Case Library / Vishing (Voice Phishing) / Los Cyber Bank-Impersonation Vishing Network Dismantled in Colombia

Los Cyber Bank-Impersonation Vishing Network Dismantled in Colombia

A 16-member Colombian crime ring called and WhatsApp-messaged bank customers posing as fraud-prevention officers, talked mostly over-50 victims into sharing their phone screens, and drained COP 1.685 billion from 94 people across 10 departments before a joint Fiscalia-Policia Nacional operation captured the group, including alleged leader alias "Ralf."

Share:

Reviewed by the Social Engineering Examples team.

What Happened

Between June 2025 and March 2026, a Colombian criminal organization known as "Los Cyber" ran a large-scale bank-impersonation vishing operation, contacting victims, overwhelmingly adults over 50, by bulk SMS/WhatsApp message followed by phone calls or WhatsApp voice/video calls in which operators posed as bank fraud-prevention or customer-service staff. Claiming they needed to help block a suspicious transaction or protect the account from identity theft, the callers persuaded victims to share their phone screen live, allowing the operators to see usernames, passwords, balances and SMS one-time codes in real time and to execute transfers straight out of the accounts. Stolen money was rapidly moved through multiple intermediary/mule accounts and then withdrawn in cash via ATMs, bank branches and banking correspondents to frustrate tracing. The scheme reportedly affected at least 94 documented victims across 10 Colombian departments and totaled roughly COP 1.685 billion in losses. On July 9-10, 2026, a joint operation by the Fiscalia General de la Nacion, Policia Nacional and CTI carried out simultaneous raids in five cities and arrested 16 alleged members, including the accused ringleader known by the alias "Ralf." A later wave of coverage on July 22-24, 2026 revealed that one of those same 16 detainees, Mateo Ramirez Florez, is a former professional footballer and the son of the late Millonarios/Colombia idol Jhon Mario Ramirez, allegedly recruited to provide a bank account used to receive laundered funds; this was public identification of an existing detainee, not a new arrest. Investigators indicated the case remained open and the final victim count/loss total could grow.

How the Attack Worked

The ring, known as "Los Cyber," first blasted mass SMS/WhatsApp messages to potential victims, then followed up with direct phone calls or WhatsApp voice/video calls in which operators posed as fraud-prevention or customer-service staff from unnamed Colombian banks. Using a masking/impersonation technique authorities described as "spoofing," callers warned victims of supposed unrecognized transactions or identity-theft attempts on their account and, under the pretext of a "preventive security block" or identity verification, talked them through opening their banking app and sharing their phone screen live during the call (in some cases via a WhatsApp video call). With the screen shared, operators watched in real time as victims entered usernames, passwords, balances and SMS one-time codes, then used that access to transfer funds out of the accounts. Stolen funds were rapidly layered through multiple intermediary and mule accounts to break the audit trail before being withdrawn as cash at bank branches, ATMs, and authorized banking correspondents. One investigative follow-up (El Tiempo) also described victims being directed to a fake WhatsApp "assistant" bot and a fabricated in-branch appointment as part of the con. Later profile coverage (El Heraldo, Jul 22; Focus Noticias, Jul 23, 2026) of one of the original 16 detainees, a professional footballer alleged to have provided a bank account used to receive laundered funds, added that the group also used fraudulent WhatsApp links and, per those two outlets, AI-assisted tools/video calls to bolster the impersonation; this detail is not corroborated across the main July 9-11 wave of coverage.

The Lure & the Tell

Lure: an unsolicited call or WhatsApp message/video call from someone claiming to be a bank fraud-prevention or customer-service officer, warning of a suspicious transaction or possible identity theft on the victim's account and offering to help "protect" the funds with a same-call "preventive block." One captured audio quoted by El Tiempo has an operator saying: "Lo que pasa es que en este caso debemos realizar por seguridad un bloqueo preventivo, ya que es probable que usted este siendo victima de suplantacion de identidad" ("For security we need to do a preventive block, since you may be a victim of identity theft"). Tell/red flags: a legitimate bank will never ask a customer to share their phone screen, read out passwords, or hand over one-time SMS codes over a call or WhatsApp chat it initiated; the urgency ("your account is compromised right now"), the request for real-time screen access, and the shift from a text message to an unsolicited voice/video call are all hallmarks of the scam that police highlighted in their public warning.

