CiberLATAMbywhalemate

Banco de Bogotá Warns on Digital Fraud

The bank published official channels to help customers spot impersonation attempts during the transfer of more than 250,000 Itaú clients.

Whalemate Labs · AI-assisted researchAug 5, 20262 min read

Banco de Bogotá published security recommendations for the transfer of more than 250,000 Itaú customers and specified its only official channels for SMS, email, WhatsApp and Servilínea, aiming to reduce fraud risk during the migration.

Banco de Bogotá published security recommendations for the transfer of more than 250,000 Itaú customers and specified its only official channels for SMS, email, WhatsApp and Servilínea, aiming to reduce fraud risk during the migration.

The warning comes as the integration could create room for impersonation attempts. According to Infobae Colombia, legitimate text messages from Banco de Bogotá are sent only from specific short codes, while its emails, WhatsApp service and official phone line are limited to the channels published by the bank. The goal is to help customers clearly tell which messages really come from the bank and which could be fraudulent.

The case fits into a regulatory environment in which Colombian authorities have been tightening controls on digital fraud, personal data handling and security in financial services. The Superintendencia Financiera currently has in force External Circular 007 of 2023 on security in digital financial services, External Circular 020 of 2021 on operational risk and cybersecurity management, External Circular 012 of 2024 on financial services security and quality, and Circular Letter 008 of 2024 on operational and cyber incident management.

Also in force is Circular Letter 014 of 2024, focused on reporting fraud and cybersecurity incidents, in a context where the Superfinanciera has warned about fraud methods in consumer loans and maintains public guidance for preventing fraud and financial crimes. At the same time, the SIC has sanctioned financial sector entities for failures in personal data protection, and has also imposed measures on RappiPay and other companies for noncompliance in that area.

On the institutional side, the Ministry of ICT said the country already has the National Cybersecurity Network, while the National Policy on Digital Trust and Security and Decree 1297 of 2022, on open finance in Colombia, round out a framework that also includes oversight of critical technology providers. Asobancaria, meanwhile, has been warning about the growth of phishing in digital banking services and, together with the National Police, has cautioned about electronic fraud in financial services.

Sources

View all