Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America
Palo Alto Networks, Thursday, September 3rd, 2026
Unit 42 details how attackers targeting Latin American organizations use AI for data exfiltration and leak their own operations through OpSec errors.
Unit 42 researchers examined a campaign against entities in Latin America in which the threat actors incorporated AI tooling into their workflow, notably for processing and exfiltrating stolen data.
The investigation was possible because the operators made basic operational security mistakes that exposed their infrastructure and tradecraft.
Palo Alto Networks uses the case to show how AI is being folded into routine criminal operations rather than acting as a wholly new class of threat. The research also outlines how defenders can use those same OpSec failures to detect and disrupt the activity.