Outcome

On July 9-10, 2026, the Fiscalia General de la Nacion, Policia Nacional (Risaralda Police/DIJIN-SIJIN) and the Cuerpo Tecnico de Investigacion (CTI) carried out simultaneous raids in Bogota, Soacha, Bucaramanga, Ibague and Filandia (Quindio), arresting 16 alleged members of "Los Cyber," including the accused leader, alias "Ralf" (identified in press reports as Ralf Sebastian Nieva, also rendered Ralf Sebastian Nieva Vasquez). Other named detainees included Karen Sofia Posada Sanchez, Heidy Alexandra Posada Sanchez, Angel Camilo Salamanca Daza, Yasmin Eliana Naranjo Aguirre, Andrea Alejandra Castano Ferro, Manuel Roberto Clavijo Gutierrez, Mateo Ramirez Florez, Kevin Andres Menjura Nieto, Jaime Andres Bedoya Montana, Juan Andres Leon Pena, Esneda Munoz Nunez, Carlos Santiago Fuentes Parra, Margeydys Vides Pineda, Hernan Dario Pico Hoyos and Victor Alejandro Monroy Garcia. Authorities seized 35 bank cards, 22 cell phones, 4 laptops, 6 USB drives, 5 SIM cards and about COP 7 million in cash. All 16 were charged with concierto para delinquir (criminal conspiracy), aggravated illicit enrichment by private individuals, computer-facilitated theft, unauthorized access to an information system, and violation of personal data; a control-of-guarantees judge legalized the arrests. A later wave of coverage beginning July 22, 2026 (El Heraldo, Infobae, El Espectador, GolCaracol, Pulzo, Marca) identified one of the original 16 as Mateo Ramirez Florez, a 26-27-year-old former professional footballer (debuted with Patriotas Boyaca in 2021) and son of the late Millonarios/Colombia idol Jhon Mario Ramirez; a Dijin investigator told El Tiempo that Ramirez "presto su cuenta bancaria" (provided his bank account) to receive funds from the fraud. This was public identification/profiling of a detainee already captured July 9-10, 2026, not a new or 17th arrest. Investigators said they were continuing to work to identify further victims and members and to establish the full amount defrauded, which they said could exceed the reported COP 1.685 billion.

Why It Matters

The case is a textbook, well-documented illustration of classic bank-impersonation vishing at organized-crime scale: no malware, no sophisticated exploit, just a scripted authority-impersonation call plus a victim being talked into voluntarily sharing their own phone screen, the single action that handed operators everything they needed (passwords, balances, live OTP codes) to empty the account in real time. It also shows the full criminal supply chain behind such scams in emerging markets: mass outbound contact, a scripted "call-center" social-engineering layer, and a separate money-mule/cash-out layer using ordinary bank branches, ATMs and correspondent agents to launder proceeds before authorities can freeze them. The disproportionate targeting of adults over 50, and the reported use of victim-specific personal/banking details to boost credibility, underscore why age-aware fraud education and out-of-band transaction verification (not just OTPs a victim can be talked into revealing) remain essential complements to bank fraud controls. The involvement of a public figure's son among the 16 detainees as an alleged money-mule facilitator also illustrates how far into ordinary life bank-impersonation fraud networks can recruit for the laundering stage.

