CiberLATAMbywhalemate

Colombia Sees Rise in AI Phishing

Bloomberg Línea reported hyperrealistic phishing and polymorphic malware in Colombia. Sumsub also flagged more account takeover attempts.

Whalemate Labs · AI-assisted researchPublished:Updated 2 min read

In Colombia, hyperrealistic phishing and polymorphic malware were the most detected cyberattack methods in the first half of 2025, according to Bloomberg Línea, in a regional context where generative AI was amplifying attacks across Latin America. Bloomberg Línea also said the same technology was being used on the defensive side to identify incidents and speed up response, with AI engines cutting false positives in the region.

In Colombia, hyperrealistic phishing and polymorphic malware were the most detected cyberattack methods in the first half of 2025, according to Bloomberg Línea, in a regional environment where generative AI was boosting attacks across Latin America and defensive tools as well. Another report, based on Sumsub data, also found more account takeover attempts and greater use of deepfakes.

What did Bloomberg Línea show about cyberattacks in Colombia?

Bloomberg Línea identified hyperrealistic phishing and polymorphic malware as the most detected cyberattack methods in Colombia during the first half of 2025, within a regional setting where generative AI was strengthening attacks in Latin America, with effects across different sectors, including financial services.

The report framed that finding within a broader wave of AI-driven threats. Its coverage described a regional environment where deception tactics were becoming more convincing through generative AI, affecting several industries.

How is AI being used on the defensive side?

The same coverage said AI was also being used defensively, and that AI engines were helping identify incidents, speed up response, and reduce false positives in the regional context cited by Bloomberg Línea.

The technology therefore appeared on both sides of the conflict. On one hand, it helped make attacks more convincing. On the other, it supported faster detection systems with fewer errors.

What did Sumsub say about deepfakes and account takeover in Colombia?

Another report, this time by Infosertecla based on a Sumsub report, said account takeover attempts in Colombia rose 188% and deepfake use increased 77% in the period covered by that study.

That point should be read with caution, since the journalistic reference presented it as information attributed to the Sumsub study and not as independently confirmed data in this note. Even so, the coverage described deepfakes and AI-generated identities as growing fraud vectors in the region, with impact in Colombia as well within the secondary report.

The focus is no longer limited to malicious emails or links. It now also includes techniques designed to impersonate identities and build trust with synthetic material.

What does Microsoft add to this trend?

Microsoft also published a post about threats in the era of AI that mentioned AI-backed social engineering using LLMs to generate phishing emails as an example of offensive AI capability.

That material was not focused on Colombia, but it helps explain the kind of automation threat actors are already using to make campaigns more convincing. Taken together, the cited reports show that Colombia is already part of a regional map where AI is speeding up both deception and defense, while deepfakes, synthetic identities and hyperrealistic phishing continue to emerge as vectors worth watching closely.

Sources

View all