CiberLATAMbywhalemate

Colombia Hit in Ransomware Campaigns

Kaspersky linked Colombia to StrikeShark, while the Justice Ministry confirmed a ransomware attack that disrupted digital services.

Whalemate Labs · AI-assisted researchPublished:Updated 2 min read

Kaspersky identified the StrikeShark campaign, which uses SharkLoader malware and targeted government agencies, diplomatic entities and software development companies in several countries, including Colombia. Separately, Colombia’s Ministry of Justice and Law confirmed a ransomware attack on Aug. 2, 2026 that compromised part of its technology infrastructure and affected the availability of some digital services.

Kaspersky identified a cyberattack campaign called StrikeShark, tied to the SharkLoader malware, that targeted government agencies, diplomatic entities, and software development companies in several countries. Colombia was among the Latin American countries affected, according to the material provided. In parallel, Colombia’s Ministry of Justice and Law confirmed in an official statement that it had been hit by a ransomware attack on Aug. 2, 2026. The incident compromised part of its technology infrastructure and affected the availability of some digital services.

What did Kaspersky say about StrikeShark?

Kaspersky said the operation is still under investigation and has not been attributed to any known advanced persistent threat group. The campaign’s origin and any possible link to state-backed actors remain unconfirmed.

The campaign, called StrikeShark and associated with SharkLoader malware, targeted government agencies, diplomatic entities, and software development companies in several countries, according to Kaspersky.

Colombia is listed among the affected states in Latin America, according to the material provided.

What did the Ministry of Justice confirm?

Colombia’s Ministry of Justice and Law confirmed in an official statement that it was the victim of a ransomware attack that took place on Aug. 2, 2026. The incident compromised part of its technology infrastructure and affected the availability of some digital services.

COLCERT inspected the datacenter, secured evidence and logs for forensic analysis, and remediation efforts began.

The ministry also said it had not received prior alerts about the attack and that, so far, the theft or leak of information has not been publicly confirmed.

National outlets including Publimetro, El Universal, El Colombiano, Caracol Radio, and Red+ Noticias documented the case and reported that cybersecurity protocols and preventive system isolation were activated.

They also reported that acting minister Cielo Rusinque and appointed minister Iván Cancino asked prosecutors, police, and other authorities to move quickly to identify those responsible, with no public attribution to a specific APT group.

How does this case fit into the public sector context?

DataEnforce placed the episode within a recurring pattern of ransomware campaigns against Colombia’s public sector. Its analysis recalled the IFX Networks case in September 2023, which had a cascading impact on multiple state entities, including the Judicial Branch, the Ministry of Health, and the Superintendency of Industry and Commerce.

The report also outlined behavioral indicators typically seen before ransomware deployment and recommended measures such as phishing-resistant MFA, inventory and oversight of shared infrastructure providers, and immutable offline backups.

Sources

View all