Colombia: cybersecurity landscape, July 2026
July closed with Ecopetrol, ransomware, and new rules for minors, while pressure from fraud and the public sector remained high.
Key findings
- Ecopetrol dominated July’s agenda with data exfiltration, a blocked ransomware attempt, and later extortion pressure attributed to The Gentlemen.
- Ransomware was the month’s leading threat, but most cases did not show the same technical impact, so data extortion gained relative weight.
- Decree 0769 of 2026 clearly raised compliance obligations for digital platforms, schools, and families, with a focus on minors and reporting to MinTIC.
- The SIC took a hard line on sensitive data processing by permanently shutting down Worldcoin’s operations in Colombia.
- The most repeated attack surface remained exposed remote access, weak credentials, and abuse of legitimate tools, especially in ransomware campaigns.
- Financial fraud remained active as a structural pressure, with particular impact from identity theft, mule accounts, and contextual detection at banks and fintechs.
- The public and private sectors shared the month more because of pressure on data and contracting than because of a single technical intrusion wave.
Monthly reference modules
These modules are completed automatically with verified dated facts from within the period. Each one states its basis and counting criteria so the figures reconcile across modules. They are the recurring month-to-month reading; the later analysis develops the cases without repeating this summary.
Indicator window: 82 dated facts in July 2026 · 5 from prior months (comparative frame, not current-month volume) · 1 without confirmed date (excluded from the indicators). Facts from prior months are used only as a comparative frame in the analysis, never as volume for this period.
Executive monthly summary for Colombia
July 2026 left a clear picture in Colombia: the Ecopetrol case dominated public debate and shaped the month’s reading around ransomware, exfiltration, and extortion. The incident, later attributed in various reports to the group The Gentlemen, exposed data tied to about 3,300 user accounts in cloud storage environments belonging to 15 companies in the group. The company said from the outset that its controls blocked encryption, so the visible impact was limited to the extraction and later disclosure of information, rather than a sustained operational disruption.
The month also showed another clear pattern, the ransomware threat did not arrive alone, but alongside more basic yet effective initial-access tactics such as internet-exposed services, poorly secured RDP, leaked credentials, and weak configurations. In technical coverage of incidents in Colombia and the region, that exposure surface appears repeatedly, along with abuse of legitimate tools, corporate printers used to print ransom notes, and native Windows encryption through BitLocker. That helps explain why the month ended with 30 incidents linked to ransomware or extortion as the primary focus.
On the regulatory front, the month carried unusual weight. The government issued Decree 0769 of 2026, which implements Law 2489 of 2025 and sets concrete obligations for digital platforms, educational institutions, and families regarding minors. The text requires privacy by default, age verification proportionate to risk, semiannual reports to MinTIC, stronger reporting channels, and even immediate referral to the Attorney General’s Office when child sexual exploitation cases are detected. This was accompanied by the final sanction from the SIC against World Foundation and Tools for Humanity, as well as legislative initiatives on minors’ use of social media.
In financial services, the tone was different but just as intense. The narrative shifted between impersonation fraud, response measures from banks and institutions, and the growing use of contextual signals and artificial intelligence to reduce account takeover attempts. There was no single case that absorbed all of the attention, but there was a sustained environment of operational pressure and defensive adaptation. The overall read for Colombia is high risk, not because of the number of isolated incidents, but because of the combination of events with reputational impact, data exposure, extortion campaigns, and a regulatory pace that forces rapid control changes.
Colombia Monthly National Overview
Ransomware dominated Colombia in July, accounting for 30 of the 76 verified incidents in the period. Those incidents did not all describe the same kind of impact, and that distinction matters. There were 8 cases with confirmed asset encryption, 5 involving exfiltration without encryption, and 17 where the material does not clearly show whether encryption occurred or whether the activity was only extortion. That spread points to an ecosystem where extortion has become more common than pure system locking, and where data publication, or the threat of it, carries as much weight as technical disruption.
The Ecopetrol case is the clearest example of that shift. The company confirmed unauthorized access, data download, and a blocked ransomware attempt. Reports later emerged about information being published, attribution to The Gentlemen, and coordination with Fiscalía and MinTIC to remove leaked files. According to the company itself, the incident did not lead to a critical operational outage or immediate financial damage, but it did leave a highly visible mark on reputational exposure and data governance.
