CiberLATAMbywhalemate
Intelligence report

Latin America Regulation and Compliance, Aug 2026

August closed with 492 regulatory actions, 905 verified events, and a surge in enforcement on data, payments, and digital childhood.

Sep 1, 202626 min read
Latin America Regulation and Compliance, Aug 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are completed automatically with verified dated facts from within the period. Each one states its basis and counting criterion so the figures reconcile across modules. They are the recurring month-to-month readout, and the analysis that follows develops the cases without repeating this summary.

Indicator window: 905 dated facts in August 2026 · 58 from earlier months (comparative frame, not monthly volume) · 27 without confirmed date (excluded from the indicators) · 10 after the period (excluded). Facts from earlier months are used only as a comparative frame in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Verified Signal Monthly Dashboard August 2026 · Latin America Primary threat: Regulation (492 of 905 events). Coverage: 905 dated events in August 2026 · 58 out of months an… VERIFIED EVENTS 905 period base: all counts measured from the bottom is based on this total RANSOMWARE / EXTORTION 0 no classification available UNCLASSIFIED INCIDENTS 28 breaches or outages without declared threat type FRAUD / PHISHING 64 documented fraud campaigns REGULATION 492 rules, resolutions, or sanctions UNIQUE CVEs 0 none in the material analyzed (does not imply absence in the region)
Verified Signal Monthly Dashboard — Base: 905 verified events dated within the period for Latin America.
MONTHLY FIXED MODULE Threat axis distribution August 2026 · Latin America Each event counts in only one axis, so the total is exactly 905. "Unclassified incidents" is the remainder. Regulation 492 Unclassified 315 Fraud 64 Incidents 28 Vulnerabilities 6
Threat axis distribution — Each event is assigned to a single axis based on its classification; the total reconciles with the 905 events in the period.
FIXED MONTHLY MODULE Sectoral Distribution of Signals August 2026 · Latin America Base: 905 incidents in the period · total 1142 because 194 incidents are classified in more than one sector. Other / no sector ident… 339 Public sector / OIV 316 Financial services 244 Telecom 107 Technology 52 Retail / Consumer 48 Education 25 Healthcare 11
Sectoral Distribution of Signals — Heuristic classification by victim sector. One incident may involve more than one sector, so totals may exceed the base.
MONTHLY FIXED MODULE Geographic Distribution of Coverage August 2026 · Latin America Each event is assigned to a single country or to regional coverage, so the total is exactly 905 out of 905 events … Argentina 474 Brazil 337 Chile 61 Bolivia 33
Geographic Distribution of Coverage — Verified events for the period grouped by country or regional coverage; each event is counted once.

Executive monthly summary

August 2026 in Latin America was shaped by regulation and compliance, with 905 verified events during the period and 492 regulatory developments recorded as the main threat category. The month combined new public consultations, legislative initiatives, major sanctions and operational changes in payments, data protection and financial supervision, with Brazil, Mexico, Chile, Argentina and Paraguay standing out as the main focal points.

The strongest signal came from enforcement. In Brazil, ANPD fined ByteDance over the processing of children’s and adolescents’ data on TikTok, and the decision also imposed specific orders to delete data, strengthen privacy controls and regularize representation for teenage accounts. The coverage also points to a more active ANPD with a broader agenda, including multiple ongoing cases against major platforms and a more defined use of its powers as a regulatory agency.

In Mexico, the month was defined by a regulatory agenda covering payments and financial supervision. Banxico opened public consultations on rules for payment clearinghouses for card transactions and on payment network schemes, while specialized media reported cybersecurity, corporate governance, continuity and incident-notification requirements for fintech and regulated entities. That was accompanied by political progress on a federal cybersecurity law that, as of August 2026, still has not been approved.

Chile showed a clear contrast between regulatory progress and the risk of delay. The future Personal Data Protection Agency remains scheduled for December 1, 2026, but the executive branch is considering postponing full enforcement of the new law by one year. That debate is unfolding alongside the legislative process for bills on digital childhood and deepfakes, reinforcing a regional pattern, data protection and child digital safety agendas are moving forward, but under heavy strain from state capacity, institutional setup and implementation deadlines.

