AI-Driven Phishing Attacks Surge in Latin America, Harming Millions

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

AI-powered phishing attacks have surged across Latin America, with Costa Rica and the Dominican Republic experiencing significant increases in detected cases. Cybersecurity firm Kaspersky attributes the rise to AI-generated deepfakes and automated messaging, enabling large-scale scams and fraud that have harmed individuals through deception and financial loss.[AI generated]

Why's our monitor labelling this an incident or hazard?

The event involves the use of AI systems in the development and deployment of phishing attacks, including AI-generated deepfakes and automated mass messaging via RPA, which directly lead to harm by enabling large-scale scams and fraud targeting individuals. The harms include injury to people through deception and financial loss, fitting the definition of an AI Incident. The report documents actual occurrences and impacts, not just potential risks, thus it is classified as an AI Incident.[AI generated]
AI principles
AccountabilityPrivacy & data governanceRespect of human rightsSafetyRobustness & digital securityTransparency & explainabilityHuman wellbeingDemocracy & human autonomy

Industries
Digital securityFinancial and insurance services

Affected stakeholders
General public

Harm types
Economic/Property

Severity
AI incident

AI system task:
Content generationInteraction support/chatbots


Articles about this incident or hazard

Thumbnail Image

Reporte: Ataques de phishing aumentan 132% en el país, detectan más de 8 millones de casos

2025-09-11
CRHoy.com | Periodico Digital | Costa Rica Noticias 24/7
Why's our monitor labelling this an incident or hazard?
The event involves the use of AI systems in the development and deployment of phishing attacks, including AI-generated deepfakes and automated mass messaging via RPA, which directly lead to harm by enabling large-scale scams and fraud targeting individuals. The harms include injury to people through deception and financial loss, fitting the definition of an AI Incident. The report documents actual occurrences and impacts, not just potential risks, thus it is classified as an AI Incident.
Thumbnail Image

Ataques con mensajes falsos aumentan 14% en RD; 4 millones de casos detectados

2025-09-10
Noticias SIN
Why's our monitor labelling this an incident or hazard?
The event involves the use of AI systems in the development and execution of phishing attacks that have already caused harm to people through scams and fraud. The AI systems are used to generate more convincing fake content and automate mass messaging, directly contributing to the realized harm. Therefore, this qualifies as an AI Incident because the AI system's use has directly led to harm to persons and communities through fraudulent activities.
Thumbnail Image

Costa Rica: Ataques con mensajes falsos aumentan 132%

2025-09-10
Revista Summa
Why's our monitor labelling this an incident or hazard?
The article explicitly states that AI is used to automate and improve phishing attacks, which have resulted in millions of detections and presumably many successful scams causing harm. The use of AI-generated deepfakes and automated message distribution directly contributes to realized harm through fraud and deception. Therefore, this qualifies as an AI Incident because the AI system's use has directly led to significant harm to people and communities through phishing scams and fraud.
Thumbnail Image

Ataques con mensajes falsos aumentan 22% en Perú,110 millones de casos detectados: Kaspersky

2025-09-11
Agencia de Noticias Órbita
Why's our monitor labelling this an incident or hazard?
The article explicitly states that AI is used to automate and improve phishing attacks, including the use of deepfake technology and robotic process automation to send mass fraudulent messages. These AI-driven attacks have directly led to realized harm in the form of scams and fraud attempts affecting millions of people, including 110 million detections in Peru alone. The AI system's use in automating and enhancing these attacks is a direct contributing factor to the harm, meeting the criteria for an AI Incident under the OECD framework.
Thumbnail Image

Ciberataques impulsados por inteligencia artificial: el mundo oscuro de la web y las estrategias que revela Kaspersky para no caer en estafas

2025-09-12
El Tiempo
Why's our monitor labelling this an incident or hazard?
The article explicitly states that AI is used to automate and scale phishing attacks, which have resulted in actual harm to victims through data theft and fraud. The harms include violations of privacy and financial security, which are covered under the definitions of AI Incident. The involvement of AI in the development and use of these cyberattack methods is clear and directly linked to the harms described. Although AI is also used defensively, the primary focus is on the realized harms caused by AI-enabled attacks. Hence, the classification as AI Incident is appropriate.
Thumbnail Image

Estas son las 6 principales amenazas en ciberseguridad que enfrentan Chile y Latinoamérica, según Kaspersky - La Tercera

2025-09-12
LA TERCERA
Why's our monitor labelling this an incident or hazard?
The article explicitly mentions AI's role in enabling more sophisticated and automated phishing attacks (e.g., use of Robotic Process Automation), and the use of deepfakes, which are AI-generated content. These represent credible cybersecurity threats that could plausibly lead to harm such as data theft, extortion, and fraud. However, the article primarily provides an overview of threats, statistics on blocked attacks, and expert advice, without detailing a specific incident where AI caused harm. Therefore, the event is best classified as Complementary Information, as it enhances understanding of AI-related cybersecurity risks and responses but does not report a new AI Incident or AI Hazard.
Thumbnail Image

Ataques con mensajes falsos aumentan 56% en Guatemala, más 6 millones de casos detectados - El Siglo

2025-09-14
ElSiglo
Why's our monitor labelling this an incident or hazard?
The article explicitly states that AI is being used to automate and improve phishing attacks, which have resulted in millions of detections and presumably many victims of fraud. The use of AI to generate convincing fake content and automate mass messaging directly contributes to harm to communities through financial scams and deception. Therefore, this qualifies as an AI Incident because the AI system's use has directly led to realized harm (mass phishing scams) in Guatemala and the broader region.