Energy, Electricity and Utilities Critical Infrastructure
Ransomware and data leaks marked July in Latin American utilities, with Ecopetrol, Oldelval, and Sinop Energia at the center.
Key findings
- Ecopetrol was the month’s most sensitive case due to exfiltration, corporate scope, and a formal SEC filing.
- Oldelval showed an incident that affected administrative systems without interrupting oil transport.
- Sinop Energia was linked to a leak site and ransomware trackers, but the source material did not show an equivalent corporate confirmation.
- Ransomware was the leading threat, with 24 of 81 incidents, though most did not allow precise impact classification.
- Alerts about Hitachi Energy reinforced OT/IT risk in software used by the energy sector.
- The month showed no documented regulatory moves, but it did show signs of reactive compliance and corporate disclosure.
- The region remained at high risk due to the combination of extortion, data leakage, and exposure of critical platforms.
Monthly reference modules
These modules are completed automatically with the verified dated facts within the period. Each one states its basis and counting criterion, so the figures reconcile across modules. They are the recurring month-to-month read; the later analysis develops the cases without repeating this summary.
Indicator window: 83 dated facts in July 2026 · 1 without confirmed date (excluded from the indicators). Facts from earlier months are used only as comparative context in the analysis, never as volume for this period.
Monthly executive summary
July ended with a clear pattern for energy, electricity, and utilities in Latin America, with three cases drawing regional attention: Oldelval in Argentina, Sinop Energia in Brazil, and Ecopetrol in Colombia. In the source material, all three appear as security incidents with different levels of verification and impact. Oldelval reported an incident that affected administrative systems but did not disrupt oil transport. Sinop Energia was listed on leak sites and ransomware trackers as a victim of Global Secret Group. Ecopetrol, by contrast, was at the center of the month’s most sensitive incident because of the volume of information involved, its corporate reach, and the combination of data theft, extortion pressure, and regulatory reports filed with the SEC.
Ransomware was the dominant signal in the month, with 24 of 81 verified events in the period, and most cases did not allow a determination of whether there was encryption, exfiltration, or only a claim on a leak site. That ambiguity matters. In a sector where operational continuity weighs as much as confidentiality, the difference between a public mention and an intrusion with real impact defines material risk. In July, only a limited share of cases made it possible to say with precision what happened: Ecopetrol reported data theft and controls that prevented encryption, Oldelval described administrative disruption without operational impact, and Sinop Energia was exposed mainly through third-party publication linking it to an extortion attempt with data leakage.
The month was also shaped by a relevant technical layer for OT and critical infrastructure. INCIBE warned about two high-severity vulnerabilities in Hitachi Energy products used in the energy sector, and the alerts were also echoed by WaterISAC, CISA, CSIRTS, and ISS Source. In PROMOD V, the issue was described as insecure HTTP communication with the potential for credential theft, session hijacking, and unauthorized access. In e-mesh EMS, a buffer overflow flaw was reported with the potential to cause application crashes and code execution. For energy and utilities operators, this block matters as much as the incidents, an environment with administrative exposure, remote integrations, and energy management platforms cannot tolerate slow patching or weak segmentation.
The regional picture is not uniform, but it is consistent on the criticality axis. Colombia concentrated the most sensitive case through Ecopetrol, along with a broader backdrop of pressure from cyberattacks and ransomware. Brazil added another point of attention with Sinop Energia and with regional data placing the country among those hardest hit by ransomware. Argentina appeared with the Oldelval incident, with lower confirmed operational impact but strategic value because it is the country’s largest oil pipeline. Paraguay did not show a utilities incident with confirmed impact, although it did show a picture of compromised state activity and institutional response that serves as a reminder of the regional threat environment. The result is a snapshot in which the critical attack surface remains open to campaigns that blend extortion, leakage, and exposure of support systems.
Based on the evidence available, the risk for this vertical in the month stands at high. Not because there were multiple mass service disruptions, there were none in the material, but because of the combination of three factors: ransomware in several cases, exposure of sensitive data in companies with systemic weight, and the appearance of OT/IT vulnerabilities in energy control and administration platforms. Severity rises less from the noise and more from the quality of the targets.