Argentina added a more fragmented but highly active front. The BCRA kept moving financial system rules, this time with the Cobro con Transferencia mechanism for loans, plus updates tied to payments, payroll accounts and formal administrative channels. At the same time, several provinces and subnational jurisdictions pushed bills on cybersecurity, digital violence and artificial intelligence. The combination points to regulation that is becoming more granular, less uniform and more demanding for legal, compliance and operational risk teams.

Regional overview for the month

August’s regional readout is high-risk for compliance, not because of a wave of traditional critical incidents, but because of the density of regulation, enforcement, and penalties. Most of the month’s developments centered on rules, draft measures, consultations, and resolutions that change concrete obligations for banks, fintechs, platforms, public agencies, and data controllers. The pressure did not come from a single jurisdiction, but from several at once.

Three patterns defined the month. First, data protection stopped being an abstract debate and became operational, with notification deadlines, incident logs, duties to appoint accountable parties, privacy-by-default changes, and transparency rules. Second, financial cybersecurity is being folded into prudential and anti-fraud compliance, especially in Mexico and Argentina. Third, digital childhood protection and synthetic content became a policy track of their own, with legislative progress in Chile and new regulatory pressure on platforms in Brazil.

The risk is high because the regulatory response is no longer aimed only at punishing after the harm, but at imposing a control architecture beforehand. That shows up in reporting requirements, appointment duties, audits, simplified transparency, interoperability, business continuity, and supervisory capacity. For security and compliance teams, August confirms that digital compliance in the region is moving toward a model built on evidence, traceability, and permanent governance.

TIMELINE Verified events in the period 4/8 Othercoverageindicatedthat 4/8 Covers secondaryreported that 4/8 The Bill ProjectLaw 4/8 During thehearing on 4/8 At the publichearing on 5/8 Infobaereportedthat the
Verified events timeline, August 2026 — Milestones with confirmed dates within August 2026. Events from earlier months are left out of the timeline and used only as context.

Period indicators

Indicator August 2026 Previous month Change
Verified events in the period 905 531 +374
Indicator time window 905 events dated August 2026 58 events from earlier months (comparative frame, not monthly volume) 27 without confirmed date excluded, 10 after the period excluded
Unclassified incidents (breaches or outages) 28 17 +11
Cases with ransomware or extortion as the primary focus 0 6 -6
Documented fraud or phishing cases 64 39 +25
Documented regulatory moves 492 314 +178
Critical CVEs mentioned 0, none in the material analyzed (does not imply absence in the region) no comparable data for the previous month n/a
Sectors with at least one documented event 8 8 unchanged
Predominant threat of the month Regulation (492 of 905 events) Regulation (314 of 531 events) unchanged
Verified events with direct source confirmation 98% n/a n/a

The baseline for all indicators is 905 verified events in the period. The time window includes 905 events dated August 2026, 58 events from earlier months for comparison only, 27 without confirmed dates excluded from the indicators, and 10 after the period also excluded.

Category Detail
Geographic scope Latin America
Subject scope Cybersecurity and data protection regulation and compliance
Period August 2026
Base source Verified facts from the provided material

Relevant incidents

The month did not show a ransomware wave as its main thread, but it did produce several compliance and security cases with regulatory impact, especially around platforms, payments, and personal data. The most visible incidents were not centered on asset encryption, but on enforcement actions, remediation obligations, and oversight processes for digital and financial operators.

ANPD and TikTok in Brazil

The ANPD decision against ByteDance was the month’s strongest case at the intersection of regulation and enforcement. The authority fined the company for violations tied to the data of children and adolescents, and also ordered the deletion of data obtained irregularly, changes to privacy settings, and regularization requirements for the legal representation of teenage accounts. The press also reported specific deadlines for appeal and remediation.

