Threat feed liveUpdated — 30.07.2026 12:36 CET58 dossiersMITRE ATT&CK mappingThreat feed liveUpdated — 30.07.2026 12:36 CET58 dossiersMITRE ATT&CK mapping

Unidentified external actor — Ecopetrol itself says so in its SEC filinghigh

Ecopetrol: the ransomware was stopped, the extortion was not

On 17 July 2026 Ecopetrol, Colombia's largest company, told the market it had identified unauthorized access to its cloud file storage environments and those of about fifteen subsidiaries, with data associated with roughly 3,300 user accounts downloaded. The ransomware attempt, the company says, was blocked by its security controls. The extortion arrived anyway: the actor threatened to publish the extracted information. This is the model that has moved beyond encryption, and this case shows it in pure form.

A defence that half worked

Some statements tell a success and a defeat in the same sentence. The one Ecopetrol filed with the SEC on 17 July 2026 is one of them: the company's security controls blocked the ransomware attempt, and in the same period an external actor downloaded data from the group's cloud storage environments and demanded a ransom, threatening to publish it.

This is where it is worth pausing, because it is the heart of how ransomware works today. Stopping the encryption means avoiding operational paralysis: no inaccessible systems, no halted production, no restoring from backup under pressure. It does not mean avoiding extortion at all. If the data is already out, the criminal's leverage is no longer "you won't be able to work" but "everyone will read it" — and that leverage is not defused by a perimeter control.

What the filing actually says

Ecopetrol writes that it identified unauthorized access to certain digital resources owned by the company and its subsidiaries, by an unidentified external actor, as well as an attempted ransomware attack that was blocked by the cybersecurity controls implemented across the group.

~15
subsidiaries involved
cloud-based file storage environments
~3,300
user accounts
data downloaded without authorization
0
material disruptions reported
to critical operations, production capacity and essential services

The actor communicated extortion demands, threatening to publicly disclose the unlawfully extracted information. As of the report date, the company said it had not identified any material disruption to critical operations, production capacity or essential services, nor any direct financial impact preventing it from continuing to do business, nor any disclosure of the information subject to the access. With one caveat that market filings always include and that is best not ignored: the exposure assessment is ongoing, it could involve confidential, proprietary or personal data, and the company cannot guarantee that the incident will not have a material adverse effect on its business, reputation, results or financial condition.

The response, point by point

The list of measures taken is unusually detailed for a statement of this kind, and is worth reading as a checklist.

  1. 01
    Containment
    immediate revocation of unauthorized access and blocking of mass-download mechanisms
  2. 02
    Analysis
    identification and containment of the actor's tactics, techniques and procedures
  3. 03
    Authorities
    criminal complaint to Colombia's Attorney General and cooperation with specialized agencies

Beyond these, the company said it had identified the external infrastructures used to store or download the information, in order to pursue restriction or blocking actions; activated support mechanisms with insurers and specialized capital markets teams; begun a detailed assessment of the downloaded information to determine its criticality; and enhanced monitoring of its technology infrastructure under critical alert protocols.

Two elements deserve a note. Blocking mass-download mechanisms is the specific countermeasure against exfiltration, not against access: it acknowledges that in this model the damage is measured in data leaving, not in doors opening. And the hunt for the external staging infrastructure is an operational choice rarely discussed, aimed at making publication impractical rather than at negotiating.

Why an oil company is a target that matters

Ecopetrol is not just any company. It is Colombia's largest, with more than 19,000 employees, responsible for over 60% of the country's hydrocarbon production and for most of its transport, logistics and refining systems. Through the acquisition of 51.4% of ISA's shares it participates in power transmission and in real-time systems management (XM), and through ISA and its subsidiaries it holds leading positions in power transmission in Brazil, Chile, Peru and Bolivia.

A cyber incident at a company like that is by definition a national and energy security matter, even when — as here — it does not touch the plants. The fact that the access concerned cloud document storage and not industrial systems is why production did not stop, and it is a distinction worth holding on to before reading alarmist headlines.

  1. Before 17 July 2026
    Unauthorized access and data download

    Cloud environments of Ecopetrol and about 15 subsidiaries.

  2. Same period
    Ransomware attempt blocked

    Security controls prevent encryption.

  3. 17 July 2026
    Market disclosure (Form 6-K)

    Extortion demands reported; no material disruption identified.

The uncertainties

No criminal group is publicly named in the corporate documentation, and the company itself says it has not identified the actor: any attribution in circulation should be treated as unconfirmed. The initial vector is not public — the filing speaks of access to storage environments, not of how it was reached. Neither the start date nor the duration of the access is stated. We do not know the actual content of the data tied to the roughly 3,300 accounts, because the criticality assessment was still under way at the time of the report. And the "approximately 15" figure for the entities involved is the company's own, not verified by third parties.

The lesson, without rhetoric

If your ransomware strategy stops at "we won't get encrypted", this case is the counter-proof that it is not enough. Ecopetrol won the encryption round and still has an extortion demand on the table, an open criminal complaint and an exposure assessment to finish. The defences that count against the second half of the attack are different ones: capping how much data a single account can pull, spotting an anomalous download from a cloud archive in real time, knowing what is inside those archives before someone else does. They are less spectacular than restoring from backup, and in this model they are worth more.

More dossiers