Ecopetrol Coordinates Takedown of Leaked Files
Ecopetrol is working with Colombian authorities to remove leaked content after unauthorized access to its cloud environments.
Ecopetrol is working with Colombia’s Attorney General’s Office and the Ministry of Information and Communications Technologies to remove leaked content from the internet and limit access to it after a cybersecurity incident in its cloud environments. The company has also stepped up security measures as it continues containment efforts and digital forensics on the unauthorized access.
Ecopetrol is working with Colombia’s Attorney General’s Office and the Ministry of Information and Communications Technologies to remove leaked content from the internet and limit access to it after a cybersecurity incident in its cloud environments.
What is known about the attack
In statements issued after the incident, the company said it had reinforced cybersecurity measures on its cloud platforms and was continuing containment work and digital forensic analysis tied to the unauthorized access. Ecopetrol also said the full impact of the incident has not yet been determined, and that it cannot rule out additional leaks, legal action, or effects on its operations and financial position.
Coverage from El País reported that the ransomware-as-a-service group The Gentlemen publicly claimed to have stolen as much as 1 terabyte of information from Ecopetrol and its subsidiaries, including more than 327,000 files. The entities named by the group include Hocol, Cenit, Eust in Houston, Texas, and Econova, broadening the known scope of the incident beyond the parent company.
Forensic analysis and technical scope
A forensic analysis cited by Caracol Radio estimates that attackers obtained about 1 terabyte of information, equivalent to 327,095 files. Of that total, 11 were classified as critical and 3 as high risk. The same analysis identified 429 files tied to credentials and access controls, about 64 GB of financial and treasury operations data, and 584 files associated with payments made by Ecopetrol.
Forensic researcher Yefrin Garavito described the attack in two phases. First, information theft through access to credentials and cloud services. Then, an attempt to encrypt systems to block access and demand ransom. That sequence reinforces the characterization of the incident as ransomware with an extortion component.
According to Fiscalía sources cited by Caracol Radio, the attack appears to have originated at one of Ecopetrol’s refineries and exploited a third party with administrator privileges. The same sources said the attackers used Kali Linux to compromise IT systems and extract data from Active Directory, including employee emails and potentially board-level correspondence. They also said that, despite the company’s cybersecurity team responding in time, the attackers still managed to take a little more than 1 terabyte of information.
Exposure perimeter
Infobae reported that Ecopetrol’s review of possible impacts also extends to transactional technology solutions at subsidiaries and across its network of commercial and financial partners. At the same time, El Universal de Cartagena stressed that, according to the company, none of its transactional technology solutions were compromised, so the incident was concentrated in cloud storage environments and not in transactional support systems or OT.
Video coverage from Noticias Caracol added that The Gentlemen is threatening to leak the stolen information if its financial demands are not met, leaving the extortion front open while authorities work with the company to limit the circulation of the leaked files.
Sources
- Comunicado Ecopetrol refuerza medidas de ciberseguridad en plataformas de nubeecopetrol.com.co· Ecopetrol
- Ecopetrol confirma ciberataque: acceso ilegal comprometió información de 3.300 cuentas de usuarioportafolio.co· Portafolio
- Un ciberataque a Ecopetrol expone información del negocio y de sus empleadoselpais.com· El PaísUnverified URL
- Comunicado Ecopetrol investiga posible acceso no autorizado a información en entornos de almacenamiento en la nubeecopetrol.com.co· Ecopetrol
- Comunicado Ecopetrol avanza en investigación sobre posible acceso no autorizado a informaciónecopetrol.com.co· Ecopetrol
- Comunicado Ecopetrol reitera normalidad en sus operaciones tras investigar acceso no autorizadoecopetrol.com.co· Ecopetrol
- Ciberataque contra Ecopetrol: la empresa coordina con la Fiscalía y el MinTIC el retiro de archivos filtradosinfobae.com· Infobae
- Hackean a Ecopetrol: revelan filtración de datos confidenciales de 15 empresasyoutube.com· Noticias Caracol
- Ciberataque a Ecopetrol: filtran información de 15 empresas del grupoeluniversal.com.co· El Universal (Colombia)
- “La información ya se encuentra en la dark web”: experto sobre ciberataque a Ecopetrolcaracol.com.co· Caracol Radio
- Así se orquestó el ciberataque a Ecopetrol: Fiscalía investigacaracol.com.co· Caracol Radio
- Información relevante para el mercado (comunicados sobre incidente de ciberseguridad)ecopetrol.com.co· Ecopetrol
- Cyber Assault on Ecopetrol: Data Breach Shakes Energy Giantground.news· Ground News / Reuters



