A few days ago an intelligence alert went around on X about a Telegram bot that advertises itself as able to take a Colombian banking identifier and return that person's full name, their ID number, and the bank where they keep their money. The thread got a fair amount of reach.

Two clarifications before we start.

The first is from the original report: what was seen proves what the bot offers, not where it gets the data. That is not enough to attribute the source to a specific data breach.

The second is mine: I don't link the bot or explain how it's operated.

This affects you even if you don't work in security and have never opened Telegram.

Before the call

When someone tells you they got scammed, the story almost always starts with the call. "The bank called me, they told me there was a suspicious charge, they asked me for the code that came in by message."

Before that call, someone figured out who you are. Your name, your ID number, and which bank holds your account. That step decides whether the call works or whether you hang up in ten seconds.

Your key is meant to be shared

Bre-B is Colombia's instant-payment system, running since 2025. It works with keys: you register your ID number, your phone, your email, or an alphanumeric identifier, and with that people pay you without you handing over your account number.

You hand that key out on purpose and in public: the WhatsApp status, the Marketplace listing, the shop's Instagram, the group chat pooling money for a gift. The Banco de la República (Colombia's central bank) says it plainly: you can only receive payments by sharing your key.

It's a piece of data you give out many times, by design. If it can be turned into your full identity, then every time you share it, your name, your ID number, and your bank go with it. And if your key is your ID number, your phone, or your email, the identifier is already the personal data.

The store also asks for more than you think

You pay by card and at the register they ask for your name, phone, and ID number. They tell you it's for the invoice or for loyalty points. You write it on the payment slip and you leave.

The purchase also says things about you. You paid with a gold card, you took home a five-million-peso TV, and you put it on a single installment. That reveals the credit limit you carry and that you could let go of that money without financing it.

Before any of it touches a system, someone had all of that in front of them. The person at the register, with access they never asked for, that comes with the job.

After that you have no way to know where it goes next. It might stay in the store or reach the vendor that runs their loyalty program. I don't know either when I give my ID number at the pharmacy. And this repeats at every store that asks.

With the name, the ID number, and what you bought, someone can build a list of people ranked by how much money they have.

They know your ID number, and that no longer proves anything

A common way to decide whether a call really comes from the bank is that the caller knows things only the bank would know: your full name, your ID number, which card you have.

The person who falls for one of these calls is rarely careless. They're using a test that worked their whole life, against someone who already knows what the test is.

Bogotá's District Security Secretariat has been warning since July about text messages that announce a pending Bre-B transfer and send you to a link. The link opens a copy of your bank's page. There you hand over your password and the code, and the money is gone.

With your name and your ID number up front, that message stops looking generic.

Where that data can come from without a breach

In the thread someone replied, with no likes, that it wasn't hard to imagine how they did it: the masking of names happens only on the app's screen.

When you go to transfer, the app shows you who you're paying with the name half-covered. That's specified, not left to each bank: the Banco de la República describes it and gives the example, AnXXXa PXXez. It's a sensible requirement, showing just enough for you to recognize the person without handing a stranger's identity to anyone who types in numbers.

That documentation doesn't say whether the full name reaches your phone and the covering happens only there, on the screen. Finding out would mean digging into a bank's app from the inside, and that crosses a very fine line. It's not the point of this post. It stays a hypothesis. Even so, the core holds: your data doesn't always need a breach to become public or to end up within someone else's reach.

The system has to say who you are

The system showing you who you're paying exists for a good reason: to keep you from transferring to the wrong recipient in an operation that completes in seconds. The Banco de la República leaves that check on your side, reviewing the recipient before you confirm.

Returning identity from an identifier is therefore a deliberate function. That same function, queried thousands of times by someone who pays for nothing, becomes a directory of identities. The difference is in how much each answer returns and how many in a row it gives the same asker.

Those limits are written down and public. Here, in Bre-B's rulebook. In Brazil, in the manual for its system.

What you can do

Six concrete things:

Whoever calls you can know your ID number, your bank, even what you bought. None of that makes them your bank.