Regional landscape for the month
July showed sustained pressure across organizations with critical functions in the region, but the clearest signal was not a wave of outages. It was a mix of extortion, data leaks, and exploitable vulnerabilities in software used by the energy sector. That means the month has to be read through business continuity, not just data protection. In utilities, an incident that does not shut down a plant can still compromise billing, engineering, contracts, maintenance, internal communications, and access to support environments. The verified facts point to that gray area: administrative impact without service interruption, data publication without critical downtime, and mentions on leak sites without independent confirmation of impact.
The intensity varied by country, but the common denominator was pressure on companies with large data volumes and complex technology dependencies. Ecopetrol is the most visible case because of the volume mentioned and the number of subsidiaries affected. Oldelval illustrates an incident that stayed outside the physical operation of the pipeline, though that does not make it any less relevant. Sinop Energia appears as a case where third-party disclosures and ransomware tracking platforms build a narrative of exfiltration and extortion, but the source does not provide the same level of confirmation as in Ecopetrol. That methodological difference matters to avoid overstating the damage while still not underestimating exposure.
The vulnerability layer also had its own weight. In energy and utilities, management and control platforms are part of the business, not a peripheral add-on. That is why the alerts on Hitachi Energy are especially relevant. The combination of insecure communications, denial-of-service potential, and remote code execution does not describe a lab curiosity, but a vector that, in poorly segmented environments, can enable anything from credential theft to lateral movement toward higher-privilege systems. The presence of advisories from CISA and WaterISAC reinforces the operational priority assessment, although the material does not document specific exploitation in Latin America during July.
In risk terms, the region sat in a high band. Not because of a single catastrophic intrusion, but because of the density of events affecting organizations that support essential infrastructure or services, the centrality of ransomware as the dominant tactic, and the recurrence of cases where confidentiality is broken before physical operations are disrupted. For a CISO in the sector, that means looking beyond uptime status. The question is not only whether the plant is still producing, but which part of the support ecosystem was exposed, which credentials circulated, which backups were touched, and what recovery paths exist if the next event reaches OT.
Period indicators
| Indicator | Value |
|---|---|
| Verified events in the period | 81 |
| Indicator time window | 83 events dated in July 2026 · 1 without confirmed date (excluded from indicators) |
| Unclassified incidents (breaches or outages) | 21 |
| Cases with ransomware or extortion as the primary focus | 24 |
| Confirmed asset encryption | 4 |
| Exfiltration without encryption (simple extortion) | 1 |
| Leak site mention only | 1 |
| Classification cannot be determined from the material | 18 |
| Documented fraud or phishing cases | 1 |
| Documented regulatory moves | 0 |
| Critical CVEs mentioned | 9 |
| Sectors with at least one documented event | 5 |
| Dominant threat of the month | Ransomware (24 of 81 events) |
| Events with direct source confirmation | 94% |
| Aggregated telemetry figures excluded from volume | 2 (aggregated attempts or blocks: these are not incidents with confirmed impact) |
| Calculation base | 81 events in the period |
Relevant incidents
Ecopetrol and the data exfiltration attack
Ecopetrol was the most significant case of the month for the sector, because of its reach, the sensitivity of the information involved, and the company’s formal response. Reuters reported that the company disclosed a cyber incident to the SEC involving unauthorized access to data tied to about 3,300 user accounts and a ransomware attempt blocked by internal controls. The same coverage said no critical disruption had been detected in operations or production, and no direct financial impact had been identified at the time of the report. That detail matters: in critical infrastructure, the fact that operations continue does not make the incident less serious, because data loss and exposure of digital assets can lead to extortion, reputational pressure, and downstream risk for vendors and subsidiaries.
The center of this case was the leak. Ecopetrol confirmed the illegal publication of information copied from 15 companies in the Ecopetrol Group and said it was working with the Fiscalía General de la Nación and MinTIC to remove the content and limit its spread. El País added that the group The Gentlemen claimed responsibility for the attack and said it had up to one terabyte of information, including more than 327,000 files and data from subsidiaries such as Hocol, Cenit, Eust and Econova. Infobae, meanwhile, said the Fiscalía opened an investigation into the leak of sensitive information and that the case was still in the preliminary inquiry stage. The overlap between the company, the press and the authorities shows a material incident that is already established, even if the exact amount of data taken is not fully aligned across the sources.
