CiberLATAMbywhalemate
Intelligence report

Colombia Cybersecurity Report, September 2026

September ended with rising incidents and regulation, an ICETEX case, pressure on finance and health, and 2 critical CVEs mentioned.

Oct 1, 202617 min read
Colombia Cybersecurity Report, September 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are filled automatically with verified dated facts from the period. Each one states its source base and counting criterion, so the figures reconcile across modules. They serve as the recurring month-by-month reading; the analysis that follows expands on the cases without repeating this summary.

Indicator window: 55 dated facts in September 2026 · 1 from prior months (comparative frame, not monthly volume). Facts from prior months are used only as a comparative frame in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Verified Signal Monthly Panel September 2026 · Colombia Top threat: Incidents (15 of 48 events). Coverage: 55 dated events in September 2026 · 1 of months an… VERIFIED EVENTS 48 period baseline: all counts measured from below on this total RANSOMWARE / EXTORTION 13 1 encrypted asset confirmed · 1 exfiltration no encryption (simple extortion) UNCLASSIFIED INCIDENTS 15 breaches or outages without declared threat type FRAUD / PHISHING 3 documented fraud campaigns REGULATION 9 regulations, resolutions, or sanctions UNIQUE CVEs 2 CVE-2025-25249 / CVE-2026-87902
Verified Signal Monthly Panel — Base: 48 verified dated events for Colombia in the period.
MONTHLY FIXED MODULE Distribution by threat axis September 2026 · Colombia Each incident counts in only one axis, so the total is exactly 48. "Unclassified incidents" is the remainder. Incidents 15 Ransomware 13 Regulation 9 Unclassified 5 Fraud 3 Vulnerabilities 3
Distribution by threat axis — Each incident is assigned to a single axis based on its classification; the total reconciles to the 48 incidents in the period.
FIXED MONTHLY MODULE Sectoral Distribution of Signal September 2026 · Colombia Base: 48 incidents in the period · total 57 because 7 incidents are classified in more than one sector. Other / no sector ident… 24 Public sector / OIV 16 Technology 6 Healthcare 4 Telecom 2 Retail / Consumer 2 Education 2 Finance 1
Sectoral Distribution of Signal — Heuristic sector classification by victim sector. One incident may affect more than one sector, so the total can exceed the base.
MONTHLY FIXED MODULE Critical Infrastructure in Colombia September 2026 · Colombia 3 of 48 facts in the period involve critical infrastructure. One fact may appear in more than one category. Public sector / government 15 Explicit critical infrastructure 1 Telecom / connectivity 1
Critical Infrastructure in Colombia — Verified facts on public sector, utilities and essential services

Monthly executive summary for Colombia

September 2026 in Colombia was defined by operational incidents and a much more active regulatory agenda than the previous month. The period brought an impact at ICETEX due to an incident at an external provider, unauthorized access to the Medellín Metro account on X, ColCERT alerts about credential theft, and a series of regulatory measures on personal data, open finance, critical infrastructure, and digital fraud.

The overall reading for the period is high risk. Not because one attack family expanded on its own, but because service disruptions, more sophisticated fraud campaigns, sustained pressure on banking and healthcare, and signs of tighter regulation all overlapped. In the material analyzed, incidents not otherwise classified were the most common category, with 15 cases, ahead of cases where ransomware or extortion was the primary focus, which totaled 13.

In ransomware and extortion, the pattern was mixed. There was confirmation of operational impact in the case of the regional hospital of Caldas, references to an intrusion with exfiltration at Perimetral Oriental de Bogotá S.A.S., and several mentions of alleged victims on leak sites. In many cases, however, the source did not specify whether there was encryption, exfiltration, or only a claim by the actors. That lack of clarity limits precise attribution, although it does not reduce the signal of pressure on infrastructure, education, energy, and healthcare.

Banking remained the most exposed sector in digital fraud. Lumu described ShadowParasite, a panel that impersonated fifteen Colombian financial institutions and requested six-digit codes, card data, and, in some cases, live facial biometrics. At the same time, the Superintendencia Financiera moved ahead with a roadmap for open finance, new supervisory tools, and guidelines that are pushing the industry toward stricter identity, architecture, and security controls.

September 2026, Colombia1 SepCórdobacontingency11 SepColCERTalert16 SepICETEXincidentSep 17MetroX hackSep 24dataand lawMonth-end with more regulation

Colombia, September 2026: monthly highlights — A concise timeline of the most relevant events of the period, focusing on incidents, fraud, and regulation.

