Colombia Cybersecurity Report, September 2026
September ended with rising incidents and regulation, an ICETEX case, pressure on finance and health, and 2 critical CVEs mentioned.
Key findings
- Colombia shifted from an August dominated by ransomware to a September dominated by incidents, with 48 verified events and 15 unclassified incidents.
- ICETEX, the Medellín Metro, and the Córdoba Governor's Office showed that institutional attack surface remains concentrated in vendors, digital accounts, and citizen services.
- Digital fraud remained the most stable pressure on banking and payments, with ShadowParasite as the clearest case of impersonating financial institutions and stealing credentials plus biometrics.
- The month closed with a more intense regulatory agenda, especially in data protection, open finance, critical infrastructure, and identity validation.
- Health maintained a structurally high exposure to ransomware and operational disruption, although September did not close with a new major confirmed breach in the sector.
- ColCERT's warning about stolen credentials and exposed administrative access reinforces that authentication and exposed interfaces remain concrete weak points.
- Ransomware classification was incomplete in most cases, requiring strict separation of encryption, exfiltration, and simple mentions on leak sites.
Monthly reference modules
These modules are filled automatically with verified dated facts from the period. Each one states its source base and counting criterion, so the figures reconcile across modules. They serve as the recurring month-by-month reading; the analysis that follows expands on the cases without repeating this summary.
Indicator window: 55 dated facts in September 2026 · 1 from prior months (comparative frame, not monthly volume). Facts from prior months are used only as a comparative frame in the analysis, never as volume for this period.
Monthly executive summary for Colombia
September 2026 in Colombia was defined by operational incidents and a much more active regulatory agenda than the previous month. The period brought an impact at ICETEX due to an incident at an external provider, unauthorized access to the Medellín Metro account on X, ColCERT alerts about credential theft, and a series of regulatory measures on personal data, open finance, critical infrastructure, and digital fraud.
The overall reading for the period is high risk. Not because one attack family expanded on its own, but because service disruptions, more sophisticated fraud campaigns, sustained pressure on banking and healthcare, and signs of tighter regulation all overlapped. In the material analyzed, incidents not otherwise classified were the most common category, with 15 cases, ahead of cases where ransomware or extortion was the primary focus, which totaled 13.
In ransomware and extortion, the pattern was mixed. There was confirmation of operational impact in the case of the regional hospital of Caldas, references to an intrusion with exfiltration at Perimetral Oriental de Bogotá S.A.S., and several mentions of alleged victims on leak sites. In many cases, however, the source did not specify whether there was encryption, exfiltration, or only a claim by the actors. That lack of clarity limits precise attribution, although it does not reduce the signal of pressure on infrastructure, education, energy, and healthcare.
Banking remained the most exposed sector in digital fraud. Lumu described ShadowParasite, a panel that impersonated fifteen Colombian financial institutions and requested six-digit codes, card data, and, in some cases, live facial biometrics. At the same time, the Superintendencia Financiera moved ahead with a roadmap for open finance, new supervisory tools, and guidelines that are pushing the industry toward stricter identity, architecture, and security controls.
National snapshot for the month in Colombia
Colombia ended September with a broad risk surface, driven by concrete incidents, massive digital fraud, and a regulatory response that is no longer limited to isolated alerts. The verified total for the month was 48 incidents, with 7 sectors hit by at least one documented case and a clear shift in the leading threat, which moved from ransomware in the previous month to incidents in September.
The severity comes not only from the number of cases, but from their nature. ICETEX suffered service disruption after an incident at a third-party provider, Medellín Metro had to recover a compromised account, ColCERT warned about credential theft affecting 27 organizations, and the financial sector concentrated new fraud schemes using automation and AI. All of this unfolded alongside a regulatory agenda covering personal data, critical infrastructure, open finance, digital identity and incident reporting.
The risk reading for Colombia is high. The month showed service disruption, pressure on identities and payment channels, and an institutional response that is active but still fragmented across sectors. The material also suggests that the line between fraud, impersonation, extortion and unauthorized access is becoming increasingly blurred, which complicates both operational response and precise impact measurement.
In the regional context, Colombia sits within a Latin American dynamic where fraud and ransomware campaigns continue to pressure banking, healthcare and public services. The Colombian case is not an exception, but it stands out for the combination of new rules, credential alerts, provider incidents and a financial sector that is investing, at the same time, in digital expansion and stronger controls.
Colombia period indicators
| Indicator | September 2026 | Previous month | Change |
|---|---|---|---|
| Verified events in the period | 48 | 122 | -74 |
| Time window for the indicators | 55 events dated September 2026, 1 from prior months (comparative frame, not monthly volume) | Same | N/A |
| Unclassified incidents (breaches or outages) | 15 | 22 | -7 |
| Cases with ransomware or extortion as the primary focus | 13 | 66 | -53 |
| Confirmed asset encryption | 1 | 0 | +1 |
| No-encryption exfiltration (simple extortion) | 1 | 0 | +1 |
| Mentioned only on a leak site | 1 | 0 | +1 |
| Classification not determinable from the material | 10 | 0 | +10 |
| Documented fraud or phishing cases | 3 | 12 | -9 |
| Documented regulatory moves | 9 | 6 | +3 |
| Critical CVEs mentioned | 2 | 1 | +1 |
| Sectors with at least one documented event | 7 | 7 | unchanged |
| Dominant threat of the month | Incidents (15 of 48 events) | Ransomware (66 of 122 events) | shift in focus |
| Events with direct source confirmation | 69% | N/A | N/A |
| Aggregated telemetry figures excluded from volume | 7 (aggregate attempts or blocks: not incidents with confirmed impact) | N/A | N/A |
| Calculation base | Verified events in the period: 48 | Verified events in the period: 122 | N/A |
Relevant Incidents in Colombia
ICETEX and the incident at an external provider
ICETEX was one of the month’s most visible operational disruptions. The agency said a security incident at one of its external providers interrupted the availability of some services and processes, triggered containment and forensic analysis, and forced it to keep alternative service channels open while recovery moved forward. The public source did not identify the provider or give technical detail on the scope of the event.