There is a second reason Ecopetrol stands out in a utilities and energy report. The company did not limit itself to an internal or local notice, it filed a Form 6-K with the SEC on July 28, according to El País, and also issued a version distributed by PR Newswire and republished by Yahoo Finance, where it said it activated its response protocols, revoked unauthorized access, and filed a criminal complaint. From a corporate governance perspective, that places the event at the level of a material incident with disclosure implications and possible cross-border fallout. For Latin America, it is a forced benchmark for maturity, because it pushes cyber response beyond technical containment and into regulatory and market reporting.
The operational readout is stark. When a company of this size says the intruder reached data from multiple subsidiaries, the problem does not end with first containment. Questions remain about credentials, privileged identities, cloud repositories, business documentation, and the traceability of what left the affected environments. Reuters and the company itself said no critical production outages had been observed. Even so, that does not reduce the case’s value as a risk reference: in utilities and energy, attackers often target administrative and support repositories that let them apply pressure without touching the systems that keep service running.
Oldelval and the incident that did not stop the pipeline
Oldelval, operator of Argentina’s largest oil pipeline, notified the Comisión Nacional de Valores of a computer security incident affecting certain administrative systems, without affecting oil transport operations or interrupting crude movement. Ámbito added that the company activated its response protocols, restored the affected platforms, and was evaluating a possible legal complaint. This is a case of high sector relevance, even if its physical operational impact was limited. For a pipeline, continuity is reassuring, but it should not be read as evidence of no damage. Administrative disruption can include email, documentation, procurement, service orders, contract information, or support tools that, if escalated, can affect response times.
Dexpose placed the first public claim in the case with TheGentlemen on July 23, before the late-month news coverage. That post said sensitive data would be released if there was no negotiation. Ransomware.live linked the case to the group, but its entry was presented as not constituting independent validation of a breach confirmed by the company. GalaxyWarden also listed it as a third-party mention on a leak site and noted that, at that point, there was no official breach notice. That sequence matters methodologically. The material supports confirmation of an administrative incident and an extortion claim, but it does not justify stating, with the same level of certainty as in Ecopetrol, a verified exfiltration or a ransomware encryption event with material impact.
The difference between a public claim and a validated intrusion matters a great deal for a hydrocarbon transport operator. Criminal groups use leak sites to pressure targets and often amplify a case before the company can assess its scope. Oldelval appears to fit that pattern. Operations continued, administrative systems were touched, and the story spread alongside an extortion claim. For the sector, the lesson is twofold. First, resilience in the industrial layer should not create false confidence about the administrative layer. Second, early and precise communication with regulators and markets reduces the space for the leak site to shape the incident narrative.
Sinop Energia and exposure on leak sites
Sinop Energia, a Brazilian power company, was listed by Global Secret Group on a leak site and appeared associated with a supposed exfiltration of about 300 GB. Breachsense recorded it as a ransomware victim in July 2026 and attributed the case to the same group. Ransomware.live followed it as leak activity, while warning that attribution should be treated cautiously until independently verified. DarkField Orizon also categorized it as a victim of leaked data, repeating the approximate figure. The combination of sources supports the view that trackers and aggregators treated the case as an extortion incident with data leakage, but the available material does not provide a corporate confirmation comparable to Ecopetrol’s.
That does not make it irrelevant. On the contrary, Sinop Energia is a sign of pressure on Brazilian utilities in a context where the country appears repeatedly among the region’s most heavily hit by ransomware. The distinction between a third-party posting and a victim confirmation should remain in the report because it affects how risk is read. A leak-site listing does not automatically equal a validated intrusion, but it does signal exposure and potential reputational impact. In energy environments, the mere publication can also trigger contractual demands, customer audits, or questions from regulators and financial counterparties.
The 300 GB figure stands out, but it should be treated cautiously. The sources cited repeat the number, although they do not support it with verifiable technical evidence in the material provided. For that reason, the case should be read as an exfiltration claim echoed by specialized trackers, not as a volume independently confirmed by the company.
Active threats and campaigns
Ransomware and extortion
The month was dominated by ransomware, but the internal breakdown requires separating the typologies. Only four cases in the period clearly indicate confirmed asset encryption. There was one exfiltration case without encryption, one case mentioned only on a leak site, and eighteen situations where the source does not allow a precise determination of whether there was encryption, data theft, or only a public claim. That mix is typical of today’s extortion ecosystem, where attackers gain value through both pressure and ambiguity. In utilities, that ambiguity is dangerous because it can delay containment decisions, notifications, and talks with third parties.
