Skip to content

Digital surveillance and control spread across Latin America under governments of all stripes

A report by the organization Derechos Digitales has documented more than 100 cybersecurity violations over the course of a year

Deagreez (Getty Images)

Digital surveillance and data leaks may seem far removed from everyday life, but they are becoming increasingly common. In Venezuela, for example, authorities blocked messaging apps and social media platforms including Signal, X, TikTok and Telegram, as well as YouTube, VPN services and websites. In Nicaragua, independent media outlets had their domains blocked. In Paraguay, a leak from the electoral authorities exposed the data of nearly seven million people. And in Argentina, more than 665,000 medical records were put up for sale.

These are just a few of the more than 100 cases recorded over less than a year, between June 2024 and May 2025, and documented in the report In the Crosshairs 2: An Overview of Digital Threats in Latin America, published by the nonprofit organization Derechos Digitales.

Governments and companies, acting separately or in concert, are increasingly being called out for surveillance, censorship, violence and control in digital spaces, practices that, according to the organization, are undermining the exercise of human rights across the region.

“These practices are not so different between authoritarian and more democratic regimes,” Ximena Cuzcano, a digital security and resilience analyst at Derechos Digitales, tells EL PAÍS. “In Venezuela, spyware tools are used against activists, journalists and ordinary citizens. In Argentina, cyberpatrolling has been authorized; the authorities monitor people without oversight. Someone who is critical of the government or belongs to the opposition cannot speak freely because they are already being monitored through automated systems.”

In Latin America, an additional layer of complexity arises from the region’s reliance on imported technologies. Because governments use software developed abroad, they are exposed to tools they do not fully understand, which deepens their dependence on the countries that produce them.

“Latin American states adopt these technologies from other countries, for example, Israeli spyware,” explains Cuzcano. “The same is true of surveillance practices. Other cases are not even visible. Afterwards, these practices and technologies are quickly legalized.”

Law as a trap?

These tools do not exist in a vacuum. Rather, they are part of a regional landscape in which surveillance and security practices are increasingly being institutionalized through specific legislation that, according to the report, “directly affects the exercise of human rights in the digital environment.”

Cuzcano pointed to the case of Ecuador, where the government of Daniel Noboa enacted the Organic Intelligence Law in 2025, a measure that, she says, “authorized surveillance and the detention of individuals without necessarily requiring a court order.”

Regulations are moving in different directions: some expand governments’ surveillance powers in digital spaces, often under the banner of national security and public order. In Argentina, for example, Resolution 428/2024 of the Ministry of Security under the government of Javier Milei authorizes the systematic monitoring of open sources and the use of automated technologies to analyze online information. Decree 383/2025, meanwhile, added cyberpatrolling to the powers of the Federal Police, allowing it, according to the report, to conduct such monitoring “without the need for judicial authorization” when dealing with publicly available information.

Once again, the political orientation of a government does not appear to alter these practices. In 2024, El Salvador passed a Cybersecurity Law and created the State Cybersecurity Agency (ACE), measures that could facilitate the removal of online content. In Cuba, the Social Communication Law came into force, regulating digital content and media while strengthening state control over information.

And despite these practices gaining ground across the region, there has been little progress in expanding transparency safeguards or strengthening tools for public oversight.

Data leaks: The vulnerability of personal data

The examples above are government actions that reveal a political and legal context that makes incidents of cybersecurity possible — and, in some cases, legitimate. But beyond intentional actions, there are also breaches caused by negligence or a lack of technical capacity. Large-scale data leaks are one example.

“Leaks have occurred in 12 countries in the region, and most of these attacks do not happen because of a sophisticated hacker, but because databases are left open, without authentication, or legitimate access is misused,” says Cuzcano.

“These data are then sold on the dark web or via Telegram at low cost. Citizens are left saying, ‘well, they already have all my data,’ but sometimes we are not even told what they can do with it,” she adds.

The consequences can range from identity theft and fraud to opening bank accounts in someone else’s name. In Ecuador, a data leak from the emergency health service ECU 911 to funeral companies allowed them to contact relatives of critically ill patients even before a death had occurred, raising ethical concerns and highlighting shortcomings in data protection for people in vulnerable situations.

Disinformation in elections and gender-based violence

Casting doubt on the integrity of elections through supposedly technical “evidence,” or by withholding such evidence altogether, is not a new practice in the region. In Brazil, former president Jair Bolsonaro (2018-2022) promoted that narrative; at the other extreme, in Venezuela’s 2024 election, authorities failed to provide the technical evidence, namely voting records, needed to demonstrate the transparency of the process.

However, the widespread adoption of artificial intelligence tools has changed the game. In Brazil, disinformation campaigns took an explicitly misogynistic turn, with at least five cases involving sexually explicit deepfakes targeting female candidates.

Gender-based violence facilitated by technology (GBV-T) is one of the most common threats. The helpline run by Fundación InternetBolivia.org recorded 377 cases during the period covered by the report. Sexual abuse carried out through information and communications technologies (ICTs) and online harassment accounted for more than half of all complaints, followed by cases involving defamation, extortion and hacking.

The report was produced by the Latin American Observatory of Digital Threats (OLAD), combining weekly monitoring of open sources with fieldwork conducted by organizations within the network.

Sign up for our weekly newsletter to get more English-language news coverage from EL PAÍS USA Edition

Archived In