Virtual Round Table · Jul 22

View the event
Ecopetrol Says It Blocked a Ransomware Attack, But Data on 3,300 Accounts Was Still Stolen
Cybersecurity

Ecopetrol Says It Blocked a Ransomware Attack, But Data on 3,300 Accounts Was Still Stolen

Colombia's state-controlled oil giant says its controls stopped encryption before it took hold, yet an intruder still exfiltrated data tied to 3,300 accounts across 15 group companies and is now demanding payment.

PublishedJuly 19, 2026
Read time6 min read
Share

What Ecopetrol disclosed

Ecopetrol, the state-controlled energy company that accounts for more than 60 percent of Colombia's hydrocarbon production, disclosed a cybersecurity incident on July 17, 2026. According to the company, an unidentified external actor gained unauthorized access to cloud-based file storage environments used by roughly 15 companies within the Ecopetrol group, including the parent. The attacker exfiltrated data tied to 3,300 user accounts, then attempted to deploy ransomware. Ecopetrol says its security controls stopped that encryption attempt before it could take hold, so the operational side of the business kept running while the data theft had already occurred.

The company framed the outcome as a partial success for its defenses, and on the encryption question that is fair. Preventing ransomware from locking systems avoids the operational paralysis that has shut down manufacturers and utilities elsewhere this year. Ecopetrol reported no material disruption to operations or direct financial impact as of the disclosure. It also filed the matter with Colombia's Attorney General's office. For a company that sits at the center of a national economy, keeping production running through an active intrusion is a meaningful result, even as the data question remains open and unresolved.

The extortion that followed

Blocking the payload did not end the incident. Ecopetrol says the intruder contacted the company to demand money in exchange for not publishing the stolen information, the classic extortion move that survives even a failed encryption attempt. The company has not disclosed the amount demanded, and as of its statement there was no evidence the exfiltrated data had appeared on leak sites or any other public channel. That leaves Ecopetrol in the familiar and unenviable position of deciding how to respond to a threat whose credibility it cannot fully verify and whose follow-through it cannot control.

Crucially, Ecopetrol stopped short of reassurance on the financial side. The company said it could not guarantee the breach would avoid a material adverse impact, careful language that acknowledges the story is not finished. Extortion cases like this often play out over weeks as attackers test whether public pressure or a looming leak deadline will move a victim toward payment. For a publicly traded, state-linked enterprise, the calculus involves regulators, investors and national-security sensitivities, not just the immediate cost of the demand, which makes a quick, clean resolution unlikely.

Why blocked encryption still leaves a costly gap

The most useful lesson for security leaders is in the sequence of events. The attacker got in, moved through cloud storage, downloaded data on 3,300 accounts, and only then tried to encrypt. The defense caught the last step. That ordering is common: exfiltration precedes encryption in most modern ransomware operations, because stolen data is the leverage that makes the extortion work whether or not the lock succeeds. Stopping the encryption is genuinely valuable for keeping systems online, and it clearly helped Ecopetrol avoid an operational crisis. It does nothing, though, to undo a breach that has already happened.

This is the gap many boards do not fully appreciate. A program measured on whether ransomware managed to encrypt anything will score this incident as a success, while a program measured on whether sensitive data left the building will score it as a failure. Both readings are accurate, and the tension between them is exactly why detection needs to catch the earlier stages, the initial access and the bulk data movement, not just the final payload. By the time an encryption attempt fires, the most damaging part of the attack is usually already complete and beyond recall.

The cloud storage exposure

Ecopetrol pointed specifically to cloud-based file storage as the compromised environment, which tracks with where a lot of sensitive enterprise data now lives. Cloud object stores and file shares are convenient, sprawling and easy to over-permission, and they frequently hold exactly the confidential, proprietary and personal information an extortion crew wants. When access controls on these repositories are loose, or when a single compromised credential unlocks storage across many affiliated companies, one foothold becomes access to a group-wide trove. The 15-company footprint here suggests shared or federated access that let the intruder reach well beyond a single subsidiary.

For enterprises with complex group structures, and PE-backed portfolios are a prime example, this is a pointed warning. Shared identity and storage across affiliated entities creates efficiency, and it also means a breach at one company can become a breach at all of them. Segmenting access so that a credential compromised in one subsidiary cannot enumerate and download the file stores of fourteen others is unglamorous work, but it is precisely the control that limits blast radius. Data-loss prevention and anomaly detection on bulk downloads from cloud storage would also have had a chance to flag this exfiltration while it was underway.

Critical infrastructure in the crosshairs

Energy companies remain a magnet for both financially motivated and state-aligned attackers, and Ecopetrol's national importance makes it an obvious target. The fact that production continued uninterrupted is the headline reassurance, and it reflects an increasingly important separation between corporate IT and operational technology. When the two are properly segmented, an attacker who lands in file storage and business systems has a much harder path to the control systems that actually run pipelines and refineries. That boundary appears to have held here, which is the difference between a data-extortion headache and a national supply disruption.

Still, the incident is a reminder that critical-infrastructure operators are being probed constantly, and that the corporate side is the softer, more accessible target. Data theft and extortion against an energy major carry their own weight even without an operational hit, because the stolen material can include commercially sensitive and personal information, and because the reputational and regulatory fallout lands regardless. Operators in this sector should assume they are on target lists and invest accordingly in both the IT-OT boundary and the detection of data movement inside their business environments.

What leaders should take from it

The Ecopetrol case is a clean illustration of a modern breach that a purely ransomware-focused defense would misread. The right scorecard has two lines: did the attacker disrupt operations, and did the attacker steal data. Ecopetrol can point to a win on the first and is still exposed on the second. Technology leaders should build their own metrics and their board reporting around both questions, because conflating them creates a false sense of safety every time a payload is blocked but data has already walked out the door in the hours or days beforehand.

Practically, the roadmap items are consistent with the rest of this year's incidents. Tighten access across affiliated entities so one credential cannot reach everything, instrument cloud storage for anomalous bulk access, and make sure detection targets initial access and exfiltration rather than waiting for the encryption stage. And prepare the extortion playbook in advance, including legal, communications and regulatory steps, because the decision of how to respond to a leak threat is far better made ahead of time than under a countdown clock set by the attacker.

Tagged#news#security#cybersecurity#breach#cisa#ransomware#zero-day#supply-chain#ai-security#ecopetrol#energy-sector#data-extortion#cloud-storage#critical-infrastructure#colombia