Ecopetrol fits the exfiltration category, with controls that prevented encryption. Reuters reported a blocked ransomware attempt and unauthorized access to data. ITWareLatam reinforced the continuity-of-operations reading and said there was no system encryption. This is the kind of case that now dominates many campaigns against critical sectors, attackers obtain data, extract extortion value, and leave the operational layer intact to maximize pressure. The damage, then, is measured not only in downed systems, but also in compromised accounts, copied documentation, and downstream risks for group companies.
Oldelval represents another form of exposure. The TheGentlemen claim, the extortion tone on the leak site, and the company’s response suggest an incident aligned with double-pressure tactics, but the material does not allow a precise classification within the operational taxonomy. There is no confirmation of encryption or company-validated exfiltration. That lack of precision is not a flaw in the report, it is part of the month’s reality, many incidents reach public view before their real technical architecture is known. For a security team, that means the first hour of response should assume the worst reasonable case without taking the public mention as the end of the matter.
Sinop Energia sits in a similar zone, although with greater weight on the leak narrative. Trackers followed it as a victim and repeated the 300 GB figure, but the material does not include its own statement that would clearly separate simple extortion, a leak site case, or encryption. In threat terms, that still matters because the criminal business model depends on the rapid publication of victims and speculation about the scope of the leak. In energy operations, a rushed attribution can affect contracts, insurance, and trust relationships with customers and investors.
Fraud and phishing
This month’s material documents only one fraud or phishing case, and it is not concentrated in the energy vertical as a dominant campaign. That does not mean the vector is absent, only that it was not the focus of the verified July incidents. Even so, the data is useful because it shows that, in energy and utilities companies, the entry point is often email, identity, or third-party interaction. When the month is dominated by ransomware and leaks, phishing acts more as an access and persistence mechanism than as a standalone threat with its own narrative.
APT and hacktivism
Paraguay produced the most visible case of activity attributed to actors linked to the Chinese government against state systems. Although this is not an incident in the energy and utilities vertical, it does provide regional context on the intrusion climate and on institutional attention to sustained cyberoperations. MITIC told the Senate that information breaches were detected in 120 state institutions, and later a criminal investigation was mentioned by the Prosecutor’s Office. For the energy sector, the reading is not that there is a campaign specifically targeting Paraguayan utilities, but that the region is dealing with persistent actors capable of moving between state, corporate, and infrastructure targets.
Critical vulnerabilities
| CVE | Software | Exploitation | Source |
|---|---|---|---|
| CVE-2026-42945 | Hitachi Energy e-mesh EMS | Heap-based buffer overflow. It can cause application crashes and possible arbitrary code execution. | ISS Source |
| CVE not reported in the material | Hitachi Energy PROMOD V | Insecure HTTP communication instead of HTTPS, with risk of credential theft, session hijacking, and unauthorized access. | CSIRTS |
| CVE not reported in the material | Hitachi Energy PROMOD V | Two high-severity vulnerabilities, with potential for denial of service and remote code execution. | Moncloa.com |
| CVE not reported in the material | Hitachi Energy e-mesh EMS | One of the two high vulnerabilities flagged by INCIBE, with no CVE details in the provided material, with possible DoS and RCE. | Moncloa.com |
| CVE not reported in the material | CISA ICS advisories for Hitachi Energy PROMOD V | Advisory published by CISA, focused on energy-sector exposure. | WaterISAC |
| CVE not reported in the material | CISA ICS advisories for Hitachi Energy e-mesh EMS | Advisory published by CISA, focused on energy-sector exposure. | WaterISAC |
| CVE not reported in the material | Hitachi Energy PROMOD V | Product used in critical energy infrastructure environments, with affected versions 1.0.10 and earlier. | CSIRTS |
| CVE not reported in the material | Hitachi Energy e-mesh EMS | Affected versions 4.1.6, 4.4.2 and 4.7.0, with the issue present in NGINX v1.30.0 and earlier. | ISS Source |
| CVE-2026-58644 | Microsoft SharePoint Server 2016 / Enterprise Server 2016 | Deserialization of untrusted data and remote code execution capability, requiring Site Owner privileges according to Microsoft. | F5 Labs |
Hitachi Energy's alerts are the only vulnerabilities this month with a clear impact on the energy sector. The material does not show a large volume of confirmed exploitation in Latin America for these CVEs, but it does make clear that security teams in the sector should treat them as a priority. The risk chain is direct: insecure access, credentials, sessions, exposed consoles, and possible movement to more sensitive components if segmentation is weak. In OT environments, the problem rarely starts inside the PLC. It usually begins in the layer that manages, monitors, or connects.
