Home / Technology / Ecopetrol Ransomware Attack: Data Stolen, But Not Encrypted
Ecopetrol Ransomware Attack: Data Stolen, But Not Encrypted
20 Jul
Summary
- Ransomware attackers stole data from 3,300 Ecopetrol user accounts.
- Security controls prevented attackers from deploying the encryptor.
- No user identities or credentials were compromised in the breach.

Energy producer Ecopetrol recently experienced a ransomware attack where threat actors infiltrated IT systems and exfiltrated data from 3,300 user accounts. Despite the successful data theft, the attackers were thwarted by Ecopetrol's robust security controls, preventing the deployment of their encryptor and avoiding any disruption to daily operations.
The compromised files are reportedly pseudonymous, with no user identities or credentials being captured during the incident. This means that transactional systems, subsidiaries, and partner networks remained secure and unaffected. Ecopetrol has since removed the attackers from its network.
An internal investigation is underway, and relevant Colombian authorities have been notified. As of the report, no ransom demand details have surfaced, and the stolen data has not been leaked publicly. The ongoing investigation aims to fully assess the breach's scope and impact.