← Back to list

Colombian Elections and Hacktivism Overview

Monitoring by the National Electoral Council shows that Colombia is preparing a segmented digital infrastructure for different components…

VECERT · 2026-06-04 13:47 · 0 claps · 7.6 min read
#colombia #hacktivi #hacker #cybersecurity #osint-investigation
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity 🏛️ · Politics

Colombian Elections and Hacktivism Overview

Monitoring by the National Electoral Council shows that Colombia is preparing a segmented digital infrastructure for different components of the electoral process. The existence of specific domains for the presidency, congress, special elections, and training indicates an operational separation strategy that seeks to reduce risks and maintain control over each environment of the Colombian electoral system.

electoral evolution, monitoring subdomain activity and creation

electoral evolution, monitoring subdomain activity and creation

The domains related to “electoral actors” reflect that the focus is not only on voting or counting, but also on all the people and organizations that participate in the electoral ecosystem, such as poll workers, officials, political parties, observers, and technical operators. In electoral cybersecurity, the human factor is one of the main targets of attack, and therefore training platforms are a critical part of institutional defense.

Colombia faces constant threats related to disinformation, phishing, influence campaigns, DDoS attacks, and digital espionage operations. In many cases, the objective of malicious actors is not to directly alter votes but to undermine public trust, generate information chaos, or weaken institutional legitimacy during elections. The training subdomains suggest that the National Electoral Council (CNE) and related entities are strengthening training and authentication processes to reduce human error and unauthorized access. This is typically complemented by technical measures such as SOC monitoring, network segmentation, DNS protection, multi-factor authentication, SIEM systems, and mitigation of attacks against public portals. The dates observed in the subdomain certificates and registrations show progressive activations throughout 2026, which may indicate phases of deployment and pre-election preparation.

From an OSINT perspective, this allows for an analysis of how the digital infrastructure of the Colombian electoral process evolves and how the State’s exposed surface is organized in the face of cyber threats. The public existence of these subdomains does not necessarily imply a vulnerability.

Many services must be accessible by design to allow for training, consultation, or interaction by electoral actors. The important thing is to evaluate the security of configurations, the unnecessary exposure of services, and the capacity to respond to incidents. In the current context, electoral cybersecurity in Colombia not only consists of protecting servers or voting systems but also of defending democratic stability, citizen trust, and institutional continuity against malicious actors who seek to affect the electoral process from multiple digital fronts.

Hacktivism and cyber pressure on the Colombian electoral environment

The recent increase in cyber incidents, data leaks, and hacktivist activity against Colombian public and private institutions adds a new dimension to the electoral cybersecurity landscape. Throughout 2025 and 2026, multiple threat actors have publicly claimed compromises affecting government entities, educational institutions, healthcare systems, financial organizations, and public service platforms in Colombia.

Among the most sensitive events are alleged leaks related to Colombian government infrastructure, including references to Registraduría-related databases, municipal government portals, public employment systems, and other state digital services. Threat actors such as NyxarGroup, Petro_Escobar, ArcRaidersPlayer, CryptoDead, and others have repeatedly published datasets, credentials, or access claims associated with Colombian organizations and institutions.

From a strategic perspective, these campaigns demonstrate several relevant patterns for electoral security analysis:

A growing targeting of public-sector infrastructure and citizen data repositories.

Increased exposure of authentication credentials and administrative access.

Repeated attacks against educational and training environments, which are often connected to identity systems and institutional networks.

The use of data leaks not only for financial gain, but also for psychological impact, propaganda, reputational damage, and institutional destabilization.

In an electoral context, hacktivist operations do not necessarily need to compromise voting systems directly to generate significant impact. Attacks against peripheral systems — such as voter information portals, training platforms, authentication services, municipal infrastructure, or communication channels — can still produce operational disruption and public distrust. The objective may shift from altering electoral results to creating uncertainty, amplifying disinformation narratives, or weakening confidence in democratic institutions.

The exposure of government-related databases and administrative services observed during 2026 also suggests that adversaries may be mapping Colombian institutional infrastructure well before major electoral phases. This reconnaissance-oriented behavior is consistent with tactics commonly associated with influence operations, cyber-enabled psychological operations, and pre-positioning activities designed to exploit politically sensitive periods.

Another critical factor is the role of hacktivist branding and public leak channels. Many of these actors seek visibility and media amplification rather than stealth persistence. During electoral periods, this dynamic can accelerate information chaos, especially if leaked or manipulated datasets are weaponized through social networks, coordinated disinformation campaigns, or politically motivated narratives.

From an OSINT perspective, the correlation between electoral infrastructure expansion and the increase in cyber incidents affecting Colombian institutions highlights a broader reality: electoral cybersecurity is no longer limited to protecting ballot systems or vote transmission mechanisms. It now involves defending the entire digital trust ecosystem surrounding democratic governance, including identity systems, institutional communications, public transparency platforms, and citizen confidence itself.

Potentially Relevant Actors in Electoral Scenarios

Ideological Hacktivists:

Groups seeking political impact, media exposure, or institutional delegitimization.

Opportunistic Cybercriminals: Actors focused on monetization through data breaches, selling access, or ransomware.

Hybrid Actors: Groups that combine political and criminal motivations, especially through public leak campaigns.

APTs or Actors Aligned with State Interests: Although not publicly acknowledged, election periods often attract strategic espionage operations, intelligence gathering, and influence campaigns.