Regulation and compliance
July showed no new documented regulatory moves in the period materials, at least not in the form of a rule, resolution, or formal compliance change specific to energy and utilities in Latin America. That zero should not be read as a lack of regulatory pressure, but as the absence of a normative move captured by the analyzed corpus. What did appear were signs of reactive compliance and corporate reporting that matter for the sector. Ecopetrol notified the SEC through a Form 6-K, and also reported actions before Fiscalía and MinTIC. In practice, that sets a high threshold for how formalized the event became.
The link between a cyber incident and regulatory disclosure became more visible in the region. When an energy company with significant operations and affected subsidiaries has to report to the U.S. market, the incident is no longer just technical. Materiality, corporate governance, and notification timing enter the picture. For other utilities in the region, the Ecopetrol case is a concrete reference point showing that legal and communications handling must be built into the response from the first phase. In an exfiltration event, the window between detection, validation, classification, and reporting can be just as sensitive as technical containment.
Countries and most affected subsegments
Colombia
Colombia had the month’s heaviest case, centered on Ecopetrol. The company confirmed the illegal publication of information from 15 companies in the group, reported access to about 3,300 accounts, and moved in parallel through corporate, judicial and regulatory channels. The Fiscalía opened an investigation, and local media tracked the case closely. This also comes against a backdrop of rising regional pressure on Colombian companies, although those aggregate figures are not part of this report’s monthly volume. The most exposed subsegment here is not energy in the classic sense alone, but the ecosystem of holding companies, subsidiaries, cloud services and vendors that supports operations.
Brazil
Brazil appeared through Sinop Energia and the broader regional ransomware context. The electric company case was linked to Global Secret Group and to a reported exfiltration of 300 GB. While the material does not provide independent corporate confirmation, it does show that the country remains a priority target in Latin America’s extortion ecosystem. For Brazilian utilities, the lesson is clear: brand reputation, a broad digital surface and dependence on vendors mean a leak site posting can quickly escalate into a communications crisis.
Argentina
Argentina appeared through Oldelval, with one key difference from other cases this month, the oil transport operation was not interrupted. According to the company, the incident affected administrative systems and was contained. For the pipeline and midstream subsegment, that leaves a useful takeaway. Physical continuity does not remove the need to review exposure in support systems, access to administrative platforms, user privileges and recovery processes. An incident that does not move crude today can open the door to the next one.
Paraguay
Paraguay did not record a confirmed energy-sector incident during the month, but it did present a climate of alert around compromises in state systems. Copaco proactively took down its website after detecting a security incident, with no confirmed impact on critical systems, and MITIC reported that information from 120 public institutions had been compromised, attributed to groups linked to China. For utilities and energy, this serves as regional context on cyber hygiene and digital infrastructure exposure, especially for organizations that share dependencies or vendors with the public sector.
Subsegments under the most pressure
Within the vertical, the most sensitive subsegment was integrated energy with heavy dependence on administration and data management, as seen in holdings and large operators. Next was hydrocarbon transport and logistics, exemplified by Oldelval. Finally, power generation and distribution were exposed through the visibility of Sinop Energia and the need to take Hitachi Energy industrial software alerts seriously. In all cases, the most fragile surface was not the isolated physical asset, but the digital ecosystem around it.
Trends and signals to watch
There is no month-over-month baseline, because this is the first archived period with this indicator format for Latin America. Even so, the material does identify signals that should remain under observation in the coming months. The first is ransomware becoming more firmly established as a mixed extortion method, with cases in which exfiltration carries more weight than encryption. The second is the growing weight of formal communications to regulators and markets, something visible in Ecopetrol. The third is the exposure of industrial software and energy platforms to high-severity vulnerabilities that can be used as a bridge to remote access or denial-of-service attacks.