For compliance, the key point is not only the amount, but the shape of the sanction. The ANPD imposed targeted, traceable corrective measures aimed at verifiable compliance, which reinforces the expectation of internal documentation, evidence of remediation, and sustained controls over products aimed at minors. The doctrinal reading cited in the material also underscores the expanded role of the encarregado as the formal guarantor of compliance.

Banxico, clearing houses, and payment networks

In Mexico, Banxico opened a public consultation on rules for card payment clearing houses and on payment instrument networks. Although this is not an incident in the strict sense, it is a high-impact operational event for payments infrastructure, because it anticipates requirements for organization, operation, interoperability, and operational security. The consultation points clearly toward a more formalized system.

The relevance for risk teams lies in the combination of costs, operational friction, and controls. The material says the project seeks to reduce friction and costs, while also strengthening interoperability and the secure operating framework. For entities that process payments, that means reviewing technology dependence, continuity, transaction traceability, and auditability.

Cobro con Transferencia in Argentina

The BCRA’s Cobro con Transferencia mechanism took effect on August 31 and enables automatic debits of installments from any bank account held by the user, under specific conditions for prior notice, a cap on attempts, and explicit authorization. The direct impact is not cyber in the classic sense, but it is significant for compliance, fraud, and operations. The regime forces banks, wallets, and lenders to adjust flows, consent, and responsibilities.

The key point is that the control burden shifts to the lender. The press coverage even indicates that liability in the event of fraud would fall directly on that entity. From a governance standpoint, that requires reviewing origination, delinquency management, customer notification, reversals, and evidence of consent. If processes and systems do not align, the risk will not be only financial, but also regulatory.

Brazil and the expansion of oversight over large platforms

This month’s material shows at least ten ongoing ANPD supervisory processes against large platforms, focused on possible violations of the LGPD, protection of children and adolescents, and the fight against illegal content. Not all of those cases are closed, but the signal is consistent, the authority has expanded its oversight perimeter and is doing so with criteria that reach not only sanctions, but also preventive duties and transparency.

For regional compliance, the case matters because it sends a spillover signal. Companies with cross-border operations can no longer treat regulation affecting minors and data as an isolated local issue. Brazil’s pressure, because of its market size and sanctioning power, tends to set de facto standards for regional platforms and providers.

Chile and the debate over delaying the data law

The Chilean debate over the new Personal Data Protection Law is not an incident, but it is a regulatory event with very concrete operational consequences. The August 31 source warns about the Executive’s intention to delay full entry into force of the law by one year, on the grounds of finishing the launch of the Agency and its regulations. The legal sector, for its part, is asking that any delay, if it happens, does not become a habit.

That leaves companies in an awkward position. They have to prepare for a law that still lies ahead, even if the effective date could be pushed back. The risk is not abstract uncertainty, but that internal adaptation projects get delayed because of an overly complacent reading of the postponement.

Verified events by category, August 2026RegulationIncidentsFraudSectors49228648

Regulatory Pressure by Category — Comparison between regulatory prominence and the rest of the month’s signals, based on verified events during the period.

Active Threats and Campaigns

There were no ransomware or extortion cases that could be classified as the primary focus during the period, a meaningful shift from the previous month. The month's pressure shifted toward fraud, phishing, oversight, and regulatory enforcement. In other words, the main strain on organizations was not system disruption, but the need to prove compliance and reduce operational exposure.

Fraud and phishing

The documented fraud or phishing category reached 64 verified incidents in August, up from July. The available material does not describe a single homogeneous regional campaign, but it does show several recurring vectors: virtual scams using the identity of financial authorities, anti-fraud adjustments in payments, measures to track diverted money, and new rules on responding to attacks on the financial system.

In Argentina, the previous month's material and the current one intersect with the new Cobro con Transferencia scheme and alerts about liability in fraud cases. In Mexico, risk-based supervision of money transmitters and exchange houses reinforces a preventive approach aimed at keeping fraud and money laundering from blending with control failures. In Brazil, regulatory pressure on minors and platforms also works as a form of mitigation against identity fraud and data abuse.