The other side of the month was regulatory. Colombia moved forward with a decree that directly affects the architecture of digital services for minors, changing the compliance agenda for platforms, schools, families and public entities. At the same time, the SIC kept a tough line on sensitive data processing with the permanent shutdown of Worldcoin in the country. The result is an environment where regulators are more active, while the implementation burden falls on organizations already under pressure from fraud, intrusion and extortion.
The qualitative risk reading for Colombia in July is high. Not because the country suffered a single systemic collapse, but because of the accumulation of incidents with real impact across multiple layers, personal data, operational continuity, the reputation of strategic companies, regulatory compliance and financial fraud. In a regional context where Colombia remains among the most attacked countries, the month reinforced an uncomfortable lesson for security teams, defense is no longer just about stopping intrusions, but about containing the value of what is taken, what is published, and what ends up in regulatory or legal dispute.
The Latin American context helps explain that pressure. In the reports cited during the month, Brazil and Mexico remained ahead of Colombia in regional volume, but the country stayed among the most closely watched by attackers and intelligence providers. That was visible in the attention drawn by Ecopetrol, the recurring mention of active ransomware groups in the region, and the scrutiny given to exposed infrastructure, both corporate and state-owned.
Colombia period indicators
| Indicator | Value | Base / window |
|---|---|---|
| Verified events in the period | 76 | Base for all indicators. Only events dated within July 2026 |
| Indicator time window | 82 events dated in July 2026, 5 from previous months, 1 with no confirmed date | Archive frame, not monthly volume |
| Unclassified incidents (breaches or outages) | 18 | Within July 2026 |
| Cases with ransomware or extortion as the primary focus | 30 | Within July 2026 |
| Confirmed asset encryption | 8 | Ransomware breakdown by impact type |
| Exfiltration without encryption (simple extortion) | 5 | Ransomware breakdown by impact type |
| Unclassifiable with the available material | 17 | Ransomware breakdown by impact type |
| Documented fraud or phishing cases | 1 | Within July 2026 |
| Documented regulatory moves | 18 | Within July 2026 |
| Critical CVEs mentioned | 1 | Within July 2026 |
| Sectors with at least one documented event | 7 | Within July 2026 |
| Dominant threat of the month | Ransomware (30 of 76 events) | Within July 2026 |
| Events with direct source confirmation | 66% | Base: verified events in the period |
| Aggregated telemetry figures excluded from the volume | 6 | Aggregated attempts or blocks, not incidents with confirmed impact |
Relevant incidents in Colombia
Ecopetrol, exfiltration and extortion attributed to The Gentlemen
The month’s most visible case was Ecopetrol. On July 17, the company reported unauthorized access to digital resources that affected cloud storage environments belonging to about 15 group companies and enabled the download of data tied to approximately 3,300 user accounts. The company itself said the ransomware attempt was blocked by internal controls and that it had not identified, at least at that point, any critical disruptions or direct financial impact.
Subsequent coverage shifted the case from exfiltration to extortion. Different sources reported financial demands, threats to publish the material, and the appearance of leaked files on sites linked to The Gentlemen. Ecopetrol activated online takedown protocols and coordinated with the Attorney General’s Office and MinTIC. By the end of the month, the Attorney General’s Office had already opened an investigation. The key operational issue was not encryption, which did not succeed, but the full cycle of extraction, extortion pressure, and public exposure.
Bogotá Mobility Secretariat, data leak and phishing risk
The Bogotá Mobility Secretariat incident remained relevant in July because of its downstream effects. Media coverage describes a leak from a historical database managed by an external vendor, with evidence preservation, traceability review, and technical tracking of the intrusion vector. The agency said it did not have a final consolidated count of affected data and rejected claims about manipulation of traffic fines or speed camera enforcement.
The most practical consequence highlighted in the coverage is the increased risk of phishing and scams aimed at drivers, using exfiltrated data. This was not just an abstract leak, but a leak with operational value for personalized campaigns involving licenses, traffic fines, vehicles, and payments. That kind of data reuse is what turns an administrative breach into a platform for later fraud.
DIAN, scheduling incident and criminal complaint
DIAN said that in its 2026 incident there was unauthorized access to the virtual appointment scheduling system operated by an external vendor, with exposure of users’ personal data, but no compromise of tax or customs information, passwords, or credentials. The agency disabled the affected service, activated incident management protocols, and strengthened the protection of the systems involved.
