CiberLATAMbywhalemate
Intelligence report

Neobanks, FinTechs, and PSPs, September 2026

September saw 59 verified incidents in LatAm, focused on fraud, active campaigns, and new regulation for neobanks

Oct 1, 202626 min read
Neobanks, FinTechs, and PSPs, September 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly Reference Modules

These modules are automatically completed with the verified dated facts within the period. Each one states its source basis and counting criterion so the figures reconcile across modules. They are the recurring month-to-month readout, while the analysis that follows develops the cases without repeating this summary.

Indicator window: 59 dated facts in September 2026. Facts from earlier months are used only as comparative context in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Monthly Verified Signal Dashboard September 2026 · Latin America Top threat: Unclassified (28 of 59 events). Coverage: 59 dated events in September 2026 VERIFIED EVENTS 59 period base: total count measured from below against this total RANSOMWARE / EXTORTION 4 4 undetermined classification with the material UNTYPED INCIDENTS 10 breaches or outages without declared threat type FRAUD / PHISHING 12 documented fraud campaigns documented REGULATION 4 standards, resolutions, or sanctions UNIQUE CVEs 0 none in the analyzed material (does not imply absence in the region)
Monthly Verified Signal Dashboard — Base: 59 verified dated events for Latin America.
MONTHLY FIXED MODULE Threat Axis Distribution September 2026 · Latin America Each event is counted in only one axis, so the total is exactly 59. "Unclassified incidents" is the remainder. Unclassified 28 Fraud 12 Incidents 10 Ransomware 4 Regulation 4 Vulnerabilities 1
Threat Axis Distribution — Each event is assigned to a single axis based on its classification; the total reconciles to the 59 events in the period.
FIXED MONTHLY MODULE Sector distribution of signal September 2026 · Latin America Base: 59 incidents in the period · total 88 because 25 incidents are classified in more than one sector. Finance 40 Public sector / OIV 11 Telecom 10 Retail / consumer 10 Other / no sector ident… 9 Technology 7 Energy 1
Sector distribution of signal — Heuristic sector classification by victim. One incident may affect more than one sector, so the total may exceed the base.
MONTHLY FIXED MODULE Geographic Distribution of Coverage September 2026 · Latin America Each fact is assigned to one country or to regional coverage, so the total is exactly 59 of 59 facts... Regional 43 Brazil 10 Paraguay 6
Geographic Distribution of Coverage — Verified facts from the period grouped by country or regional coverage; each fact is counted only once.

Executive monthly summary

September 2026 closed with 59 verified incidents in Latin America across the neobanks, fintechs, and payment processors axis, a picture dominated by unclassified activity, fraud, payment manipulation campaigns, and four regulatory moves. The month saw lower volume than August, but greater operational pressure in Brazil, Mexico, Paraguay, Argentina, and Colombia, with a clear impact on instant payments, transaction fraud, and compliance.

The most visible signal was BREEZE COMET, the actor Google Threat Intelligence Group and Mandiant describe as financially motivated and focused on manipulating payment systems and banking software in Brazil to carry out fraudulent transfers. The campaign is not framed as classic ransomware. Its logic is different, because it prioritizes abuse of legitimate access, credential theft, remote tools, and transaction execution through valid channels, with Pix, STR, and Boleto as the area of interest.

The month’s second main focus was the set of incidents and alerts around BRBJUS, in Bahia. The available material shows an attack that affected services linked to the judicial system operated with the Banco Regional de Brasília, with partial disruption, gradual restoration, and an investigation still open. The court stressed that the compromised environment was external, owned and managed exclusively by BRB, which narrows the attribution of internal technical failures but does not eliminate operational exposure for the service.

At the same time, Revolut returned to the regional spotlight because of a leak that affected about 680 customers, with fraudulent requests made from a legitimate domain belonging to a government agency. The available coverage points to exposure of personal data, passports, emails, phone numbers, and financial information, but does not describe any impact on core infrastructure or accounts. There were also unconfirmed claims about a US$3 million ransom demand, which the material itself treats as a reconstruction by the attacker or the press, not as fully independent validation.