Ransomware and extortion

No ransomware or extortion cases were recorded as the primary focus in the material reviewed for August. There were also no sufficient elements to classify asset encryption, exfiltration without encryption, or even a simple mention on a leak site. That absence should not be read as proof that the threat does not exist in the region, only as a lack of verifiable facts in the corpus provided.

For a compliance report, this matters because it shifts attention away from ransomware response and toward preventive governance. If the month was not dominated by encryption or extortion, the regulatory discussion was more useful for anticipating controls than for reconstructing a continuity crisis. That changes monitoring priorities, contracts, and reporting.

APT and hacktivism

The material does not provide any APT or hacktivist campaigns with solid attribution during the period. It does include references to incidents and debates involving platforms, child safety, and payment systems, but not to persistent or actor-driven operations with clear TTPs. In practical terms, that limits tactical analysis and reinforces the need not to overstate findings based on secondary coverage.

Critical Vulnerabilities

No critical CVEs were recorded in the August 2026 material analyzed, and that does not mean critical vulnerabilities exploited in the region were absent. The corpus for the period does not document a specific CVE case that can be included with sufficient audit value and traceability.

CVE Software Exploitation Source
No critical CVEs were recorded in the material analyzed n/a n/a n/a

Regulation and Compliance

August was, by a wide margin, the most active regulatory month in the recent series. The volume of regulatory moves, 492 out of 905 verified events, not only confirms the axis’s dominance, it also points to a more scattered and demanding agenda. This is no longer just about framework laws, but about secondary rules, public consultations, technical resolutions, sanctions, and institutional reforms that force compliance to become operational.

Brazil, a tougher and more visible ANPD

Brazil accounted for a large share of the region’s signal. The fine against ByteDance over children’s data is only the most visible expression of an authority that is consolidating itself as a regulator, with guidelines, resolutions, and a stepped-up enforcement agenda. The material also says the ANPD is keeping proceedings open against several major tech companies and has been refining incident notification deadlines and obligations, although in those cases the source is sometimes secondary and should be read carefully.

The depth of the Brazilian discussion lies in the compliance architecture. Resolução CD/ANPD nº 15/2024 sets a three-business-day deadline to notify relevant incidents and requires incident records to be kept for at least five years. That recasts incident management as a continuous documentation process, not an ad hoc reaction. The cited doctrine even notes that the initial notification can be supplemented later, which supports preliminary reporting within the deadline.

The agenda does not stop with incidents. It also includes Resolução CD/ANPD nº 18/2024 on the role of the encarregado and Resolução nº 19/2024 on international transfers and adequate protection. The combined effect is clear. Brazil is building a more granular body of rules that demands internal governance, formal responsibilities, and the ability to demonstrate decisions. For regional companies, that makes the country a de facto compliance benchmark.

Mexico, payments, fintech, and prudential cybersecurity

Mexico combined regulatory changes in payments with a stronger emphasis on internal controls, corporate governance, and incident reporting. Banxico opened public consultations on card clearinghouses and on payment network systems, while specialized press reported cybersecurity obligations for regulated entities, including IFPE and IFC, with risk frameworks, business continuity measures, and reporting deadlines. The DOF appears as the formal publication channel for these adjustments.

The Federal Cybersecurity Law bill is still pending and had not been approved as of August 2026. The material makes clear that the bill was introduced in 2025, that it includes 64 articles, a National Cybersecurity Agency, a Critical Infrastructure Registry, and the designation of formal officers. But it is not yet law, so companies should not confuse political expectations with binding obligations. The main mandatory framework for personal data remains the 2025 amended LFPDPPP.

The most interesting regulatory signal in Mexico is the convergence between information security, financial compliance, and system design. Risk-based supervision of exchange houses and money transmitters, along with discussions on biometrics and authentication, suggests a regulatory push to close fraud and traceability gaps. For legal teams, the priority is to understand which obligation comes from a rule, which from a consultation, and which from journalistic interpretation.

Chile, personal data and digital childhood

Chile remains one of the month’s most sensitive cases because of the tension between an approved law and institutional capacity. The new data protection law was sent forward in 2024, has not yet entered fully into force, and the Executive is studying whether to delay implementation by another year. At the same time, the future Personal Data Protection Agency is scheduled to start operating on December 1, 2026. That combination explains much of the public debate.

