A 16-member Colombian crime ring called and WhatsApp-messaged bank customers posing as fraud-prevention officers.
Social Engineering Examples·9 sources
Between June 2025 and March 2026, a Colombian criminal organization known as "Los Cyber" ran a large-scale bank-impersonation vishing operation, contacting victims, overwhelmingly adults over 50, by bulk SMS/WhatsApp message followed by phone calls or WhatsApp voice/video calls in which operators posed as bank fraud-prevention or customer-service staff.
Claiming they needed to help block a suspicious transaction or protect the account from identity theft, the callers persuaded victims to share their phone screen live, allowing the operators to see usernames, passwords, balances and SMS one-time codes in real time and to execute transfers straight out of the accounts. Stolen money was rapidly moved through multiple intermediary/mule accounts and then withdrawn in cash via ATMs, bank branches and banking correspondents to frustrate tracing.
The scheme reportedly affected at least 94 documented victims across 10 Colombian departments and totaled roughly COP 1.685 billion in losses. On July 9-10, 2026, a joint operation by the Fiscalia General de la Nacion, Policia Nacional and CTI carried out simultaneous raids in five cities and arrested 16 alleged members, including the accused ringleader known by the alias "Ralf." A later wave of coverage on July 22-24, 2026 revealed that one of those same 16 detainees, Mateo Ramirez Florez, is a former professional footballer and the son of the late Millonarios/Colombia idol Jhon Mario Ramirez, allegedly recruited to provide a bank account used to receive laundered funds; this was public identification of an existing detainee, not a new arrest.
Investigators indicated the case remained open and the final victim count/loss total could grow.
The ring, known as "Los Cyber," first blasted mass SMS/WhatsApp messages to potential victims, then followed up with direct phone calls or WhatsApp voice/video calls in which operators posed as fraud-prevention or customer-service staff from unnamed Colombian banks. Using a masking/impersonation technique authorities described as "spoofing," callers warned victims of supposed unrecognized transactions or identity-theft attempts on their account and, under the pretext of a "preventive security block" or identity verification, talked them through opening their banking app and sharing their phone screen live during the call (in some cases via a WhatsApp video call).
With the screen shared, operators watched in real time as victims entered usernames, passwords, balances and SMS one-time codes, then used that access to transfer funds out of the accounts. Stolen funds were rapidly layered through multiple intermediary and mule accounts to break the audit trail before being withdrawn as cash at bank branches, ATMs, and authorized banking correspondents.
One investigative follow-up (El Tiempo) also described victims being directed to a fake WhatsApp "assistant" bot and a fabricated in-branch appointment as part of the con. Later profile coverage (El Heraldo, Jul 22; Focus Noticias, Jul 23, 2026) of one of the original 16 detainees, a professional footballer alleged to have provided a bank account used to receive laundered funds, added that the group also used fraudulent WhatsApp links and, per those two outlets, AI-assisted tools/video calls to bolster the impersonation; this detail is not corroborated across the main July 9-11 wave of coverage.
Lure: an unsolicited call or WhatsApp message/video call from someone claiming to be a bank fraud-prevention or customer-service officer, warning of a suspicious transaction or possible identity theft on the victim's account and offering to help "protect" the funds with a same-call "preventive block." One captured audio quoted by El Tiempo has an operator saying: "Lo que pasa es que en este caso debemos realizar por seguridad un bloqueo preventivo, ya que es probable que usted este siendo victima de suplantacion de identidad" ("For security we need to do a preventive block, since you may be a victim of identity theft").
Tell/red flags: a legitimate bank will never ask a customer to share their phone screen, read out passwords, or hand over one-time SMS codes over a call or WhatsApp chat it initiated; the urgency ("your account is compromised right now"), the request for real-time screen access, and the shift from a text message to an unsolicited voice/video call are all hallmarks of the scam that police highlighted in their public warning.
On July 9-10, 2026, the Fiscalia General de la Nacion, Policia Nacional (Risaralda Police/DIJIN-SIJIN) and the Cuerpo Tecnico de Investigacion (CTI) carried out simultaneous raids in Bogota, Soacha, Bucaramanga, Ibague and Filandia (Quindio), arresting 16 alleged members of "Los Cyber," including the accused leader, alias "Ralf" (identified in press reports as Ralf Sebastian Nieva, also rendered Ralf Sebastian Nieva Vasquez).
Other named detainees included Karen Sofia Posada Sanchez, Heidy Alexandra Posada Sanchez, Angel Camilo Salamanca Daza, Yasmin Eliana Naranjo Aguirre, Andrea Alejandra Castano Ferro, Manuel Roberto Clavijo Gutierrez, Mateo Ramirez Florez, Kevin Andres Menjura Nieto, Jaime Andres Bedoya Montana, Juan Andres Leon Pena, Esneda Munoz Nunez, Carlos Santiago Fuentes Parra, Margeydys Vides Pineda, Hernan Dario Pico Hoyos and Victor Alejandro Monroy Garcia.