The value of this case in July was not in its scale, but in the institutional response. The agency confirmed that it filed a complaint with the Attorney General’s Office over facts that could amount to extortion and other criminal conduct, and that it would also report the case to the SIC as the data protection authority. This is a useful risk signal, incidents in citizen service environments are now treated not only as technical failures, but as events with a legal and regulatory path attached.
Government and public cybersecurity procurement
There was also friction around public procurement of cybersecurity services. The Attorney General’s Office asked for explanations over alleged inconsistencies in a Colombia Compra Eficiente contract to implement cybersecurity tools in public entities. Later, the agency itself suspended the provider selection process for 30 days, responding to the Attorney General’s Office observations and thousands of comments from interested parties.
This is not a technical incident, but it is a high-value development for the month because it affects how the state buys defensive capabilities. In a period dominated by exfiltration, extortion, and fraud, a procurement suspension does not by itself change the risk, although it does affect deployment timelines and the perception of governance around cybersecurity spending.
Threats and active campaigns in Colombia
Ransomware and extortion with confirmed encryption
The clearest campaign of the month with confirmed encryption was the one attributed to XEntry Team in Kaspersky analysis and related coverage. The material describes the use of BitLocker, corporate printers to leave ransom notes, and initial access through exposed remote services. In Colombia, at least one case was reported with systems encrypted and legitimate network mechanisms used to expand the impact. The campaign did not rely on traditional encryption malware, but on abuse of native functions and weak configurations.
The other confirmed encryption case in the period was the Ecopetrol incident, although there the encryption never fully materialized because of early containment. For that reason, the case fits more cleanly under exfiltration with extortion than successful encryption. Even so, the double pressure technique, prior data theft, and threat of publication were well documented and dominated public discussion.
Ransomware and extortion with exfiltration and no encryption
Ecopetrol appears here again because the verifiable material from the month shows an attack that exfiltrated data, tried to encrypt, and was blocked. The exfiltration of about 3,300 accounts and the later leak of information from 15 companies in the group place the case on the extortion-by-data side, not on system hijacking. That distinction is essential for response teams: the priority does not end when encryption is stopped, because the second phase of the incident can remain active on forums, leak sites, and coordinated posts.
Ransomware and extortion, type undetermined
The month’s material also includes cases where the source does not specify whether there was encryption, exfiltration, or only a claim on a leak site. That was the case with several mentions of groups such as Deadlock or The Gentlemen on incident tracking and aggregation sites. These are useful intelligence signals, but by themselves they are not enough to treat them as incidents with confirmed impact. In the body of the report, they are treated as indicators of extortion pressure, not as equivalent to a proven intrusion.
Fraud and phishing
The only clearly documented case in July within this track was the increased risk of phishing against Bogotá drivers following the leak of mobility data. This was not an isolated mass phishing campaign, but a concrete offshoot of a prior incident. The pattern is classic, but effective, stolen personal and operational data, victim segmentation, and believable messages about procedures or penalties.
Financial coverage also showed strong pressure from identity fraud, although the material for the period focuses more on prevention and response than on a single case. Banks and fintechs appear forced to sharpen detection engines, rely on contextual signals, and respond to a rise in impersonation attempts and account takeovers. That does not point to one campaign, but it does point to a persistent threat class.
APT and operational relay networks
On the advanced-threat front, the strongest signal came from ColCERT with its alert on the CHARLIE/ORB3 operational relay network. The material attributes its use to APT5 and APT15, with infrastructure that works as a covert channel for tactical operations and with specific recommendations for segmentation, phishing-resistant MFA, and access controls. This is a relevant finding for telecommunications, closer to support infrastructure for espionage or persistence than to an incident with immediate mass impact.
Critical vulnerabilities with impact in Colombia
| CVE | Software | Exploitation | Source |
|---|---|---|---|
| CVE-2024-55591 | Fortinet FortiGate and FortiProxy | Authentication bypass exploited by the group The Gentlemen, with combined use of valid credentials, brute force against SSL VPN and RDP | ColCERT, cited in IntelFusions and Scrutex |
The only critical CVE mentioned in the material analyzed was CVE-2024-55591. The fact that the monthly indicator shows 1 does not mean there are no other critical vulnerabilities in the region, only that in the July material this was the single concrete, verifiable reference.
