
ESET warns that cybercriminals continue to exploit human error, leading to email scams maintaining high levels of regional impact.
According to data from the latest “ESET Security Report”, 73% of companies in Latin America reported being targeted by phishing campaigns in 2025. Manufacturing organizations account for 81.4%, and the banking sector reaches 100% of institutions reporting phishing attempts.
ESET, a leading company in proactive threat detection, asserts that what makes phishing so lethal is not the sophistication of the technology but manipulation. Social engineering remains the most exploited attack vector, surpassing unauthorized access, malware, and vulnerability exploitation. Unlike a technical attack that can be detected by tools, phishing relies on a human click.
“Phishing isn’t a sophisticated attack because it uses advanced technology. It’s sophisticated because it exploits the weakest link in any security system: the human being. Furthermore, sectors with sensitive data or access to critical resources are a priority for criminals. And it’s no coincidence that the industries with the weakest defenses end up being the most attacked”, says David González, cybersecurity researcher at ESET Latin America.

The report reveals that not all sectors in Latin America experience phishing to the same degree. The data shows a concentration of risk in specific industries, and the reasons vary from the nature of the work to the maturity of the defenses. The manufacturing sector appears as one of the most attacked, with 81.1% of Latin American organizations reporting having suffered phishing attacks, indicating that manufacturing companies are particularly attractive targets. On the other hand, the education sector registers 81.4%, explained in part by a phenomenon that combines older infrastructures, slower update cycles, and teams with less security experience. The Banking and Finance sector accounts for 79.6% of phishing attempts in Latin America. Government and Healthcare, in turn, account for 72.6% and 67.6% respectively in the region, figures that remain alarmingly high.
Social engineering continues to be the most exploited attack vector in Latin America, surpassing unauthorized access, malware, and vulnerability exploitation. Criminals understand that defeating a person is much easier than bypassing a firewall. Phishing works because it exploits three things: trust, urgency, and limited knowledge. An email that appears legitimate, seemingly from a colleague or manager, with an urgent request generates panic. At this point, the brain is in reactive, not reflective, mode. The person clicks before thinking.
Globally, data from the ESET Threat Report for the first half of 2026 shows the evolution of this tactic. Criminals are not only sending obvious emails with typos. They are personalizing attacks, using company-specific information, spoofing domains, and expanding to new platforms like QR codes in emails, which evade traditional scanning.

“Phishing works because it’s easy to carry out, highly effective, and, in most cases, the victim doesn’t realize they’ve been targeted until much later. Today’s phishing isn’t the obvious email with typos and strange links. It’s too sophisticated to be easy to detect. Criminals are using several new techniques”, the researcher adds.
ESET identified a recent campaign that sent emails with the subject line “New Voicemail” to impersonate the victim’s own account as the sender, creating the illusion that the message originated from within the company. In this case, the attachment was an .svg file, a less common format that can bypass traditional security filters. When the victim opened the file, they were redirected to a page that mimicked the Outlook login page, where their credentials were stolen. Globally, ESET warns that other tactics have been reported, such as using QR codes distributed in emails or the ClickFix, technique, which simulate browser errors and prompt users to take urgent action.
To stay protected against this threat, ESET shares the following recommendations: do not click on links in unsolicited or suspicious emails and be especially wary of subject lines that create a sense of urgency or alarm. Also, be particularly careful with unexpected attachments, especially those in less common formats like .SVG.
González advises: “In short, if something seems urgent and arrives via email, it’s a red flag; it’s best to contact the sender through an official channel. Anti-phishing security isn’t solely the company’s responsibility. It’s shared between the organization and every individual who uses corporate email. For companies, the first security step, according to ESET, is visibility. If an attack can’t be detected, there’s no way to respond. Firewalls, EDR, and backup systems are basic defenses that must be in place and, more importantly, monitored. And of course, strengthen authentication policies and keep systems updated.”
Security training isn’t a boring annual activity; it’s what distinguishes companies that leak data from those that don’t. Phishing continues to work because it truly works. Criminals don’t change their weapon when the weapon follows corporate defenses. Security only changes when organizations understand that invisibility is the real problem, not a lack of tools. And when each person understands that a wrong click is not a personal mistake, it is exactly what the criminal planned.