Coordinated Disinformation Operations: Actors that use real or perceived breaches to amplify narratives of fraud, manipulation, or institutional crisis.

Recent history of exposure and potential operational compromise

events malware

events malware

One of the most relevant cybersecurity precedents affecting the Colombian electoral environment involves the exposure of credentials associated with the National Electoral Council (CNE) within multiple combolist and infostealer-related datasets observed during 2026. The records indicate repeated appearances of institutional accounts linked to the

cne.gov.co

domain across several credential collections, suggesting possible credential harvesting activity, password reuse, endpoint compromise, or malware infections affecting devices used by electoral personnel.

Although the public presence of credentials does not automatically confirm a direct compromise of core electoral systems, this type of exposure is highly relevant in an electoral cybersecurity context because attackers frequently use stolen credentials as an initial access vector against institutional infrastructure.

From a defensive perspective, these events are consistent with tactics commonly associated with:

Information-stealing malware infections on employee computers.

Credential stuffing attacks against public utilities.

Phishing campaigns targeting election officials and contractors.

Session hijacking and unauthorized access attempts.

Reconnaissance operations prior to politically sensitive events.

The risk becomes particularly significant when election ecosystems rely on distributed platforms for training, poll watchers, consultations, authentication, or remote administrative access. In these scenarios, compromised accounts can allow attackers to access sensitive operational information, internal communications, administrative dashboards, or interconnected services.

The repeated appearance of election-related credentials during 2026 also coincides with the progressive activation of new election subdomains and training environments associated with presidential, legislative, and special elections. This temporal overlap suggests increased interest from malicious actors in monitoring or attacking the growing digital footprint of Colombia’s electoral infrastructure.

In modern election threat models, attackers do not necessarily require direct access to vote-counting systems to have an impact. Access to peripheral systems, internal communications, training environments, or identity services can be sufficient to carry out influence operations, leak confidential information, disrupt services, or undermine public trust in the electoral process.

Final Conclusion:

The evolution of Colombia’s digital electoral infrastructure during 2025–2026 demonstrates a clear process of technological expansion, segmentation, and operational specialization by the National Electoral Council (CNE). The creation of specific subdomains for presidential elections, legislative elections, poll watchers, special elections, and training platforms reflects an architecture designed to separate functions, reduce operational risks, and improve administrative control within the electoral ecosystem.

However, this expansion also increases the digital surface exposed to malicious actors.

In parallel with the progressive activation of new electoral platforms and services, Colombia has experienced a sustained increase in cyber incidents affecting government entities, educational institutions, healthcare organizations, financial systems, and public infrastructure. Various hacktivist and cybercriminal groups have published leaks of databases, credentials, administrative access, and sensitive information related to Colombian institutions, revealing an active and persistent threat landscape.

The appearance of credentials associated with electoral environments within the logs of infostealers and clandestine leak ecosystems reinforces the reality that modern electoral threats are no longer focused exclusively on voting systems. Attackers now seek to compromise the entire operational ecosystem surrounding the electoral process: authentication services, training platforms, administrative portals, communication systems, cloud infrastructure, and human operators.

In this context, the most dangerous scenario is not necessarily the direct manipulation of votes, but rather the erosion of institutional legitimacy through cyber operations, disinformation campaigns, data leaks, service disruptions, and psychological warfare operations. Even limited compromises of peripheral systems can be amplified to generate public distrust, political tension, information chaos, and narratives that question the integrity of the electoral process.

LEGAL & ETHICAL DISCLAIMER

This report is based exclusively on publicly available information obtained through Open-Source Intelligence (OSINT). No intrusion, hacking, unauthorized system access, interception, credential harvesting, exploitation, or acquisition of private or confidential data has been performed.

All observations, indicators, infrastructure references, metadata, signals, or correlations presented in this report are derived from publicly accessible sources and must be treated as technical intelligence, not as definitive or judicial attribution.

The presence of domains, IP addresses, log patterns, underground references, or leaked information does not constitute a formal accusation or legal determination of responsibility. Attribution, motivation, and actor identity may require additional validation by competent authorities, legal entities, or digital forensics.

The content contained in this report may include potential false positives, infrastructure that later changes ownership, expired datasets, or previously exposed material. Intelligence derived from OSINT should always be corroborated and verified before any operational, legal, investigative, financial, or organizational action is taken.

The analysis provided here is strictly for educational, academic, security research, cyber risk evaluation, and threat-intelligence purposes. It must not be used for harassment, personal retaliation, unauthorized surveillance, doxing, stalking, profiling of individuals, or any unethical or illegal activity.

Vecert does not store, distribute, commercialize, or trade stolen, private, or illicit data. All data indexed, referenced, or analyzed is already publicly available at the time of research.

Any interpretation, operational decision, investigative direction, mitigation action, or use of the intelligence included in this report is performed entirely at the reader’s own responsibility. This publication does not replace formal legal advice, law-enforcement investigation, digital forensics, or compliance assessments.

메타데이터
post_id
392f55d402bc
slug
colombian-elections-and-hacktivism-overview-392f55d402bc
url
https://medium.com/@vecert/colombian-elections-and-hacktivism-overview-392f55d402bc
canonical_url
https://medium.com/@vecert/colombian-elections-and-hacktivism-overview-392f55d402bc
author_url
https://medium.com/@vecert
status
ok
fetched_at
2026-06-09 15:37:30