Situación Nacional de Ciberseguridad - Junio 2026 - Colombia
Colombia ended June with 45 incidents, 18 fraud cases, and 26 regulatory moves in a month marked by leaks and critical alerts.
Key findings
- Colombia closed June with 45 documented incidents, and the leading threat was incident exposure, leaks, and unauthorized access campaigns.
- The Defensores de la Patria leak was the largest public event, with 1.4 million records exposed and data from government officials and .gov.co accounts.
- The presidential runoff ended without cybersecurity incidents on election infrastructure, but CNE ecosystem credentials were exposed in clandestine channels.
- FortiBleed left Colombia among the hardest-hit countries, with more than 2,400 exposed administration interfaces and 27 affected organizations.
- Law 2573 of 2026 tightens digital identity controls and shifts the burden to financial institutions, telecoms, and retailers to prove verification controls.
- Fraud and phishing pressure continued to grow, with campaigns by the SIC and the Financial Superintendence focused on prevention and response.
- In June, Colombia remained one of the most attacked countries in Latin America, with high-risk signals in the public sector, finance, health, education, and BPO.
Monthly reference modules
These modules are automatically completed with verified facts and sources from the period. They are the recurring reading month after month, and the later analysis develops the cases without repeating this summary.
June in Colombia
June left Colombia with an uneasy mix of volume, public exposure and regulatory pressure. The period’s indicators show 45 documented incidents, 18 fraud or phishing cases, 9 ransomware or extortion episodes, 26 regulatory moves and 9 critical CVEs mentioned. Incidents were the dominant threat, not because there were no concrete campaigns, but because the month was shaped by alerts, verified leaks, exposed credentials and tighter scrutiny of sensitive infrastructure.
The strongest signal came from two fronts. On one side, the electoral ecosystem closed the presidential runoff without cybersecurity incidents affecting election infrastructure, according to ColCERT and the Registraduría, but with findings tied to exposed institutional credentials, identity spoofing and disinformation narratives linked to fraudulent domains and bots. On the other, public debate centered on the leak of data from Defensores de la Patria, with 1.4 million records exposed online, along with information tied to officials, institutional email accounts and precise geographic locations in part of the database.
The attack surface kept expanding alongside pressure on platforms and services. Semana and Portafolio place Colombia among the most attacked countries in Latin America, with a regional concentration of incidents and a May crisis that continued to have reputational and operational effects during June. Added to that were CC-CSIRT warnings about malware campaigns, alert AL-20260619-101 for FortiBleed and tracking of actively exploited vulnerabilities, a combination that pushed the agenda back toward early detection and credential rotation.
On the regulatory front, the country made important moves. Law 2573 of 2026, the SIC campaign against identity spoofing, the Superintendencia Financiera’s new tool against fraud, and the resolutions from health, transport and the Presidency reinforce a tougher line on identity validation, traceability, data protection and information governance. The regulatory message is clear, Colombia is raising the compliance bar at the same time digital fraud is gaining traction.
Colombia National Monthly Overview
Colombia moved through June under high risk. That assessment does not come from a single isolated case, but from a combination of verified signals, 45 documented incidents, large-scale leaks, exposed credentials, malware alerts, fraud campaigns, and a regulatory package that explicitly acknowledges the deterioration of the threat environment. The volume and severity together were enough to make the month one of high operational pressure for both public and private sectors.
The activity was not concentrated in a single type of actor. It included extortion without classic encryption, identity fraud, phishing, credential exposure, and critical vulnerabilities in widely used products, from Fortinet to LiteLLM, Android, and Cisco SD-WAN. At the same time, the institutional ecosystem responded with stronger monitoring, prevention campaigns, and rules that are beginning to turn into formal obligations what had previously been treated more as good practice than a requirement.
The regional reading supports that conclusion. Semana and Portafolio agree that Colombia ranked as the third most targeted country in Latin America, with 8% of recent regional incidents. In other words, June did not only show that the country is under pressure, it also confirmed that this pressure is now visible at the Latin American scale and that the exposure of Colombian sectors has become part of the regional problem, not a local anomaly.