Regulation and compliance in Colombia
Decree 0769 of 2026, protections for minors and technical obligations
The decree signed in July by the national government is the month’s most significant regulatory text, by both the number of mentions and its regulatory density. It implements Law 2489 of 2025 and sets out default privacy obligations, age verification proportional to risk, semiannual reports to MinTIC, parental controls, complaint channels, and interagency coordination. It also explicitly bans measures that amount to prior censorship, mass monitoring of private communications, or weakening of end-to-end encryption.
The compliance implications are substantial. The decree does not stop at broad principles, it pushes platforms, schools, and families to adopt specific controls. It also requires reporting every six months and the integration of mechanisms to escalate serious cases to Fiscalía and ICBF. In practice, that means documenting processes, updating Terms and Conditions, reviewing age-gating flows, and adjusting how minors’ data is handled.
SIC, Worldcoin and sensitive data processing
The SIC made final the permanent shutdown of World Foundation and Tools for Humanity’s sensitive data processing operation in Colombia, and ordered the deletion of all data collected in the country, including iris codes. The decision reinforces a strict enforcement line on biometrics and sensitive data processing. For any organization working with identity verification, biometrics, or high-risk profiles, the message is clear, using sensitive data without sufficient legal basis, proportionality, and controls can end in a complete shutdown.
Identity theft and the shifting burden of proof
Law 2573 of 2026 and related coverage also mark a change in approach. When a person claims identity theft in loans or other obligations, the entity must suspend collections, provide supporting records, and show what mechanisms it used to verify identity. In practice, this redistributes the burden of proof and forces banks, merchants, and operators to better document onboarding and authentication decisions.
Public procurement of cybersecurity
A review of Colombia Compra Eficiente’s procurement process exposed the political and technical sensitivity of cybersecurity contracting for state entities. The Procuraduría stepped in, the agency suspended the process, and questions emerged about the sequence, the tender documents, and the governance of the framework agreement. Beyond the contract dispute, the episode shows that buying digital defense is now subject to public scrutiny on par with a major public works project or a strategic purchase.
Most affected sectors in Colombia
The business sector was under the heaviest pressure, both by volume and by case value. Ecopetrol drew the most attention, but it was not an isolated incident. Data exposure, extortion, and leaks also surfaced in technology infrastructure, service providers, and highly digitized companies. The pattern is consistent: where there is cloud storage, remote services, or outside vendors with broad privileges, the attack surface grows.
The public sector also had a busy month. DIAN, Bogotá’s Mobility Secretariat, and Colombia Compra Eficiente each raised different concerns, but all pointed to the same tension between citizen service, data exposure, and response capacity. In some cases there was exfiltration, in others questions about procurement, and in others a clear need for coordination with criminal or data protection authorities.
In financial services, the pressure was more diffuse but still very present. The focus was on fraud, impersonation, mule accounts, and more sophisticated access techniques supported by AI. That scenario is forcing institutions to improve contextual detection, review onboarding processes, and maintain a fast response capability when faced with false identity or impersonation claims.
There was also a regulatory component affecting the telecom sector and digital platforms, mainly because of obligations under Decreto 0769. Although this was not one of the sectors most exposed by incidents in July, it is among those that will need to invest the most in compliance during the second half of the year.
Trends and signals to watch in Colombia
The comparison with the previous month shows a clear shift in the nature of the signal. In the prior report, incidents dominated, with 45 such events. In July, the focus shifted to ransomware, with 30 of 76 events. This is not just a change in label, but in threat dynamics. Attention moved from broader intrusion or leak events to campaigns centered on extortion pressure and data publication.
The number of documented fraud or phishing cases also fell, from 18 the previous month to 1 in July. That does not mean fraud declined in the country, only that the July material documented it less as concrete cases and more as structural context. At the same time, regulatory moves decreased from 26 to 18, but the quality of those changes was different: July produced rules and decisions with greater operational weight, such as Decree 0769 and the SIC decision on Worldcoin.
The drop in critical CVEs mentioned, from 9 to 1, should not be read as a general technical reprieve either. It simply means that in the July material analyzed, only one explicit and verifiable critical vulnerability appeared. That calls for caution, since absence of mention does not mean absence of exploitation in the country or across the region.
