related technical summaries continued adding actively exploited CVEs to the KEV catalog, including flaws in Oracle E-Business Suite, Fortinet FortiOS, FortiSandbox, SonicWall SMA1000, Adobe ColdFusion, SharePoint and several third-party components. For a payments security team, this is not an abstract list. Oracle EBS and its Oracle Payments File Transmission component appeared explicitly in the discussion, with CVE-2026-46817 described as critical, unauthenticated and HTTP-accessible. In other words, the month reinforced that corporate back-office assets, billing, reconciliation, admin portals and middleware remain as relevant as customer-facing channels.
One additional data point helps frame the regional climate. Although the report includes economic references on tax pressure, financing costs and energy prices, those pieces should not be confused with security telemetry or with a direct increase in incidents. They do, however, help explain a context in which operational risk management, control spending and remediation priorities compete with squeezed margins. For a neobank or PSP, that environment can translate into patch delays, supplier dependence and greater exposure to legacy platforms or rushed integrations.
Regional overview for the month
July’s regional picture points to high risk, driven by the volume and severity of verified incidents. Actively exploited vulnerabilities were the dominant issue, alongside regulatory developments and at least one incident with visible operational impact. The source material does not document a phishing or fraud wave as the month’s main category, but it does include an explicit warning from Peru’s SBS about complaints involving identity theft and unauthorized banking transactions, with phishing and phone calls used to obtain personal and financial data. Because that item has no confirmed date, it is not counted in the indicators, but it does help round out the picture of abuse across digital channels.
Latin America showed the usual tension seen in the payments industry in July, regulators are pushing for more traceability, notification, and controls for ecosystem participants, while the technical layer continues to expose exploitable flaws in general-purpose software and enterprise applications that support financial operations. The coexistence of those two layers is critical. Incidents do not always turn into visible theft or confirmed exfiltration, but a critical vulnerability in a payments, authentication, or administration component can erode trust, slow transactions, and trigger emergency workarounds that affect users and merchants.
The clearest regulatory pressure came from Brazil and Peru. Brazil’s Central Bank studied tying access to Pix to the cyber maturity of banks and fintechs, suggesting a risk-based supervision model rather than one based only on licensing. In Peru, the regulatory package published by SBS pushes incident and outage reporting to happen fast enough to force internal processes for classification, escalation, and customer contact to mature. For compliance teams, the challenge is not only legal. It is also operational: record the event correctly from the start, distinguish an outage from a cyberincident, and keep technical diagnosis aligned with public communication.
On the technical side, the regional signal was heavily skewed toward exposed software and active exploitation. Oracle E-Business Suite, Fortinet, SonicWall, Adobe ColdFusion, SharePoint, Langflow, and WordPress and Joomla components all appeared in July’s summaries. That suggests attackers and threat researchers kept finding value in large attack surfaces, many of them outside the core banking stack but embedded in the value chain that supports it. For a PSP, the risk is not limited to the visible gateway. It also extends to ERP, CRM, supplier portals, help desks, ticketing systems, and any application with privileged credentials or connectivity to payment data.
The regional qualitative assessment, then, is not one of a market in broad crisis, but of a high-exposure environment with strong sensitivity to third-party failures and a growing regulatory capacity to force entities to report and remediate faster. The most dangerous failure point is not necessarily the one that gets the most attention. It is usually the combination of an actively exploited component, delayed patching, and a payments architecture that cannot absorb the loss of an intermediate link well.
