Colombia logs 1.3 million cyber detections
Trellix counted 1.3 million detections in six months in Colombia, with banking, government and health accounting for most activity.
Colombia registered about 1.3 million cyberthreat detections in six months, according to a Trellix report cited by local media. The largest share was concentrated in banking and financial services, with 55.8% of detections, followed by government at 23.1% and health at 6.1%. At the same time, the Financial Superintendency stepped up a campaign against phishing and deceptive links, while an OSINT radar reported an unconfirmed sample of alleged leaks that would include Banco de Bogotá, Banco Popular and ICFES.
Colombia recorded about 1.3 million cyberthreat detections in six months, according to a Trellix report cited by local technology media. The same material places banking and financial services at the center of that activity, with 55.8% of detections, followed by government at 23.1% and health at 6.1%. At the same time, an official public campaign stressed phishing and digital fraud, while an OSINT radar circulated a non-validated sample of alleged leaks that would include Banco de Bogotá, Banco Popular and ICFES.
Where did attack pressure concentrate?
The heaviest load fell on financial systems and official identity infrastructure, according to the coverage summarizing the Trellix report. Technocio said the banking and financial sector absorbed 55.8% of detections, while Tecnogus added that government identification tools and financial transfer channels faced the greatest pressure.
That split leaves Colombia with a sharply defined attack surface in payment services, account access and state validation mechanisms. Health, at 6.1%, shows that the activity was not limited to banking and government, although those two segments continued to set the pace.
What kinds of campaigns are active?
Colombia's Financial Superintendency launched a public awareness campaign on digital fraud, with a focus on phishing, fake messages and deceptive links. The effort was carried out with ColCERT and the Ministry of ICT, as part of a strategy aimed at users of the financial system.
That official message matches the kind of pressure described in Trellix-based coverage, where vectors tied to payments and official identity appear most exposed. The available material does not detail individual campaigns, but it does show a steady institutional focus on credential theft and messaging-based deception.
What is known about the alleged leaks?
An independent social media radar reported a supposed aggregation of data leaks that could include Banco de Bogotá, Banco Popular and ICFES as potential victims. However, the analysis itself said the package's authenticity had not yet been confirmed and that only an initial, unvalidated sample was available.
For that reason, the finding should be read as a preliminary alert, not as confirmation of an incident. Based on the information provided, there is no official validation of the package and no additional evidence to establish the real scope of the alleged data.
What does the threat actor tracking say?
APT-C-36 is a group suspected of operating in South America and linked by the source to campaigns against government institutions and financial and energy-sector entities in Colombia and other Latin American countries. In the available material, the group appears as a relevant actor for understanding the continued pressure on strategic sectors.
The reference to the group adds to the regional picture described by the sources, where digital fraud campaigns, mass detections and early leak reports coexist. Together, they point to an environment with sustained focus on banking, government, payments and official identity, without the material allowing all of those events to be attributed to a single actor.
Sources
- El reto de proteger servicios básicos y puertos frente a ciberataques en el paísacis.org.co· ACIS
- APT-C-36 (G0099) | Threat Actor Indexapt.controlassurance.com· Threat Actor Index
- Resumen de entidades supuestamente afectadas en filtración de datos agregada (Banco de Bogotá, Banco Popular, ICFES) — estado NO confirmadox.com· VECERTRadar (perfil OSINT en X)
- Campaña #LaSeguridadDigitalNosUne sobre phishing y fraudes digitales, en coordinación con ColCERT y MinTICx.com· Superintendencia Financiera de Colombia
- Colombia registra 1,3 millones de detecciones de ciberamenazas en seis mesestechnocio.com· Technocio
- Colombia registra 1,3 millones de ciberamenazas en 6 mesestecnogus.com.co· Tecnogus