Another strong signal is the consolidation of extortion campaigns that combine data theft, public pressure and leak channels. Ecopetrol is the emblematic case, but it is not the only context pointing in that direction. The material on The Gentlemen, XEntry Team and Deadlock shows that attackers continue to find returns in double-extortion models, sometimes without needing to deploy traditional encryption malware.
Security guidance for teams in Colombia
Organizations operating in Colombia should start from a simple assumption: ransomware containment is no longer enough if exfiltration and the later public exposure of data are not also controlled. That means tightening cloud storage monitoring, reviewing third-party permissions, auditing administrative access, and preparing rapid procedures to remove leaked information. In incidents like Ecopetrol, stolen data retains value even when encryption is not completed.
Remote access surfaces also need to be hardened. This month’s evidence again points to RDP, exposed services, RMM tools, and weak credentials as core parts of the attack chain. The priority is to reduce direct internet exposure, require phishing-resistant MFA, and review which management services remain accessible without real segmentation.
In environments with BitLocker or native encryption mechanisms, recovery keys should be centralized, with alerts when unusual activations appear. The campaign attributed to XEntry Team offers a very specific lesson, if an attacker is living inside the network, hardening administration is just as important as antimalware.
For fraud teams, the month reinforces the value of contextual signals. Device, geolocation, time of use, transaction history, and session behavior provide more value than standalone authentication once an attacker already has credentials or is using deepfakes and impersonation. In the financial sector, defense depends on correlating context, not just adding friction for the user.
Legal and compliance teams also need speed. Decree 0769, the sanction against Worldcoin, and Law 2573 point in the same direction, tighter scrutiny of data handling, minors, biometrics, and impersonation. This is not only a privacy issue, it is an operational design issue. Teams should review retention policies, consent flows, reporting procedures, and response times for incidents involving personal data.
Finally, public-sector and private-sector organizations with high external exposure should rehearse data publication scenarios. Preparation is not limited to restoring systems. They need to know how to verify leaks, coordinate with authorities, respond to the press, protect third parties, and reduce the potential for fraud reuse of exfiltrated information.
Material limitations
This report covers only facts dated within July 2026 and uses the supplied file as its sole reference base. The comparative framework block contains facts from earlier months and was used only to assess changes, never as part of the period total. The undated item was excluded from the indicators and could only be used as qualitative context if mentioned.
A zero indicator, especially for critical CVEs, means it did not appear in the material analyzed for the month, not that there were no critical vulnerabilities exploited in Colombia or in the region. The same applies to fraud, uncategorized incidents, or sectors: the value reflects what the file documented, not the complete absence of activity.
The declared time window for the indicators includes 82 facts dated in July 2026, 5 facts from earlier months used as a comparative framework, and 1 fact without a confirmed date excluded from the counts. The indicators reproduced in this report correspond only to the verified facts from the period, using the base already calculated in the material provided.
Sponsored content, advertorials, social media posts, and LinkedIn references were excluded as trend evidence. Aggregated telemetry was also avoided as if it were confirmed-impact incidents. Counts of attempts, blocks, and scans are considered only when the material explicitly presents them as activity volume, not as verified intrusion.
