CiberLATAMbywhalemate

Colombia Warns on Phishing

Colombia’s police flagged campaigns impersonating state agencies, plus a mass operation targeting multiple government entities.

Whalemate Labs · AI-assisted researchPublished:Updated 2 min read

Colombia’s police, through CC-CSIRT, issued alerts on malware and phishing campaigns impersonating the Registraduría, ICETEX and the Fiscalía General de la Nación, along with another mass operation aimed at multiple state entities in the country.

Colombia’s Police, through CC-CSIRT, issued alerts about malware and phishing campaigns impersonating the Registraduría, ICETEX, and the Fiscalía General de la Nación. It also warned about a separate mass campaign aimed at multiple state entities in Colombia. At the same time, the city government of Santiago de Cali issued a preventive alert over a malicious email, and Caracol Radio reported unconfirmed developments in the attack on Ecopetrol.

What did Colombia’s Police warn about?

The CC-CSIRT advisory, released on July 27, 2026, focused on deception attempts that seek to impersonate public agencies familiar to users. In practice, that means emails and messages using the identity of institutions such as the Registraduría, ICETEX, and the Fiscalía to make malicious payloads or phishing attempts look legitimate.

The alert was not limited to those three names. Police also reported a mass campaign against multiple state entities, broadening the scope of the activity they detected and suggesting sustained interest in Colombian public institutions.

What happened in Cali?

In the same pattern of pressure against the public sector, the Santiago de Cali city government issued a preventive alert on July 28, 2026, after a malicious email began circulating. The message appeared to be tied to a judicial process and was designed to trick public employees.

Cali’s warning reinforces the pattern described in the national alerts, with lures built around sensitive issues and administrative contexts to raise the chances that someone will open them.

What was reported about Ecopetrol?

In parallel, Caracol Radio reported, citing sources in the Fiscalía, that the attack on Ecopetrol may have involved access through a third party with administrator privileges and the use of Kali Linux. The report also made clear that the investigation was still in the inquiry stage, so that scenario was not definitively confirmed.

A day later, the outlet said that, according to an expert cited in its coverage, part of the information stolen from Ecopetrol was already on the dark web. That claim was also presented as an expert-source reference, not as a final conclusion from the official investigation.

The incidents reported in Colombia add to earlier investigations into campaigns targeting government and education organizations in the country, including one attributed to BlindEagle by Zscaler. The available material also includes an active campaign aimed at government and education entities in Colombia, although without attribution to a known APT in that case.

Sources

View all