Period indicators
| Indicator | Value |
|---|---|
| Verified events in the period (basis for all indicators) | 66 |
| Indicator time window | 66 dated events in July 2026 · 1 undated (excluded from the indicators) |
| Unclassified incidents (breaches or outages) | 3 |
| Cases with ransomware or extortion as the primary focus | 1 |
| Ransomware breakdown by impact type: Type could not be determined from the material | 1 |
| Documented fraud or phishing cases | 0 |
| Documented regulatory moves | 3 |
| Critical CVEs mentioned | 15 |
| Sectors with at least one documented event | 6 |
| Main threat of the month | Vulnerabilities (40 of 66 events) |
| Events with direct source confirmation | 97% |
Relevant Incidents
Caixa lottery system
Defender360’s reporting indicated that a cyberattack affected the system that runs Caixa’s lotteries and led to specific service restrictions, including transaction limits, suspension of deposits, and ticket payments. The outlet also reported a diversion of R$ 1 million and five days of restricted services at the time of publication. For sector analysis, the most important detail is not only the alleged financial loss, but the disruption to a system tied to retail payments, collections, and user experience.
Although this was not a neobank or a pure PSP, it does affect the same transactional infrastructure ecosystem, where a disruption in inbound and outbound flows can quickly become a reputational and operational problem. The case fits the category of an incident with verifiable operational impact. No evidence of exfiltration or confirmed encryption was provided in the material available, so it should be read as a service interruption or degradation associated with an attack, not as a fully defined ransomware case.
The lesson for payments operators is clear, when the affected channel is part of the acceptance or settlement flow, the interruption stops being a technical anecdote. It becomes a business issue, a customer support issue, and a counterparty compliance issue. In environments where trust depends on availability, a sustained degradation over several days has effects that go beyond the initial incident.
Brazil’s regulatory response on Pix
On July 6, O Globo reported that Brazil’s Central Bank was studying restrictions on access to Pix for banks and fintechs with cybersecurity controls considered weak. The wording matters, this was a regulatory consideration, not an executed sanction. Even so, the message to the market is strong. Access to such a critical payment rail is beginning to be tied more explicitly to security posture and to the ability to demonstrate minimum controls.
For the fintech segment, the announcement works as a disciplinary signal. Entities that rely on Pix to originate payments, collect funds, make withdrawals, or move money between accounts should interpret the news as a warning that the balance between innovation and operational risk will be increasingly conditioned on evidence of cybersecurity maturity. This can affect both smaller players and larger platforms that outsource sensitive parts of their stack.
There is also an indirect reading for PSPs and processors. If a bank or fintech loses access to a rail, or sees its integration rights compromised because of weak controls, the entire settlement and reconciliation chain can face delays, contractual reviews, or greater audit demands from counterparties.
New notification requirements in Peru
Peru concentrated three regulation and compliance developments in July. On July 2, Infobae Perú reported that the SBS established that financial entities must notify users, within 24 hours of becoming aware of events that may affect them, including cybersecurity incidents and service interruptions in customer service channels. The same coverage added that, in cases other than customer service channel interruptions, user notification must be made within ten business days, with information about the event and the actions taken. Later, Brújula Digital reported that Resolution SBS 01741-2026 requires public reporting of cybersecurity incidents within 24 hours of the event being known.
On July 13, iupana reinforced the idea that Peruvian banks and fintechs face a new incident communication challenge. Taken together, the three reports point to the same shift, less tolerance for opacity, less room for delayed responses, and greater pressure on the teams coordinating cybersecurity, legal, customer service, and corporate communications. For a payments operator, the practical effect is immediate. Detection and containment are not enough. The incident also has to be classified, documented, and communicated within very short deadlines.
The change affects the incident response playbook. If the entity does not have a clear asset inventory, criteria for distinguishing security interruptions, and approval workflows that have already been tested, meeting the deadline may be harder than the technical containment itself. In an ecosystem where many functions rely on vendors and third parties, internal validation speed matters as much as SOC response.
Unconfirmed Section9 claim against a Brazilian fintech
On July 26, DeXpose reported that the Section9 group claimed an attack against a Brazil-based fintech and threatened to publish data if there was no contact. The publication, however, is the actor’s own allegation and not an independent confirmation. For that reason, it should not be read as a verified incident, but as a sign of possible extortion or reputational pressure activity that did not receive further validation in the available material.