The rest of the month combined large-scale digital fraud in Mexico, spoofing alerts tied to QR Code Pix in Brazil, parliamentary requests for information on cyber fraud in Paraguay, and new rules for fraud risk management in Argentina. The risk picture is high, not because of a single encryption outbreak or one major breach, but because of the convergence of payment channel abuse, social engineering, credential abuse, and regulatory pressure on financial entities and PSPs.

Regional outlook for the month

September’s regional signal was one of high risk for the segment because the material combines active campaigns, incidents with operational impact, and a regulatory agenda that no longer treats fraud as a peripheral issue. The month’s dominant threat was classified as unclassified, with 28 of 59 events, which in this case does not indicate the absence of a pattern but rather a spread of typologies and partial descriptions in the sources.

Brazil concentrated the most technical narrative, and the one most sensitive for PSPs and digital banks. The BRBJUS case, warnings about QR Code Pix fraud, and the BREEZE COMET campaign all appeared there, and that campaign targets organizations authorized to operate with banking software, APIs, and systems such as Pix, STR, and Boleto. That combination shows that the real risk perimeter is not only the bank or the fintech, but also the flows, integrations, and payment scheme administrators.

Mexico offered two distinct but complementary readings. On one hand, the country remains a strong target for digital fraud, with 6.3 million complaints reported by Milenio and alerts about fake apps and malware issued by ABM and Condusef. On the other hand, SCILabs data cited by La Jornada place Mexico as a major ransomware focus in the region, with an impact that also reaches financial services. This does not mean all fraud turns into ransomware, but that extortion, intrusion, and deception coexist, putting pressure on entities with uneven levels of maturity.

Paraguay showed a more institutional than technical risk. The Senate asked the BCP for reports on disciplinary processes and investigations related to cyber fraud complaints against Banco Itaú Paraguay, and that sequence reflected regulatory and political concern over controls, audits, and corrective measures. The material does not independently confirm a concrete technical incident against Itaú, but it does point to growing scrutiny of the system’s response capacity.

Argentina added a compliance front with BCRA Communication A 8471 and regulatory approval for Revolut’s entry. Colombia, meanwhile, moved ahead with its open finance roadmap and the standardization of information exchange. Taken together, the month points to medium-to-high risk by volume and severity, with a clear tension between digital expansion, controls still in development, and attackers exploiting the weakest point, operational trust in legitimate transactions.

Period indicators

Indicator September 2026 Previous month Change
Verified facts for the period, the basis for all indicators 59 83 -24
Time window for the indicators 59 facts dated September 2026 83 facts dated August 2026 N/A
Unclassified incidents, breaches, or outages 10 19 -9
Cases with ransomware or extortion as the primary focus 4 2 +2
Ransomware breakdown by impact type, classification not determinable from the material 4 2 +2
Documented fraud or phishing cases 12 25 -13
Documented regulatory moves 4 4 unchanged
Critical CVEs mentioned 0, none in the material analyzed, this does not imply absence in the region no comparable data N/A
Sectors with at least one documented fact 6 7 -1
Predominant threat of the month Unclassified, 28 of 59 facts Fraud, 25 of 83 facts pattern shift
Facts with direct source confirmation 85%

The basis for these indicators is exactly the September 2026 window, with 59 facts dated within the period. The comparison data correspond to the previous month and are included only as analytical reference, not as part of the volume for the month under review.

TIMELINE Verified events from the period 1/9 A threatactoridentifiedas 1/9 Google ThreatIntelligenceGroup 1/9 Valor Econômicoreported that 1/9 According toGTIG andMandiant, 1/9 An analysistechnical independent 1/9CommunicationA 8471
Timeline of verified events, September 2026 — Milestones with confirmed dates within September 2026. Events from earlier months are excluded from the timeline and used only as a comparative reference.