Sources
- Alerta por fraude cibernético en Bucaramanga: 866 denuncias y tres claves para proteger sus cuentasVanguardia
- Vulnerabilidades y ransomware elevan el riesgo operativo para industrias estratégicas, advierte KaseyaITware Latam / Kaseya
- Versiones falsas de Google y archivos PDF atacan gobiernos y empresas en LatinoaméricaInfobae
- Casos de ciberataques aumentan 38% en México, empresas registran escalada en diversos sectoresInfobae
- Fábricas de fraude: cuatro presiones críticas sobre bancos y fintechsIupana
- Denunciar una estafa en Colombia: banco, pruebas y FiscalíaColombia en Regla
- Entró en vigencia decreto para proteger a niños y adolescentes en entornos digitalesSeguridad (canal de noticias)
- Fraude fintech 2026: 4 presiones críticas que debes conocerEcosistemaStartup
- El 'spoofing', la modalidad de estafa digital que tiene en la cárcel al hijo de un reconocido exfutbolistaSemana
- ¡No caiga! Ojo con engaños por llamadas o con inteligencia artificial; capturaron a un futbolistaCanal de televisión colombiano (YouTube)
- Fraude con tarjetas de créditoMinisterio de Justicia y del Derecho de Colombia
- Fraude financiero: Crecen las estafas con identidades generadas con IATabulado
- El fraude con IA dominará los ciberataques en 24 meses y multiplicará las pérdidas: CEO de IncodeEl Cronista
- Congreso estudia proyecto para restringir redes sociales a menores de 16 años en Colombia: habría multas de hasta $8.500 millonesCol Mundo Radio
- Colombia busca fortalecer protección de niños en entornos digitalesPrensa Latina
- “Tenemos en riesgo la mayor parte de nuestros niños por ciberacoso”: MinTicCaracol Radio
- Errores de configuración que alimentan el ransomware: lecciones de Colombia y MéxicoCarmona.mx
- Expertos alertan sobre una creciente táctica de ransomware: hackers imprimen demandas de rescate durante ataques en América LatinaTrendTIC
- Prohibición de redes sociales para menores: Nuevo decreto y proyecto de leySin Carreta
- Radican proyecto para prohibir uso de redes sociales a menores de 16 añosEL TIEMPO
- Tecno: en Colombia, ley para prevenir violencias y delitos digitales contra niñosLa Nación (agencia)
- Gobierno nacional expidió decreto para proteger a menores de edad con respecto al uso de internetInfobae Colombia
- ¿Protege el nuevo decreto a los menores en internet? Expertos encuentran vacíosUniversidad El Bosque
- Gobierno firma decreto con medidas para proteger a niños y adolescentes en entornos digitalesYouTube / Canal de noticias colombiano
- Gobierno nacional expide decreto para fortalecer entornos digitales sanos y seguros de niñas, niños y adolescentesAlcaldía de Santiago de Cali / Gobierno nacional
- Extorsión BitLocker: el esquema XEntry con impresorasHelpRansomware
- BitLocker Extortion: The XEntry Printer Ransom SchemeHelpRansomware
- Gobierno niega irregularidades en contrato de ciberseguridad y aclara fecha de adjudicaciónInfobae Colombia
- Ecopetrol descarta afectación a sus operaciones tras ciberataqueEl Espectador
- Bancos suspenderán cobro de cuotas y eliminarán reporte en DataCrédito: ley comienza a regir tras aprobación de Corte ConstitucionalRed+ Noticias
- Colombia refuerza la protección digital infantil: claves del Decreto 0769 de 2026 y sus nuevas obligacionesPulzo
- Brazil Is Quietly Building the Research Docket for Its Next Wave of Martech EnforcementEmailExpert
- ¿Lo suplantaron y sacaron un crédito a su nombre? Esta es la nueva ley que lo protegeEl Colombiano
- Aclaran futuro del Banco de Talentos Patria Milagro: plataforma de Abelardo De La Espriella despeja duda de quienes buscan trabajoRed+ Noticias
- 102 Alerta Red de Retransmisión Operativa CHARLIEColCERT
- Nueva campaña de GodDamn ransomware combina captura de credenciales, acceso remoto y cifrado de sistemasCSIRT Asobancaria
- Suplantación de identidad: empresas deberán frenar cobros y corregir reportes mientras investigan el fraudeInfobae Colombia
- Ciberataque a conductores en Bogotá: cómo evitar exponer tus datos personales y los del vehículoInfobae
- Filtran base de datos de la Secretaría de Movilidad de Bogotá: esto se sabe sobre el incidenteEl Tiempo
- Secretaría de Movilidad de Bogotá confirmó filtración de datos tras incidente de ciberseguridadNoticias RCN