National snapshot for the month in Colombia

Colombia ended September with a broad risk surface, driven by concrete incidents, massive digital fraud, and a regulatory response that is no longer limited to isolated alerts. The verified total for the month was 48 incidents, with 7 sectors hit by at least one documented case and a clear shift in the leading threat, which moved from ransomware in the previous month to incidents in September.

The severity comes not only from the number of cases, but from their nature. ICETEX suffered service disruption after an incident at a third-party provider, Medellín Metro had to recover a compromised account, ColCERT warned about credential theft affecting 27 organizations, and the financial sector concentrated new fraud schemes using automation and AI. All of this unfolded alongside a regulatory agenda covering personal data, critical infrastructure, open finance, digital identity and incident reporting.

The risk reading for Colombia is high. The month showed service disruption, pressure on identities and payment channels, and an institutional response that is active but still fragmented across sectors. The material also suggests that the line between fraud, impersonation, extortion and unauthorized access is becoming increasingly blurred, which complicates both operational response and precise impact measurement.

In the regional context, Colombia sits within a Latin American dynamic where fraud and ransomware campaigns continue to pressure banking, healthcare and public services. The Colombian case is not an exception, but it stands out for the combination of new rules, credential alerts, provider incidents and a financial sector that is investing, at the same time, in digital expansion and stronger controls.

Colombia period indicators

Indicator September 2026 Previous month Change
Verified events in the period 48 122 -74
Time window for the indicators 55 events dated September 2026, 1 from prior months (comparative frame, not monthly volume) Same N/A
Unclassified incidents (breaches or outages) 15 22 -7
Cases with ransomware or extortion as the primary focus 13 66 -53
Confirmed asset encryption 1 0 +1
No-encryption exfiltration (simple extortion) 1 0 +1
Mentioned only on a leak site 1 0 +1
Classification not determinable from the material 10 0 +10
Documented fraud or phishing cases 3 12 -9
Documented regulatory moves 9 6 +3
Critical CVEs mentioned 2 1 +1
Sectors with at least one documented event 7 7 unchanged
Dominant threat of the month Incidents (15 of 48 events) Ransomware (66 of 122 events) shift in focus
Events with direct source confirmation 69% N/A N/A
Aggregated telemetry figures excluded from volume 7 (aggregate attempts or blocks: not incidents with confirmed impact) N/A N/A
Calculation base Verified events in the period: 48 Verified events in the period: 122 N/A
Colombia, monthly comparisonVerified facts and key themes, September 2026 versus the previous monthFactsPrevious factsIncidentsPrevious incidentsFraudPrevious fraudRegulationPrevious regulation
Axis comparison for the period — Comparative reading of the dominant signal type versus the previous month, without mixing telemetry with incidents.

Relevant Incidents in Colombia

ICETEX and the incident at an external provider

ICETEX was one of the month’s most visible operational disruptions. The agency said a security incident at one of its external providers interrupted the availability of some services and processes, triggered containment and forensic analysis, and forced it to keep alternative service channels open while recovery moved forward. The public source did not identify the provider or give technical detail on the scope of the event.

The incident matters for two reasons. First, it shifts the failure point to the digital supply chain. Second, it shows an institutional response coordinated with ColCERT, the SIC and other authorities, suggesting the case was handled as a material incident, although no public confirmation of data exfiltration was made. In the documentation reviewed, the agency said personal data was neither compromised nor exposed.

Medellín Metro and the unauthorized access to X

The Medellín Metro confirmed unauthorized access to its official X account, which was used to publish content unrelated to the transportation system. The agency activated its protocols, regained control of the profile, and clarified that the event was limited to that account, with no compromise of other operational or information systems.

This episode does not rise to the level of a major incident, but it does offer a clear signal about the attack surface of institutional digital identities. The compromised account served as a broadcast channel, not a vector for disrupting core operations. Even so, the case confirms that corporate social media accounts remain sensitive assets for public bodies and infrastructure operators.

ColCERT and the credential theft alert

In September, ColCERT issued a high-risk alert over credential theft that affected 27 organizations in the country as part of a global password-harvesting campaign. The alert added an important technical detail, 2.436 exposed administrative logins on compromised VPN gateways and firewalls, placing Colombia among the countries with the highest exposure of administrative interfaces in that context.

What this signals is not an isolated intrusion, but an access surface that is too exposed for an environment where identity has become the perimeter. The combination of stolen credentials, open administrative interfaces and pressure on authentication systems helps explain why the month was marked by availability incidents and fraud campaigns that exploit valid credentials.