Colombia threat indicators for the period
| Indicator | Value |
|---|---|
| Documented incidents | 45 |
| Documented ransomware or extortion cases | 9 |
| Documented fraud or phishing cases | 18 |
| Documented regulatory moves | 26 |
| Critical CVEs mentioned | 9 |
| Sectors with at least one documented event | 8 |
| Dominant threat of the month | Incidents (45 events) |
| Events with direct source confirmation | 89% |
| Comparative baseline | No comparative baseline, it is the first archived period with this indicator format for this country |
Relevant incidents in Colombia
Presidential election and election cyber defense by ColCERT and Registraduría
The most sensitive case of the month was the monitoring of the presidential runoff on June 20. Boletín PMU Ciber Electoral 2026 N.º 005 reported that no cybersecurity incidents were recorded on electoral infrastructure and that system availability remained stable. Registraduría’s SOC operated normally, and traffic was absorbed without denial-of-service attacks or impact on the WAF.
That result should not be read as a lack of risk. The same bulletin described an exposed electoral ecosystem, with CNE institutional credentials found on Telegram and underground forums, along with identity spoofing through fraudulent domains and bots. The operation was completed without interruptions, but the environment was far from benign.
Confirmed Defensores de la Patria leak
The leak linked to Defensores de la Patria was the month’s most consequential communications event. MuchoHacker.lol reported that at least 1.4 million Colombians were exposed online, with public access to data such as name, ID document, mobile number, email, gender, date of birth, geographic location and cross-references between users. The same coverage added that 149.995 records contained precise coordinates.
La Silla Vacía, based on an investigation by CLIP and other partner media, confirmed that the records were public and unprotected on the internet. It also noted that the data included emails from public officials and more than 5.000 institutional addresses with the .gov.co domain. The platform denied the leak and claimed digital sabotage, but the material published by the journalistic coverage sustained the existence of the exposed file.
FortiBleed and exposure of Fortinet interfaces in Colombia
ColCERT issued alert AL-20260619-101 on the global FortiBleed campaign. The bulletin described an international-scale impact affecting approximately 73.900 Fortinet devices in 194 countries, with more than 2.400 exposed management interfaces in Colombia and 27 affected organizations, some in the public sector.
The campaign was not tied to electoral infrastructure, but it was flagged as a preventive risk for the public sector. This matters for two reasons, first because it shows a very broad exposure vector in edge infrastructure, and second because it confirms that state monitoring was not focused only on the electoral domain, but on the technology perimeter of multiple entities.
Malware findings and compromise in Colombia
CC-CSIRT published Informational Bulletin No. 038 on June 16 with multiple indicators of compromise tied to malware campaigns in the country. The document was not a generic warning, but an operational support piece to update detection mechanisms and strengthen controls in exposed organizations.
In the same vein, the period’s indicators show that this was not a month dominated by a single vector. The consolidated evidence points to incidents, leaks, social engineering, malware campaigns and regulatory moves happening at the same time. The picture is of an attack surface being actively worked by adversaries rather than by accidental noise.
Attack signals on mobility and operational sectors
Material from X corroborated with in-depth research included a lead on a mobility data leak in Bogotá and another on a possible fine-deletion case attributed by attackers in Bogotá Mobility systems. This report only takes what was confirmed by the available sources, that is, the signal of activity and the exposure context, not definitive validation of a massive alteration of records.
That kind of event helps explain June’s pattern, where attacks were not limited to credential theft or political leaks. There were also signals involving administrative systems and urban services, widening concern to everyday operations with direct impact on citizens and public administration.
Threats and active campaigns in Colombia
Ransomware and extortion in Colombia
The month was not defined by classic encrypting ransomware, but by extortion centered on data theft, remote access, and pressure on corporate victims. Silent Ransom Group was the most useful reference for understanding that shift. The reports cited by SOSRansomware, Rescana, SocPrime and TechCrunch describe a model that prioritizes vishing, phishing, legitimate remote access, USB devices, and even the insertion of people posing as IT technicians to gain physical access to offices.
In Colombia, that tactic matters because it fits professional services, BPO, education, health care and corporate environments, the same sectors Semana identified among the hardest hit during the May crisis and which kept appearing in June as higher-risk areas. There is no evidence in the material of a ransomware encryption incident in Colombia during the month, but there is evidence of sustained pressure on data and credentials that feeds extortion and fraud.
Fraud and phishing in Colombia
Fraud was the second major theme of the period. The Superintendencia Financiera launched the microsite "Protégete de los fraudes", focused on phishing, smishing and warning signs tied to digital financial transactions. The SIC, meanwhile, rolled out a campaign in response to the rise in identity theft in the country, supported by complaints received since 2022.
Law 2573 of 2026 strengthens this front by requiring identity validation, traceability and response mechanisms for impersonation, with direct effects on banks, fintechs, telecoms and retailers with lending capabilities. In June, the issue was no longer just a warning. Regulators began turning it into a process, evidence and response obligation.
