Cybersecurity Research

AI-Powered Attacks on Latin American Organizations Reveal Attacker Mistakes

Unit 42 · 3 Sept 2026
Key Takeaway Even AI-assisted attacks can be caught early by monitoring for unusual data transfers and unfamiliar software activity on your network.

Security researchers at Unit 42 have uncovered an ongoing campaign in which attackers targeting organizations across Latin America are using artificial intelligence tools to assist with data exfiltration. Rather than relying purely on traditional hacking techniques, the attackers appear to be leveraging AI to streamline parts of their operations, reflecting a broader trend of threat actors adopting AI to speed up and scale their activities.

Despite this technological edge, the research found that the attackers made basic operational security (OpSec) mistakes, exposing details about their methods and infrastructure. These errors gave defenders valuable insight into how the campaign operates, allowing security teams to identify and disrupt malicious activity more effectively than they might against a more disciplined adversary.

The findings highlight two important trends for businesses: attackers are increasingly experimenting with AI to improve efficiency, but even sophisticated-seeming campaigns can contain exploitable weaknesses. Organizations that monitor for unusual data movement and unfamiliar tools on their networks stand a better chance of catching such activity early, regardless of the attacker's technical sophistication.

Summarised by CISO AI from Unit 42. We link back to every original so you can read it yourself.