The incident matters for two reasons. First, it shifts the failure point to the digital supply chain. Second, it shows an institutional response coordinated with ColCERT, the SIC and other authorities, suggesting the case was handled as a material incident, although no public confirmation of data exfiltration was made. In the documentation reviewed, the agency said personal data was neither compromised nor exposed.
Medellín Metro and the unauthorized access to X
The Medellín Metro confirmed unauthorized access to its official X account, which was used to publish content unrelated to the transportation system. The agency activated its protocols, regained control of the profile, and clarified that the event was limited to that account, with no compromise of other operational or information systems.
This episode does not rise to the level of a major incident, but it does offer a clear signal about the attack surface of institutional digital identities. The compromised account served as a broadcast channel, not a vector for disrupting core operations. Even so, the case confirms that corporate social media accounts remain sensitive assets for public bodies and infrastructure operators.
ColCERT and the credential theft alert
In September, ColCERT issued a high-risk alert over credential theft that affected 27 organizations in the country as part of a global password-harvesting campaign. The alert added an important technical detail, 2.436 exposed administrative logins on compromised VPN gateways and firewalls, placing Colombia among the countries with the highest exposure of administrative interfaces in that context.
What this signals is not an isolated intrusion, but an access surface that is too exposed for an environment where identity has become the perimeter. The combination of stolen credentials, open administrative interfaces and pressure on authentication systems helps explain why the month was marked by availability incidents and fraud campaigns that exploit valid credentials.
Ministry of Justice and technology recovery
The Ministry of Justice activated a comprehensive technology recovery plan after a cyber breach and reported impacts on systems such as SICOQ and MICC, with partial or unavailable operation depending on the case. The plan included alternative channels for procedures, with support from the Attorney General’s Office, ColCERT, Microsoft’s DART team and BID partners.
Here there was a real operational impact and continuity of service was at risk. The source did not publicly confirm that the case was ransomware, but it did show a major event handled as a high-impact institutional incident. The use of alternative channels and the involvement of external forensic actors reinforce the picture of a material disruption, not a minor one.
Córdoba Governor’s Office and the contingency over departmental revenues
The Córdoba Governor’s Office reported a cyberattack against the technology infrastructure supporting systems of the Departmental Revenue Directorate, with temporary disruption of services and digital channels such as the tax payment portal. The administration activated contingency protocols, but did not confirm whether the incident was ransomware.
This adds to the picture of exposed critical surface in territorial governments. There was no definitive technical attribution, but there was a direct interruption of services that matter to citizens and taxpayers. In a month when attacks on identities, payments and digital channels were recurring, the Córdoba case fits as a disruption that affected service continuity.
Active threats and campaigns in Colombia
Ransomware and extortion, with incomplete classification in most cases
The month produced 13 cases with ransomware or extortion as the main focus, but the source allowed clear classification in only a minority of them. There was one case with confirmed encryption, one with exfiltration without encryption, one that was mentioned only on a leak site, and ten in which the material did not allow the exact impact to be determined. That breakdown means the phenomenon has to be read cautiously, without overinterpreting every claim posted in forums or on leak sites.
In the case of Perimetral Oriental de Bogotá S.A.S., NightSpire said it had carried out an attack and threatened to publish sensitive information. Other sources added alleged exfiltrated data, but there was no independent public confirmation from the company or the regulator. For that reason, the report keeps the classification as a ransomware claim with impact that cannot be conclusively determined.
The only confirmed encryption case in the material analyzed was the regional hospital of Caldas, used by several reports as an example of an intrusion that disrupted technology operations and forced systems to be restored from backups and records to be kept manually. That reference confirms that operational damage and extortion pressure remain very present in healthcare, even if September leaned more toward incidents and fraud than toward major public ransomware campaigns.
Digital fraud, phishing, and AI-powered impersonation
Banking and payment services generated the clearest signs of fraud. Lumu documented ShadowParasite, a fraud panel that impersonates fifteen Colombian financial institutions with a single code base and asks for six-digit verification codes, card data, and, at six entities, live facial biometrics capture. That detail is especially relevant because it combines phishing, credential theft, and bypassing biometric controls.
At the same time, local coverage kept emphasizing vishing, voice deepfakes, and impersonation of official or financial entities. La FM and other outlets repeated response recommendations, while the Superintendence of Finance and the Bank of the Republic reinforced prevention messages. The operational signal is clear, fraud no longer depends only on fake links, but on authentication and verification processes that are being mimicked with considerable precision.
APT and persistent campaigns against public institutions
The month also left traces of persistent campaigns associated with actors such as Blind Eagle or APT-C-36, with lures based on court notices and traffic fines, aimed mainly at public institutions. Although that line appears in material from previous weeks, in September it continued to serve as a reference point for a regional pattern of specialized phishing designed to drop loaders and stay inside institutional networks.
