Colombia Justice Ministry Confirms Ransomware
Colombia’s Justice Ministry confirmed ransomware hit part of its infrastructure. No data theft was detected, and recovery is ongoing.
Colombia’s Justice Ministry confirmed a ransomware attack that affected part of its technology infrastructure. Some files were encrypted, no data theft was detected, and the agency continues its recovery and hardening efforts.
Update August 22, 2026: Check Point Research confirmed that some files were encrypted and that no data theft was detected during the incident. It also detailed the impact on illicit drug monitoring services and legal processes, while the ministry maintains an ongoing forensic analysis and the IDB has joined with technology support.
Colombia’s Justice Ministry confirmed a ransomware attack against part of its technology infrastructure and disabled services as a precaution to contain the incident. The agency reported disruptions in some technology services and in public digital services, and later said the case also affected illicit drug monitoring services and legal processes.
What did the Justice Ministry confirm?
Colombia’s Justice Ministry confirmed on August 3, 2026, a ransomware attack against part of its technology infrastructure. In its official statement, the agency said it disabled certain services as a precaution, activated cybersecurity and containment protocols, and isolated affected systems to prevent the incident from spreading.
The official text also described interruptions to some technology services and a drop in the availability of public digital services. It did not include any explicit claims about exfiltration or data theft, something Check Point Research later clarified by saying no data theft was detected during the incident, although files were encrypted.
How are the response and recovery progressing?
Minister Iván Cancino said the Justice Ministry has been working since August 8, 2026, with the Office of the Attorney General and Colombia’s Cyber Emergency Response Group, ColCERT, to determine what happened. That investigation includes attempted unauthorized access dating back to January and a review of possible internal and external sources of the attack.
Cancino also said the ministry activated a comprehensive plan to restore services gradually and safely with support from Microsoft’s DART, the Disaster Assistance Response Team, and BIT. Later coverage said that response plan also includes ColCERT and partners from the Inter-American Development Bank, IDB, to strengthen recovery and harden the infrastructure. Las2orillas also reported that the IDB joined with technology support in the response, while the ministry keeps a forensic analysis underway to determine the full scope of the attack.
As an operational contingency measure, the agency enabled alternate channels for submitting requests and supporting documentation, including PQRS, through specific email addresses and in-person service at its Chapinero office. The move came in response to the temporary unavailability of platforms such as MICC and licensing procedures, and later the ministry adopted a temporary contingency measure to handle PQRDSF after the SGDEA became unavailable.
What services remained under recovery?
National media reported that, days after the attack, some Justice Ministry services began to come back online gradually, while others remained under review and in recovery as part of the security plan activated after the incident.
Check Point Research said the incident disrupted public services tied to illicit drug monitoring and legal processes, in addition to the broader impact on public digital services. That combined impact led the ministry to maintain contingency measures for citizen services while restoration continues.
The case adds to other ransomware incidents that have affected Colombia’s public sector in recent years, with effects also seen in health-related services, including the earlier IFX Networks attack that affected Health Ministry services and the episode now confirmed at Justice.
Sources
- Ransomware Hit Colombia's Justice Ministry Five Days Before a New President Took Officethreatvectr.com· ThreatVectr
- Ransomware in Colombia: Paralysis in the Ministry of Justicetechnoid.gr· Technoid.gr
- Ransomware golpea al Ministerio de Justicia de Colombiax.com· White Hunters (X)
- 17th August – Threat Intelligence Reportresearch.checkpoint.com· Check Point Research
- Ataque ransomware inutiliza Ministerio Justicia Colombiamentehackers.com· MenteHackers
- Así se recupera el Ministerio de Justicia tras ciberataque que redujo la disponibilidad de algunos serviciosinfobae.com· Infobae
- Minjusticia activa plan de seguridad luego de sufrir ataque cibernéticoelespectador.com· El Espectador
- Ransomware Attack on Colombian Justice Ministry Amid Presidential Transitionaviatrix.ai· Aviatrix Threat Research Center
- コロンビア法務省がランサムウェア被害を公式発表cyber.nexsight.co· NexSight Cyber
- Ransomware Hits Colombian Justice Ministry Ahead of Presidential Transition: Detection, Response, and Hardening Guidesecurityarsenal.com· Security Arsenal
- El Ministerio de Justicia explica cómo avanza la recuperación de sus servicios digitales tras ciberataqueeltiempo.com· El Tiempo
- Κολομβία: Επίθεση ransomware παρέλυσε το Υπουργείο Δικαιοσύνης λίγο πριν την ορκωμοσία του νέου προέδρουgr.pcmag.com· PCMag Grecia / Dark Reading (referenciado)
- Minjusticia adopta medida temporal de contingencia para la atención de PQRDSFminjusticia.gov.co· Ministerio de Justicia y del Derecho de Colombia
- Los ciberataques a la información de la justicia que el ministro Cancino ha tenido que enfrentarlas2orillas.co· Las2orillas
- Weekly Review, 2026-08-17buttondown.com· WiseGuru