From an analytical perspective, this type of entry still matters because it shows the persistence of leak sites and post-breach pressure channels as negotiation tools. But editorial discipline requires not overstating an uncorroborated claim. If there is no confirmation of encryption, exfiltration, or even real contact with the victim, the prudent approach is to leave it in the category of an allegation attributed to the actor.
Unconfirmed claim about a major acquirer and gateway in Brazil
On July 12, Minuto da Segurança published a manifesto from the 1877 Team group claiming to have compromised the infrastructure of a major acquirer and payment gateway provider operating in Brazil, with a reference to PagBank. The report itself clarified that there was no official confirmation from the Central Bank, CERT.br, or local acquiring networks. Therefore, the case cannot be read as a confirmed breach for the month.
Even with that caveat, the report is useful for vertical threat mapping. Processors and gateways are often high-value targets because they concentrate authentication, authorization, antifraud rules, tokenization, and payment orchestration. A mere claim does not validate impact, but it does suggest where attackers are seeking to position themselves when targeting Brazil’s payments ecosystem.
Active threats and campaigns
Ransomware and extortion, one mention with impact that could not be determined
This month’s material contained a single case centered primarily on ransomware or extortion, and the impact classification could not be determined with precision. DeXpose’s piece on Section9 at a Brazilian fintech is the best fit for that category, but the source itself presents the information as the threat actor’s claim. There is no confirmation in the material of asset encryption, validated data exfiltration, or verified negotiation with the victim.
That ambiguity matters. In the payments sector, many malicious actors use ransomware language to create urgency, but the operational outcome is not always the same. It may be only a mention on a leak site, extortion without encryption, or a deeper intrusion. When the evidence is not enough to distinguish among those scenarios, the report should preserve that uncertainty, because the risk facing the organization and the immediate countermeasures are not identical in each case.
The practical reading is that the ecosystem remains attractive to actors seeking reputational pressure against financial companies that depend heavily on public trust. In a fintech, a single credible allegation of exposure can affect onboarding, partnerships and perceptions of operational solvency, even without fully proven technical damage.
Fraud and phishing
There were no documented fraud or phishing cases reported as incidents during the period within the July-dated corpus. That does not mean there was no activity in the region, only that the material for this month did not typify any such incidents. The closest reference comes from Peru’s SBS, in an undated event, warning of rising complaints about digital fraud tied to identity theft and unauthorized banking transactions, with phishing and phone calls used to obtain personal and financial data.
The absence of a formal category in the indicators should not lead to a complacent reading. On the contrary, Peru’s regulatory environment and the pressure on payment channels suggest that identity fraud remains a structural threat, especially when it combines with service disruptions or incidents that push users toward less secure alternative channels. For fintechs and PSPs, operational friction often enables social-engineering fraud.
APT, opportunistic intrusion and pressure on exposed software
The month did not provide enough evidence to attribute classic APT campaigns in the vertical. What it did show was a sustained chain of opportunistic exploitation against critical and actively exploited vulnerabilities. That pattern, while less flashy than a sophisticated intrusion, is the one that can do the most damage in payments environments when affected systems are administration portals, back-office components or middleware with access to financial information.
Oracle E-Business Suite appeared several times in the material, with particular attention to CVE-2026-46817, a critical flaw in Oracle Payments File Transmission described as exploitable without authentication and through HTTP access. There were also references to Fortinet FortiOS, FortiSandbox, SonicWall SMA1000 and SharePoint. The presence of these names does not mean they were all used against Latin American entities, but it does show that the software ecosystem underpinning critical business operations came under heavy pressure during the period.
For a fintech or PSP CISO, the message is not abstract. The most dangerous campaigns in July were not necessarily the loudest ones, but the ones that exploited the gap between patch release and real-world deployment. In a payments chain, that delay can reach branches, back office, reconciliation dashboards, links to sponsor banks and poorly segmented test environments.
