Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

Ecopetrol confirms ransomware attempt, data stolen from 3,300 accounts

The article details a ransomware attack against Ecopetrol where an unidentified threat actor gained access to its IT infrastructure and exfiltrated pseudonymous data from 3,300 user accounts. The attackers attempted to deploy an encryptor but were blocked by the company's security controls, preventing system encryption and operational disruption. Ecopetrol has since evicted the attackers, launched an investigation, and notified Colombian authorities.
Read Full Article →

Ransomware Ecopetrol confirms ransomware attempt, data stolen from 3,300 accounts July 20, 2026 Share By SC Staff (Adobe Stock) Ecopetrol, a Latin American energy producer, has confirmed a ransomware attack where attackers stole data from 3,300 user accounts but were prevented from deploying an encryptor due to security controls, according to a recent report by Tech Radar. The incident involved an unidentified threat actor accessing Ecopetrol's IT infrastructure and exfiltrating pseudonymous data from 3,300 user accounts. While the attackers attempted to install an encryptor, the company's security measures successfully blocked its deployment, preventing disruption to transactional systems and partner networks. No user identities or credentials were compromised. Ecopetrol has since removed the attackers from its systems and launched an internal investigation. The company has also notified Colombian authorities, including the Attorney General's Office and the Military Forces' Joint Cyber Command. No ransom demand details or confirmation of data leaks have been publicly disclosed thus far. The stolen files are reported to be pseudonymous, potentially limiting their utility to the attackers. Source: Tech Radar An In-Depth Guide to Ransomware Get essential knowledge and practical strategies to protect your organization from ransomware attacks. Learn More SC Staff Related Breach Craneware confirms customer and employee data exposed in security incident SC Staff July 20, 2026 The breach, which occurred on July 20, saw a significant volume of file names viewed and exfiltrated by unauthorized individuals. Supply chain New npm malware cluster targets Vite ecosystem SC Staff July 20, 2026 The ViteVenom campaign, attributed to the threat actor SuccessKey, builds upon the tactics seen in the earlier ChainVeil attack. Malware ACR Stealer exploits user interaction to steal sensitive data SC Staff July 17, 2026 Microsoft has detailed two primary intrusion chains used by ACR Stealer. Related Events Cybercast Ransomware reloaded: Finding resilience when attackers wield AI On-Demand Event Virtual Conference Ransomware Resilience: Strategies to Defend, Mitigate, and Recover On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe You can skip this ad in 5 seconds

Share this article