In parallel, Chile’s digital childhood agenda is moving forward with legislative urgency on a bill for safe digital environments, and the lower house approved a general version of a bill on deepfakes. That outlines a more fragmented regulatory ecosystem, where data protection, synthetic content, minors’ exposure, and platform liability are being legislated on separate tracks. The risk for companies is having to deal with obligations that converge in practice but originate in different files.

Argentina, financial architecture and subnational fragmentation

Argentina had a dense month for financial rules and subnational bills. The BCRA enabled Cobro con Transferencia for installment payments, and the change affects consent, debit, prior notice, and fraud liability. In addition, the Central Bank continued issuing communications and circulars that shape the operation of financial institutions and PSPs, reinforcing a model of continuous compliance rather than episodic compliance.

At the same time, provinces and legislatures pushed bills on cybersecurity, data protection, artificial intelligence, and digital violence. Mendoza, Santa Fe, Salta, Río Negro, Zacatecas no, Mexico no, and other jurisdictions show that regional regulation no longer depends only on the national level. For companies with multi-jurisdictional operations, the challenge is not just reading laws, but mapping differences between provinces, states, and agencies.

Paraguay, a law in force and a visible procedural gap

The material on Paraguay is interesting because it shows two levels at once. On one side, organizations and participants in the public debate cite Ley N.º 7.593/2025 de Protección de Datos Personales as the current framework for discussing consent and data control. On the other, a review of the official Senate website did not identify a specific bill on new data protection or cybersecurity legislation under review for 2024-2026.

That combination suggests a system where the law exists, but the visible processing of new changes does not appear consolidated in the source consulted. For compliance, that means monitoring the public debate without assuming that every press comment corresponds to a real legislative file. In the report, Paraguay appears more as a case of regulatory maturation than as a source of new formal moves.

Colombia and Bolivia, fragmented or still-forming frameworks

In Colombia, the press reviewed indicates that there is still no comprehensive cybersecurity law and that the country operates under Law 1273 of 2009, Decree 338 of 2022, and the National Cybersecurity Strategy 2025-2027. That fragmented setup explains why the country appears this month more as a diagnosis of dispersion than as a producer of new, closed obligations.

In Bolivia, part of the comparative and contextual material shows bills under review on cybersecurity and artificial intelligence. However, for August 2026 the main corpus does not provide a consolidated legislative piece comparable to Brazil, Chile, or Mexico. That does not reduce the country’s relevance, but it does mean the signal should be treated as an agenda still taking shape rather than as an already hardened regulatory package.

Latin America’s Most Affected Countries

The month’s regional pattern was clearly concentrated in the markets with the highest regulatory and supervisory density. Brazil and Mexico led in enforcement volume and in the pace of regulatory change. Chile and Argentina followed in the top tier because of the mix of projects, consultations, and implementation changes. Paraguay and Colombia had lower volume, but still showed structurally important issues.

Brazil

Brazil was the center of the month. The fine against ByteDance, the number of ANPD proceedings, the agency’s growing role as a regulator, and the debates over notification deadlines and international transfers all point to a highly active regulatory environment. The common thread is the demand for demonstrable governance.

For companies operating in Brazil, the month calls for a review of processing inventories, legal bases, incident flows, contracts with processors, and policies for children and adolescents. It also calls for a review of how DPO or encarregado decisions are documented, because the ANPD is strengthening the evidentiary value of that role.

Mexico

Mexico combined payments, anti-fraud, cybersecurity, and personal data. Banxico and the CNBV are pushing adjustments in payments infrastructure and supervision of financial entities, while the federal cybersecurity bill remains under review. The result is an environment where existing obligations, open consultations, and still-pending projects coexist without creating direct duties yet.

The operational takeaway is that Mexico’s financial sector cannot wait for a single omnibus law to sort everything out. It has to read the DOF, circulars, consultations, and regulatory speeches as part of the same compliance stream. In particular, biometric issues and incident reporting require documented traceability.