Relevant incidents

BREEZE COMET and payment manipulation in Brazil

The BREEZE COMET campaign was the month’s most technically significant event for banks, fintechs, and PSPs because it centered not on encryption, but on abusing trust in payment systems themselves. Google Threat Intelligence Group and Mandiant described the actor as financially motivated, focused on Brazil, with targets including banks, payment processors, fintechs, and banking software providers.

The operating pattern is clear. Sources point to password spraying, vishing, and impersonation of support staff to induce victims to install remote administration tools such as AnyDesk, after which the actor reportedly used privileged access to operate within core financial applications. Hive Security emphasized that the logic was payment system manipulation, not the direct theft of card numbers, and that the operational risk rested on legitimate accounts and validly signed payment commands.

The interest in Pix, STR, and Boleto is not minor. In practice, that puts scheme administrators, PSPs, integrators, and platforms that sustain the instant payments cycle in the crosshairs. Prodist and GBHackers added that the group may also have persisted through backdoors and multiple waves of fraudulent transactions, although part of those figures was presented as third-party reconstruction, not as an independently confirmed metric from a single primary source.

The operational takeaway is that the risk is not limited to endpoint malware. The attack aims at the point where a privileged user can submit legitimate transfers into compromised infrastructure. For a CISO in the region, that means reviewing identity controls, remote support validation, segregation of duties, and monitoring for abnormal activity in the transaction core.

BRBJUS, fund diversion, and partial restoration in Bahia

The incident associated with BRBJUS showed how a judicial-use platform can become a pressure point for a financial institution providing technology infrastructure. Convergência Digital reported that the attack affected services linked to the system operated with the Banco Regional de Brasília and that some functions had been partially restored while BRBJUS payment orders remained unavailable.

The sequence that followed was significant. The TJBA announced full restoration of the service and noted that the incident was still under investigation, with administrative proceedings underway to clarify what happened and assess possible contractual measures. In another statement, the court said the incident occurred entirely in an external technology environment, owned and exclusively administered by BRB, and that no issues were identified in its own systems.

Press coverage, meanwhile, spoke of diversion of judicial deposit funds. AloAlô Bahia said BRB was investigating how the attack occurred and that there would be no financial harm to courts, judicial accounts, or beneficiaries. Correio Braziliense went further and attributed a diversion of R$43 million, although that figure does not appear to be confirmed with the same level of support by BRB or TJBA, so it should be treated cautiously.

This case leaves two lessons. The first is that outsourcing does not eliminate operational responsibility for the service. The second is that critical flows, even when they belong to an external environment, can affect public perception, judicial timelines, and contractual relationships. For the PSP segment, that reinforces the need for continuity clauses, transaction monitoring, and regularly tested rollback or contingency scenarios.

Revolut and the exposure of high-profile data

Revolut occupied a different part of the map, closer to data exposure and extortion than to disruption. Reuters reported that around 680 customers may have been affected and that the core infrastructure, databases, and customer accounts would not have been breached. The company described the entry point as the disclosure of sensitive information after fraudulent requests sent from a legitimate government agency domain.

SecurityWeek detailed that potentially compromised information included personal data, passports, email addresses, phone numbers, and financial information. That combination raises the potential impact of identity theft, follow-on fraud, and the use of the data in secondary campaigns. Arkham Intelligence added that the attacker may have used blockchain analysis to identify targets and that complete KYC data had been requested for 680 holders, although that part is presented as the researcher’s reconstruction and as a claim linked to the attacker, not as full independent confirmation.

Claims about a US$3 million ransom also circulated. Investidor10 reported that version, but the company itself said it had not received direct contact or requests from those groups. The case should therefore be read with a strict distinction between the confirmed exposure, the not necessarily validated ransom demand, and the absence of evidence that funds or core infrastructure were affected.

The relevance for the region is significant. Revolut received approval from the Central Bank of the Argentine Republic in September, so the episode serves as an early reference point for the risks of expansion in markets where customer trust, KYC, and verification of sensitive requests are critical components.