There was no new large-scale attribution during the period that would justify saying the APT campaign changed, but there was a consistent environment of legal and document-based lures. In Colombia, that combination remains effective because it exploits the operational habits of users in government, justice, and other document-heavy services.
Critical vulnerabilities affecting Colombia
| CVE | Software | Exploitation | Source |
|---|---|---|---|
| CVE-2025-25249 | Fortinet FortiOS, FortiSwitchManager, FortiSASE | Active exploitation since at least July 2026 through CAPWAP packets to UDP 5246; CISA added it to KEV on 09-09-2026 | ZeroHour |
| CVE-2026-87902 | WordPress 7.1.2 | Critical vulnerability fixed by a security update released on 22-09-2026; the material does not document exploitation in Colombia | WordPress.org |
| CVE not specified by the source | WordPress 7.1.1 | Security and maintenance update released on 17-09-2026; the material does not indicate local exploitation | WordPress.org |
Regulation and compliance in Colombia
September was a month of intense regulatory activity in Colombia, with bills, consultations, sanctions, and road maps focused on personal data, identity, critical infrastructure, and open finance. The direction is clear, more traceability, more reporting obligations, and stricter demands on security controls and information handling.
The most structural move was Bill 282 of 2026, Constitutional Statute, in the House of Representatives, on personal data protection. The text introduces new legal bases for processing, classifies geolocation and neurodata as sensitive, requires impact assessments for certain processing activities, sets out the appointment of data protection officers in specific cases, and raises fines to as much as 10,000 minimum wages or 5% of the previous year’s operating revenue. It also requires security incidents to be reported within 72 hours and data subjects to be notified when there is a high risk.
The Superintendency of Industry and Commerce’s public consultation on identity verification and personal data processing added a practical layer to the same issue. The process focused on identity verification mechanisms, authentication, biometrics, technical standards, and good practices, with a defined schedule for consultation, participant selection, working sessions, and issuance of the protocol. At the same time, the Constitutional Court upheld the use of biometric data for passports, strengthening the line on robust identification without weakening privacy obligations on its own.
In finance, the Financial Superintendency made several moves at once. It published draft rules for the transitional regime for open finance, announced a road map tied to cybersecurity, privacy, and financial stability standards, and maintained supervision and control tools against money laundering. It also confirmed a sanction against Coltefinanciera for SARLAFT failures, with the fine reduced to 295.5 million pesos.
The other major regulatory line was critical infrastructure. Bill 343 of 2026, in the House of Representatives, filed on September 9, seeks to protect critical infrastructure and the continuity of essential services against actions by organized armed groups, organized crime, and illegal economies. That connects directly with this month’s incidents at public institutions and with the vulnerability of essential services when an outside provider or digital channel is disrupted.
Most Affected Sectors in Colombia
The financial sector was the most visible in digital fraud and the second most pressured technically by aggregated detections, although those telemetry figures are not counted as incidents. In this month’s material, banking and financial services appear in regulatory queries, sanctions, fraud campaigns, digital identity analysis, and open finance deployments. There was no single confirmed major banking breach, but there was a buildup of operational and identity risk.
Health remained the sector most affected by ransomware in terms of structural exposure. The material cited by Portafolio, HSB, and other outlets returns to the regional hospital in Caldas and to the concentration of attacks on hospitals and clinics. Even though September did not close with a new major confirmed leak in health, the sector pattern remains unchanged, with heavy dependence on clinical and administrative systems and very low tolerance for disruption.
Government and public entities were also marked by availability incidents and impersonation. ICETEX, the Ministry of Justice, Metro de Medellín, and the Gobernación de Córdoba show four different forms of exposure, from third-party providers to social media profiles and tax services. Taken together, that suggests the state perimeter is failing not only because of technology, but also because of third-party management and institutional accounts.
Trends and signals to watch in Colombia
The main trend this month is the shift from mass ransomware to more fragmented incidents and fraud, but with a stronger ability to disrupt operations. Compared with August, verified incidents fell from 122 to 48, ransomware or extortion cases dropped from 66 to 13, and documented fraud or phishing declined from 12 to 3. At the same time, regulatory actions increased from 6 to 9.
That does not mean risk declined in a straight line. It means September brought less noise from amplified campaigns and more concrete events tied to disruption, compromised identities, and regulatory control. In other words, less volume and more focus on the points that keep operations running, such as vendors, institutional accounts, payment channels, and authentication mechanisms.
The second signal is a tightening regulatory cycle. Personal data, open finance, critical infrastructure, digital identity, and card fraud all advanced at the same time. The financial regulator is not only moving forward with roadmaps and draft circulars, it is also strengthening consumer education, AI-based supervision, and security criteria for new models. If that agenda holds, October and November could bring more decisions that affect fintechs, banks, and technology vendors.
The third signal is that fraud now combines automation, social engineering, and biometric verification. ShadowParasite showed how a single panel can mimic many entities and request credentials, codes, and facial biometrics. Cases like that are pushing a review of the real strength of enrollment, authentication, and account recovery processes, especially in digital banking and wallets.
Security recommendations for teams in Colombia
Prioritize reviews of third parties and vendors that support critical services. The ICETEX case showed that an incident at an external provider can affect availability without any direct intrusion into internal systems. Organizations should require a dependency inventory, segmentation, access controls, continuity testing, and early notification clauses.
