STORY-TRÅD·teknik
Social engineering behind 40% of financial scams in Brazil
Social engineering–based scams account for 40 percent of reported financial fraud cases in Brazil. The strategy includes fake call centers, criminals posing as bank employees, and even fake police operations to convince victims to provide personal information or make transfers. According to a recent survey by Quod, a data analytics firm specializing in data intelligence for the credit market, in the first half of 2026, more than 9 million instances of fraud were reported, including both suspected and confirmed cases – a 10.26 percent increase compared to the second half of 2025. Social engineering accounted for more than 3.6 million of these incidents. Notícias relacionadas:Brazil’s data protection agency launches investigation into Discord.IMF praises Brazil’s most popular payment method, Pix.According to Quod, cell phones were the primary channel used in these scams, appearing in 78 percent of cases. The instant payment system Pix was the method in 85 percent of the incidents. More sophisticated scams Social engineering exploits the victim’s trust and emotions, rather than relying on a breach of banking systems. Criminals simulate scenarios of urgency, fear, or false authority to coerce quick decisions. In the fake call-center scam, for example, the criminal claims to have identified a suspicious transaction and instructs the victim to take steps to supposedly protect the account. In fake police operations, the scammer uses authority to intimidate the target and demand financial transactions. Attacks may also combine phone calls, WhatsApp messages, text messages, and emails over the course of days or weeks before the attempted transfer. AI has made these approaches even more convincing, with voice cloning, image manipulation, and the production of forged documents. According to José Oliveira, director of technology at Certta, a smart verification company that unifies anti-fraud solutions on a single platform, social engineering targets a different layer than traditional security. “Anti-fraud AI wasn’t designed to combat social engineering; it was designed to combat fraud. These are different layers of the same problem, where social engineering targets human decision-making, while fraud targets the system, the document, and the identity,” he said. Technology New mechanisms for combating fraud were introduced in 2026. Central Bank Resolution 501 expanded the sharing of information on signs of fraud among financial institutions, while the Unified Fraud Registry (RUFRA) aggregates data to identify patterns and support preventive measures. Institutions also use AI and behavioral biometrics to analyze factors such as device, time, location, and transaction history. Advances in AI investments, however, have not prevented the rise of scams involving social engineering. In Oliveira’s view, prevention must occur before any loss occurs. “For institutions, the approach must be exactly the opposite – i.e., using technology to recognize signs, anticipate risks, and adapt protective measures before a vulnerability turns into a loss,” Oliveira pointed out. Limited discussion According to a recent survey by Certta and Nexus on data intelligence, only 11 percent of social media mentions related to digital scams and fraud focus on prevention. “The public debate is dominated by reports of incidents and cries for help after the damage has already been done, and Brazilians still cannot distinguish between cybersecurity and anti-fraud protection,” Oliveira argued. “For consumers, the best defense is to combine technology with preventive behavior. Since nearly 78 percent of fraud cases occur via cell phones and social engineering is the main cause of scams, the rule is to be wary of any sense of urgency,” Danilo Coelho, director of products and data at datatech Quod, warned. Young victims Young people aged 18 to 34 account for 49.06 percent of victims, according to the Quod survey. People earning up to two minimum wages make up 58 percent of those affected. In total, 3.1 million people fell victim to fraud in the first half of the year, and about 799,000 were scammed two or more times. This situation shows that, in addition to investment in technology, prevention depends on the user’s ability to recognize attempts at manipulation before authorizing a transaction.