Critical vulnerabilities
The material reviewed identified 15 critical CVEs mentioned. The table below summarizes those explicitly linked to active exploitation or to technical descriptions relevant to this vertical.
| CVE | Software | Exploitation | Source |
|---|---|---|---|
| CVE-2026-46817 | Oracle E-Business Suite, Oracle Payments File Transmission component | Actively exploited, HTTP access, unauthenticated according to the source | CISA, F5 Labs, The New Times Tech |
| CVE-2026-15409 | SonicWall SMA1000 | Active exploitation, included in KEV | F5 Labs, Quasa |
| CVE-2026-15410 | SonicWall SMA1000 | Active exploitation, included in KEV | F5 Labs, Quasa |
| CVE-2026-58644 | Microsoft SharePoint Server 2016 and Enterprise Server 2016 | Active exploitation, RCE according to the source | F5 Labs |
| CVE-2026-25089 | Fortinet FortiSandbox | Allows command execution through HTTP requests | F5 Labs |
| CVE-2026-39808 | Fortinet FortiSandbox | System command injection vulnerability | F5 Labs |
| CVE-2026-16812 | Arista VeloCloud Orchestrator | RCE through system command injection | HackerStorm |
| CVE-2025-68686 | Fortinet FortiOS | Added to KEV, active exploitation | HackerStorm |
| CVE-2026-48282 | Adobe ColdFusion | Path traversal, active exploitation, CVSS 10.0 | The Hacker News, RadioCSIRT, Elite Center |
| CVE-2026-55255 | Langflow | Active exploitation, included in KEV | The Hacker News, Threat-Modeling |
| CVE-2026-56290 | Joomlack Page Builder | Active exploitation, included in KEV | The Hacker News, Threat-Modeling |
| CVE-2026-48908 | JoomShaper SP Page Builder | Active exploitation, included in KEV | The Hacker News, Threat-Modeling |
| CVE-2026-56164 | SharePoint | Included in KEV | Device Security Lab |
| CVE-2026-32201 | SharePoint | Included in KEV | Device Security Lab |
| CVE-2026-45659 | SharePoint | Included in KEV | Device Security Lab |
The operational priority here should not be limited to cataloging each CVE, but to mapping where dependencies on those products exist. In this vertical, Oracle EBS may coexist with reconciliation, billing or order management; SharePoint can host sensitive internal portals; Fortinet and SonicWall usually appear at the perimeter and in remote access; Adobe ColdFusion and Joomla builders can support customer-facing applications or legacy integrations. The risk changes based on where the asset sits, but the pattern is the same: active exploitation and short remediation windows.
Regulation and Compliance
Brazil and access to Pix
O Globo's report on the possible restriction of access to Pix for banks and fintechs with weak cybersecurity is one of the month’s most important regulatory signals for the sector. The significance of the move lies in its logic: access to the payments rail would not be treated as an operational right, but as a capability conditioned on showing reasonable controls. That changes the market tone, because it shifts part of cybersecurity risk from the technical team to the core of the business.
For participants in the ecosystem, this means strengthening maturity testing, monitoring evidence, vulnerability management, and incident response capabilities. It could also speed up third-party audits and tighten contractual requirements among sponsoring banks, fintechs, PSPs and processors. If the regulator starts comparing risk profiles, control documentation stops being a formality and becomes part of business continuity.
Peru and incident notification
Peru was the clearest market on notification deadlines. Coverage from Infobae Perú, Brújula Digital and iupana agrees that financial institutions must inform users and, in some cases, the public, within very tight time windows. The 24-hour rule for reporting events that affect users, including cybersecurity incidents, forces faster initial triage, legal validation and coordination with customer support.
The impact on banks, fintechs and PSPs is significant. A notification that is poorly written, late or inconsistent can worsen reputational damage, but a rushed and misclassified communication also creates regulatory exposure. The only sustainable way to comply is to have preapproved criteria for severity, scope, minimum messaging, approvers and the point of contact with the regulator.