The most sensitive area is the combination of leak sites and operational continuity. If a criminal group publishes data but does not take operations down, many organizations tend to underestimate the event. In utilities, that is a mistake. Operations may continue, but reputational, contractual, and legal damage is already underway. That pattern appears in Ecopetrol and, less conclusively, in Oldelval and Sinop Energia. The focus for August should be whether these campaigns continue to favor data theft over physical disruption, because that model is usually harder to detect in time and slower to eliminate.
The other signal is the significance of alerts about Hitachi Energy. This is not just a vendor, but a class of systems used to monitor and operate energy infrastructure. When CISA, WaterISAC, INCIBE and other agencies issue matching warnings about products of that type, the message for the region is that the risk is neither theoretical nor peripheral. The priority should not be limited to patching, but should include external exposure, segmentation, access accounts, logging and response capability in the event of remote exploitation.
Security team recommendations
First, split ransomware response into three operational tracks, confirmed encryption, exfiltration with operations intact, and a leak site mention without independent validation. Treating all three as the same leads to containment and communications mistakes. In energy and utilities, the difference between lost availability and lost confidentiality changes the decision chain. Technical, legal, and communications teams should work from the same taxonomy from minute one.
Second, strengthen identity hygiene and privileged access controls across administrative, cloud, and support environments. Ecopetrol showed that an intrusion can affect thousands of accounts and several subsidiaries without touching the operational core. That means reviewing MFA, account segregation, privilege reviews, session expiration, activity logging, and credential rotation across the corporate chain, not just in the OT bastion.
Third, audit environments using Hitachi Energy software and any similar industrial or energy management platform. Verify versions, remote exposure, segmentation, access lists, patching, and contingencies for application outages. The vulnerabilities reported in July are not only an IT issue: they can become a pivot path toward sensitive assets if management, telemetry, and operations are loosely integrated.
Fourth, review restoration capacity and backup quality with a focus on exfiltration scenarios. A healthy backup does not solve leakage or secret exposure, but it does limit operational pressure if the attacker escalates to encryption. In a critical operator, restore availability should be tested cold and hot, with measured times and real separation between administrative and operational copies.
Fifth, harden third-party management. The Ecopetrol material mentions data from multiple subsidiaries and the possibility of access through distributed corporate resources. That pattern requires a vendor inventory, review of temporary access, controls over administrator accounts, monitoring of service credentials, and testing of access revocation when the contractual relationship ends.
Sixth, prepare regulatory and public communications scripts before an incident. The Ecopetrol case shows that reporting to the SEC, Fiscalía, MinTIC, and the press can happen almost at the same time. If the organization has not defined materiality thresholds, reporting owners, and messages by event type, the attacker gains narrative speed. Coordination among security, legal, institutional relations, and the business should be practiced with exercises that include data leaks and leak sites.
Seventh, monitor leak sites and trackers, but do not treat their claims as final truth. Sinop Energia and Oldelval appear on third-party platforms with details about volume and the attributed group, but the July report makes clear that these elements should be treated as indicators, not validation. Watching these sources is useful for early detection, not for closing the analysis.
Material limitations
This report covers only the facts from the July 2026 block provided as research material. Facts from earlier months, although they may appear in the corpus as comparative context, were not counted in the period indicators. The declared time window for the indicators is as follows: 83 facts dated July 2026, 1 undated item excluded from the indicators. The values reproduced in the table match that base exactly.
For executive reading, one important point is that an indicator at 0 does not mean a real absence in the region, only that no record appeared in the material analyzed. This applies in particular to the documented regulatory moves, which appear as 0. The figure does not mean there was no policy or compliance activity in Latin America, only that it did not appear in the corpus used for this report. The same applies to any other category where the material did not show verifiable facts.
It is also worth stressing that the 9 critical CVEs mentioned do not represent the full set of relevant vulnerabilities for the month, only those reflected in the sources available for this report. As a result, a low or zero indicator does not justify concluding that no other vulnerabilities were exploited in the region. This section summarizes only what the material confirmed or documented with sufficient traceability.
On sources, this analysis excluded consumer social networks, sponsored posts, press releases, and commercial content that do not meet the editorial standard required to support trends. For that reason, some facts carry a different degree of certainty depending on the source, especially those coming from trackers, leak sites, or incident aggregators. When the material does not allow a determination of whether there was encryption, exfiltration, or only a mention on a leak site, the report states that explicitly and avoids forcing an artificial classification.