Authorities seized 35 bank cards, 22 cell phones, 4 laptops, 6 USB drives, 5 SIM cards and about COP 7 million in cash. All 16 were charged with concierto para delinquir (criminal conspiracy), aggravated illicit enrichment by private individuals, computer-facilitated theft, unauthorized access to an information system, and violation of personal data; a control-of-guarantees judge legalized the arrests.
A later wave of coverage beginning July 22, 2026 (El Heraldo, Infobae, El Espectador, GolCaracol, Pulzo, Marca) identified one of the original 16 as Mateo Ramirez Florez, a 26-27-year-old former professional footballer (debuted with Patriotas Boyaca in 2021) and son of the late Millonarios/Colombia idol Jhon Mario Ramirez; a Dijin investigator told El Tiempo that Ramirez "presto su cuenta bancaria" (provided his bank account) to receive funds from the fraud.
This was public identification/profiling of a detainee already captured July 9-10, 2026, not a new or 17th arrest. Investigators said they were continuing to work to identify further victims and members and to establish the full amount defrauded, which they said could exceed the reported COP 1.685 billion.
The case is a textbook, well-documented illustration of classic bank-impersonation vishing at organized-crime scale: no malware, no sophisticated exploit, just a scripted authority-impersonation call plus a victim being talked into voluntarily sharing their own phone screen, the single action that handed operators everything they needed (passwords, balances, live OTP codes) to empty the account in real time.
It also shows the full criminal supply chain behind such scams in emerging markets: mass outbound contact, a scripted "call-center" social-engineering layer, and a separate money-mule/cash-out layer using ordinary bank branches, ATMs and correspondent agents to launder proceeds before authorities can freeze them. The disproportionate targeting of adults over 50, and the reported use of victim-specific personal/banking details to boost credibility, underscore why age-aware fraud education and out-of-band transaction verification (not just OTPs a victim can be talked into revealing) remain essential complements to bank fraud controls.
The involvement of a public figure's son among the 16 detainees as an alleged money-mule facilitator also illustrates how far into ordinary life bank-impersonation fraud networks can recruit for the laundering stage.
Colombian police (Coronel Jaime Enrique Higgins Pacheco, commander of the Risaralda Police Department, and Henry Hernando Hernandez Granados, Fiscalia Risaralda sectional director) publicly urged citizens never to share their phone screen or hand over banking credentials/OTP codes to anyone contacting them by phone or WhatsApp, even when the caller claims to represent a bank, and to verify any account-security alert only through official bank channels (branch, official app, verified phone line) before acting; they also urged reporting suspected fraud attempts to help identify remaining ring members.
From a control standpoint the case underscores several gaps exploited: (1) no real-time detection of live screen-mirroring during a "banking help" call; (2) reliance on victim self-initiated screen-share as the sole authentication bypass, with no secondary out-of-band verification before high-value transfers; (3) money-mule layering across many receiving accounts and same-day cash-out via ATMs/branches/banking correspondents that outpaced transaction-velocity fraud controls; (4) elderly/over-50 demographic targeting, where device/OS-level screen-share warnings and family/bank staff education are typically weaker.
Investigators noted authorities were also examining whether bank insiders supplied victim profile data, which remains unproven.
Social Engineering Examples. “Los Cyber Bank-Impersonation Vishing Network Dismantled in Colombia”. Accessed 19 September 2026. https://socialengineeringexamples.com/los-cyber-bank-impersonation-vishing-colombia-2026
Consistent with the roughly 94-victim, 10-department reach described by Fiscalia/Policia, Los Cyber likely assembled or bought lists of potential targets, phone numbers and basic personal or banking details skewed toward older adults, using sources typically available to rings like this, such as leaked-data marketplaces, prior breach dumps or commercially available contact-list brokers, rather than hand-picking each victim individually.
Consumer-level exposure to leaked personal data or purchased contact lists is very hard for any single bank to prevent. The realistic control sits upstream, in breach-notification laws and data-broker regulation, and in banks assuming attackers already have a customer's phone number and basic details rather than treating a caller's accurate personal information as proof of legitimacy.
Before contacting victims, the ring needed a standing network of bank accounts, cards and cash-out points to receive and launder stolen funds quickly. Per the case, this included recruiting individuals such as a former professional footballer alleged to have provided his own bank account for this purpose, alongside the broader mule layer implied by the 35 bank cards investigators seized.
Banks and regulators can apply money-mule detection controls, such as flagging newly opened or low-activity accounts that suddenly receive many small third-party inbound transfers followed by rapid cash withdrawal, and can require enhanced onboarding checks that make recruiting and using a mule account slower and more visible.
Authorities described the group's core technique as 'spoofing,' so the ring likely used commercially available caller-ID or number-spoofing methods and WhatsApp account setups to make calls and messages appear to originate from a legitimate bank, though the specific tooling was not detailed in reporting.
