This summary is generated by artificial intelligence and reviewed by the editorial team.

More than half of Latin American companies detected attempts to attacks against their computer systems in the last year, according to the ESET Security Report 2026. Among organizations that did not record incidents, one in four admit that they could have occurred without being discovered due to a lack of sufficient technology.

The main attack vectors

The report also reveals the most frequent attack vectors in the region: phishing or social engineering (73 %), aunauthorized access (40 %), malware infections (31,6 %), vulnerability exploitation (29.2%) andkidnapping or information leak (8,4 %).

Phishing, the most recurring vector, consists of impersonating companies, public entities or other legitimate institutions to obtain sensitive information, such as cards, accounts or credentials. Through emails, messaging applications or calls—generally accompanied by urgent messages—attackers seek to get their victims to share confidential data or download malicious files.

Its age has not made it any less effective.. Cybercriminals continue to obtain results with this technique and, with the help of artificial intelligencecan generate messages that are increasingly credible and closer to potential victims.

Emerging technologies make it possible to generate increasingly credible messages, reducing traditional signals that allowed fraud attempts to be identified. Therefore, its persistence cannot be attributed solely to a lack of internal controls; also responds to Constant evolution of tactics used by cybercriminals”says Gonzales.

Unauthorized access can occur in a variety of ways: from brute force attacks to session hijacking or the use of exposed credentials. These intrusions can exploit weaknesses in the security infrastructure or resort to strategies to trick users into obtaining their access codes.

Meanwhile, malware, the exploitation of vulnerabilities and the leak or hijacking of information are usually linked to malicious files, outdated systems or uncorrected flaws in the programs used by companies.

The key piece: the human factor

In any business environment, technology is an essential component of cybersecurity strategy, but Gonzales explains that alone is not enough. “The most frequent attacks identified in the report, such as phishing and unauthorized access, have a strong component associated with user behavior. Which shows that security depends on the balance between people, processes and technology”.

Even if an organization has advanced protection tools, if collaborators and users do not adopt good security practices or are unaware of the risks to those who are exposed, the defense is not complete.

The gap is also reflected in user practices. Although 81.4% of non-technical employees use antivirus on their work computers, only 52.2% activate double authentication on their work accounts. The report warns that this additional layer of protection remains insufficient against the risk of theft or leak of credentials.

Corporate telephones, for their part, appear as another weak point: one in four employees (26.9%) recognizes Do not use any security measures on your mobile device of work.

Phishing remains one of the most successful techniques because it exploits the human factorwhich continues to be one of the more difficult elements to protect within any organization. Although this modality has been known for years, attackers have considerably refined their methods through more personalized, convincing and scalable campaigns.”, comments the ESET specialist.

For Gonzales, the training continues and the strengthening of the culture security are as important as investment in technological solutions.

Outdated systems and unpatched vulnerabilities can open the door to intrusions. (Photo: Shahadat Rahman)

Small businesses, big risks

The ESET report was prepared with responses from 1,563 professionals of the sector, linked to 962 companies of different areas in Latin America. Although these types of attacks are often thought to primarily target large organizations, small businesses They are also exposed and, in some cases, may be more vulnerable.

There is a perception that cybercriminals focus only on large corporations, but in practice many attack campaigns are automated and They look for vulnerable targets regardless of their size”says the ESET executive to this newspaper.

The problem is worsened because the SMEs they usually have fewer specialized resourceslower monitoring capacity and less mature security processes. All of this makes both the prevention and detection of incidents difficult.

For Gonzales, the differentiating factor is not so much the size of an organization, but rather its level of preparation and awareness of the risks it faces.

Another element that concerns all types of companies is the reactive role that many maintain: they act mainly after an attack occurs. This strategy, although necessary, is insufficient facing the need to prevent and anticipate threats.

The strategy must shift from a model focused on reacting to incidents to one based on anticipation and the continuous risk management. This involves strengthening monitoring capacity, timely identifying vulnerabilities, understanding the threat landscape, permanently training collaborators, and developing effective response capabilities.

Prevention does not completely eliminate the possibility of suffering an incident, but it does significantly reduce its probability and minimize its impact. The most mature organizations are those that assume that attacks will occur and prepare to detect and contain them as quickly as possible.” says Gonzales.