APT, hacktivism and exposure campaigns in Colombia
There was not enough verifiable material to attribute a classic, nationwide APT campaign in June. There was, however, evidence of pressure aimed at public exposure, impersonation and disinformation. The electoral bulletin from ColCERT and Registraduría referred to fraudulent domains and bots, manipulated narratives with artificial intelligence, and credential findings in clandestine forums. It is a surface where hacktivism and criminal operations overlap without requiring major technical sophistication.
That mix also appears in the Defensores de la Patria leak. The dispute between a platform that denies the breach and media outlets that say they verified public access to the data creates a typical digital-pressure scenario, where the exposure of information serves political, reputational and operational purposes at the same time.
Critical vulnerabilities affecting Colombia
| CVE | Software | Exploitation | Source |
|---|---|---|---|
| CVE-2026-42824 | Microsoft 365 Copilot Enterprise Search | Email and corporate data exfiltration, disclosed as a critical chain | Ecosistema Startup |
| CVE-2026-47101 | LiteLLM | Privilege escalation chain and remote code execution | Ecosistema Startup |
| CVE-2026-47102 | LiteLLM | Privilege escalation chain and remote code execution | Ecosistema Startup |
| CVE-2026-40217 | LiteLLM | Privilege escalation chain and remote code execution | Ecosistema Startup |
| CVE-2026-42271 | LiteLLM | Added to CISA KEV for active exploitation | Ecosistema Startup |
| CVE-2026-20245 | Cisco Catalyst SD-WAN | Privilege escalation in control components | Cisco |
| CVE-2026-20262 | Cisco vManage SD-WAN | Arbitrary file write on affected systems | Cisco |
| No CVE assigned in the source | FortiBleed in Fortinet | Mass credential abuse and exposure of management interfaces | ColCERT |
| No CVE assigned in the source | Android June 2026 | 18 critical vulnerabilities patched, with signs of active exploitation in one of them | Notimerica, Infobae |
Regulation and compliance in Colombia
Law 2573 of 2026 and its impact on digital identity in Colombia
Law 2573 of 2026 was the month’s most sensitive regulatory change on fraud and identity. The law expands habeas data, privacy, and reputation rights in cases of identity theft, and requires financial institutions, fintechs, SEDPE, telecom operators, and credit merchants to put in place reasonable and sufficient controls to verify identity.
The strongest part of the regime is the dynamic burden of proof. If a person files a claim for identity theft, the institution must show that its controls worked. That shifts the center of the dispute, written procedures are no longer enough, their effectiveness has to be provable. In addition, the material from Facephi, Cuatrecasas, and DataCrédito Experian agrees that there are now mechanisms to suspend collections, correct negative reports, and provide specific treatment for victims of identity fraud.
SIC and the anti-identity theft campaign in Colombia
The Superintendence of Industry and Commerce launched a campaign to prevent digital fraud and warned about the rise in identity theft. Cuatrecasas also reported a draft resolution that amends Title V of the Single Circular, with new rules on certification of authorizations, blocking of information, prior notice before negative reporting, data retention, and annual reporting of complaints.
The practical takeaway for entities is straightforward. Compliance is no longer limited to document formalities. Institutions are now expected to respond to claims, keep authorization traceability, and apply differentiated treatment for fraud victims. The regulatory framework is becoming more aligned with the operational pressure created by the crime.
Health, transportation, and public administration in Colombia
Resolution 1058 of 2026 from the Ministry of Health adopted the National Health Quality Policy 2026 to 2035 and set standards for patient safety, data protection, and technical competence in remote services. Resolution 8150 from the Superintendency of Transportation, meanwhile, tied the processing of sensitive data, such as biometric and audiovisual data, to Law 1581 of 2012 and defined obligations for the data processor.
In the Presidency, Resolution 0419 promoted the strategic use of data, analytics, open data, and interoperability. Taken together, these measures show a public administration that is beginning to better organize data use, while also recognizing that the data requires stronger controls, traceability, and clearer limits.
Superintendency of Finance and internal control in Colombia
Resolution 0877 of June 11 created the roles of Information Security and Business Continuity Officer, and Personal Data Protection Officer within the Superintendency of Finance. It is a sign of institutional maturity, because it moves the security discussion from the technical level to corporate governance and compliance.