QR Pix fraud and payment redirection in Brazil

Procon-SP alerts about QR Code Pix point to a simpler fraud, but one that is highly effective in practice. The agency warned that certain payments in online stores could be redirected to recipients other than the real merchant when the QR code on the payment page was altered. It then recommended notifying the bank or payment institution immediately and requesting reimbursement through MED 2.0 when applicable.

Coverage from Correio da Manhã, Procon-SP’s official communication, and a Viva report all aligned on the main point, the problem is not a flaw in Pix itself, but the manipulation of the payment identifier shown to the consumer. That shifts the defensive burden to e-commerce, gateways, and end users, especially in environments where beneficiary validation is not sufficiently visible in the payment experience.

This kind of fraud has a different operational impact from BREEZE COMET. There is not necessarily prolonged privileged access or a persistent actor inside the network. What exists is a manipulation of trust in the payment interface. The damage to PSPs and merchants can show up in disputes, refunds, complaints, and reputational loss, as well as added pressure on mechanisms such as MED 2.0.

Cyber fraud and parliamentary scrutiny in Paraguay

Paraguay did not record a confirmed technical incident against a specific bank, but it did register a regulatory and political signal of scrutiny over cyber fraud. The Chamber of Senators approved a resolution requesting information from the Central Bank of Paraguay on disciplinary processes, investigations, and possible corrective measures linked to fraud complaints against Banco Itaú Paraguay.

The important point is the precision of the coverage. La Nación Paraguay detailed that the request included cybersecurity controls, audits, and technical inspections carried out during 2025 and 2026. ABC Color and 5Días placed the discussion in the context of heightened attention on the financial system, with several institutions covered by the information request. RDN also clarified that it did not provide figures on victims, losses, or technical scope.

That places Paraguay in a zone of scrutiny where the main risk for institutions is not only the materialization of an incident, but also the ability to document controls and respond to the regulator and the legislature. For banks and fintechs, compliance risk mixes with reputational risk, especially when user complaints are tied to cyber fraud.

Banking malware and digital fraud in Mexico

Mexico contributed two layers of exposure. World Cyber News reported the Casbaneiro banking trojan campaign against financial institutions and users in Argentina, Peru, Colombia, and Mexico. The infection started with emails carrying PDFs and used lures such as unpaid invoices or court procedures, with the ability to collect Outlook data and display fake bank-specific windows to capture credentials.

At the same time, Brújula Digital reported stronger alerts from ABM and Condusef regarding fake apps and malware capable of intercepting verification codes or taking control of the phone. That combination is critical because it blends social engineering with persistence on the device, a vector that often ends in account takeover and unauthorized transfers. Milenio also reported 6.3 million complaints of digital fraud, providing scale context for the pressure on the system.

The convergence of those signals leaves Mexico as a market where access fraud, phishing, and mobile malware intersect with a large user base. For fintechs and PSPs, that means attention cannot remain only on the corporate account or the back office. Controls also need to be strengthened around onboarding, authentication, device changes, and recipient validation.

Active threats and campaigns

Ransomware and extortion

September saw four cases in which ransomware or extortion was the primary focus, but the material does not allow a precise classification of the impact in any of them, so the source does not specify whether assets were encrypted. The key point here is not just volume, but the technical ambiguity of the sources and the difficulty of separating encryption, exfiltration, or simple claim-making.

One of the most cited references was SCILabs' report on ransomware in LATAM during the first half of 2026. La Jornada said the report recorded at least 290 formal attacks in the region and approximately 52 Mexican companies and entities targeted, with financial services among the affected sectors. That does not belong to September's operational volume, but it does help explain the context in which the month's alerts moved.

In the Revolut case, the mention of a US$3 million ransom appears in press coverage and third-party reconstructions, but the material does not establish an independent confirmation of encryption or completed extortion. For this report, the useful classification remains a leak with possible associated extortion pressure, not confirmed ransomware.

