A stolen cellphone in Panama is no longer just a lost device — it has become the front door to a victim’s bank account, email, and messaging apps. Cybercriminals who obtain a victim’s physical phone are finding ways to bypass security locks and drain bank accounts, contributing to a sharp rise in fraud complaints across the country.
What Happened
Panama’s Ministerio Público confirmed it is pursuing multiple investigations into complaints tied to this modus operandi. Between January 1 and July 31, 2026, prosecutors registered 3,970 criminal cases for fraud and related offenses — a 14% increase over the 3,482 complaints filed during the same period last year.
That averages out to roughly 18 fraud complaints per day nationwide. Complaints specifically for the modification or manipulation of computer programs surged 273% in the first half of 2026, jumping from 40 to 149 cases, showing that digital channels have become the preferred mechanism for modern criminal networks.
Enoch Santamaría, director of Strategy and Transformation at the Superintendencia de Bancos de Panamá (SBP), told La Prensa that criminals who seize a phone first try to take control of as many elements of the device as possible. They review which apps the victim has and then attempt to access email, WhatsApp, online banking, and other services.
If they get into a messaging app, they may impersonate the owner and ask family members or contacts for money. If they reach online banking, the risk escalates to the movement of funds — potentially emptying the account entirely.
Background
According to Santamaría, the greatest weakness lies not in protection tools but in users’ preference for convenience. Common risky practices include using short numeric codes for easy recall instead of complex passwords, reusing the same password for email and online banking, and failing to activate a SIM card PIN — all of which can hand criminals control of the device.
Even biometrics — facial or fingerprint recognition — is not a guarantee. John Kent, manager of Institutional Cybersecurity at the SBP, warned that technologies capable of duplicating identities through deepfakes — AI-manipulated files that make it appear a person said or did something they never did — are undermining biometric-only protections.
The SBP recommends “security in layers”: combining multiple authentication factors such as fingerprints, security questions, passwords, tokens, and PINs, and avoiding storing passwords in phone browsers or note-taking apps. Users should also be wary of text messages about pending packages, debts, or payments — common lures designed to trick people into clicking malicious links — and avoid logging in on public Wi-Fi networks.
Institutionally, specialists note that attacks are massive and automated, executed continuously at global scale through malware, social engineering, and phishing. Most attempts fail thanks to financial platforms’ containment filters, and banks impose strict additional controls when they detect an unusual login from a stolen device. Banks are legally required to implement security controls; when a victim files a claim, the institution has up to 30 calendar days to respond. Dissatisfied customers can turn to SBP mediation for banking-law-covered products, provided the amount does not exceed $30,000.
What This Means for Panama
For Panamanians, the message from regulators is clear: speed of response is decisive. Experts say the first minutes after a phone is lost or stolen should follow three essential steps:
1. Notify your bank and phone carrier immediately. The first action should not be tracking the phone, but requesting an immediate block of online banking and suspension of the cellular line — including blocking the SIM card. This prevents criminals from receiving SMS verification codes needed to change email and banking passwords.
2. Lock the device remotely. Use centralized management tools such as iCloud or Google’s Find My Device to locate, lock, or wipe the phone’s information from a distance.
3. Change your credentials. Prioritize changing the passwords of email accounts and compromised apps from another secure device. If the criminal changes the password first, the victim loses the ability to control their other applications.
With fraud complaints rising steadily and digital manipulation cases growing exponentially, phone security is now effectively bank security. The faster the line, accounts, and access points are blocked, the smaller the window of opportunity for criminals.
This story was originally reported by La Prensa.