Phishing

Cybercriminals in the Andes Use Phishing to Empty Accounts Linked to Banco de Venezuela and Sistema Patria

On March 28, 2025, reports citing the CICPC and authorities in Táchira described the dismantling of Los Ciberandinos, a gang that used phishing, mirror sites, fake profiles, and foreign WhatsApp numbers to obtain credentials and drain accounts associated with Banco de Venezuela and the Patria System/Platform. Sources describe a single criminal organization, a single investigation, and a common pattern of credential theft, transfers to third parties, currency conversion, and the purchase of goods. Banco de Venezuela and Patria remain platforms that were exploited or impersonated, not confirmed infrastructure breaches. More than 200 victims were reported, including the municipal governments of San Cristóbal and Jauregui; six people were arrested in total (including a minor); and an alleged leader has fled to Colombia.

Overview

Missing evidence

independent forensic reportsBreakdown of losses by platform or municipalityEvidence of the security breach in the BDV or Patria infrastructure

Impact details

200 Affected people

Media reports describe a phishing and cyberfraud operation carried out by Los Ciberandinos that emptied the accounts of individuals and entities linked to Banco de Venezuela and the Patria System, with a haul of approximately $10 million and some 200 people and institutions affected. The BDV and Patria are considered to have been misused, although it has not been confirmed that a security breach occurred in their infrastructure.

credentialsaccount accesspersonal informationuser accountsonline bank accountspatria accounts

Classification & severity

Category
Fraud
Subtype
Phishing
Confidence
High

Several media outlets are reporting cases of phishing and cyberfraud that have emptied accounts linked to Banco de Venezuela and the Patria System. The primary incident is fraud or phishing, and it has not been confirmed that the infrastructure of BDV or Patria has been compromised.

Severity assessment

High
Functional impact
None
Information impact
Credentials
Affected scope
Multiple users
Critical service
Potential
Public confidence
Moderate

Public sources systematically report cases of phishing and the misuse of credentials or accounts, affecting some 200 individuals or institutions and resulting in approximately 10 million U.S. dollars in thefts. There is no public evidence confirming a breach in the infrastructure of BDV or Patria.

ConfidentialityIntegrity

Timeline

Compromise

The cybercrime group "Los Ciberandinos" steals user credentials from Banco de Venezuela and the Patria System through phishing (using mirror websites and profiles, as well as fake WhatsApp profiles), and empties accounts of an estimated $10 million, affecting more than 200 victims.

Remediation

The CICPC and Redip Los Andes dismantled the gang in Táchira state and arrested six people (five adults and one teenager).

Disclosure

The CICPC, through its director Douglas Rico, publicly announces the case; the alleged ringleader is believed to have fled to Colombia, and a Red Notice will be requested from Interpol.

Evidence & sources

8 sources