The expansion of electronic payment methods in Brazil has significantly broadened financial inclusion and transaction efficiency, but it has also heightened exposure to financial fraud. The growth of e-commerce, in-person card payments (offline), online purchases (card-not-present), Pix, bank slips (boletos), and the integration fostered by Open Finance has created new opportunities for criminals to exploit technological vulnerabilities, social engineering, identity theft, and credential compromise.
Digitalization has scaled both transactions and risks
Pix remains the country’s primary payment instrument. In 2025, the system recorded strong expansion relative to 2024, sustaining double-digit growth in transaction volume and reaching new usage records, with over 170 million users and more than 7 billion transactions in January 2026 alone. Monthly financial volume already exceeds BRL 3 trillion, consolidating Pix as one of the world’s largest instant payment systems.
Despite this growth, the Central Bank of Brazil and Febraban emphasize that the increase in operations does not represent a proportional rise in fraud, since the vast majority of transactions remain legitimate and protected by the security mechanisms of the National Financial System.
Payment cards also continued to grow in 2025, driven by e-commerce, contactless payments, and digital wallets. The 2026 Febraban Banking Technology Survey shows that the Brazilian banking sector processed approximately 240.8 billion transactions in 2025—an 11% increase over 2024—with 83% carried out through digital channels and 78% via mobile banking. Pix remained the fastest-growing payment method, including transactions at merchant establishments through POS terminals.
How the fraudster’s profile has become more sophisticated
Organized operations and social engineering
In parallel with the growth of electronic payment methods, the fraudster’s profile has evolved significantly. Fraud is no longer predominantly carried out by isolated individuals; it is now conducted by highly structured criminal organizations with a division of roles among specialists in social engineering, malware development, money laundering, the opening of mule accounts, production of forged documents, and the trafficking of personal data obtained through data breaches.
These organizations operate much like businesses, using technological infrastructure, automation, and even “Fraud-as-a-Service” models, significantly raising the sophistication level of attacks. The most recurring types of fraud include unauthorized use of cards in online purchases, credential compromise, issuance of counterfeit bank slips, tampering with Pix QR Codes, phishing, account takeover, mobile device malware, and social engineering scams.
Increasingly, criminals manipulate victims into voluntarily authorizing transactions themselves, making detection by traditional prevention mechanisms far more difficult.
Open Finance and identity fraud
Open Finance has also expanded the challenge for financial institutions. Although it represents a major advance for competition, innovation, and service personalization, the consensual sharing of financial data has begun to be exploited by fraudsters who simulate consent flows, hijack authentication sessions, or use social engineering to convince customers to authorize unauthorized access. As a result, the primary risk has shifted from being exclusively technological to heavily involving the manipulation of human behavior.
Another relevant attack vector remains identity fraud during onboarding processes for credit origination and Anti-Money Laundering (AML) compliance. Key examples include the use of forged or tampered documents, account opening with third-party identities, synthetic identity fraud (combining real and fictitious data), and AI-manipulated selfies (deepfakes) used to bypass facial biometrics.
These modalities directly undermine Know Your Customer (KYC) processes and are receiving increasing regulatory attention, including obligations under Brazil’s General Data Protection Law (LGPD) and Central Bank regulations on money laundering prevention. The impact extends beyond financial losses: it entails significant regulatory and reputational risks for institutions.
Artificial Intelligence Operates on Both Sides
Artificial intelligence has come to play a central role both in the evolution of fraud and in defense strategies. On the criminal side, generative models enable the creation of highly realistic deepfakes, voice cloning, highly personalized phishing campaigns at scale, and large-scale attacks at lower operational cost.
In response, financial institutions have been using AI and Generative AI for behavioral analysis, continuous authentication, real-time anomaly detection, automated document analysis, and the identification of suspicious accounts. The 2026 Febraban Banking Technology Survey shows that Generative AI and cybersecurity rank among the top strategic priorities of Brazilian banks — cybersecurity received a medium or high priority rating from 100% of participating institutions, while Generative AI reached 84%.
Prevention must keep pace with the speed of fraud
Why do some institutions still take a reactive stance?
Despite the available technological advances, not all institutions operate predominantly in a preventive mode. Factors such as high implementation costs, the need to minimize friction in the customer experience, budget constraints, legacy systems, and economic assessments of acceptable losses lead some organizations to focus their efforts on investigation and recovery after fraud has occurred.
This approach may reduce immediate investment, but it tends to increase financial losses, operational costs, regulatory risks, litigation, and reputational damage, especially given the growing speed of criminal organizations. In the context of financial fraud in Brazil, where digital transaction volumes are growing at double-digit rates annually, a reactive posture represents an increasing and difficult-to-reverse risk.
Although the absolute volume of fraud attempts represents a small fraction of total operations—the Brazilian financial system processes hundreds of billions of transactions per year and tens of trillions of reais—the speed and sophistication of attacks demand increasingly agile and integrated responses.
Risk management as a competitive advantage
The rapid digital transformation, the expansion of Open Finance, and the evolution of artificial intelligence impose a scenario of permanent adaptation. Institutions that treat fraud prevention as a strategic asset—rather than merely an operational cost, tend to better preserve customer trust, reduce regulatory exposure, and build sustainable competitive advantage.
Prevention, continuous monitoring, information sharing among institutions, and technological innovation are no longer differentiators, they have become requirements for responsible operation within the Brazilian financial ecosystem.