Chile

Chile is facing the sharpest tension between an approved rule and its effective date. A delay in the Data Protection Law, if confirmed, would affect implementation timelines, but it would not remove the need to prepare. At the same time, projects on digital childhood and deepfakes confirm that Chile’s agenda is among the most crowded in South America.

The underlying issue is institutional capacity. If the Agency is set up late or the law is postponed, the private sector should not read that as an open-ended pause. The framework is already defined, and the public debate shows that regulatory pressure will continue.

Argentina

Argentina showed fragmentation and, at the same time, faster change in the financial system. The BCRA is moving pieces on payments, payroll accounts, loans, and service channels, while provinces and subnational jurisdictions are advancing their own rules. That combination requires a careful separation of national and provincial measures and a local review of processes.

From a risk standpoint, the country stands out not because of a single incident, but because of the number of simultaneous changes affecting banking, PSPs, provincial governments, and digital education. The compliance challenge lies in the coexistence of different frameworks for issues that sometimes overlap, such as identity, payments, transparency, and data protection.

Paraguay

Paraguay appears with an existing regulatory base and public debate about data control and the use of AI. The source reviewed did not identify a new consolidated legislative proposal on cybersecurity or data protection for 2024-2026. That does not make the country less relevant, but it does reduce the volume of comparable developments versus the regional leaders.

Colombia

Colombia continues to operate under a fragmented framework and without an identified comprehensive cybersecurity law in the source material. The main reference is the existing structure of cybercrime, digital governance, and the national strategy. For the compliance reader, the signal is continuity rather than abrupt change.

Bolivia

Bolivia shows signs of regulatory debate on AI and cybersecurity, but not a regulatory closeout comparable to other countries in the month. The key issue is to monitor whether the projects under discussion manage to consolidate over the coming months. For now, the material places the country in a phase of regulatory construction.

Compared with July, the regulatory axis clearly accelerated. Verified incidents rose from 531 to 905, regulatory actions increased from 314 to 492, and fraud or phishing cases climbed from 39 to 64. At the same time, ransomware or extortion cases as the primary focus fell from 6 to 0. The most prudent reading is that the month shifted from a hard operational threat picture toward a more intensive compliance and anti-fraud agenda.

The second signal is the growing strength of regulators in Brazil and Mexico. In Brazil, the ANPD is consolidating itself as an agency with sanctioning power and its own agenda, not just a reactive body. In Mexico, Banxico and the CNBV are driving changes that affect payments, fintech, and prudential supervision. If August was a month of consultation and sanctions, September is likely to be a month of internal adjustment for many entities.

The third signal is in digital childhood and synthetic content. Chile advanced on deepfakes and child protection, while Brazil continues to tighten obligations on platforms and minors. This points to a more homogeneous regional agenda than it may first appear, the debate is no longer whether to regulate, but how to do it without breaking interoperability, innovation, or supervisory capacity.

The fourth signal is fragmentation risk. Argentina is deepening financial regulation, and provinces are pushing their own bills. Colombia still has dispersed frameworks. Paraguay has a law in force, but no new legislative wave visible in the source consulted. For regional groups, the challenge will be managing different calendars and obligations under a single governance structure.

Security team recommendations

First, turn compliance into a continuous documentation workflow. August made it clear that several authorities are requiring incident traceability, decision logs, remediation evidence, and formal assignment of responsibility. That affects DPOs as well as CISOs, compliance teams, and legal. Policies are not enough, execution has to be provable.

Second, review incident notification and escalation processes immediately. In Brazil, the three business-day deadline to report relevant incidents and the requirement to keep records for five years force a rethink of detection, classification, and decision timelines. In Mexico, reporting obligations to financial authorities and cybersecurity frameworks for regulated entities require a matrix showing who reports, when, and with what evidence.

Third, audit processing tied to minors, age profiling, and consent. The ByteDance penalty and Chile’s digital childhood agenda show that children’s data is no longer treated as a minor subcategory of the digital business. Companies need to review onboarding, age verification, default settings, targeted advertising, and deletion mechanisms.

