Ecopetrol, Colombia’s state-controlled energy giant and one of Latin America’s largest oil companies, has disclosed a cybersecurity incident in which an external attacker accessed cloud-based file storage, stole data tied to roughly 3,300 user accounts, and attempted to deploy ransomware — an encryption attempt the company says its defenses blocked before it could take hold.

What happened

Ecopetrol revealed the incident publicly on July 17, 2026. According to the company, an external actor gained unauthorized access to cloud-based file storage environments used by approximately 15 subsidiaries, then unlawfully downloaded data associated with about 3,300 user accounts.

The intruder then attempted to execute ransomware — and, per Ecopetrol, the company’s cybersecurity controls successfully blocked encryption before it could deploy. That distinction matters: this is a data-theft-and-extortion incident, not a systems-lockup event. The attacker walked away with data but did not manage to cripple Ecopetrol’s environment.

The extortion play

Having failed to encrypt, the attacker fell back to the modern ransomware crew’s plan B: extortion by threat of exposure. The external actor communicated demands, threatening to publicly disclose the unlawfully extracted data.

As of Ecopetrol’s disclosure, there was no evidence the stolen data had been published on any leak site or public channel. The company reported no material disruption to operations and no direct financial impact from the incident.

A blocked attack is still a breach

It would be easy to read “ransomware blocked” as a clean win. It’s a partial one. Ecopetrol’s controls did the hard job — stopping encryption across an environment spanning 15 subsidiaries is a genuine defensive success, and it’s the difference between “we lost some files” and “our operations are frozen.” The blocked encryption is exactly the outcome that critical-infrastructure operators drill for.

But data on 3,300 accounts is already gone, and that half of the “double extortion” model doesn’t require encryption to work. The leverage now is disclosure, not downtime. Whether Ecopetrol’s incident stays a footnote or becomes a leak-site headline depends on what’s in those files and how the company handles the extortion demand — a dynamic playing out across the energy and critical-infrastructure sector this year, from Latvia’s state forestry service to utilities worldwide.

Why energy operators are prime targets

State-controlled energy companies are attractive on two counts: they hold operationally sensitive and personal data, and their governments have strong incentives to avoid public disruption — which extortion crews read as pressure to pay. That Ecopetrol’s file storage spanned 15 subsidiaries underscores how a single cloud storage misconfiguration or credential compromise can expose a sprawling corporate group at once. Consolidation of data into shared cloud tenants concentrates both convenience and risk.

For now, Ecopetrol’s message is measured: operations intact, encryption blocked, no data published — but an active extortion demand outstanding. This is a developing story.

Sources