Ministry of Justice and technology recovery

The Ministry of Justice activated a comprehensive technology recovery plan after a cyber breach and reported impacts on systems such as SICOQ and MICC, with partial or unavailable operation depending on the case. The plan included alternative channels for procedures, with support from the Attorney General’s Office, ColCERT, Microsoft’s DART team and BID partners.

Here there was a real operational impact and continuity of service was at risk. The source did not publicly confirm that the case was ransomware, but it did show a major event handled as a high-impact institutional incident. The use of alternative channels and the involvement of external forensic actors reinforce the picture of a material disruption, not a minor one.

Córdoba Governor’s Office and the contingency over departmental revenues

The Córdoba Governor’s Office reported a cyberattack against the technology infrastructure supporting systems of the Departmental Revenue Directorate, with temporary disruption of services and digital channels such as the tax payment portal. The administration activated contingency protocols, but did not confirm whether the incident was ransomware.

This adds to the picture of exposed critical surface in territorial governments. There was no definitive technical attribution, but there was a direct interruption of services that matter to citizens and taxpayers. In a month when attacks on identities, payments and digital channels were recurring, the Córdoba case fits as a disruption that affected service continuity.

Active threats and campaigns in Colombia

Ransomware and extortion, with incomplete classification in most cases

The month produced 13 cases with ransomware or extortion as the main focus, but the source allowed clear classification in only a minority of them. There was one case with confirmed encryption, one with exfiltration without encryption, one that was mentioned only on a leak site, and ten in which the material did not allow the exact impact to be determined. That breakdown means the phenomenon has to be read cautiously, without overinterpreting every claim posted in forums or on leak sites.

In the case of Perimetral Oriental de Bogotá S.A.S., NightSpire said it had carried out an attack and threatened to publish sensitive information. Other sources added alleged exfiltrated data, but there was no independent public confirmation from the company or the regulator. For that reason, the report keeps the classification as a ransomware claim with impact that cannot be conclusively determined.

The only confirmed encryption case in the material analyzed was the regional hospital of Caldas, used by several reports as an example of an intrusion that disrupted technology operations and forced systems to be restored from backups and records to be kept manually. That reference confirms that operational damage and extortion pressure remain very present in healthcare, even if September leaned more toward incidents and fraud than toward major public ransomware campaigns.

Digital fraud, phishing, and AI-powered impersonation

Banking and payment services generated the clearest signs of fraud. Lumu documented ShadowParasite, a fraud panel that impersonates fifteen Colombian financial institutions with a single code base and asks for six-digit verification codes, card data, and, at six entities, live facial biometrics capture. That detail is especially relevant because it combines phishing, credential theft, and bypassing biometric controls.

At the same time, local coverage kept emphasizing vishing, voice deepfakes, and impersonation of official or financial entities. La FM and other outlets repeated response recommendations, while the Superintendence of Finance and the Bank of the Republic reinforced prevention messages. The operational signal is clear, fraud no longer depends only on fake links, but on authentication and verification processes that are being mimicked with considerable precision.

APT and persistent campaigns against public institutions

The month also left traces of persistent campaigns associated with actors such as Blind Eagle or APT-C-36, with lures based on court notices and traffic fines, aimed mainly at public institutions. Although that line appears in material from previous weeks, in September it continued to serve as a reference point for a regional pattern of specialized phishing designed to drop loaders and stay inside institutional networks.

There was no new large-scale attribution during the period that would justify saying the APT campaign changed, but there was a consistent environment of legal and document-based lures. In Colombia, that combination remains effective because it exploits the operational habits of users in government, justice, and other document-heavy services.

Critical vulnerabilities affecting Colombia

CVE Software Exploitation Source
CVE-2025-25249 Fortinet FortiOS, FortiSwitchManager, FortiSASE Active exploitation since at least July 2026 through CAPWAP packets to UDP 5246; CISA added it to KEV on 09-09-2026 ZeroHour
CVE-2026-87902 WordPress 7.1.2 Critical vulnerability fixed by a security update released on 22-09-2026; the material does not document exploitation in Colombia WordPress.org
CVE not specified by the source WordPress 7.1.1 Security and maintenance update released on 17-09-2026; the material does not indicate local exploitation WordPress.org

Regulation and compliance in Colombia

September was a month of intense regulatory activity in Colombia, with bills, consultations, sanctions, and road maps focused on personal data, identity, critical infrastructure, and open finance. The direction is clear, more traceability, more reporting obligations, and stricter demands on security controls and information handling.

