When AI Starts Making Payments: The New Challenge of Trusting a Machine
The next transformation in payments won't just be about making transactions faster; it will be about allowing artificial intelligence to act on our behalf.
Insights, guides, and updates on identity verification, fraud prevention, and digital security.
The next transformation in payments won't just be about making transactions faster; it will be about allowing artificial intelligence to act on our behalf.
For years, artificial intelligence has been touted as a technology capable of transforming fraud detection. Analyzing vast amounts of data, identifying anomalies, and recognizing patterns that are difficult to spot manually are among its most obvious applications. But there is another side to this evolution.
When people think of identity fraud, the most common image is that of an attacker stealing a document or credentials to impersonate a real person. However, a growing share of modern attacks no longer relies on that scheme. A digital identity can be compromised without a single piece of sensitive data being stolen.
A valid document doesn't always mean a low-risk identity When an organization evaluates whether to approve an account, a loan, or a transaction, it often relies on a seemingly simple question: Is the presented document valid? But that question alone leaves out an essential component of the decision: the real risk associated with that identity.
In the conversation about digital identity, two terms are frequently used interchangeably: identity proofing and identity verification. However, they represent distinct stages in the trust process, and confusing them can lead organizations to assume they are more protected than they actually are.
Latin America has become an increasingly attractive target for cybercrime groups. The rapid digitization of financial services, e-commerce, and digital channels has expanded the attack surface, while criminal groups have professionalized their operations using ransomware-as-a-service, infostealers, and increasingly scalable attack models.
Malware continues to evolve in Latin America, but one of the most relevant findings lies not only in the families detected, but also in the patterns that are repeated across different countries.
For decades, risk decisions in financial institutions were dominated by rule engines. If a transaction exceeded a certain amount, originated from an unusual location, or violated a specific policy, the system responded with a predefined actio
Technologies evolve. Programming languages change. Architectures migrate toward microservices and APIs. However, injection attacks remain one of the most widely used techniques by cybercriminals to compromise applications and access sensitive information.
Instead of breaking into a system, attackers convince victims to install legitimate remote access applications themselves. Once installed, these tools provide criminals with direct control of the device, allowing them to observe user activity, manipulate online banking sessions and authorize fraudulent transactions in real time.
Modern financial fraud is no longer carried out by individuals. It operates through criminal networks.
The ability of artificial intelligence to generate increasingly realistic synthetic images, videos, and content is transforming how organizations understand digital identity.
When we think of identity fraud, we usually imagine a straightforward scenario: an attacker obtains stolen information from a real person and uses it to open an account, apply for a financial product, access digital services, or commit fraud in their name.
When a widely used malware family disappears or loses strength, the risk doesn't disappear with it. In many cases, the criminal ecosystem simply reorganizes, reuses infrastructure, adapts techniques, and migrates to new tools capable of performing the same function more discreetly.
Today, artificial intelligence, Fraud-as-a-Service ecosystems, and automation tools are lowering the barriers to entry, allowing advanced fraud techniques to become more accessible, scalable, and difficult to detect.
Advances in generative AI have made voice cloning technology more accessible, allowing attackers to replicate a person's voice using only a few seconds of publicly available audio.
New malware operations such as OverlordMX are part of a growing wave of threats focused on session abuse, browser manipulation and authenticated fraud against financial institutions and digital banking users.
These campaigns are increasingly being used to steal credentials, payment information and digital identities through phishing techniques and malicious user flows.
Techniques such as Adversary-in-the-Middle (AiTM) phishing, infostealer malware and session hijacking illustrate this shift clearly. Instead of relying on invalid access, attackers operate using legitimate, authenticated sessions. From the system’s perspective, the interaction appears normal, even though control has already been compromised.
Attackers no longer need to break authentication systems to gain access. In many cases, they simply inherit already authenticated sessions and operate as legitimate users inside trusted environments.
For financial institutions, fintechs and enterprises operating in Microsoft 365 environments, this has become one of the most critical identity risks in modern fraud prevention.
One of the tools frequently used for this purpose is Raccoon Infostealer, a malware designed to extract sensitive data such as passwords, session cookies and financial information.
What was once largely opportunistic activity carried out by individuals is increasingly becoming organized, coordinated, and digitally enabled. Today, structured fraud networks operate across multiple sectors of the financial ecosystem.
The user scans a QR code that appears to belong to a bank, service provider, or even a public institution. The code might appear in an email, SMS message, digital advertisement, or even on a physical poster.
“Jinkusu,” a deepfake-based fraud kit circulating in underground markets, specifically designed to evade identity verification processes at banks, fintechs, and exchanges.
The adoption of instant payments is transforming the global financial infrastructure. Transfers in seconds, 24/7 availability, and frictionless experiences are already the new standard.
In Latin America and globally, governments, financial institutions, and digital platforms are moving toward digital identity wallets based on verifiable credentials.
This type of attack exploits a common behavior: the reuse of passwords across different platforms. If a user uses the same password on multiple services, a leaked credential from one site can grant access to multiple accounts on others.
Agent Smith is a mobile trojan/adware designed to operate silently once installed
For years, Apple’s ecosystem has been perceived as one of the most secure mobile environments. However, the discovery of the Coruna exploit kit, publicly documented by security researchers in 2026, shows that even highly protected platforms can become targets for attackers.
As digital banking expands across Latin America, regulatory pressure and cyber risk are converging on a critical point: identity. New audit findings show that digital risk is no longer just technical it is operational, financial, and reputational. This article explores how identity verification and behavioral risk analysis are becoming central to compliance, fraud prevention, and digital trust in the region.
When Fraud Originates Outside the Official Channel: Spoofing and Digital Impersonation In the last two years, there has been sustained growth in spoofing and brand impersonation campaigns that no longer seek to directly compromise organizational infrastructure, but rather to manipulate the end user into interacting with fraudulent environments that mimic legitimate channels.
Fraudsters are using virtual camera software to inject stolen or AI-generated videos into banking apps, bypassing facial recognition in real time. Identity fraud in LATAM surged 137% in 2024.
Mexico alone blocks over 1,000 daily attempts from predatory lending apps. These fraudulent platforms steal personal data, charge abusive interest rates, and escalate to physical threats.
A new generation of Remote Access Trojans is giving cybercriminals full control of victims' smartphones across the region. Learn how these attacks work and what financial institutions can do to protect their users.