Strengthen protection for institutional accounts and public profiles. The unauthorized access to the Medellín Metro account on X confirms that social networks and communication channels are also part of the perimeter. Privileged accounts should use phishing-resistant MFA, session monitoring, controlled recovery, and permission reviews.
Harden authentication flows in banking, fintech, and digital services. ShadowParasite and vishing and deepfake campaigns show that fraud is already exploiting OTP codes, facial biometrics, and identity validation. Teams should review friction levels, risk logic, account recovery, device-change alerts, and stronger verification for sensitive transactions.
Treat exposure of administrative interfaces as a containment priority. ColCERT's alert about exposed administrative access in VPNs and firewalls suggests an attack surface that is too open. At a minimum, teams should inventory access, close unnecessary exposure, rotate credentials, apply allowlists, and audit remote administration traceability.
Prepare regulatory and compliance responses now. Bill 282 on personal data, the SIC consultation, and the new requirements in open finance point to shorter reporting windows and more formal controls. Legal, security, and privacy teams should align incident classification, evidence logging, notification deadlines, and internal responsibilities.
Frequently Asked Questions
How did the risk focus change between August and September in Colombia?
It shifted from ransomware to incidents and fraud. In August, the previous month, ransomware was the main threat, with 66 of 122 events. In September, incidents became the main category, with 15 of 48 events, while regulatory moves rose from 6 to 9. That points to lower volume, but more pressure on operations, identity, and compliance.
Which September cases show why external providers matter, not just internal systems?
ICETEX and the Ministry of Justice show that pattern. ICETEX reported an impact that originated with an external provider, and the Ministry activated technology recovery after a cyber breach with support from third parties and authorities. Both cases reinforce that the supply chain and outsourced services are central to the risk picture.
What is the link between fraud cases and the month’s financial regulatory agenda?
The link is direct. While Lumu described ShadowParasite, a panel that impersonated fifteen Colombian financial institutions, the Superintendency of Finance moved forward on open finance, supervision tools, and security instructions. The combined message is that the financial sector’s digital expansion now depends as much on innovation as on identity verification and fraud control.
Which sector combined the most ransomware exposure with operational pressure during the month?
Health remains the sector with the greatest structural fragility. The period’s material revisits the case of the regional hospital in Caldas, the concentration of attacks on hospitals and clinics, and the heavy dependence on clinical and administrative systems. Although September had more incidents and fraud than confirmed large-scale extortion, health still shows the highest potential cost from disruption.
What does it mean that 2 critical CVEs were mentioned if the report does not show a large local exploitation wave?
It means there was meaningful technical exposure, not necessarily a confirmed major local outbreak. The material analyzed mentions CVE-2025-25249 in Fortinet with active exploitation, and a critical WordPress vulnerability patched in September. That does not mean both had the same impact in Colombia, only that the month’s technical radar did record high-risk flaws.
Technical appendix: indicators of compromise and TTPs
ShadowParasite
Lumu's research on ShadowParasite identified a panel that imitated fifteen Colombian financial institutions with a single codebase. The system asked for a six-digit verification code, card data, and, in six entities, live facial biometric capture. The material also described clone domains, payment page impersonation, and operational persistence for months.
ColCERT credential theft campaign
ColCERT, according to Tecnogus, reported 27 affected organizations in a global password collection campaign and 2,436 exposed administrative accesses in compromised VPNs and firewalls. The useful defensive takeaway is that the focus is not only on phishing, but also on exposed interfaces and reused credentials. No hashes or domains were published in the included material.
Exploitation of CVE-2025-25249
ZeroHour reported active exploitation of CVE-2025-25249 through CAPWAP packets to UDP 5246 in Fortinet FortiOS, FortiSwitchManager and FortiSASE. The source added that CISA added the flaw to the KEV catalog on 09-09-2026. The material does not provide additional IoCs such as hashes, IPs or domains, but it does confirm the technique and attack surface.
Material limitations
This report was prepared exclusively from the material provided for Colombia and for September 2026. The indicator window includes 55 dated events in September 2026 and 1 earlier event used only as a comparative reference, not as part of the month's volume. Undated events were excluded from the indicators.
A zero value in an indicator, especially in the CVE breakdown, means only that the data point was not recorded in the material reviewed, not that there was no activity in the region. This month, there were also 2 critical CVEs mentioned, but the analytical value depends on what the source could confirm, not on what may have happened outside the corpus reviewed.
There is also an important distinction between telemetry and incidents. Counts of attempts, blocks, scans, or aggregated detections were excluded from the event total because they are not intrusions with confirmed impact. If they are mentioned, they should be read explicitly as noise volume or automated attempt volume, with vendor and measurement window.
Social media aimed at consumers, as well as sponsored content or press releases not accepted as primary sources for trends, were excluded from the report build, along with any material not included in the available source list for citation. When a claim depended on third-party coverage or a threat actor index, the language preserved the level of direct confirmation or uncertain attribution, as appropriate.