Telecom-level caller-ID authentication standards, such as STIR/SHAKEN-style call-origin verification, and carrier-level spoofed-number blocking reduce, though do not eliminate, a caller's ability to convincingly impersonate a bank's outbound number. Banks can reinforce this by publicly stating they never demand urgent account action on an inbound, unsolicited call.
Bulk SMS and WhatsApp messages, typically sent through bulk-messaging services, cast a wide net across the targeted departments to identify which numbers were live and responsive before investing operator time in a live call.
Telecom and platform-level bulk-messaging abuse detection, SMS and WhatsApp spam filtering and sender verification, can catch and throttle mass fraudulent outreach campaigns before they reach large numbers of potential victims, and public police or bank warnings about unsolicited 'bank' texts shrink the pool of people who respond.
A scripted operator called or WhatsApp-called responding victims posing as bank fraud-prevention or customer-service staff, warning of a suspicious transaction or identity-theft attempt and offering a same-call 'preventive block,' consistent with the captured audio quoted by El Tiempo.
The single most effective control is customer education, repeated by Colombian police in this case, that a legitimate bank will never ask a customer to act urgently in response to an inbound, unsolicited call or WhatsApp message. Training customers to hang up and call the bank back on an official number breaks the pretext at its most critical point.
Having built enough trust and urgency, the operator talked the victim through opening their banking app and activating phone screen-sharing, in some cases via a WhatsApp video call, the single action that gave the operator a live view of the victim's own device.
Device and app-level warnings when screen-sharing is activated during an active call, plus explicit bank guidance that it will never ask a customer to share their phone screen, directly target the single action that gave operators full visibility into the victim's banking session.
With the screen shared, the operator watched in real time as the victim entered usernames, passwords and SMS one-time codes, in some cases reportedly guiding the victim step by step, then used that visibility to initiate transfers directly out of the account.
Banks can require secondary out-of-band transaction verification, such as a callback or app-based confirmation on a channel the fraudster cannot see or influence, before executing high-value transfers, so a password or OTP visible to a screen-sharing observer is not sufficient on its own to move money.
Stolen funds were rapidly moved through multiple intermediary and mule accounts, the kind pre-arranged in stage 2, to break the audit trail before banks or authorities could freeze them.
Real-time transaction-velocity and mule-network fraud analytics that flag rapid multi-hop transfers between newly linked accounts can interrupt layering before funds are fully dispersed, which is faster and more effective than after-the-fact investigation.
Funds were withdrawn as cash at ATMs, bank branches and authorized banking correspondents, in some cases reportedly verified by facial recognition or fingerprint at the counter, completing the theft and finalizing the ring's objective.
Cash-out controls, such as lower daily withdrawal limits on newly funded accounts, mandatory identity verification at high-value ATM, branch or correspondent withdrawals, and bank-correspondent monitoring for withdrawal patterns consistent with fraud proceeds, are the last practical checkpoint before stolen funds are irretrievably converted to cash.
Browse by what this case has in common with others in the library.
Two Quebec fraudsters acting as courier and driver for an AI-voice-cloned "grandchild in crisis" vishing scheme that defrauded Saskatchewan seniors.
JLR's five-week production halt and record £1.9bn UK economic hit were first blamed on helpdesk-vishing by a criminal collective calling…
DOJ/IRS-CI unsealed four indictments charging 28 members of a Chinese organized-crime money-laundering ring tied to India-based "mistaken refund".
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
Fraudsters hijacked a WhatsApp account via a malicious ZIP file, swapped in their own number while keeping the real display…
The FTC's first major consumer alert on QR-code scams (Dec 6, 2023) warned of fake QR stickers on parking meters…
Tejay Fletcher founded and ran iSpoof, a Bitcoin-subscription caller-ID spoofing and OTP-interception platform that let fraudsters impersonate bank.
Scammers papered roughly 200 counterfeit QR-code stickers over legitimate ParkMobile decals on downtown Orlando parking meters.
A lone, unidentified hacker jailbroke Anthropic's Claude Code coding agent with a fake "authorized bug bounty/pentest" pretext and paired it.
Ghanaian social-media personality Frederick Kumi ("Abu Trica") and co-defendant Daniel Yussif were federally indicted for leading a romance-fraud network.
DOJ/IRS-CI unsealed four indictments charging 28 members of a Chinese organized-crime money-laundering ring tied to India-based "mistaken refund".
Evaldas Rimasauskas ran a five-year, $120M fraud against Google and Facebook using forged Quanta Computer invoices.
A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…
A four-man Manhattan fraud ring compromised a nonprofit CFO's and a portfolio company employee's business email accounts to redirect $3.49M…
Costa Rica-based ringleader Roger Roger used spoofed government caller ID to convince hundreds of elderly victims they had won sweepstakes…
DOJ's first-of-its-kind nationwide takedown charged 61 defendants and five Ahmedabad.