Colombia Sees Rise in AI Phishing
Bloomberg Línea reported hyperrealistic phishing and polymorphic malware in Colombia. Sumsub also flagged more account takeover attempts.
In Colombia, hyperrealistic phishing and polymorphic malware were the most detected cyberattack methods in the first half of 2025, according to Bloomberg Línea, in a regional context where generative AI was amplifying attacks across Latin America. Bloomberg Línea also said the same technology was being used on the defensive side to identify incidents and speed up response, with AI engines cutting false positives in the region.
Offensive and defensive AI on the same board
In Colombia, hyperrealistic phishing and polymorphic malware were the most detected cyberattack methods in the first half of 2025, according to Bloomberg Línea. The report placed that finding in a regional setting where generative AI was amplifying attacks across Latin America, with an impact on several sectors, including financial services.
The same coverage said AI was also being used on the defensive side. According to the report cited by Bloomberg Línea, AI engines were helping identify incidents, speed up response, and reduce false positives across the region. The technology therefore appeared on both sides of the conflict, supporting more convincing attacks and faster detection systems.
Deepfakes and synthetic identities
Another report, this time from Infosertecla based on a Sumsub study, said that in Colombia account takeover attempts rose 188% and deepfake use increased 77% during the period analyzed in that study. That point should be read cautiously, since the journalistic reference itself presented it as information attributed to Sumsub's research and not as independently confirmed data in this note.
Even so, the coverage described deepfakes and AI-generated identities as growing fraud vectors in the region, with an impact in Colombia as well within the secondary report. The focus is no longer just on malicious emails or links, but on techniques designed to impersonate identities and build trust with synthetic material.
Technical context from Microsoft
Microsoft also published a post about threats in the age of AI that mentioned social engineering backed by LLMs to generate phishing emails as an example of offensive artificial intelligence capabilities. That material was not focused on Colombia, but it helps explain the kind of automation threat actors are already using to make their campaigns more convincing.
Taken together, the reports cited show Colombia already sits within a regional map where AI is speeding up both deception and defensive response, while deepfakes, synthetic identities, and hyperrealistic phishing continue to stand out as vectors to watch closely.
Sources
- La IA potencia los ciberataques en Latambloomberglinea.com· Bloomberg Línea
- Identidades creadas con IA: el nuevo peligro de las estafasinfosertecla.com· Infosertecla
- AILA: Evaluación del Panorama de la Inteligencia Artificial en Colombiaundp.org· PNUD Colombia
- Mantenerse a la vanguardia de los actores de amenazas en la era de la IAnews.microsoft.com· Microsoft
- Colombia le vuelve a apostar al uso ético de la inteligencia artificialminciencias.gov.co· Ministerio de Ciencia, Tecnología e Innovación de Colombia
- Corte Constitucional fija límites al uso de la inteligencia artificial en decisiones judicialeslafm.com.co· La FM
- 46 % de los trabajadores colombianos afirma que podría caer en estafas basadas en la inteligencia artificialacis.org.co· ACIS
- Cinco claves para usar la Inteligencia Artificial con ética, seguridad y transparencia en las organizacionesitsitio.com· ITSitio Colombia



