fraud

5.000 Cybersecurity in LATAM 2026: The Threats Redefining Digital Risk

August 25, 2026 4 min read
 5.000 Cybersecurity in LATAM 2026: The Threats Redefining Digital Risk

A recent threat landscape identifies 138 active groups in 2025, a 20% increase over the previous year, while global cyberattacks increased by 47% during the first quarter of 2025 compared to the same period in 2024.

Risk can no longer be analyzed solely from the perspective of corporate infrastructure. It must also be considered from the point where the user, the device, and digital services interact.

Latin America Under Pressure

Regional data shows significant differences between markets, but a common trend: compromised devices continue to be a relevant source of risk.

Brazil has registered 1,296,896 compromised devices, followed by Mexico with 421,647, Argentina with 292,385, Colombia with 248,195, Chile with 169,310, and Peru with 164,392. In the case of Chile, the figure represents a 34% increase compared to 2014.

A compromised device can represent much more than a cybersecurity incident.

It can become the starting point for the theft of credentials, session cookies, authentication tokens, and other elements that subsequently allow attackers to take control of accounts or commit fraud.

Infostealers are especially relevant in this scenario. Among the prominent threats is RedLine, associated with more than 15 million infections, followed by Lumma and Raccoon. These ransomware families seek information that can later be used to access digital services and accounts.

Ransomware is Becoming more Professional

Ransomware-as-a-Service (RaaS) allows actors with limited technical capabilities to use infrastructure, tools, and services developed by other criminal groups.

Within the regional landscape, Qilin and Akira account for more than 55% of ransomware attacks, according to the analyzed report.

This trend is also observed in independent research. An analysis of ransomware activity in Latin America identified at least 74 variants operating in 23 countries during 2025, with Qilin and Akira among the most active families.

This highlights a significant shift: the attacker no longer needs to build the entire infrastructure from scratch. They can acquire capabilities, access specialized services, and focus on finding vulnerable organizations. The problem doesn't end when the malware is blocked.

For a financial institution, the impact of these threats can extend far beyond the compromised infrastructure.

An infected device may contain credentials. A stolen credential can grant access to an account. A compromised session can subsequently lead to a fraudulent transfer. That's why cybersecurity and fraud prevention are increasingly intertwined.

A strategy focused solely on detecting malware can identify the initial event, but not necessarily all the risks that emerge afterward. The crucial question is what happens when an attacker manages to breach that first barrier.

From Isolated Detection to Continuous Visibility

Organizations need to connect signals from different points in the digital journey.

The device can provide information about the environment from which an interaction takes place. The session can reveal behavioral changes or signs of compromise. Identity allows us to contextualize who is performing the action. And the transaction shows when the risk can ultimately become a financial loss.

This approach is especially relevant because cybersecurity in Latin America continues to exhibit visibility gaps. A recent study found that 69% of companies in the region consider themselves to have a proactive cybersecurity strategy, although significant discrepancies persist between this perception and actual detection and prevention capabilities.

The evolution of risk demands a shift from protection based solely on events to a strategy capable of understanding the context and continuously monitoring digital interactions.

The New Challenge for Financial Organizations

The growth of criminal groups, infostealers, ransomware, and credential theft is changing the nature of digital risk in Latin America.

But the biggest challenge isn't just knowing which threats are active.

It's determining what this threat means something for every user, device, session, and interaction in real time.

In an environment where attackers can scale their operations faster than ever before, prevention needs to combine multiple signals and maintain visibility throughout the entire digital journey.

Because detecting a threat is important. Understanding how that threat can turn into fraud is what allows you to anticipate it.

Stay one step ahead of fraud

Subscribe to our newsletter and receive a new article every Wednesday with analysis on fraud prevention, digital identity, cybersecurity, and emerging threats.

Schedule a meeting with our specialists to explore how to strengthen the protection of your digital channels through a strategy based on multiple risk signals.

Back to articles