A 16-member Colombian crime ring called and WhatsApp-messaged bank customers posing as fraud-prevention officers, talked mostly over-50 victims into sharing their phone screens, and drained COP 1.685 billion from 94 people across 10 departments before a joint Fiscalia-Policia Nacional operation captured the group, including alleged leader alias "Ralf."
Reviewed by the Social Engineering Examples team.
Between June 2025 and March 2026, a Colombian criminal organization known as "Los Cyber" ran a large-scale bank-impersonation vishing operation, contacting victims, overwhelmingly adults over 50, by bulk SMS/WhatsApp message followed by phone calls or WhatsApp voice/video calls in which operators posed as bank fraud-prevention or customer-service staff. Claiming they needed to help block a suspicious transaction or protect the account from identity theft, the callers persuaded victims to share their phone screen live, allowing the operators to see usernames, passwords, balances and SMS one-time codes in real time and to execute transfers straight out of the accounts. Stolen money was rapidly moved through multiple intermediary/mule accounts and then withdrawn in cash via ATMs, bank branches and banking correspondents to frustrate tracing. The scheme reportedly affected at least 94 documented victims across 10 Colombian departments and totaled roughly COP 1.685 billion in losses. On July 9-10, 2026, a joint operation by the Fiscalia General de la Nacion, Policia Nacional and CTI carried out simultaneous raids in five cities and arrested 16 alleged members, including the accused ringleader known by the alias "Ralf." A later wave of coverage on July 22-24, 2026 revealed that one of those same 16 detainees, Mateo Ramirez Florez, is a former professional footballer and the son of the late Millonarios/Colombia idol Jhon Mario Ramirez, allegedly recruited to provide a bank account used to receive laundered funds; this was public identification of an existing detainee, not a new arrest. Investigators indicated the case remained open and the final victim count/loss total could grow.
The ring, known as "Los Cyber," first blasted mass SMS/WhatsApp messages to potential victims, then followed up with direct phone calls or WhatsApp voice/video calls in which operators posed as fraud-prevention or customer-service staff from unnamed Colombian banks. Using a masking/impersonation technique authorities described as "spoofing," callers warned victims of supposed unrecognized transactions or identity-theft attempts on their account and, under the pretext of a "preventive security block" or identity verification, talked them through opening their banking app and sharing their phone screen live during the call (in some cases via a WhatsApp video call). With the screen shared, operators watched in real time as victims entered usernames, passwords, balances and SMS one-time codes, then used that access to transfer funds out of the accounts. Stolen funds were rapidly layered through multiple intermediary and mule accounts to break the audit trail before being withdrawn as cash at bank branches, ATMs, and authorized banking correspondents. One investigative follow-up (El Tiempo) also described victims being directed to a fake WhatsApp "assistant" bot and a fabricated in-branch appointment as part of the con. Later profile coverage (El Heraldo, Jul 22; Focus Noticias, Jul 23, 2026) of one of the original 16 detainees, a professional footballer alleged to have provided a bank account used to receive laundered funds, added that the group also used fraudulent WhatsApp links and, per those two outlets, AI-assisted tools/video calls to bolster the impersonation; this detail is not corroborated across the main July 9-11 wave of coverage.
Lure: an unsolicited call or WhatsApp message/video call from someone claiming to be a bank fraud-prevention or customer-service officer, warning of a suspicious transaction or possible identity theft on the victim's account and offering to help "protect" the funds with a same-call "preventive block." One captured audio quoted by El Tiempo has an operator saying: "Lo que pasa es que en este caso debemos realizar por seguridad un bloqueo preventivo, ya que es probable que usted este siendo victima de suplantacion de identidad" ("For security we need to do a preventive block, since you may be a victim of identity theft"). Tell/red flags: a legitimate bank will never ask a customer to share their phone screen, read out passwords, or hand over one-time SMS codes over a call or WhatsApp chat it initiated; the urgency ("your account is compromised right now"), the request for real-time screen access, and the shift from a text message to an unsolicited voice/video call are all hallmarks of the scam that police highlighted in their public warning.