Defenses

Colombian police (Coronel Jaime Enrique Higgins Pacheco, commander of the Risaralda Police Department, and Henry Hernando Hernandez Granados, Fiscalia Risaralda sectional director) publicly urged citizens never to share their phone screen or hand over banking credentials/OTP codes to anyone contacting them by phone or WhatsApp, even when the caller claims to represent a bank, and to verify any account-security alert only through official bank channels (branch, official app, verified phone line) before acting; they also urged reporting suspected fraud attempts to help identify remaining ring members. From a control standpoint the case underscores several gaps exploited: (1) no real-time detection of live screen-mirroring during a "banking help" call; (2) reliance on victim self-initiated screen-share as the sole authentication bypass, with no secondary out-of-band verification before high-value transfers; (3) money-mule layering across many receiving accounts and same-day cash-out via ATMs/branches/banking correspondents that outpaced transaction-velocity fraud controls; (4) elderly/over-50 demographic targeting, where device/OS-level screen-share warnings and family/bank staff education are typically weaker. Investigators noted authorities were also examining whether bank insiders supplied victim profile data, which remains unproven.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance and victim-list acquisition: Consistent with the roughly 94-victim, 10-department reach described by Fiscalia/Policia, Los Cyber likely assembled or bought lists of potential targets, phone numbers and basic personal or banking details skewed toward older adults, using sources typically available to rings like this, such as leaked-data marketplaces, prior breach dumps or commercially available contact-list brokers, rather than hand-picking each victim individually.
Countering Stage 1: Consumer-level exposure to leaked personal data or purchased contact lists is very hard for any single bank to prevent. The realistic control sits upstream, in breach-notification laws and data-broker regulation, and in banks assuming attackers already have a customer's phone number and basic details rather than treating a caller's accurate personal information as proof of legitimacy.
2
Mule-account and cash-out infrastructure: Before contacting victims, the ring needed a standing network of bank accounts, cards and cash-out points to receive and launder stolen funds quickly. Per the case, this included recruiting individuals such as a former professional footballer alleged to have provided his own bank account for this purpose, alongside the broader mule layer implied by the 35 bank cards investigators seized.
Countering Stage 2: Banks and regulators can apply money-mule detection controls, such as flagging newly opened or low-activity accounts that suddenly receive many small third-party inbound transfers followed by rapid cash withdrawal, and can require enhanced onboarding checks that make recruiting and using a mule account slower and more visible.
3
Caller-ID and identity spoofing setup: Authorities described the group's core technique as 'spoofing,' so the ring likely used commercially available caller-ID or number-spoofing methods and WhatsApp account setups to make calls and messages appear to originate from a legitimate bank, though the specific tooling was not detailed in reporting.
Countering Stage 3: Telecom-level caller-ID authentication standards, such as STIR/SHAKEN-style call-origin verification, and carrier-level spoofed-number blocking reduce, though do not eliminate, a caller's ability to convincingly impersonate a bank's outbound number. Banks can reinforce this by publicly stating they never demand urgent account action on an inbound, unsolicited call.
4
Mass initial contact: Bulk SMS and WhatsApp messages, typically sent through bulk-messaging services, cast a wide net across the targeted departments to identify which numbers were live and responsive before investing operator time in a live call.
Countering Stage 4: Telecom and platform-level bulk-messaging abuse detection, SMS and WhatsApp spam filtering and sender verification, can catch and throttle mass fraudulent outreach campaigns before they reach large numbers of potential victims, and public police or bank warnings about unsolicited 'bank' texts shrink the pool of people who respond.
5
Live vishing pretext call: A scripted operator called or WhatsApp-called responding victims posing as bank fraud-prevention or customer-service staff, warning of a suspicious transaction or identity-theft attempt and offering a same-call 'preventive block,' consistent with the captured audio quoted by El Tiempo.
Countering Stage 5: The single most effective control is customer education, repeated by Colombian police in this case, that a legitimate bank will never ask a customer to act urgently in response to an inbound, unsolicited call or WhatsApp message. Training customers to hang up and call the bank back on an official number breaks the pretext at its most critical point.
6
Induced screen-sharing: Having built enough trust and urgency, the operator talked the victim through opening their banking app and activating phone screen-sharing, in some cases via a WhatsApp video call, the single action that gave the operator a live view of the victim's own device.
