Ecopetrol Coordinates Takedown of Leaked Files
Ecopetrol is working with Colombian authorities to remove leaked content after unauthorized access to its cloud environments.
Ecopetrol is working with Colombia’s Attorney General’s Office and the Ministry of Information and Communications Technologies to remove leaked content from the internet and limit access to it after a cybersecurity incident in its cloud environments. The company has also stepped up security measures as it continues containment efforts and digital forensics on the unauthorized access.
Ecopetrol is working with Colombia’s Attorney General’s Office and the Ministry of Information and Communications Technologies to remove leaked content online and limit access to it after a cybersecurity incident in its cloud environments.
What is known about the attack
In statements issued after the incident, the company said it has strengthened cybersecurity measures across its cloud platforms and continues with containment efforts and digital forensic analysis into the unauthorized access. Ecopetrol also said the full impact of the incident has not yet been established and that it cannot rule out further leaks, litigation, or effects on its operations and financial position.
Coverage from El País said the ransomware-as-a-service group The Gentlemen publicly claimed to have stolen up to 1 terabyte of information from Ecopetrol and its subsidiaries, across more than 327,000 files. Among the victims named by the group are Hocol, Cenit, Eust in Houston, United States, and Econova, expanding the known scope of the incident beyond the parent company.
Forensic review and technical scope
A forensic analysis cited by Caracol Radio estimates the attackers obtained about 1 terabyte of information, equivalent to 327,095 files. Of that total, 11 were classified as critical and 3 as high risk. The same analysis identified 429 files tied to credentials and access controls, about 64 GB of financial and treasury operations data, and 584 files associated with payments made by Ecopetrol.
Forensic researcher Yefrin Garavito described the attack in two stages. First came the theft of information through access to credentials and cloud services. Then came an attempt to encrypt systems to block access and demand a ransom payment. That sequence reinforces the characterization of the incident as a ransomware case with an extortion component.
According to Fiscalía sources cited by Caracol Radio, the attack reportedly began at one of Ecopetrol’s refineries and took advantage of a third party’s administrator-level access. Those same sources said the attackers used Kali Linux to compromise IT systems and extract data from Active Directory, including employees’ emails and potentially those of the board of directors. They also said that, despite the company’s cybersecurity team responding promptly, the attackers still managed to take just over 1 terabyte of information.
Risk perimeter
Infobae reported that Ecopetrol’s review of possible impacts also extends to transactional technology solutions used by subsidiaries and by its network of commercial and financial partners. At the same time, El Universal de Cartagena emphasized that, according to the company, none of the transactional technology solutions were compromised, so the incident was concentrated in cloud storage environments and not in transactional support systems or OT.
Video coverage from Noticias Caracol added that The Gentlemen is threatening to publish the stolen information if its financial demands are not met, leaving the extortion front open while coordination with authorities continues to limit the spread of the leaked files.
The Gentlemen and Ecopetrol: what is known about the August 2026 leak
The case involving The Gentlemen and Ecopetrol in August 2026 falls within the same cybersecurity incident described in the report, involving the theft and leak of files from cloud environments. The company is working with authorities to limit the circulation of the material while the forensic review continues.
The coverage cited in the body attributes to the group a theft of up to 1 terabyte and more than 327,000 files. It also says the episode included encryption attempts, extortion, and the exposure of data linked to Ecopetrol and some of its subsidiaries.
Sources
- Comunicado Ecopetrol refuerza medidas de ciberseguridad en plataformas de nubeecopetrol.com.co· Ecopetrol
- Ecopetrol confirma ciberataque: acceso ilegal comprometió información de 3.300 cuentas de usuarioportafolio.co· Portafolio
- Un ciberataque a Ecopetrol expone información del negocio y de sus empleadoselpais.com· El PaísUnverified URL
- Comunicado Ecopetrol investiga posible acceso no autorizado a información en entornos de almacenamiento en la nubeecopetrol.com.co· Ecopetrol
- Comunicado Ecopetrol avanza en investigación sobre posible acceso no autorizado a informaciónecopetrol.com.co· Ecopetrol
- Comunicado Ecopetrol reitera normalidad en sus operaciones tras investigar acceso no autorizadoecopetrol.com.co· Ecopetrol
- Ciberataque contra Ecopetrol: la empresa coordina con la Fiscalía y el MinTIC el retiro de archivos filtradosinfobae.com· Infobae
- Hackean a Ecopetrol: revelan filtración de datos confidenciales de 15 empresasyoutube.com· Noticias Caracol
- Ciberataque a Ecopetrol: filtran información de 15 empresas del grupoeluniversal.com.co· El Universal (Colombia)
- “La información ya se encuentra en la dark web”: experto sobre ciberataque a Ecopetrolcaracol.com.co· Caracol Radio
- Así se orquestó el ciberataque a Ecopetrol: Fiscalía investigacaracol.com.co· Caracol Radio
- Cyber Assault on Ecopetrol: Data Breach Shakes Energy Giantground.news· Ground News / Reuters
- Información relevante para el mercado (comunicados sobre incidente de ciberseguridad)ecopetrol.com.co· Ecopetrol