Sources
- Denuncian un intento de ciberataque al operador del mayor oleoducto de la ArgentinaÁmbito
- TheGentlemen Ransomware Group Strikes Oldelval Oleoductos del ValleDexpose
- Victim: Oldelval Oleoductos del Valleransomware.live
- Oldelval Oleoductos del Valle Listed by thegentlemenGalaxyWarden
- El INCIBE alerta de dos vulnerabilidades altas en Hitachi Energy que permiten denegación de servicio y RCEMoncloa.com
- Sinop Energia Listed by Global Secret Group Ransomware ...Galaxy Warden
- Sinop Energia Data Breach in 2026Breachsense
- Victim: Sinop Energia – Global Secret GroupRansomware.live
- Sinop Energia data breach — Global Secret Group ransomware leak (2026)DarkField Orizon
- La Fiscalía investiga el ciberataque contra Ecopetrol: se habría infiltrado información sensibleInfobae
- Un ciberataque a Ecopetrol expone información del negocio y de sus empleadosEl País
- ¿Ciberataque a Ecopetrol? Publican información de 15 empresas del grupo y la compañía pide intervención de las autoridadesEl Colombiano
- Colombia's Ecopetrol says cyberattack stole data tied to ... - ReutersReuters
- Grupo energético colombiano Ecopetrol denuncia incidente cibernéticoReuters
- Ecopetrol Reports Cybersecurity IncidentYahoo Finance / PR Newswire
- (TLP:CLEAR) CISA ICS Advisories, Additional Alerts, Updates, and Bulletins – July 9, 2026WaterISAC
- Hitachi Energy PROMOD V - CSIRTS.comCSIRTS
- Hitachi Updates e-mesh EMSISS Source
- China rechaza acusación de ciberespionaje a sistemas estatales de ParaguayDW
- Fiscalía ordena iniciar investigación de supuesto ciberataque de ChinaLa Tribuna
- Mitic informa al Senado que 120 entes públicos fueron atacados por ChinaÚltima Hora
- Copaco desactiva su sitio web tras detectar un “incidente” de seguridad - Nacionales - ABC ColorABC Color
- Aumentan ataques de ransomware en primer semestre de 2026Agencia NVM
- Casos de ciberataques aumentan 38% en México, empresas registran escalada en diversos sectoresInfobae
- Empresas en Colombia enfrentan más de 3.000 ciberataques semanales y pérdidas millonariasInfobae Colombia
- Vulnerabilidades y ransomware elevan el riesgo operativo para industrias estratégicas, advierte KaseyaITwareLatam
- ESET alerta que DragonForce impulsa una nueva etapa del ransomware en el mundoSociedad Noticias
- Weekly Threat Bulletin – July 22nd, 2026F5 Labs
- Expertos alertan sobre una creciente táctica de ransomware: hackers imprimen demandas de rescate durante ataques en América LatinaTrendTIC
- Threat Intelligence Report — July 19, 2026 | 7 New KEVs · 169 VictimsThreatPodium
- Security News Daily Report 2026-07-18DevSecLab
- Alerta Vaca Muerta por ciberataque que puso a prueba seguridad ...iProfesional
- Colombia's Ecopetrol says cyberattack stole data tied to ...Reuters
- Security News Daily Report 2026-07-16|Device Security LabDevice Security Lab
- CISA Urges SharePoint Hardening After New ExploitationsCISA
- Microsoft security advisory – July 2026 monthly rollupCyber Centre (Canada)
- Before, during and after ransomware attackSCILabs
- The Week in Breach News: July 01, 2026Kaseya
- Weekly Cyber Alert Report: Second Week of July 2026note.com (zsecurity)
- Phishing y documentos maliciosos ponen a América Latina como la segunda región más expuesta a ciberamenazas industrialesTrendTIC
- CISA Adds Two Known Exploited Vulnerabilities to CatalogCISA
- CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV CatalogThe Hacker News
- Vulnerability Intelligence Report — July 7, 2026Threat Modeling
- The Week in Breach News: July 29, 2026Kaseya
- Kaspersky alerta por ciberataques en América LatinaPressLatam