Sources
- Superfinanciera recibió 469 quejas contra aseguradoras tras el terremoto: estas son las principales razonesLa FM
- 1 TB data leak from Ecopetrol, Colombia's state oil companyKalir
- Alleged sale and massive exfiltration of 1.0 TBVECERTRadar
- Del phishing a los deepfakes: cómo evolucionan las estafas contra clientes bancariosDiario del Sur
- Inversiones Bolívar — QILIN Ransomware AttackBreach House
- Congreso de la República, Proyecto de Ley EstatutariaCentro de Estudios Regulatorios
- UNISALLE-EDU.CO — CLOP Ransomware AttackBreach House
- Tras revisión conjunta, Procuraduría y Colombia Compra Eficiente revocó proceso de ciberseguridadProcuraduría General de la Nación
- Nuevos rostros, una misma amenazaLa República
- ICETEX reporta presunto hackeo que afecta sus servicios y activa protocolos de seguridadCaracol Radio
- Unmasking ShadowParasite: The Invisible Cyber Fraud ...Lumu
- Agrocampo — THEGENTLEMEN Ransomware AttackBreach House
- PROTECCIÓN DE INFRAESTRUCTURA CRÍTICA - Proyecto de Ley 343 de 2026 CámaraCámara de Representantes de Colombia
- Comunicado institucional sobre incidente de seguridad de ...ICETEX
- El Icetex reportó un incidente de seguridad en un proveedor externo y confirmó fallas en algunos servicios virtualesInfobae
- Icetex sufrió un incidente de seguridad de la información que afectó sus serviciosZona Cero
- Preocupación en los estudiantes: Icetex enfrenta fallas tras incidente de seguridad digitalPulzo
- El ICETEX cobrará solo la inflación a 170.000 deudores al día desde octubre: $51.605 millones de subsidio hasta que se agotenMás Colombia
- Icetex reporta afectación en sus servicios por incidente de seguridad: ¿fueron vulnerados los datos de los usuarios?El Heraldo
- Icetex reporta incidente de seguridad: varios de sus servicios fueron afectadosBlu Radio
- El ICETEX cobrará solo la inflación a 170.000 deudores al día: interrupción digital y subsidio de tasaMás Colombia
- Inteligencia artificial y deepfakes sexuales de menores: ¿qué tan preparada está Colombia?El Espectador
- ¿Son seguras las billeteras digitales en Colombia? Así opera el respaldo de sus ahorrosPortafolio
- The Gentlemen Ransomware Group Claims 42 New Victims in Global Extortion WaveTornews
- Senador Alfredo Deluque hizo propuesta para fortalecer la seguridad en Colombia: de esto se trataRevista Semana
- La nueva regulación de los criptoactivos revoluciona los mercados financieros internacionales y el derechoUNIR
- Abren consulta sobre protección de datos por validación de identidadOlarteMoure
- ¿Colombia piensa en regular activos digitales? Hay consumidores financieros desprotegidosBloomberg Línea
- Colombia registra 1,3 millones de ciberamenazas en 6 mesesTecnogus
- Bancos en Colombia deberán asumir fraudes con tarjetas si incumplen esta norma de seguridadNoticias RCN
- Agente de IA ejecutó un ciberataque sin intervención humanaCambio Colombia
- Superfinanciera dice que avanza en una hoja de ruta con el fin de ejecutar finanzas abiertasEl Heraldo
- Superfinanciera avanza en desarrollo de hoja de ruta para implementar finanzas abiertasLa República
- Superintendente financiero advierte que hay consumidores desprotegidos por falta de regulación de activos digitalesPortafolio
- Comunicados de prensa 2026Superintendencia Financiera de Colombia
- Resoluciones 2026Superintendencia Financiera de Colombia
- Superintendencia Financiera anuncia hoja de ruta para transformar el ecosistema fintech y los criptoactivos en ColombiaEl País
- Gaceta 1217 de 2026: Proyecto de Ley Estatutaria 282 de 2026 Cámara (Modificación parcial de la Ley 1581 de 2012 sobre protección de datos personales)Avance Jurídico (repositorio de Gacetas del Congreso de Colombia)
- ¿Cómo verificar su identidad digital en Colombia sin caer en fraudes?Noticias RCN
- Superfinanciero pide construir un sistema financiero más eficiente, competitivo y dinámicoCaracol Radio
- Latinoamérica archivos - Compliance Latam (sección Colombia, referencia a Ley 2502 de 2025 sobre deepfakes)Compliance Latam
- Ruta de acción de la SFC (publicación en X)Superintendencia Financiera de Colombia
- Colombia Fintech pide acelerar cambios en pagos y regulación criptoDiarioBitcoin
- “La prohibición no es efectiva”: experta sobre límites de regulación de redes sociales para menoresCaracol Radio
- Icetex reporta problemas en varios servicios tras incidente de seguridadVanguardia
- Se acabaron las excusas y Colombia tendrá herramientas para proteger a las mujeres en los colegios, los estrados judiciales y en internetSenado de la República de Colombia
- Estafas con voz clonada por IA: qué es un deepfake de voz y cómo proteger a su familiaEl Colombiano
- Superfinanciera habilita herramienta con IA para consultar fallos y decisionesBlu Radio
- Gabriel Santos, presidente de Colombia Fintech, sobre desafíos del sector y cronograma de finanzas abiertasLa República
- Colombia estrena nuevas reglas contra las llamadas y mensajes fraudulentos: así funcionaránEnter.co
