Colombia Warns on Phishing
Colombia’s police flagged campaigns impersonating state agencies, plus a mass operation targeting multiple government entities.
Colombia’s police, through CC-CSIRT, issued alerts on malware and phishing campaigns impersonating the Registraduría, ICETEX and the Fiscalía General de la Nación, along with another mass operation aimed at multiple state entities in the country.
Colombia’s police, through CC-CSIRT, issued alerts about malware and phishing campaigns impersonating the Registraduría, ICETEX and the Fiscalía General de la Nación. The agency also warned about another mass campaign aimed at multiple state entities in Colombia.
Official alerts
The CC-CSIRT notice, released on July 27, 2026, focused on deception attempts designed to pose as public institutions familiar to users. In practice, that means emails and messages using the identity of agencies such as the Registraduría, ICETEX and the Fiscalía to lend legitimacy to malicious payloads or phishing attempts.
The warning was not limited to three names. Police also reported a mass campaign targeting multiple state entities, widening the scope of the activity detected and showing sustained interest in Colombian public agencies.
Another front against officials in Cali
Along the same line of pressure on the public sector, the city government of Santiago de Cali issued a preventive alert on July 28, 2026, about a malicious email in circulation. The message appeared to be tied to a legal proceeding and was meant to deceive officials.
Cali’s warning reinforces the pattern described in the national alerts, with lures designed to exploit sensitive topics and administrative contexts to increase the chance of opening the message.
The Ecopetrol case remains under investigation
Meanwhile, Caracol Radio reported, citing sources within the Fiscalía, that the attack on Ecopetrol may have involved access through a third party with administrator privileges and the use of Kali Linux. The coverage also made clear that the investigation was still in the inquiry stage, so that scenario had not been definitively confirmed.
A day later, the outlet reported that, according to an expert quoted in its coverage, part of the information stolen from Ecopetrol was already on the dark web. That claim was also presented as an expert-source reference, not as a final conclusion from the official investigation.
The reported incidents in Colombia add to earlier investigations into campaigns aimed at government and education organizations in the country, including one attributed to BlindEagle by Zscaler. Available material also describes an active campaign targeting government and education entities in Colombia, although without attribution to a known APT in that case.
Sources
- BlindEagle APT: DCRAT & Caminho Malware Target Colombian Government Agencyzscaler.com· Zscaler
- Campaña de malware activa apunta a entidades gubernamentales y de educación en Colombiaeset.com· ESET
- Alertas y tips | Equipo de Respuesta a Incidentescc-csirt.policia.gov.co· CC-CSIRT Policía de ColombiaUnverified URL
- ¡Atención! Alcaldía de Cali alerta sobre correo con archivo maliciosointranet.cali.gov.co· Alcaldía de Santiago de Cali
- Panorama del cibercrimen en América Latina y el Cariberecordedfuture.com· Recorded Future
- Así se orquestó el ciberataque a Ecopetrol: Fiscalía investigacaracol.com.co· Caracol Radio
- “La información ya se encuentra en la dark web”: experto sobre ciberataque a Ecopetrolcaracol.com.co· Caracol Radio



