File photo showing people working at an operations center in Madrid, Spain. EFE/Fernando Villar

Latin America cybersecurity on alert as nearly 38% of threats go unseen

Mexico City, Feb 11 (EFE).- Nearly 38% of cyber threats detected globally are no longer identified as traditional malware or trigger visible alerts, but instead operate covertly within networks, according to the Compromise Report 2026 by Lumu Technologies.

“The greatest risk today is not the attack that triggers alerts, but the one that goes unnoticed,” warned Ricardo Villadiego, founder and CEO of Lumu Technologies, stressing that a growing share of current intrusions evade preventive controls and remain active for long periods without detection.

The report specifies that 18.9% of detections correspond to active “malicious behaviors,” while 18.7% are linked to phishing domains in operation. Both categories reflect activity that goes beyond blocked perimeter attempts and directly affects organizations’ internal environments.

“Permanent visibility into compromise has become a pillar of modern security operations,” Villadiego added. He noted that this shift requires moving from a prevention-centered logic to one based on the continuous validation of an organization that has already been breached.

Exposed sectors and cybersecurity risk in Latin America

The sectors most affected by these threats include education, telecommunications and government, the report said.

According to the findings, the malicious use of anonymization services such as Tor and VPNs affects 22.1% of cases in the education sector, followed by telecommunications at 19.6% and government at 16.4%.

Specialists warned that these figures are particularly relevant for Latin America, where universities and public agencies often operate with open environments, high device turnover and limited cybersecurity resources, conditions that facilitate attacks designed to persist without causing visible disruptions.

File photo showing a person using a computer in Cartagena, Colombia. EFE/Ricardo Maldonado Rozo
File photo showing a person using a computer in Cartagena, Colombia. EFE/Ricardo Maldonado Rozo

Cybersecurity challenges from internal threats

Another emerging priority identified in the report is the transformation of the concept of internal threats, driven by the adoption of AI copilots and autonomous agents with access to sensitive systems and data.

“We are entering a stage in which internal threats are no longer exclusively human. AI agents are part of the operating environment and must be treated as such from a risk and control perspective,” said Christian Torres, CEO of Kriptos.

Industry players warned that many insider-threat and information-governance programs still fail to address this new risk, creating additional gaps amid accelerated digitalization.

From alerts to decision-making

The rise of silent threats is also affecting daily security operations, increasing fatigue and operational noise among cybersecurity teams.

“We are seeking an approach that empowers cyber defenders through comprehensive defense to deliver responses by enhancing human expertise with artificial intelligence (Wise), allowing teams to focus on high-impact strategic decisions,” said Stephen Fallas, Americas Field CTO at Trellix.

Fallas stressed that integrating workflows and unified threat analysis is key to prioritizing the riskiest assets and delivering effective responses before incidents occur.

New priorities for the region

According to specialists, these findings are pushing public and private organizations in Latin America to redefine cybersecurity priorities, with greater emphasis on visibility, resilience, data governance and responsible AI use.

The assessment points to the need for coordinated action among technology providers, independent experts, the public sector, and academia to strengthen regional preparedness for emerging cyber risks and build trust in the digital economy. EFE

EFE published this report with the support of Digi Americas Alliance.