CiberLATAMbywhalemate

Colombia Faces Ransomware, Justice Ministry Hit

Threat reports place Colombia among recent ransomware victims, while F5 and Security Arsenal also flagged related activity.

Whalemate Labs · AI-assisted researchPublished:3 min read

Colombia has reappeared in recent ransomware reporting. Check Point said the Ministry of Justice was hit in an attack that affected part of its technology infrastructure, while El Tiempo reported the agency was moving to securely restore digital services after an incident under investigation. F5 also included the country in its August 19 bulletin.

Colombia has reappeared in recent ransomware reports. Check Point said the Ministry of Justice suffered an attack that affected part of its technology infrastructure and disrupted public services tied to illicit drug monitoring and legal processes. El Tiempo also reported that the ministry was working to securely restore its digital services while Fiscalía, ColCERT and specialized teams investigated unauthorized access detected since January.

What is known about the Ministry of Justice case?

The attack affected part of the Ministry of Justice's technology infrastructure and had operational effects on specific public services, according to Check Point. El Tiempo added that the ministry is working to restore its digital services and that the investigation points to unauthorized access dating back to January.

Taken together, the two sources point to two clear layers. One is the immediate impact on systems linked to illicit drug monitoring and legal processes. The other is an ongoing recovery effort and an open investigation involving Fiscalía, ColCERT and specialized teams.

What do the reports show about ransomware activity?

Colombia also appeared in F5's Weekly Threat Bulletin of August 19, 2026, which adds an independent signal that the country is now showing up in routine ransomware tracking. Separately, a Security Arsenal report on THEGENTLEMEN described an attack pattern focused on edge devices, including VPN gateways, firewalls and remote access tools.

That same analysis tied the most likely initial vector to abuse of those edge systems. In a later update, Security Arsenal added technical details and pointed to authentication issues in Check Point gateways and ScreenConnect as possible entry points for the campaign under review.

Which sectors were most exposed in that analysis?

Security Arsenal said THEGENTLEMEN cases were concentrated mainly in manufacturing and professional services, with additional victims in technology and SaaS, agriculture and food, government and defense, retail and e-commerce, health care and other uncategorized cases.

That sector breakdown matters because it shows a cross-industry campaign, not one limited to a single type of organization. The use of edge devices as an access path fits that broader reach and the variety of compromised environments recorded in the report.

What other case in Colombia appeared in the same window?

Dexpose reported an alleged ransomware claim against PIO PIO in Colombia by the group Majinahanashi. The post said 6,306 files were exfiltrated and warned of a leak if negotiations failed.

There is no official confirmation in the material provided for that episode, so it should be treated as a third-party attribution rather than a fact verified by the company or a government authority.

Sources

View all