On July 9-10, 2026, the Fiscalia General de la Nacion, Policia Nacional (Risaralda Police/DIJIN-SIJIN) and the Cuerpo Tecnico de Investigacion (CTI) carried out simultaneous raids in Bogota, Soacha, Bucaramanga, Ibague and Filandia (Quindio), arresting 16 alleged members of "Los Cyber," including the accused leader, alias "Ralf" (identified in press reports as Ralf Sebastian Nieva, also rendered Ralf Sebastian Nieva Vasquez). Other named detainees included Karen Sofia Posada Sanchez, Heidy Alexandra Posada Sanchez, Angel Camilo Salamanca Daza, Yasmin Eliana Naranjo Aguirre, Andrea Alejandra Castano Ferro, Manuel Roberto Clavijo Gutierrez, Mateo Ramirez Florez, Kevin Andres Menjura Nieto, Jaime Andres Bedoya Montana, Juan Andres Leon Pena, Esneda Munoz Nunez, Carlos Santiago Fuentes Parra, Margeydys Vides Pineda, Hernan Dario Pico Hoyos and Victor Alejandro Monroy Garcia. Authorities seized 35 bank cards, 22 cell phones, 4 laptops, 6 USB drives, 5 SIM cards and about COP 7 million in cash. All 16 were charged with concierto para delinquir (criminal conspiracy), aggravated illicit enrichment by private individuals, computer-facilitated theft, unauthorized access to an information system, and violation of personal data; a control-of-guarantees judge legalized the arrests. A later wave of coverage beginning July 22, 2026 (El Heraldo, Infobae, El Espectador, GolCaracol, Pulzo, Marca) identified one of the original 16 as Mateo Ramirez Florez, a 26-27-year-old former professional footballer (debuted with Patriotas Boyaca in 2021) and son of the late Millonarios/Colombia idol Jhon Mario Ramirez; a Dijin investigator told El Tiempo that Ramirez "presto su cuenta bancaria" (provided his bank account) to receive funds from the fraud. This was public identification/profiling of a detainee already captured July 9-10, 2026, not a new or 17th arrest. Investigators said they were continuing to work to identify further victims and members and to establish the full amount defrauded, which they said could exceed the reported COP 1.685 billion.
The case is a textbook, well-documented illustration of classic bank-impersonation vishing at organized-crime scale: no malware, no sophisticated exploit, just a scripted authority-impersonation call plus a victim being talked into voluntarily sharing their own phone screen, the single action that handed operators everything they needed (passwords, balances, live OTP codes) to empty the account in real time. It also shows the full criminal supply chain behind such scams in emerging markets: mass outbound contact, a scripted "call-center" social-engineering layer, and a separate money-mule/cash-out layer using ordinary bank branches, ATMs and correspondent agents to launder proceeds before authorities can freeze them. The disproportionate targeting of adults over 50, and the reported use of victim-specific personal/banking details to boost credibility, underscore why age-aware fraud education and out-of-band transaction verification (not just OTPs a victim can be talked into revealing) remain essential complements to bank fraud controls. The involvement of a public figure's son among the 16 detainees as an alleged money-mule facilitator also illustrates how far into ordinary life bank-impersonation fraud networks can recruit for the laundering stage.
Colombian police (Coronel Jaime Enrique Higgins Pacheco, commander of the Risaralda Police Department, and Henry Hernando Hernandez Granados, Fiscalia Risaralda sectional director) publicly urged citizens never to share their phone screen or hand over banking credentials/OTP codes to anyone contacting them by phone or WhatsApp, even when the caller claims to represent a bank, and to verify any account-security alert only through official bank channels (branch, official app, verified phone line) before acting; they also urged reporting suspected fraud attempts to help identify remaining ring members. From a control standpoint the case underscores several gaps exploited: (1) no real-time detection of live screen-mirroring during a "banking help" call; (2) reliance on victim self-initiated screen-share as the sole authentication bypass, with no secondary out-of-band verification before high-value transfers; (3) money-mule layering across many receiving accounts and same-day cash-out via ATMs/branches/banking correspondents that outpaced transaction-velocity fraud controls; (4) elderly/over-50 demographic targeting, where device/OS-level screen-share warnings and family/bank staff education are typically weaker. Investigators noted authorities were also examining whether bank insiders supplied victim profile data, which remains unproven.
Two Quebec fraudsters acting as courier and driver for an AI-voice-cloned "grandchild in crisis" vishing scheme that defrauded Saskatchewan seniors…
JLR's five-week production halt and record £1.9bn UK economic hit were first blamed on helpdesk-vishing by a criminal collective calling…
DOJ/IRS-CI unsealed four indictments charging 28 members of a Chinese organized-crime money-laundering ring tied to India-based "mistaken refund" call-center scams…