The most structural move was Bill 282 of 2026, Constitutional Statute, in the House of Representatives, on personal data protection. The text introduces new legal bases for processing, classifies geolocation and neurodata as sensitive, requires impact assessments for certain processing activities, sets out the appointment of data protection officers in specific cases, and raises fines to as much as 10,000 minimum wages or 5% of the previous year’s operating revenue. It also requires security incidents to be reported within 72 hours and data subjects to be notified when there is a high risk.

The Superintendency of Industry and Commerce’s public consultation on identity verification and personal data processing added a practical layer to the same issue. The process focused on identity verification mechanisms, authentication, biometrics, technical standards, and good practices, with a defined schedule for consultation, participant selection, working sessions, and issuance of the protocol. At the same time, the Constitutional Court upheld the use of biometric data for passports, strengthening the line on robust identification without weakening privacy obligations on its own.

In finance, the Financial Superintendency made several moves at once. It published draft rules for the transitional regime for open finance, announced a road map tied to cybersecurity, privacy, and financial stability standards, and maintained supervision and control tools against money laundering. It also confirmed a sanction against Coltefinanciera for SARLAFT failures, with the fine reduced to 295.5 million pesos.

The other major regulatory line was critical infrastructure. Bill 343 of 2026, in the House of Representatives, filed on September 9, seeks to protect critical infrastructure and the continuity of essential services against actions by organized armed groups, organized crime, and illegal economies. That connects directly with this month’s incidents at public institutions and with the vulnerability of essential services when an outside provider or digital channel is disrupted.

Most Affected Sectors in Colombia

The financial sector was the most visible in digital fraud and the second most pressured technically by aggregated detections, although those telemetry figures are not counted as incidents. In this month’s material, banking and financial services appear in regulatory queries, sanctions, fraud campaigns, digital identity analysis, and open finance deployments. There was no single confirmed major banking breach, but there was a buildup of operational and identity risk.

Health remained the sector most affected by ransomware in terms of structural exposure. The material cited by Portafolio, HSB, and other outlets returns to the regional hospital in Caldas and to the concentration of attacks on hospitals and clinics. Even though September did not close with a new major confirmed leak in health, the sector pattern remains unchanged, with heavy dependence on clinical and administrative systems and very low tolerance for disruption.

Government and public entities were also marked by availability incidents and impersonation. ICETEX, the Ministry of Justice, Metro de Medellín, and the Gobernación de Córdoba show four different forms of exposure, from third-party providers to social media profiles and tax services. Taken together, that suggests the state perimeter is failing not only because of technology, but also because of third-party management and institutional accounts.

The main trend this month is the shift from mass ransomware to more fragmented incidents and fraud, but with a stronger ability to disrupt operations. Compared with August, verified incidents fell from 122 to 48, ransomware or extortion cases dropped from 66 to 13, and documented fraud or phishing declined from 12 to 3. At the same time, regulatory actions increased from 6 to 9.

That does not mean risk declined in a straight line. It means September brought less noise from amplified campaigns and more concrete events tied to disruption, compromised identities, and regulatory control. In other words, less volume and more focus on the points that keep operations running, such as vendors, institutional accounts, payment channels, and authentication mechanisms.

The second signal is a tightening regulatory cycle. Personal data, open finance, critical infrastructure, digital identity, and card fraud all advanced at the same time. The financial regulator is not only moving forward with roadmaps and draft circulars, it is also strengthening consumer education, AI-based supervision, and security criteria for new models. If that agenda holds, October and November could bring more decisions that affect fintechs, banks, and technology vendors.

The third signal is that fraud now combines automation, social engineering, and biometric verification. ShadowParasite showed how a single panel can mimic many entities and request credentials, codes, and facial biometrics. Cases like that are pushing a review of the real strength of enrollment, authentication, and account recovery processes, especially in digital banking and wallets.

Security recommendations for teams in Colombia

Prioritize reviews of third parties and vendors that support critical services. The ICETEX case showed that an incident at an external provider can affect availability without any direct intrusion into internal systems. Organizations should require a dependency inventory, segmentation, access controls, continuity testing, and early notification clauses.

Strengthen protection for institutional accounts and public profiles. The unauthorized access to the Medellín Metro account on X confirms that social networks and communication channels are also part of the perimeter. Privileged accounts should use phishing-resistant MFA, session monitoring, controlled recovery, and permission reviews.