Fraud and phishing

Fraud was the category most covered by the sources this month, although not the largest by volume. The evidence ranges from BREEZE COMET and its fraudulent transfer activity to phishing campaigns, malware, and payment impersonation in Mexico and Brazil. The common pattern is that the attacker does not need to destroy systems to extract value.

What changes is how access is turned into money. In Brazil, the target was payment channels and the manipulation of legitimate transactions. In Mexico, impersonation and fake apps seek credentials, codes, and device control. In Paraguay, cyberfraud appears as a matter of institutional oversight and review. These are different expressions of the same pressure on operational trust.

The reading for PSPs and fintechs is simple in theory and hard in execution. If fraud can happen inside a legitimate flow, defense cannot rely only on perimeter controls. It requires visibility into every device change, every support request, every session token, and every transfer that falls outside the customer's historical profile.

APT, intrusion, and credential abuse

Although the material does not describe a classic APT against neobanks or PSPs, it does show persistent intrusion and credential abuse as an attack pattern. BREEZE COMET built backdoors, used privileged access, and operated on banking software. Casbaneiro, on another scale, combines email, lures, and fake windows to reach credentials and active sessions.

The difference from a ransomware incident matters. Here the goal is not to block operations and demand payment, but to infiltrate, persist, and monetize. That makes segmentation, anomaly detection, human validation of sensitive changes, and hardened remote support the most valuable defenses.

Critical vulnerabilities

No critical CVEs were recorded in the September 2026 material reviewed. That does not mean critical vulnerabilities exploited in the region were absent, only that none were verifiably mentioned in the sources for this period.

CVE Software Exploitation Source
Not recorded in the material reviewed N/A N/A Material from the period

Regulation and compliance

September brought a clear regulatory shift in Argentina, Colombia, and Brazil, with direct implications for banks, fintechs, and PSPs. The biggest signal was that fraud risk management is no longer treated as an optional best practice, but as a structural requirement of the compliance architecture.

In Argentina, BCRA Communication A 8471 set the first stage of the operational risk management and fraud prevention framework between September 1 and December 31, 2026. The Official Gazette said entities must define structure, policies, owners, risk appetite, and risk tolerance, as well as identify risks tied to products, services, processes, and digital channels. For certain PSPs, the timeline extends gradually through September 2027.

That same ecosystem expanded with the implementation schedule for administrators of instant transfer schemes and for financial institutions and PSPs that offer payment accounts. Operationally, the regulation now begins to require measurable governance over fraud, not just retrospective reporting. Revolut’s case, after receiving approval from the Central Bank of the Argentine Republic, also shows that market expansion now comes with regulatory and operational requirements before launch.

Brazil also strengthened the compliance layer, although through fraud response. Procon-SP instructed consumers to seek a response and reimbursement through MED 2.0 when they detect fraudulent Pix transfers or altered QR codes. This is not a hard regulatory change, but it is a clear message about the responsibilities of banks, payment institutions, and merchants in complaint handling.

In Colombia, the Financial Superintendency advanced a roadmap for open finance, supported by seven technical working groups and the participation of more than 157 entities. The focus is on publishing a schedule to issue information exchange standards and gradually implement the scheme under Decree 0368 of 2026. For fintechs and PSPs, that means more interoperability, but also more pressure on APIs, data governance, and authentication controls.

Paraguay showed a different signal, one centered on supervision and accountability. The Senate’s request to the BCP regarding cyber fraud and information security controls reinforces the message that entities must be able to explain not only what happened, but how they audit, correct, and document their findings.

Countries and most affected subsegments

Brazil

Brazil had the month’s strongest signal, both in volume and severity. The BREEZE COMET campaign, the BRBJUS incident, Procon-SP’s warning about QR Code Pix, and the technical debate on fraud prevention in instant payments all converged there. There were also signs of persistence, backdoors, and privileged-access abuse, making this market a reference point for the rest of the region.