Compliance effects on the operating model
These regulatory measures do not operate in a vacuum. In a month when the material also reflected intense pressure from actively exploited vulnerabilities, the obligation to report quickly becomes an amplifier of internal demands. If an entity cannot quickly determine whether a degraded service is the result of a technical failure, a cybersecurity incident or a vendor issue, the regulatory clock still starts running.
For the fintech ecosystem, that means compliance and security are no longer parallel tracks. The team monitoring the stack, the team managing vendors, the team defining external communications and the team speaking with the regulator need a shared narrative from the first moment of the incident. July made that lesson clear.
Countries and most affected subsegments
Brazil
Brazil drew the clearest signal because of the mix of an operational incident, an attributed extortion threat, and a regulatory announcement about Pix. The Caixa lotteries case showed that an attack can disrupt collection and transaction services tied to the broader financial system, even when it is not described as a bank or a traditional fintech. That matters because Brazil's payments ecosystem is dense and depends on multiple actors sharing infrastructure, authentication, and integration channels.
At the same time, a possible restriction on Pix access for entities with weak cybersecurity introduces a new systemic risk criterion. For Brazilian fintechs, the potential requirement is not limited to patching faster. It also forces them to demonstrate governance, segmentation, identity management, remote access protection, and the ability to respond to third-party compromises without taking down the whole operation.
Section9's claim involving a Brazilian fintech reinforces the interest of malicious actors in the market. Even if unconfirmed, the existence of that claim suggests the country remains a high-value target for groups looking to monetize reputational pressure.
Peru
Peru was the country with the highest regulatory intensity. The combination of SBS Resolution 01741-2026, the 24-hour deadlines for reporting incidents, and the requirement to communicate outages or events to users in less than a day puts banks and fintechs under a higher standard of response. This is not only about cybersecurity in the narrow sense, but also operational discipline and communications capacity.
The digital financial services subsegment should read this as a forced maturity shift. An entity without incident traceability, a dependency inventory, and response playbooks loses time at the most expensive moment. For a PSP, the risk also extends to merchants and end users who feel the impact of channel outages or the need to invalidate transactions.
The SBS warning about digital fraud, although without a confirmed date, completes the picture. It suggests that identity spoofing and unauthorized transactions remain active threats. Combined with stricter notification obligations, the result is a market where incident handling can no longer be improvised.
Payments, acquiring, and gateways subsegment
Payment processors and gateways were indirectly affected in July through the claim involving a major credentialing firm in Brazil, the discussion of Oracle Payments File Transmission, and the nature of the systems affected in the Caixa case itself. This subsegment concentrates high-impact functions, because authorization, routing, and settlement decisions depend on internal components and third parties that do not always receive the same public exposure as a bank or a consumer app.
The risk logic for this group is especially sensitive to enterprise software vulnerabilities. A flaw in an administrative system, a support portal, or an integration platform may not look like an attack on the payments core, but it can provide entry to credentials, configuration, or transaction data. In July, that was one of the most consistent patterns in the material.
Consumer fintech subsegment
For consumer fintechs, the mix of regulation, fraud pressure, and exposure to public complaints creates a demanding environment. Although the period did not record fraud or phishing as a documented category in the dated facts, the SBS warning in Peru makes clear that identity spoofing remains a relevant abuse path. In addition, the fact that the month was dominated by vulnerabilities indicates that product security can no longer be limited to the mobile app or onboarding, but must cover the full chain of services and vendors.
Trends and signals to watch
There is no month-over-month baseline, because this is the first archived period with this indicator format for Latin America. For that reason, it would be wrong to invent a quantitative change versus June. The signal that can be read is internal to the month itself: a dominance of vulnerabilities, few unclassified incidents, one case centered on ransomware or extortion, and three regulatory moves. That profile suggests the technical attack surface remained more active than confirmed intrusion activity.
