Hackers Used AI to Move Faster. Then They Exposed Their Own Playbook.

Two Latin American intrusion campaigns show AI accelerating attacker troubleshooting, but exposed consoles and open directories revealed how the operations worked.
BlackTree articles covering cybersecurity, privacy and digital legislation across Latin America.

Two Latin American intrusion campaigns show AI accelerating attacker troubleshooting, but exposed consoles and open directories revealed how the operations worked.

A Chinese-speaking threat cluster turned Brazilian government and university domains into trusted fronts for gambling scams, phishing and search manipulation.

BREEZE COMET stole the credentials and certificates behind trusted Brazilian payment workflows, then executed hundreds of fraudulent transactions within 24 to 48 hours.

Paraguay’s first comprehensive personal-data law creates a regulator, reaches some overseas processing and gives organisations 24 months from official publication before the regime takes effect. Paraguay’s Law No. 7.593/2025 represents a major change from a privacy landscape previously centred on…

Uruguay's Decree 276/025 creates governed test environments and data spaces for innovative projects, including AI and data uses.

Mexico's mobile-line identification rules require operators to link active numbers to verified people or organisations before the June 2026 deadline.

Brazil's ECA Digital requires digital services likely to be used by children to build safety, age assurance and parental controls into products.

Peru's Decree 115-2025-PCM classifies AI by risk and adds rules for transparency, human oversight, privacy and security.

Panama's Law 478 updates cybercrime offences, digital evidence and international cooperation while recognising authorised security testing.

Ecuador's Resolution SPDP-SPD-2025-0024-R clarifies how general privacy duties and transfer-specific rules operate together.