Fourth, map the impact of payments and fraud on operations. Argentina’s new Cobro con Transferencia, Banxico’s consultations on card payments, and tighter anti-fraud oversight across the region require a review of authorization models, reversals, customer support, reconciliation, and complaint handling. Fraud is no longer just an anti-fraud function issue, it is also a compliance and contractual liability issue.

Fifth, separate pending projects from current obligations. In Mexico, the federal cybersecurity law is still not approved. In Chile, the data law may be delayed. In Paraguay, no new consolidated bill was identified. Mixing those three situations leads to budgeting and implementation errors. Each country needs a regulatory status matrix, with date, status, and real impact on the organization.

Sixth, prepare evidence for supervisory review, not just internal audit. August showed that the regional regulatory narrative is shifting toward proof of compliance, not simple assertions. If an organization cannot demonstrate how it classifies incidents, how it keeps records, how it manages consent, or how it responds to an authority order, it remains exposed even without a serious intrusion.

Frequently Asked Questions

Which countries concentrated the highest regulatory risk this month, and why?

Brazil and Mexico faced the heaviest pressure because they combined sanctions, public consultations, and operational changes affecting payments, data, and cybersecurity. Chile and Argentina followed closely because of progress on data, digital childhood, and new financial rules. The Most Affected Countries section details the scope country by country.

Was ransomware or extortion the main issue in August?

No. The August material did not record ransomware or extortion as the primary focus, and it also did not allow for classification of asset encryption, exfiltration without encryption, or mentions on leak sites. The month was driven by regulation, fraud, and enforcement. See the Active Threats and Campaigns and Relevant Incidents sections.

What changed in Brazil with the ANPD, and why does it matter outside the country?

The ANPD fined ByteDance, ordered specific remediation measures, and continued expanding enforcement over major platforms. The material also describes short incident deadlines and record-keeping and transparency obligations. That matters beyond Brazil because it tends to set regional expectations for minors, DPOs, and compliance evidence.

What is the most sensitive issue in Mexico for banks and fintechs?

The mix of Banxico consultations on payments, CNBV risk-based supervision, and cybersecurity and reporting obligations for regulated entities. On top of that, the federal cybersecurity law still has not been approved, so compliance today depends on the current framework and several technical provisions running in parallel.

What should a regional team watch if it operates in Chile and Argentina at the same time?

It should keep deadlines and regulatory status clearly separate. In Chile, the data protection law could be delayed, but it remains on the radar and the Agency is due to begin operations on December 1, 2026 according to the material. In Argentina, the BCRA has already changed collection, payments, and supervision flows. The comparison should be made country by country, not by intuition.

Why is the CVE indicator at zero if the report says risk is high?

Because the material reviewed did not record any critical CVEs in August, and zero means exactly that, not that there were no critical vulnerabilities in the region. The high risk comes from the volume and severity of regulatory changes, sanctions, and compliance obligations. The full clarification is in Period Indicators and Material Limitations.

Material limitations

This report was built exclusively from the material provided for Latin America and for August 2026. The 58 events from earlier months were used only as a comparison frame and not as period volume. The 27 undated events were excluded from the indicators, and the 10 events after the period were also left out.

A zero indicator, especially for critical CVEs, means no such event was recorded in the material analyzed during August. It does not mean there were no critical vulnerabilities exploited in the region, nor that risk was absent. The same standard applies to ransomware or extortion as the primary focus.

The reading is also limited by the nature of the sources. Priority was given to official agencies, bulletins, courts, regulators, official gazettes, and direct press coverage. Consumer social media, sponsored content, and commercial press releases were excluded as the basis for trend claims. When a news source provided data that was not fully precise, attribution was kept and no unverifiable conclusions were drawn.

The declared time window for the indicators was 905 events dated in August 2026, 58 events from earlier months as a comparison frame, 27 without confirmed dates excluded, and 10 after the period excluded. The percentages and counts cited in the report reproduce that base exactly, with no independent aggregation or sums outside the provided indicators.

Sources