The first trend to watch is whether Peru's regulatory pressure turns into more public incident disclosure during August and September. If entities begin reporting quickly and consistently, the market will gain real visibility into the frequency of outages, attacks and third-party failures. If, instead, formal compliance lags, the first weeks could show legal noise without enough technical detail.
The second signal is Brazil. If the discussion around Pix moves from intent to an operational standard, the country could become a regional reference for how to tie access to critical rails to cybersecurity maturity. That could push banks and fintechs to speed up remediation, inventory and vendor governance programs. It could also open a tougher phase of third-party auditing for providers that are now plugged into payments without uniform controls.
The third signal is the persistence of active exploitation in widely used software. Oracle EBS, Fortinet, SonicWall, ColdFusion and SharePoint are not exotic names for security teams. They are broadly deployed platforms, often in areas not seen as part of the core payments stack. As long as that mismatch persists, the risk is that the first sign of compromise will show up in a support portal, an admin console or an integration component, not in the visible transaction layer.
The fourth signal is the gray market for actor claims. The two unconfirmed events involving Section9 and 1877 Team show that leak sites and manifestos continue to work as pressure tools, even when independent validation is weak or nonexistent. For a CISO, that means separating noise from evidence, but also recognizing that a public claim alone can trigger brand issues, customer support pressure and negotiations with partners.
Security team recommendations
First, review the real exposure to the products that dominated the month’s vulnerability agenda. It is not enough to know whether Oracle, Fortinet, SonicWall, SharePoint or Adobe are in the inventory. Teams need to know where they are, what privileges they have, what credentials they use, what interconnections they maintain, and what depends on them. In payments, a back-office application can be as critical as a production endpoint.
Second, speed up asset classification based on impact to payment continuity. If a system touches reconciliation, authorization, account provisioning, onboarding or dispute handling, its criticality should not be hidden in a generic matrix. Teams should have lists of essential services with owner, RTO, RPO and isolation criteria already defined. July showed that outages that look peripheral can end up affecting transactions and trust.
Third, rehearse the regulatory process before an incident happens. In Peru, the 24-hour windows require a coordinated response across security, legal, operations and customer service. That means communication templates, notification thresholds and a fast way to determine whether the event affects users or only internal infrastructure. In Brazil, if the logic of conditioning Pix moves forward, evidence of controls and remediation also needs to be ready for audit.
Fourth, strengthen third-party management and access segmentation. This month’s material suggests the payments value chain still has plenty of points where a technical failure or exposed credential can escalate. Remote access, administrative consoles, support providers and integration applications should all be under continuous review, with strong MFA, anomalous activity monitoring and privilege segregation.
Fifth, treat claims on leak sites as early signals, not as settled facts. They should not be ignored, but they also should not be turned into automatic confirmations. The useful process is rapid internal triage, evidence preservation, scope verification and controlled communication. In the financial vertical, overreaction can cause self-inflicted damage, but delay can too.
Sixth, prioritize remediation of actively exploited vulnerabilities over generic severity lists. July made clear that the value of an indicator is not only in CVSS, but in ongoing exploitation and how close the software sits to the business. A critical CVE in an administration platform with access to payments is more urgent in practice than a theoretical finding in an isolated system.
Material limitations
This report was built exclusively from the material provided for July 2026 and from the sources listed as available for citation. No internet was used and no external evidence was added. The indicator window is the one stated above, 66 dated facts in July 2026, plus 1 undated fact that was left out of the counts.
A zero value in an indicator, especially the one for documented fraud or phishing cases, means no fact classified that way appeared in the material analyzed this month. It does not mean there was no fraud, phishing, or identity abuse in the region. Likewise, the number of critical CVEs mentioned reflects only what was recorded in the provided corpus and does not rule out the existence of other vulnerabilities exploited in Latin America during the period.