Countering Stage 6: Device and app-level warnings when screen-sharing is activated during an active call, plus explicit bank guidance that it will never ask a customer to share their phone screen, directly target the single action that gave operators full visibility into the victim's banking session.
7
Live credential and OTP capture with unauthorized transfer: With the screen shared, the operator watched in real time as the victim entered usernames, passwords and SMS one-time codes, in some cases reportedly guiding the victim step by step, then used that visibility to initiate transfers directly out of the account.
Countering Stage 7: Banks can require secondary out-of-band transaction verification, such as a callback or app-based confirmation on a channel the fraudster cannot see or influence, before executing high-value transfers, so a password or OTP visible to a screen-sharing observer is not sufficient on its own to move money.
8
Layering through mule accounts: Stolen funds were rapidly moved through multiple intermediary and mule accounts, the kind pre-arranged in stage 2, to break the audit trail before banks or authorities could freeze them.
Countering Stage 8: Real-time transaction-velocity and mule-network fraud analytics that flag rapid multi-hop transfers between newly linked accounts can interrupt layering before funds are fully dispersed, which is faster and more effective than after-the-fact investigation.
9
Cash-out and objective completion: Funds were withdrawn as cash at ATMs, bank branches and authorized banking correspondents, in some cases reportedly verified by facial recognition or fingerprint at the counter, completing the theft and finalizing the ring's objective.
Countering Stage 9: Cash-out controls, such as lower daily withdrawal limits on newly funded accounts, mandatory identity verification at high-value ATM, branch or correspondent withdrawals, and bank-correspondent monitoring for withdrawal patterns consistent with fraud proceeds, are the last practical checkpoint before stolen funds are irretrievably converted to cash.
Quick Facts
Victim
94 documented victims (bank customers of unnamed Colombian financial institutions), the large majority adults over 50, spread across 10 Colombian departments (Risaralda, Bogota, La Guajira, Valle del Cauca, Cauca, Atlantico, Narino, Quindio, Meta, Bolivar per the most-repeated list; some outlets substitute Cesar/Cundinamarca/Tolima for a few of these)
Location
Colombia, victims mostly in Risaralda, Bogota, La Guajira, Valle del Cauca, Cauca, Atlantico, Narino, Quindio, Meta and Bolivar (10 departments; a few outlets substitute Cesar, Cundinamarca or Tolima in place of some of these, so the exact 10-department list varies slightly by source); ring members arrested in Bogota, Soacha (Cundinamarca), Bucaramanga (Santander), Ibague (Tolima) and Filandia (Quindio).
Date
Fraud scheme active June 2025 to March 2026; coordinated raids captured all 16 alleged members on July 9-10, 2026, per the Fiscalia/Policia press conference and the majority of contemporaneous outlets (El Tiempo, Infobae, El Pais, Caracol Radio), with coverage published/announced July 9-11, 2026. One outlet, El Diario (published Jul 10, 2026), instead states the physical captures occurred "el martes 7 de julio" (Tuesday, July 7, 2026), a minor cross-source date discrepancy, possibly reflecting a gap between the raid-execution date and the public press-conference/announcement date. One of the original 16 detainees, footballer Mateo Ramirez Florez, was individually profiled in a later wave of coverage on July 22-24, 2026 after his football-family lineage became public; this was a profile piece about an existing detainee, not a separate or 17th arrest.
Impact
COP 1,685,000,000 (reported by Fiscalia/Policia as "mas de $1.685 millones de pesos"). Using the official Colombian TRM exchange rate prevailing around the July 9-11, 2026 reporting window (Superintendencia Financiera de Colombia TRM: ~COP 3,339.65/USD on Jul 9, ~3,305.38 on Jul 10, ~3,248.87 on Jul 11, independently confirmed against three separate TRM-tracking sources), this converts to approximately USD $505,000-$519,000, i.e. roughly USD $500,000-520,000 (not the $400,000-420,000 previously stated, which implied an inaccurate ~4,000-4,200 COP/USD rate). Some early wire reports rounded the peso figure down to "more than COP 1.600 millones." Authorities stated the true total could be higher as the investigation continues and additional victims are identified.
Status
Confirmed
Case Type
Real-World Incident
Sector
Consumer / General Public, Financial Services & Insurance
Threat Actor
Organized Crime
Related

Related Cases

Quebec AI-Assisted "Grandparent Scam" Ring: Teodor/Condurache Sentenced After Targeting Saskatchewan Seniors

Two Quebec fraudsters acting as courier and driver for an AI-voice-cloned "grandchild in crisis" vishing scheme that defrauded Saskatchewan seniors…

Incident 2025Read →

Jaguar Land Rover Vishing-Triggered Shutdown

JLR's five-week production halt and record £1.9bn UK economic hit were first blamed on helpdesk-vishing by a criminal collective calling…

Incident 2025Read →

DOJ/IRS-CI Unseal $65M "Mistaken Refund" Elder-Fraud Indictments Against 28-Member Chinese Money-Laundering Ring

DOJ/IRS-CI unsealed four indictments charging 28 members of a Chinese organized-crime money-laundering ring tied to India-based "mistaken refund" call-center scams…

Incident 2025Read →