The problem
The gap between surface-level technical skill and critical security awareness in Colombia and at Instituto San Carlos.
// English summary below. The complete Spanish version is always available.
Colombia recorded 77,666 reported cybercrimes in 2024, up from 63,249 in 2023 — a 23 % increase in a single year — according to the Colombian Chamber of Information Technology and Telecommunications, drawing on National Police Cyber Centre data (CCIT, 2025). The most frequent offences were theft by electronic means (37,409 cases), unauthorised access to computer systems (16,955) and breach of personal data (11,954).
Medellín is the second most affected city in the country, with 6,533 reports. Digital crime does not happen to other people somewhere else. On attempted attacks, the country recorded 12 billion in 2023 (CCIT, 2024, reporting FortiGuard Labs figures).
The observation that started the project
At a science fair in Medellín in 2024 we asked 50 students — teenagers from different schools, all with a phone in hand — whether they could spot a fraudulent email. Eight raised their hand with confidence. When shown real phishing examples, 43 of those 50 admitted they would probably have clicked the link.
What this episode is, and what it is not. An informal observation, with no validated instrument and no sampling, gathered when the project was barely taking shape. It supports no conclusion and is not presented as evidence: it is the scene that started E-DIGNA.
Its value lies in the question it left open: if those students handled their devices with obvious fluency, why couldn’t they defend themselves against a three-line scam? That distance between fluency and judgement is the problem E-DIGNA addresses.
The AI factor
Generative AI did not invent fraud: it made it cheaper to produce and far more convincing. Europol, UNICRI and Trend Micro documented that shift in 2020, describing concrete criminal uses — password guessing, CAPTCHA breaking, voice cloning — and warning that many more malicious innovations were on the way.
What changes for a secondary student is not that the scam exists, but its quality. The email full of typos was detectable; the message written by a language model is not. When the traditional warning sign — “you can tell it’s fake” — stops working, judgement is the only defence left.
In the school setting
Over the school period the researcher directly observed, in his own educational environment, situations that put a face on the statistics: fraud through supposed “quick loans” advertised on social media, non-consensual additions to messaging groups, compromised institutional accounts, and passwords shared between peers.
These are direct observations by the researcher, not an institutional record or a formal collection instrument. They are reported in aggregate, with no names, grades or identifying detail. This project’s population are minors: protecting them is the first test of coherence for work that claims to teach digital care.
Added to this is a curricular gap: the technology area covers office software and programming fundamentals, but not protection against threats, digital footprint management, synthetic content verification or critical AI use. E-DIGNA is the answer to that absence.
Full translation in progress — complete Spanish version available at /investigacion/problema.