Harden authentication flows in banking, fintech, and digital services. ShadowParasite and vishing and deepfake campaigns show that fraud is already exploiting OTP codes, facial biometrics, and identity validation. Teams should review friction levels, risk logic, account recovery, device-change alerts, and stronger verification for sensitive transactions.

Treat exposure of administrative interfaces as a containment priority. ColCERT's alert about exposed administrative access in VPNs and firewalls suggests an attack surface that is too open. At a minimum, teams should inventory access, close unnecessary exposure, rotate credentials, apply allowlists, and audit remote administration traceability.

Prepare regulatory and compliance responses now. Bill 282 on personal data, the SIC consultation, and the new requirements in open finance point to shorter reporting windows and more formal controls. Legal, security, and privacy teams should align incident classification, evidence logging, notification deadlines, and internal responsibilities.

Frequently Asked Questions

How did the risk focus change between August and September in Colombia?

It shifted from ransomware to incidents and fraud. In August, the previous month, ransomware was the main threat, with 66 of 122 events. In September, incidents became the main category, with 15 of 48 events, while regulatory moves rose from 6 to 9. That points to lower volume, but more pressure on operations, identity, and compliance.

Which September cases show why external providers matter, not just internal systems?

ICETEX and the Ministry of Justice show that pattern. ICETEX reported an impact that originated with an external provider, and the Ministry activated technology recovery after a cyber breach with support from third parties and authorities. Both cases reinforce that the supply chain and outsourced services are central to the risk picture.

The link is direct. While Lumu described ShadowParasite, a panel that impersonated fifteen Colombian financial institutions, the Superintendency of Finance moved forward on open finance, supervision tools, and security instructions. The combined message is that the financial sector’s digital expansion now depends as much on innovation as on identity verification and fraud control.

Which sector combined the most ransomware exposure with operational pressure during the month?

Health remains the sector with the greatest structural fragility. The period’s material revisits the case of the regional hospital in Caldas, the concentration of attacks on hospitals and clinics, and the heavy dependence on clinical and administrative systems. Although September had more incidents and fraud than confirmed large-scale extortion, health still shows the highest potential cost from disruption.

What does it mean that 2 critical CVEs were mentioned if the report does not show a large local exploitation wave?

It means there was meaningful technical exposure, not necessarily a confirmed major local outbreak. The material analyzed mentions CVE-2025-25249 in Fortinet with active exploitation, and a critical WordPress vulnerability patched in September. That does not mean both had the same impact in Colombia, only that the month’s technical radar did record high-risk flaws.

Technical appendix: indicators of compromise and TTPs

ShadowParasite

Lumu's research on ShadowParasite identified a panel that imitated fifteen Colombian financial institutions with a single codebase. The system asked for a six-digit verification code, card data, and, in six entities, live facial biometric capture. The material also described clone domains, payment page impersonation, and operational persistence for months.

ColCERT credential theft campaign

ColCERT, according to Tecnogus, reported 27 affected organizations in a global password collection campaign and 2,436 exposed administrative accesses in compromised VPNs and firewalls. The useful defensive takeaway is that the focus is not only on phishing, but also on exposed interfaces and reused credentials. No hashes or domains were published in the included material.

Exploitation of CVE-2025-25249

ZeroHour reported active exploitation of CVE-2025-25249 through CAPWAP packets to UDP 5246 in Fortinet FortiOS, FortiSwitchManager and FortiSASE. The source added that CISA added the flaw to the KEV catalog on 09-09-2026. The material does not provide additional IoCs such as hashes, IPs or domains, but it does confirm the technique and attack surface.

Material limitations

This report was prepared exclusively from the material provided for Colombia and for September 2026. The indicator window includes 55 dated events in September 2026 and 1 earlier event used only as a comparative reference, not as part of the month's volume. Undated events were excluded from the indicators.

A zero value in an indicator, especially in the CVE breakdown, means only that the data point was not recorded in the material reviewed, not that there was no activity in the region. This month, there were also 2 critical CVEs mentioned, but the analytical value depends on what the source could confirm, not on what may have happened outside the corpus reviewed.

There is also an important distinction between telemetry and incidents. Counts of attempts, blocks, scans, or aggregated detections were excluded from the event total because they are not intrusions with confirmed impact. If they are mentioned, they should be read explicitly as noise volume or automated attempt volume, with vendor and measurement window.

Social media aimed at consumers, as well as sponsored content or press releases not accepted as primary sources for trends, were excluded from the report build, along with any material not included in the available source list for citation. When a claim depended on third-party coverage or a threat actor index, the language preserved the level of direct confirmation or uncertain attribution, as appropriate.

Sources