Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Jul 20, 2026 · 6 min read

Ecopetrol Breach: 3,300 Accounts Hit, Ransomware Blocked

Colombia's state controlled oil major disclosed on July 17, 2026 that an external actor accessed cloud file storage across roughly 15 group entities, downloaded data tied to about 3,300 accounts, and then demanded a ransom to prevent its release.

Ecopetrol, Colombia's largest company and the roughly 88.5 percent state controlled oil major that anchors much of the country's energy sector, disclosed on July 17, 2026 that an external actor broke into its cloud based file storage systems. The attacker downloaded data tied to about 3,300 user accounts spread across some 15 companies inside the Ecopetrol Group, attempted to detonate ransomware, and then sent extortion demands threatening to publish whatever it had taken, according to the company's official disclosure.

Ecopetrol says its cybersecurity controls stopped the ransomware from encrypting anything, and it has found no material disruption to production or operations so far. But the extortion threat is still open, and the company itself admits it cannot guarantee the incident will not eventually cause real damage.

Key Takeaways

  • Ecopetrol disclosed on July 17, 2026 that an external actor accessed cloud file storage systems across about 15 companies in the Ecopetrol Group and downloaded data tied to roughly 3,300 user accounts.
  • The intruder attempted to execute ransomware, but Ecopetrol says its security controls blocked the encryption before it could run.
  • The attacker followed the intrusion with extortion demands, threatening to publicly release the stolen data.
  • Ecopetrol filed a criminal complaint with Colombia's Attorney General's Office and reports no material disruption to production or operations as of the disclosure.
  • This is Ecopetrol's second major security incident in about 16 months, after a June 2025 episode involving internal surveillance tied to a compliance contract.
Industrial oil refinery and pipeline infrastructure at dusk with a server rack visible in the foreground, representing the Ecopetrol cloud storage breach

What Happened at Ecopetrol?

An external actor gained unauthorized access to cloud based file storage platforms used across the Ecopetrol Group and downloaded information tied to roughly 3,300 user accounts, spanning approximately 15 entities including the parent company itself, according to Ecopetrol's own disclosure. The company has not said how long the intruder had access before detection, nor has it named the attacker or attributed the intrusion to a known group. What it has confirmed is the shape of the intrusion: cloud storage was the target, mass downloading was the method, and an attempted ransomware deployment followed the data theft rather than preceding it.

Why Didn't the Ransomware Detonate?

Ecopetrol says the attacker attempted to execute ransomware inside its environment but that existing cybersecurity controls blocked the encryption before it could take hold. The company's response after detection included revoking unauthorized access, blocking mechanisms tied to mass data downloading, and turning on enhanced infrastructure monitoring. Stopping the encryption step matters operationally, since it means Ecopetrol did not lose access to its own systems, but it does not undo the fact that data had already left the network by the time the ransomware attempt was noticed.

What Is the Extortion Threat, and How Is Ecopetrol Responding?

After the intrusion, the attacker communicated extortion demands, threatening to publicly disclose the information it had unlawfully extracted, according to Ecopetrol's disclosure. As of the company's July 17 statement, none of the stolen data had surfaced publicly, and Ecopetrol has not said whether it intends to negotiate or pay. The company reports it filed a criminal complaint with Colombia's Attorney General's Office, engaged national cybercrime authorities, and is working with insurers and outside technology risk specialists to assess exactly what was taken. Ecopetrol has been direct about the limits of what it currently knows, stating it "continues to assess the potential exposure of corporate information" and cannot guarantee the incident will not eventually have a material adverse effect.

Investors did not react as if the breach were catastrophic. Ecopetrol's New York listed shares (ticker: EC) closed up 1.84 percent on the day of disclosure, trading at $16.09, while Colombia's benchmark COLCAP index rose 0.58 percent the same day, according to Rio Times Online's market coverage. That muted reaction reflects Ecopetrol's own framing: contained access, blocked encryption, no reported production impact, at least for now.

Why Are State Owned Energy Companies a Growing Target?

Ecopetrol is not a random target. It is Colombia's largest company, roughly 88.5 percent owned by the Colombian government, and it sits at the center of the country's oil production, refining, and export infrastructure. Extortion crews increasingly favor targets like this because the pressure to avoid public disclosure runs in multiple directions at once: shareholders, a national government, and a public that depends on the company's output all have reasons to want the story contained quietly.

The skip the encryption, just steal and threaten pattern has become the default playbook across the ransomware ecosystem, a shift documented as extortion incidents climbed 23 percent in 2025 even as traditional encryption based attacks held roughly flat. It has also shown up repeatedly against energy and critical infrastructure specifically, from federal warnings that Iranian hackers were sitting inside US water and energy systems to a SharePoint credential phishing campaign that hit multiple energy companies earlier in 2026. Ecopetrol itself is a repeat target: this is the company's second major information security episode in roughly 16 months, following a June 2025 incident involving internal surveillance tied to a compliance review contract.

What Should Security Teams at Energy and Critical Infrastructure Companies Take From This?

Ecopetrol's own account of the incident points to a few concrete lessons that apply well beyond one oil company:

  • Treat cloud file storage platforms as a primary exfiltration surface, not a secondary one. The entry point here was cloud storage, not a conventional network intrusion.
  • Build detection around unusual data movement, not just malware signatures. Ecopetrol's disclosure describes a mass download event that its team had to specifically block after the fact.
  • Rehearse the extortion scenario separately from the ransomware scenario. Recovery planning that only covers "restore from backup" does not address a threat to publish stolen files that were never encrypted.
  • Expect the criminal complaint and regulatory disclosure process to run in parallel with the technical response, since Ecopetrol moved to notify Colombia's Attorney General's Office and the market at the same time it was still assessing what was taken.

Ecopetrol has not confirmed exactly what data left its systems, and the extortion threat remains unresolved as of this writing. What is already clear is the pattern: a state controlled energy major with cloud infrastructure, roughly 3,300 exposed accounts, and an attacker banking on the threat of public disclosure rather than a locked network to get paid. That combination, more than any single technical detail, is what security and compliance teams at critical infrastructure companies should be studying right now.

Sources: Ecopetrol's official disclosure via PR Newswire, Colombia One's reporting on the breach, and Rio Times Online's coverage of the market reaction.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.