- Filtración recicla datos de 15,7 millones de colombianos del Icfes y bancosMucho Hacker
- Regulación de ciberseguridad 2026: España, Colombia y otros paísesProactivanet
- Campaña #LaSeguridadDigitalNosUne sobre phishing y fraudes digitales, en coordinación con ColCERT y MinTICSuperintendencia Financiera de Colombia
- Revolut obtiene la licencia bancaria para operar en ColombiaEuropa Press
- El vicepresidente José Manuel Restrepo y el superintendente financiero Pablo Rivas Herazo participarán en el Latam Fintech Market 2026El Heraldo
- Resumen de entidades supuestamente afectadas en filtración de datos agregada (Banco de Bogotá, Banco Popular, ICFES) — estado NO confirmadoVECERTRadar (perfil OSINT en X)
- Colombia registra 1,3 millones de detecciones de ciberamenazas en seis mesesTechnocio
- Alerta roja digital en Colombia: la inteligencia artificial está acelerando el cibercrimenMinuto60
- Report finds care providers absorb most Colombian intrusionsMedRisk.io
- Cyberattacks Target 60% of Colombian Healthcare ProvidersBiopharma Curated
- Six in 10 Cyberattacks in Colombia Target HospitalsColombiaOne
- ¿Ciberataques?: Más de 51 millones de historias clínicas ...HSB Radio
- Biofile Finds Health Sector Draws 60% of Colombia’s CyberattacksTMCnet
- ¿Necesita Colombia una nueva Ley Fintech?Forbes Colombia
- Tras 20 años de operación, PSE logró récord de transacciones y prepara oferta en finanzas abiertasValora Analitik
- Titulares del 13 de septiembre (mención a sanción de Coltefinanciera)Pantallazos Noticias
- Seis de cada 10 ciberataques en Colombia tienen como blanco a hospitales y clínicas del paísPortafolio
- Ransomware Recovery Services MarketMordor Intelligence
- ¿Ciberataques?: Más de 51 millones de historias clínicas, en juegoHSB Noticias
- Colombia registra 1,3 millones de detecciones de ciberamenazas en seis mesesTechnocio
- Superfinanciera confirmó sanción a Coltefinanciera y fijó multa por $295,5 millonesLa República
- The Gentlemen ransomware group recordRansomware.live
- Colombia: SIC Opens Consultation on Identity Verification SystemsBaker McKenzie
- Proyecto de Circular Externa 15 - 2026Superintendencia Financiera de Colombia
- Corte Constitucional avaló el uso de datos biométricos para expedir pasaporte en ColombiaEl Colombiano
- Proyectos de normaSuperintendencia Financiera de Colombia
- Bancolombia anunció el lanzamiento del segundo tomo histórico sobre el Banco de Colombia (sección sobre sanción a Coltefinanciera)La República
- NightSpire Ransomware Attack on Perimetral Oriental de Bogotá S.A.S.Dexpose
- Victim: Perimetral Oriental de Bogotá S.A.S.Ransomware.live
- Perimetral Oriental de Bogotá S.A.S. Ransomware Claim (2026) — What’s Alleged & Am I Affected?RecentBreaches
- Publicación sobre la posible víctima Perimetral Oriental de Bogotá S.A.S.VenariX en Español
- Ciberseguridad en infraestructura crítica: ¿están preparados los sectores estratégicos del país?Ser Colombiano
- Superfinanciera lanzó alerta por falsas tarjetas de crédito; la entidad entregó serias advertenciasSemana
- Colombia: SIC Opens Consultation on Identity Verification SystemsBaker McKenzie
- Ransomware Group emperador Hits: EASY JOB S.A.S.HookPhish
- Superfinanciera advierte suplantaciones - señales de control para empresas en ColombiaLegal Abogados
- La transformación del régimen fiduciario en Colombia: obligaciones, riesgos y desafíos de implementaciónLexLatin
- Nuevas reglas para los negocios fiduciariosNotaría 19 de Bogotá
- Noticias – orden de suspensión a Fundación FG – Administrador de Fideicomisos CivilesSuperintendencia Financiera de Colombia
- Riesgos institucionales - FNAFondo Nacional del Ahorro
- Invitación a consulta pública sobre validación de identidad y protección de datos personales (mensaje oficial en redes)Superintendencia de Industria y Comercio
- Ransomware Group thegentlemen Hits: El CarrielHookPhish
- Bitdefender Threat Debrief | September 2026Bitdefender
- Finance API Integration Controls for Audit-Ready Data FlowsSysgenPro
- TrainMe — DIREWOLF Ransomware AttackBreach House
- SFCsupervisor Alerts Public About Risky Investment PromisesCoinfomania
- Alerta por fraude agéntico en Colombia: la nueva era de la inteligencia artificial que suplanta identidades en la bancaEl Extra Medios
- La experimentación controlada fortalece la supervisión de la innovación financieraSuperintendencia Financiera de Colombia
- La IA acelera el fraude, la industria financiera debe estar unida para enfrentarloForbes Colombia
- ¿IA contra la IA? Este es el desafío que enfrenta el mundo hoySemana
- La experimentación controlada fortalece la supervisión de ...Superintendencia Financiera de Colombia
- Qué están haciendo distinto las instituciones financieras que crecen en 2026LatamFintech
- Estudio de DataCrédito Experian reveló que intento de fraude llegó a 71% de las personas en el último añoLa República / DataCrédito Experian