The same agency launched the "Protect Yourself from Fraud" tool, with practical tips to avoid phishing and smishing, and with an explicit reference to filing a complaint through CAI Virtual or the Prosecutor’s Office when a scam has occurred. The month’s financial agenda combined education, institutional design, and preventive regulation.
Most affected sectors in Colombia
The sectors with documented incidents in June were eight, but the distribution was uneven. Health, education, BPO and corporate continued to appear as the most exposed areas, according to Semana. The public sector also came under pressure from electoral ecosystem credentials, the FortiBleed campaign, and several resolutions aimed at improving controls and responsibility profiles.
At the same time, the financial sector stood out from both a regulatory and fraud perspective. Law 2573, the SIC campaign, and the Superintendency of Finance tool show that identity fraud is hitting that vertical head on. It is no coincidence that the month produced so many items on user verification, transaction validation, and report correction.
Health deserves special mention. On one hand, it was one of the sectors highlighted in regional incident reports. On the other, Resolution 1058 added requirements for care security, data, and remote service delivery. That suggests exposure is not only criminal, but also regulatory and operational. The sector needs to ensure continuity, confidentiality, and the validity of clinical information at the same time.
Transportation and public administration closed the list of visible areas in the period. The handling of biometrics, audiovisual materials, and surveillance infrastructure, along with the push for strategic data use in public agencies, reinforces the idea that June’s risks did not concentrate in a single vertical, but moved across layers of state management and critical services.
Trends and signals to watch in Colombia
There is no comparative baseline for this country, because this is the first archived period in this indicator format. For that reason, it would not be accurate to invent a month-over-month change. Even so, there are several signals to track closely starting in June.
The first is the growing weight of identity theft. The SIC, Law 2573, the Superintendencia Financiera and DataCrédito Experian all point in the same direction. Identity verification has stopped being a peripheral issue and has become central to anti-fraud compliance.
The second is the persistence of credential exposure campaigns and public leaks. The CNE case, the Defensores de la Patria leak and the indicators of compromise released by CC-CSIRT suggest that the credential front remains an important entry point. It also signals that the underground market remains active and interested in Colombian data.
The third is exposure at the technology edge. FortiBleed and references to actively exploited vulnerabilities show that perimeter devices, management systems and widely deployed platforms remain a priority for attackers. This applies both to the public sector and to companies with limited external visibility into their own assets.
The fourth signal is rising regional pressure. Semana and Portafolio already place Colombia among the most attacked countries in Latin America. That is not just a regional statistic, it is also a warning about volume, appeal for cross-border campaigns and the buildup of adverse signals in sectors with heavy digital dependence.
Security recommendations for teams in Colombia
First, review controls for exposed credentials, both in institutional accounts and third-party access. June showed that attackers continue to exploit leaks and stealer logs as operational inputs. Rotation, revocation, and monitoring for reuse should be top priorities.
Second, strengthen digital identity handling. Fraud, risk, compliance, and cybersecurity teams should work from shared metrics for validation, traceability, and impersonation response. If the organization cannot demonstrate controls, the new regulatory architecture leaves it in a weak position.
Third, review perimeter exposure and administration platforms. FortiBleed offered a clear example of how a widely deployed vendor can become a systemic risk vector. It is worth inventorying exposed interfaces, hardening, MFA, admin segmentation, and criteria for urgent patching.
Fourth, strengthen detection of phishing, smishing, and vishing. The Superintendence of Finance campaign and reports on Silent Ransom Group show that the human factor remains critical. Teams should combine training with controls for email, messaging channels, and stronger authentication.
Fifth, formalize response to leaks with regulatory impact. It is not enough to investigate the incident, evidence must be preserved, legal leadership activated, and external communication defined. In a month like June, when public exposure of databases and debate over the authenticity of the leak were both in play, response speed matters as much as technical quality.
Material limitations
The report was written exclusively from the material provided. No internet search was conducted, and no external sources outside the authorized list were used.
There is no comparative baseline for the previous month, so no quantitative month-over-month trends were built. Comparisons are limited to a qualitative reading of the period and to regional references contained in the sources.
Some of the material is presented as attributed by the source or with an explicit degree of uncertainty, so in those cases cautious wording and consolidation of confirmed facts were prioritized. When the source did not allow a point to be verified, it was not treated as certain.
