Colombia's state oil giant Ecopetrol says cyberattack stole data tied to 3,300 accounts
Ecopetrol disclosed that intruders accessed cloud-based file storage across 15 of its subsidiaries and stole data linked to roughly 3,300 accounts, while a separate ransomware attempt was blocked by its security controls.
- Victim
- Ecopetrol
On 17 July 2026, Ecopetrol โ the state-controlled oil and gas company that produces more than 60% of Colombia's hydrocarbons โ disclosed that it had suffered a cyberattack in which intruders gained unauthorized access to its digital resources and stole data. According to the company, the intrusion reached cloud-based file-storage systems used across 15 of its subsidiaries, and the attackers made off with information tied to roughly 3,300 accounts.
Ecopetrol said that, alongside the data theft, an unidentified attacker also attempted a ransomware attack, which the company's security controls blocked before it could encrypt systems. The attacker subsequently issued extortion demands, threatening to publicly release the stolen data. As of the disclosure, none of the data had surfaced publicly, and Ecopetrol had not identified the attacker nor said whether it would consider paying.
A contained breach at critical infrastructure
Crucially, Ecopetrol reported no disruption to its operations or oil production as a result of the incident. The attack appears to have been confined to file-storage repositories rather than the industrial control systems that run the company's refineries and pipelines, which limited the physical blast radius. Even so, the breach raised fresh questions about the cybersecurity posture of one of Latin America's largest energy producers โ a strategically important, state-controlled firm whose output underpins a substantial share of Colombia's national economy.
Open questions
At the time of disclosure, several details remained unconfirmed. Ecopetrol did not attribute the attack to any known threat actor or ransomware group, did not specify exactly what categories of data were tied to the 3,300 affected accounts, and did not quantify any financial impact. With the ransomware attempt blocked, the intrusion contained, and no operational disruption reported, the incident's status was best characterised as contained โ though the extortion threat remained live and the full scope of the stolen data was still under assessment.
Timeline
Ecopetrol publicly discloses that intruders gained unauthorized access to cloud-based file-storage systems across 15 of its subsidiaries and exfiltrated data tied to about 3,300 accounts; the company says its security controls blocked a separate ransomware attempt.
An unidentified attacker issues extortion demands and threatens to publish the stolen data; none had surfaced publicly as of the disclosure, and Ecopetrol reports no impact to operations or production.
Sources
- finance.yahoo.comhttps://finance.yahoo.com/energy/articles/colombias-ecopetrol-says-cyberattack-stole-042239602.html
- ibtimes.sghttps://www.ibtimes.sg/ecopetrol-cyberattack-colombian-energy-giant-says-data-3300-accounts-was-stolen-90048
- colombiaone.comhttps://colombiaone.com/2026/07/18/colombia-cyberattack-company-ecopetrol/
- 933thedrive.comhttps://www.933thedrive.com/2026/07/17/colombias-ecopetrol-says-cyberattack-stole-data-tied-to-3300-accounts/
- riotimesonline.comhttps://www.riotimesonline.com/ecopetrol-cyberattack-3300-accounts-roa-return-2026/