- El 71% de colombianos enfrentó intentos de fraude durante el último año y 46% reportó una estafa consumadaPortafolio
- IA hace que el fraude financiero sea 4,5 veces más rentableDiario del Sur
- Los fraudes y estafas con IA más recurrentes en México, Colombia, Chile, Perú y PanamáBloomberg Línea
- Estafas en Colombia: el fraude del 'llaman y cuelgan'La FM
- Transportes Montejo Data Breach in 2026BreachSense
- Banco de Bogotá advierte sobre el aumento de fraudes digitalesLa Gran Noticia
- Comisión Primera de Cámara de Representantes – Listado de proyectos, incluyendo iniciativas sobre protección de datos personales e inteligencia artificialCongreso Visible (Universidad de los Andes)
- MinJusticia activa plan de recuperación tecnológica luego de vulneración cibernética garantizando servicios esencialesMinisterio de Justicia y del Derecho de Colombia
- En apenas 72 minutos una organización puede perder sus datosiProUP
- Colombia enfrenta una nueva amenaza digital mientras crecen los casos de suplantación de identidadLa Vibrante
- Proyecto de Circular Externa 14 - 2026Superintendencia Financiera de Colombia
- Victim: Transportes Montejo S.A.S.Ransomware.live
- [Intel MX] 2026-09-01 México sin víctimas, pero el vecindario ...Ransomware.mx
- Bancolombia cumplió 20 años de tener corresponsales bancarios con una red de 28.000 puntosLa República
- Bancos invirtieron $3,6 billones en innovación digital y ciberseguridad en 2025El Universal
- Colombia enfrenta una nueva generación de fraude financieroRadar Tecnológico
- Nequi se separa de Bancolombia hoy: la entidad explica qué cambiará para los usuariosNoticias Caracol
- Informe del revisor fiscal sobre SARLAFT: revisión y controlAmezquita
- 8 claves para elegir software AML en financieras 2026Piranirisk
- Superintendencia Financiera de Colombia, Proyecto de Circular Externa 14-2026CERLATAM
- Nequi se transforma desde hoy y responde a la principal duda de sus usuarios: cuidado con los ataquesSemana
- Publicación en X sobre estándares de intercambio de información en finanzas abiertasSuperintendencia Financiera de Colombia
- Las fintech corren y la regulación intenta alcanzarlasPPU Legal
- Circular externa 008 de Superintendencia Financiera, 01-09-2026vLex Colombia
- Jornadas de atención a la ciudadaníaSuperintendencia Financiera de Colombia
- Las fintech corren y la regulación intenta alcanzarlasPPU Legal
- Gota a gota virtual: señales de alerta y cómo denunciarLucasya
- Activan plan de contingencia en la gobernación de Córdoba tras ataque cibernético a la infraestructura tecnológicaEl Heraldo
- transportesmontejo.com Listed by Krybit Ransomware GroupGalaxyWarden
- La privacidad entra en la era de la IA con una regulación que pide ser actualizadaPPU Legal
- Resiliencia y Ciberseguridad en Pasarelas de Pago para el Ecommerce en Colombia 2026Todoecommerce
- INDUMIL alerta a la ciudadanía sobre cuenta fraudulenta en TikTokINDUMIL Colombia
- Tenga en cuenta estas siete recomendaciones para la seguridad de ...Banco de la República
- Publicación en X sobre protección de cuentas y orientación confiableSuperintendencia Financiera de Colombia
- Proyecto de carta circular - Agosto 31 de 2026Superintendencia Financiera de Colombia
- Proyecto de carta circularSuperintendencia Financiera de Colombia
- Still Circling: Inside the Operator Behind the GitHub LoaderOffSeq Threat Radar
- Blind Eagle GitHub Loader (AsyncRAT/DcRat/XWorm) ...Security Arsenal
- 2000-41-7-1Comisión de Regulación de Comunicaciones (CRC)
- Cómo Prevenir Fraudes y EstafasJFK Cooperativa Financiera
- Red Team y BAE con rThreat | Starsolution ColombiaStarsolution Colombia
- Conozca las entidades ante las que puede denunciar el robo de identidadAsuntosLegales.co
- De cada 10 adultos que están bancarizados, cuatro han sufrido fraude financiero en su vidaLa República
- Los fraudes y estafas con IA más recurrentes en México, Colombia, Chile, Perú y PanamáBloomberg Línea
- Los bancos pierden hasta US$160.000 al año porque los sistemas heredados bloquean transacciones legítimas con tarjetaColombia Fintech
- Ionix Latam despliega en la región nueva plataforma para prevenir fraudes de identidadColombia Fintech
- Banca colombiana acelera su inversión digital: destina $ 3,6 billones y apuesta también por inteligencia artificialEl Tiempo
- AI Deepfake Scams Are Draining the Remittances Latino Families Send Home — Here's How to Fight BackLatin Times
- AI Deepfake Scams Are Draining the Remittances Latino Families Send Home — Here's How to Fight BackDooblia / Finnovista
- Indra Group alerta por fraude digital en la banca nacionalLa FM
- Por medio de la cual se fortalece la protección de los usuarios, se robustecen las funciones de inspección, vigilancia y control de la Superintendencia de Servicios Públicos Domiciliarios... (Proyecto de Ley Estatutaria 210/26 Senado)Congreso Visible (Universidad de los Andes)
- Cuidado con las apps de préstamos 'fáciles': estos son los riesgos que debes conocerEl Universal