Facts should also not be confused with telemetry. The material does not include aggregated figures for attempts, blocks, or scans, so this report does not use that type of data as a substitute for incidents. Mentions of CISA KEV, weekly vendor summaries, or technical reports were treated as signals of vulnerability and active exploitation, not as measured regional intrusion volume from sensors.
Sector coverage also has limits. Although the focus of this report is neobanks, FinTech, and payment processors, some facts affect the broader financial ecosystem, such as the Caixa case or the summaries on Oracle EBS and SharePoint. When interpreted, they should be read as value-chain risks for the vertical, not as evidence that all victims belong directly to a neobank or a PSP.
Finally, facts without a confirmed date were excluded from the indicators, even though some provide useful qualitative context, such as the Peruvian SBS warning about digital fraud. Also excluded from this report were sources not listed for citation, as well as consumer social media, sponsored content, and similar materials, which were not used to support analytical claims.
Graphics
Sources
- Ataque a lotéricas da Caixa desvia R$ 1 milhão e mantém serviços restritos há 5 diasDefender360
- Section9 Strikes Brazilian Fintech *****.com.br - DeXposeDeXpose
- ALERTA: Suposto Incidente Crítico no Setor de Meios de PagamentoMinuto da Segurança
- BC pode limitar acesso ao Pix de fintechs e bancos que tenham ...O Globo
- Perú refuerza sus normas de cibeseguridad: entidades tienen 24 horas para reportar incidentesBrújula Digital
- Un nuevo desafío para los CISO: comunicar incidentesiupana
- Bancos deberán informar a usuarios por ‘caídas’ e interrupciones en sus aplicativos en menos de un díaInfobae Perú
- Los hackers cambiaron de estrategia en Perú: archivos PDF y códigos QR fraudulentos podrían vaciar tus cuentas en segundosInfobae Perú
- Brazil's budget deficit nears pandemic-era levels as fiscal concerns lingerReuters
- Weekly CISA KEV Updates: 28 July 2026HackerStorm
- Boletín Semanal de Ciberseguridad, 25-31 de julioTelefónica Tech
- Weekly Threat Bulletin – July 22nd, 2026F5 Labs
- Vulnerability Summary for the Week of July 20, 2026CISA
- Panorama Económico Latinoamericano - Del 16 al 23 de julio de 2026Estrategia
- Security News Daily Report 2026-07-16|Device Security LabDevice Security Lab
- CISA marca falla crítica en Oracle E-Business Suite como ya explotada y fuerza plazo para federalThe New Times Tech
- CISA Adds Two Known Exploited Vulnerabilities to CatalogCISA
- CISA KEV Catalog Update July 14 2026: Four VulnerabilitiesQuasa
- War in Iran set to weigh on Latin America throughout 2026 ...IntelliNews
- CVE críticos julio 2026: ColdFusion, Ivanti y Fortinet | Elite Center BlogElite Center Blog
- La CEPAL advierte que Nicaragua y Honduras sufrirán el mayor deterioro comercial por el alza del petróleoInfobae
- Economía de América Latina, Venezuela, protección de mujeres ...Noticias ONU
- Resumen de noticias sobre ciberseguridad – 10 de julio de 2026Integrity360
- Vulnerability Intelligence Report — July 8, 2026Threat-Modeling
- Ep.690 - RadioCSIRT : Flash info cybersécurité du mercredi 8 juillet 2026YouTube
- 2026-07-08: CISA added four actively exploited flaws to the KEV catalog with Adobe ColdFusion attacks startingApple Podcasts
- CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV CatalogThe Hacker News
- Weekly CVE Report: 6 Exploited Bugs Hit CISA KEVSecurity Online
- Vulnerability Intelligence Report — July 5, 2026Threat-Modeling
- Resumen Macroeconómico Mensual de LATAM Julio 2026Deloitte
- Analysis - Julho/2026 - NumoNumo
- ¿Cómo se ve nuestra economía a mediados de 2026?La República
- Informe Económico Mensual | Julio 2026 - IAE Business SchoolIAE Business School
