CiberLATAMbywhalemate

Colombia Warns on Phishing

Colombia’s police flagged campaigns impersonating state agencies, plus a mass operation targeting multiple government entities.

Whalemate Labs · AI-assisted researchAug 2, 20262 min read

Colombia’s police, through CC-CSIRT, issued alerts on malware and phishing campaigns impersonating the Registraduría, ICETEX and the Fiscalía General de la Nación, along with another mass operation aimed at multiple state entities in the country.

Colombia’s police, through CC-CSIRT, issued alerts about malware and phishing campaigns impersonating the Registraduría, ICETEX and the Fiscalía General de la Nación. The agency also warned about another mass campaign aimed at multiple state entities in Colombia.

Official alerts

The CC-CSIRT notice, released on July 27, 2026, focused on deception attempts designed to pose as public institutions familiar to users. In practice, that means emails and messages using the identity of agencies such as the Registraduría, ICETEX and the Fiscalía to lend legitimacy to malicious payloads or phishing attempts.

The warning was not limited to three names. Police also reported a mass campaign targeting multiple state entities, widening the scope of the activity detected and showing sustained interest in Colombian public agencies.

Another front against officials in Cali

Along the same line of pressure on the public sector, the city government of Santiago de Cali issued a preventive alert on July 28, 2026, about a malicious email in circulation. The message appeared to be tied to a legal proceeding and was meant to deceive officials.

Cali’s warning reinforces the pattern described in the national alerts, with lures designed to exploit sensitive topics and administrative contexts to increase the chance of opening the message.

The Ecopetrol case remains under investigation

Meanwhile, Caracol Radio reported, citing sources within the Fiscalía, that the attack on Ecopetrol may have involved access through a third party with administrator privileges and the use of Kali Linux. The coverage also made clear that the investigation was still in the inquiry stage, so that scenario had not been definitively confirmed.

A day later, the outlet reported that, according to an expert quoted in its coverage, part of the information stolen from Ecopetrol was already on the dark web. That claim was also presented as an expert-source reference, not as a final conclusion from the official investigation.

The reported incidents in Colombia add to earlier investigations into campaigns aimed at government and education organizations in the country, including one attributed to BlindEagle by Zscaler. Available material also describes an active campaign targeting government and education entities in Colombia, although without attribution to a known APT in that case.

Sources

View all