- Informe de Asobancaria reveló que durante 2025 la inversión en tecnología sumó 3,6 billonesLa República
- Por medio de la cual se establecen medidas para la protección de niños, niñas y adolescentes frente a los riesgos asociados al uso de redes sociales – Niños Sin Redes (Proyecto de Ley 208/26 Cámara)Congreso Visible (Universidad de los Andes)
- Por medio de la cual se regula la comercialización, activación, registro y uso de tarjetas SIM física o virtual... (Proyecto de Ley 204/26 Senado)Congreso Visible (Universidad de los Andes)
- Cuidado con las apps de préstamos 'fáciles': estos son los riesgos que debes conocerEl Universal (Colombia)
- Circular externa 007 de Superintendencia Financiera, 26-08-2026vLex Colombia
- Indra Group plantea en Colombia una visión integrada para anticipar el fraude financiero y fortalecer la seguridad en los pagosIndra Group
- La Registraduría alertó por llamadas que suplantan a la entidad para ofrecer subsidios de Prosperidad Social: así operan los ladronesInfobae Colombia
- Instrucciones para mitigar el impacto de la situación de desastre sobre los consumidores financieros afectadosSuperintendencia Financiera de Colombia
- Boletín Minhacienda – Capítulo Superintendencia Financiera (agosto 2026)Ministerio de Hacienda y Crédito Público / Superintendencia Financiera de Colombia
- Estafas en línea en aumento en Colombia: ¿qué está cambiando?Diario del Sur
- Ciberataques golpean más fuerte a la industria energética en América LatinaBNamericas
- APT-C-36 (G0099) | Threat Actor IndexThreat Actor Index
- Colombia es el tercer país más ciberatacado de Latam, más de 3.000 amenazas semanalesEXTRA
- Colombia registró 10 billones de intentos de ciberataques y el sector empresarial el más afectadoCaracol Radio
- Colombia, tercer país más atacado de Latam: ciberataques cuestan hasta US$6 millonesAgencia Pi
- Ciberataques en Colombia superan los 4.000 intentos semanalesOccidente
- Trellix detecta 1,3 millones de ciberamenazas en ColombiaTecnogus
- Una pyme perdería $520 millones por un solo incidente de ciberseguridadLa República
- Ciberataques a empresas en Colombia: la pregunta ya no es si ocurrirán, sino cuándoEl Espectador
- Hay inversión en tecnología para frenar el fraude en Colombia, pero no es suficienteLa República
- Estos son los cinco pilares que anunció MinTic para lograr el milagro tecnológicoLa República
- Crecen los ciberataques mientras Colombia mantiene fragmentada su defensa digitalPPU Legal
- La inteligencia artificial preocupa a los colombianos, pero también la ven como aliada contra el fraude digitalSemana
- Perimetral Oriental de Bogotá S.A.S.: Unconfirmed Breach Claims & DoxxScan RatingRecentBreaches
- Nightspire ransomware group - Discover all the information about themBreach.house
- Spo**** Schools data breach — Nightspire ransomware leak (2026)Orizon / Darkfield
- Perimetral Oriental de BogotáBreachSense
- Perimetral Oriental de Bogotá S.A.S. Ransomware Attack by Nightspire (2026)Cyber Threat Intelligence
- Transportes Montejo S.A.S. Listed by Nightspire (2026)GalaxyWarden
- Ransomware Threat Intel — Daily Briefing (Sep 11, 2026)Intel and Breaches
- Feed De Noticias De Ciberseguridad [14/09/2026]CronUp
- Education Ransomware Victims & Data BreachesBreach.house
- ICETEX está trabajando en la recuperación de sus servicios luego de un incidente en proveedor externoIFM Noticias
- Alerta ColCERT: robo de credenciales afecta a 27 empresasTecnogus
- Hackearon a la Empresa Metro de Medellín: la compañía envió un mensaje a la ciudadanía tras la afectación a su cuenta en XInfobae
- Colombia registró 10 billones de intentos de ciberataquesHSB Noticias
- Colombia's third data bill would fine firms up to 5% of revenuePPC.land
- PROYECTO DE LEY ESTATUTARIA NÚMERO 282 DE 2026 CÁMARA por la cual se modifica parcialmente la Ley 1581 de 2012vLex
- Colombia: ley de datos con multas de hasta 5% de ingresosRevenue Hub Latam
- SIC multa empresa de Epa Colombia: la cifra superaría los cien millones de pesosCambio Colombia
- Siguen las malas noticias para Epa Colombia: ahora la SIC la multa con $140 millones por incumplir con sus productosEl Tiempo
- SIC sanciona a Productos EPA Colombia por fallas en protección a compradores digitalesEl Diario
- Ransomware in Latin America: The Attack That Set Off…Simcod
- Ataques de ransomware suben 25.5% en LATAMAnimal Político
- Colombia (Country): news timeline & CVEs · ZeroHourZeroHour
- WordPress 7.1.1 – Actualización de seguridad y mantenimientoWordPress.org (es)
- WordPress 7.1.2 – Actualización de seguridadWordPress.org (es)
- WordPress 7.1.2 corrige un fallo crítico presente desde 2016PasqualePillitteri.it
- Mes: septiembre 2026CSIRT Telconet
- Multiples vulnérabilités dans WordPress - CERT-FR | CybersécuritéCERT-FR
- Version 7.1.1 – Documentation – WordPress.orgWordPress.org
- WordPress Alert | 2026-7873National Cybersecurity Authority (Saudi Arabia)
- Ecopetrol | Energía y SosTECnibilidad®Ecopetrol