The key issue in Brazil is that risk cuts across banks, PSPs, banking software, and payment infrastructure administrators. This is not a single perimeter. What keeps recurring is the possibility of turning initial access into a valid transaction, which forces a review of support, monitoring, and out-of-band validation.

Mexico

Mexico remained a high-volume front for digital fraud, phishing, and banking malware. Milenio’s report on 6.3 million claims provides a sense of scale, while coverage of Casbaneiro and alerts from ABM and Condusef show that credential abuse remains highly active.

There is also a sector-specific reading. The incidents are not limited to banks, but extend to end users, mobile devices, and customer service channels. That is pushing fintechs and PSPs to strengthen authentication controls, transactional anti-fraud measures, support-simulation detection, and customer education with an operational focus, not just a communications one.

Paraguay

Paraguay stood out for supervision and for exposure to cyber fraud as a public agenda issue. Parliamentary scrutiny of Itaú Paraguay and the BCP does not amount to a confirmed incident, but it does show growing pressure on traceability, audits, and controls.

For the banking subsegment, this matters because regulatory risk grows when user complaints reach the political sphere. Entities that cannot explain their investigation, escalation, and remediation processes will face a reputational cost greater than the purely technical one.

Argentina

Argentina combined regulation and market expansion. Communication A 8471 sets concrete obligations for the first stage of the operational risk and fraud framework, while Revolut obtained approval from the Central Bank to prepare a future launch.

The case matters for neobanks and PSPs because market entry is no longer measured only by product or commercial traction. It also depends on proving minimum controls, risk functions, governance, and the ability to meet phased regulatory timelines.

Colombia

Colombia showed more of a structural transformation than a single incident. The open finance roadmap and technical work with more than 157 entities point to a more interconnected ecosystem, with information-sharing standards and greater reliance on APIs.

That brings opportunities, but also a broader attack surface for fraud, credential abuse, and integration failures. For fintechs, the message is that interoperability only works if data security and authentication are built in from the start.

PSPs, fintechs, and banking software

In the PSP and banking software subsegment, the month’s material points to a very clear pattern. Attackers are not necessarily trying to break encryption or exploit notable CVEs. They are looking for access, operational context, and the ability to sign or divert transactions through legitimate channels.

That behavior increases exposure for payment gateway providers, integrators, banking software developers, and payment scheme administrators. If an actor compromises that layer, the impact spreads beyond a single institution and can affect several clients at the same time, even if the initial event occurs in just one environment.

Compared with August, September showed fewer total incidents, fewer unclassified incidents, and fewer fraud or phishing cases, but not a real reduction in risk. What changed was the shape of the signal. September brought less quantitative noise and clearer evidence of certain high-value vectors, especially payment manipulation, privileged access abuse, and regulatory compliance.

The first trend to watch is the consolidation of attacks that use legitimate payment systems as a monetization channel. BREEZE COMET captures that shift well. If an attacker can operate from privileged accounts and present valid transactions, the problem is no longer purely about malware. It becomes a governance issue tied to access, behavioral monitoring, and segregation of duties.

The second signal is the growth of transactional fraud through consumer-facing interfaces. QR Pix fraud in Brazil and fake apps in Mexico show that the end user remains the weakest point when recipient or device validation is not locked down. That requires more visibility into session risk, device binding, and stronger confirmation steps.

The third trend is regulatory. Argentina, Colombia, and Brazil are moving in different directions, but with the same underlying theme, more accountability for fraud, interoperability, and controls. For risk and compliance teams, the month shows that the ability to report, document, and remediate will matter as much as the ability to prevent.

Monthly ComparisonBase: verified facts from the period, not aggregated telemetry.598310191225FactsPrevious MonthIncidentsPrevious monthFraudPrevious monthSeptemberPrevious month
Verified Signal Comparison — Comparison between September 2026 and the previous month, based on the indicators provided.