Technical appendix: indicators of compromise and TTPs
CC-CSIRT Information Bulletin No. 038 reported multiple indicators of compromise linked to malware campaigns in Colombia, and PMU Ciber Electoral 2026 Bulletin No. 005 issued recommendations on credential rotation, multifactor authentication, and stronger monitoring against impersonation and account exposure. In addition, the consolidated material on Silent Ransom Group describes vishing and phishing TTPs, abuse of remote access tools, use of RMM, USB, and concealed physical access by fake support technicians. In the case of FortiBleed, the source highlighted exposure of management interfaces and credential abuse on Fortinet devices.
Sources
- Colombia registró 10,9 billones de intentos de ciberataques y concentra el 8 % de los incidentes de América LatinaSemana
- El grupo Silent Ransom extorsiona sin cifrar ningún archivoSOSRansomware
- Regulación de datos personales en Colombia: fortalecimiento del régimen sancionatorio y proyeccionesGarrigues
- Boletín Informativo Nro. 038 ¡Alerta! Indicadores de compromiso de campañas maliciosasCC-CSIRT Policía Nacional de Colombia
- Vulnerabilidades en explotación activa (CISA KEV) — radar de amenazasIngeniería Telemática
- Inicia Conecta Colombia 2026: IA, ciberseguridad y el futuro de las telecomunicacionesNewslinereport
- Boletín PMU Ciber Electoral 2026 N.º 005 – Segunda vuelta presidencialColCERT / Registraduría Nacional del Estado Civil
- Silent Ransom Group (Luna Moth) extortion attacks target U.S. law firms via remote access tools and social engineeringRescana
- Silent Ransom Group Uses USB and RMM for Data TheftSocPrime
- Google and FBI warn of ransomware group that sends fake IT workers to hack victims in personTechCrunch
- Colombia entra en una nueva fase de riesgo digital: ya es el tercer país más atacado de América LatinaPortafolio
- Ley 2573 de 2026: obligaciones para bancos y telcos en casos de suplantación de identidad digital en ColombiaFacephi
- Boletín Minhacienda Capítulo Superintendencia Financiera — Junio 2026Superintendencia Financiera de Colombia
- Resolución 1058 de 2026 Ministerio de Salud y Protección SocialAlcaldía Mayor de Bogotá D.C. / Ministerio de Salud y Protección Social
- MSPS Resolución 001058 de 2026Rama Judicial de la República de Colombia / Ministerio de Salud y Protección Social
- Resolución 8150 de 2026Superintendencia de Transporte
- Resolución 0419 del 9 de junio de 2026Departamento Administrativo de la Presidencia de la República
- La SIC alerta por aumento de suplantación de identidad en el país y lanza campaña para prevenir fraudes digitalesSuperintendencia de Industria y Comercio
- Ley 2573 de 2026Secretaría del Senado de la República de Colombia
- Protección financiera y suplantaciónCuatrecasas
- Filtración confirmada expone datos de 1,4 millones de colombianos de la plataforma de Defensores de la PatriaMuchoHacker.lol
- Datos de funcionarios públicos aparecen en registro de campaña de AbelardoLa Silla Vacía
- Defensores de la Patria desmiente falsa filtración de datos y denuncia intento de sabotaje digital contra la campañaDefensores de la Patria
- Movilidad de Bogotá: atacantes dicen haber borrado multasMuchoHacker.lol
- Boletín PMU Ciber Electoral 2026 No. 001 – Segunda vuelta presidencialColCERT
- Copilot y LiteLLM: 2 vulnerabilidades críticas en junio 2026Ecosistema Startup
- Google corrige más de 100 vulnerabilidades en Android, una de ellas de día cero y bajo explotación activaNotimerica
- Google corrige más de 100 vulnerabilidades en Android, una de ellas de día cero y bajo explotación activaInfobae
- Remediate Catalyst SD-WAN Security Advisory (Junio de 2026)Cisco
- Principales amenazas de seguridad en dispositivos móviles empresariales en 2026ManageEngine
- Panorama de amenazas para pymes, 2026: IA falsa, phishing y ransomwareSecurelist / Kaspersky
- Ciberseguridad Industrial: Reporte Fortinet 2026ITware LATAM
- Ciberseguridad 2026: 68% de empresas en LATAM ya sufrió ataquesEcosistema Startup
- Trazabilidad, identidad digital y fraude: lo que exige la Ley 2573 de 2026DataCrédito Experian
- Colombianos cuentan con una nueva herramienta para reforzar la defensa frente al fraude financieroSuperintendencia Financiera de Colombia
- Protección de infraestructura crítica. Experiencia internacionalBiblioteca del Congreso Nacional de Chile
- Las 5 amenazas de ciberseguridad que están redefiniendo las empresas en 2026AMITI
