Colombia Warns on Phishing
Colombia’s police flagged campaigns impersonating state agencies, plus a mass operation targeting multiple government entities.
Colombia’s police, through CC-CSIRT, issued alerts on malware and phishing campaigns impersonating the Registraduría, ICETEX and the Fiscalía General de la Nación, along with another mass operation aimed at multiple state entities in the country.
Colombia’s Police, through CC-CSIRT, issued alerts about malware and phishing campaigns impersonating the Registraduría, ICETEX, and the Fiscalía General de la Nación. It also warned about a separate mass campaign aimed at multiple state entities in Colombia. At the same time, the city government of Santiago de Cali issued a preventive alert over a malicious email, and Caracol Radio reported unconfirmed developments in the attack on Ecopetrol.
What did Colombia’s Police warn about?
The CC-CSIRT advisory, released on July 27, 2026, focused on deception attempts that seek to impersonate public agencies familiar to users. In practice, that means emails and messages using the identity of institutions such as the Registraduría, ICETEX, and the Fiscalía to make malicious payloads or phishing attempts look legitimate.
The alert was not limited to those three names. Police also reported a mass campaign against multiple state entities, broadening the scope of the activity they detected and suggesting sustained interest in Colombian public institutions.
What happened in Cali?
In the same pattern of pressure against the public sector, the Santiago de Cali city government issued a preventive alert on July 28, 2026, after a malicious email began circulating. The message appeared to be tied to a judicial process and was designed to trick public employees.
Cali’s warning reinforces the pattern described in the national alerts, with lures built around sensitive issues and administrative contexts to raise the chances that someone will open them.
What was reported about Ecopetrol?
In parallel, Caracol Radio reported, citing sources in the Fiscalía, that the attack on Ecopetrol may have involved access through a third party with administrator privileges and the use of Kali Linux. The report also made clear that the investigation was still in the inquiry stage, so that scenario was not definitively confirmed.
A day later, the outlet said that, according to an expert cited in its coverage, part of the information stolen from Ecopetrol was already on the dark web. That claim was also presented as an expert-source reference, not as a final conclusion from the official investigation.
The incidents reported in Colombia add to earlier investigations into campaigns targeting government and education organizations in the country, including one attributed to BlindEagle by Zscaler. The available material also includes an active campaign aimed at government and education entities in Colombia, although without attribution to a known APT in that case.
Sources
- BlindEagle APT: DCRAT & Caminho Malware Target Colombian Government Agencyzscaler.com· Zscaler
- Campaña de malware activa apunta a entidades gubernamentales y de educación en Colombiaeset.com· ESET
- Alertas y tips | Equipo de Respuesta a Incidentescc-csirt.policia.gov.co· CC-CSIRT Policía de ColombiaUnverified URL
- ¡Atención! Alcaldía de Cali alerta sobre correo con archivo maliciosointranet.cali.gov.co· Alcaldía de Santiago de Cali
- Panorama del cibercrimen en América Latina y el Cariberecordedfuture.com· Recorded Future
- Así se orquestó el ciberataque a Ecopetrol: Fiscalía investigacaracol.com.co· Caracol Radio
- “La información ya se encuentra en la dark web”: experto sobre ciberataque a Ecopetrolcaracol.com.co· Caracol Radio