Security recommendations for teams

Security teams at neobanks, fintechs, and PSPs should prioritize four areas this week. First, review any workflow that allows remote support, elevated privileges, or administrative access to payment consoles. Second, tighten validation for high-risk transfers with out-of-band controls and behavioral analysis. Third, audit the integrity of QR codes, payment links, and e-commerce redirects. Fourth, align risk and documentary evidence with the new regulatory pace.

In environments with Pix, STR, Boleto, or equivalent schemes, it makes sense to deploy alerts for recipient changes, privileged account use outside business hours, unusual rule creation, and burst transactions. The BREEZE COMET logic shows that an actor can move from access to monetization very quickly, so detection has to happen before clearing or settlement.

For mobile fraud and account takeover, the most useful control is often the least glamorous. Phishing-resistant authentication, device attestation, strict session management, emulator detection, and reauthentication logic for sensitive changes. Asking users for a strong password is not enough if the flow later allows transfers with weak identity signals.

On the vendor side, the focus should be on third parties with the ability to touch payments, KYC, or support. If a provider concentrates critical functions, it should be subject to response tests, access revocation tests, and contingency exercises. The BRBJUS case shows that a service can fail in an external environment and still drag down the operation, reputation, and continuity of the entity using it.

Finally, compliance teams should map Argentina and Colombia's timelines now, along with Brazil's operational alerts. The question is not only whether the control exists, but whether it can be demonstrated with evidence, owners, and deadlines. September made clear that regulators and the market already expect that capability.

Frequently Asked Questions

Which country concentrated the most sensitive signal for PSP and digital banking this month?

Brazil concentrated the most sensitive signal because it combined an active campaign against payments, an incident in BRBJUS, and fraud alerts tied to Pix. That mix brings operation, continuity, and fraud into the same market. The full reading is in the Relevant incidents, Active threats and campaigns, and Most affected countries and subsegments sections.

Was ransomware confirmed against neobanks or payment processors?

The September material does not show confirmed ransomware against neobanks or PSPs, although it does show four cases with a primary ransomware or extortion focus. In those cases, the source does not specify whether there was asset encryption, exfiltration without encryption, or only a mention on a leak site. See the Period indicators and Active threats and campaigns sections.

The link is operational, not just reputational. The QR Code Pix alerts and the BREEZE COMET campaign show that fraud can happen at the payment interface or inside privileged accounts, without needing to break an entire system. The overlap is covered in Relevant incidents, Brazil, and Security team recommendations.

What changes for fintechs with regulation in Argentina and Colombia?

The bar is raised for governance and interoperability. In Argentina, the BCRA has already set the first stage of the operational risk and fraud prevention framework. In Colombia, the Superfinanciera is advancing standards for information exchange and open finance. The details are in Regulation and compliance and Trends and signals to watch.

What should a compliance team look at after complaints such as those in Paraguay?

It should look at traceability, internal investigations, corrective measures, and response capacity before the regulator. In Paraguay, the Senate asked the BCP for information on disciplinary proceedings and complaints of cyber fraud against Itaú Paraguay, although no specific technical incident was confirmed. That overlap appears in Relevant incidents, Regulation and compliance, and Most affected countries and subsegments.

Material limitations

This report was prepared exclusively from the material provided for September 2026, with no internet access and without adding aggregated telemetry or sources outside the authorized list. The time window for the indicators is strict, 59 dated facts in September 2026, and no facts from other months were included in the main count.

A zero indicator, especially for critical CVEs, means no critical CVEs were recorded in the material analyzed for this period. It does not mean there were no critical vulnerabilities exploited in the region, only that there was no verifiable mention in the sources received.

The threat breakdown and incident counts reflect the classification supported by the material, not a full forensic audit. In several cases, the source does not specify whether there was encryption, exfiltration, or only a claim of responsibility, so the ransomware and extortion taxonomy should be read with that limit in mind.

Also excluded from the valid evidence were sources not included in the allowed citation list, consumer social media posts, and sponsored or commercial content when that was the only basis for a claim. When there were partially attributed versions, they were kept as such and not treated as full independent confirmations.

Sources