- Colombia registró 10,9 billones de intentos de ciberataques y concentra el 8% de los incidentes de América LatinaSemana
- IA y fraude financiero: por qué los datos contextuales son la nueva línea de defensaACIS
- Publicación de A3Sec - LinkedInA3Sec
- Qué hacer si no estoy conforme con un servicio financiero o existen diferencias con un banco, aseguradora o compañía de financiamientoMinisterio de Justicia y del Derecho de Colombia
- Gobierno decreta medidas de protección en entornos digitales de la niñez y juventudZona Cero
- Cambia la forma de ver redes sociales para niños en Colombia: Gobierno tomó radical decisiónPulzo
- Newsletter de Economía del Dato, Privacidad y Ciberseguridad - Julio de 2026Garrigues
- Procuraduría advierte posibles irregularidades en proceso de ciberseguridad cercano a 300000 millonesProcuraduría General de la Nación
- Noticia Diaria Latam (Colombia) - Colombia Compra Eficiente suspende temporalmente proceso mediante el cual las entidades del Estado contratarían servicios de ciberseguridadInformación de Mercados
- Comunicado de Prensa No. 034-2026DIAN
- Colombia's Ecopetrol says cyberattack stole data tied to about 3,300 accountsReuters
- Ciberataque a Ecopetrol: criminales accedieron y extrajeron información de 3.300 cuentas de la empresaInfobae
- Ciberataque a Ecopetrol: filtran información de 15 empresas del grupoEl Universal
- Un ciberataque a Ecopetrol expone información del negocio y de sus empleadosEl País
- Cyberhebdo du 24 juillet 2026 : le plus gros pétrolier de Colombie dans la tourmenteLeMagIT
- Ciberataque contra Ecopetrol: la empresa coordina con la Fiscalía y el MinTIC el retiro de archivos filtradosInfobae
- La Fiscalía investiga el ciberataque contra Ecopetrol: se habría infiltrado información sensibleInfobae
- “La información ya se encuentra en la dark web”: experto sobre ciberataque a EcopetrolCaracol Radio
- Empresas en Colombia enfrentan más de 3.000 ciberataques semanales y pérdidas millonariasInfobae
- El país recibió más de 10 billones de ciberataques en el último añoLa República
- Ep.706 - RadioCSIRT Flash info cybersécurité du dimanche 26 juillet 2026RadioCSIRT / YouTube
- Colombia warns on Gentlemen ransomware as 30 victims land in a dayIntelFusions
- ¿Quién es The Gentlemen, la ‘mafia digital’ que hackeó a Ecopetrol y le robó miles de datos?El Colombiano
- ¿Ciberataque a Ecopetrol? Publican información de 15 empresas del grupoEl Colombiano
- dian.gov.co Data Breach Exposes 731k AccountsLunarCyber
- A bizarre new malware campaign hacks your printer and forces it to print out ransomware demandsTechRadar
- Weekly Ransomware Intelligence Report, July 12, 2026Scrutex
- Gentlemen Ransomware Reference | Malware ProtectionManageEngine
- thegentlemenRansomware.live
- Cyberattack at Ecopetrol, Colombia Energy ProviderICSStrive
- Ecopetrol Listed by thegentlemen Ransomware GroupGalaxy Warden
- Ecopetrol Confirms Ransomware Intrusion With Data TheftMallory.ai
- El país recibió más de 10 billones de ciberataques en el último añoDPLNews
- Por qué se disparan los ciberataques: Colombia, entre los países más atacados de la regiónBluRadio
- Así opera The Gentlemen, el grupo de ransomware que atacó y robó datos a EcopetrolLa República
- Ciberataque a Ecopetrol: criminales accedieron y extrajeron información de 3.300 cuentas de la empresaInfobae
- Ciberataque a Ecopetrol: filtran información de 15 empresas del grupoEl Universal
- Así se orquestó el ciberataque a Ecopetrol: Fiscalía investigaCaracol Radio
- Ciberataque a Ecopetrol: activó protocolos para retirar de internet información robada; riesgos para tercerosSemana
- Gobierno congela licitación de ciberseguridad por denuncia de pacto entre empresasInfobae
- El Grupo de Respuesta a Emergencias Cibernéticas de Colombia ColCERT asumió apoyo a emergencia cibernética en EcopetrolHalcones y Palomas
- Ciberataque en Ecopetrol ColombiaPulzo
- Colombia refuerza la protección digital infantil: claves del Decreto 0769 de 2026 y sus nuevas obligacionesPulzo
- SIC dejó en firme el cierre de Worldcoin y Tools for Humanity en ColombiaEl Colombiano
- Congresistas del Centro Democrático radicaron proyecto de ley que prohíbe el acceso y uso de redes sociales a menores de 16 añosInfobae
- Ciberataque a Ecopetrol: 15 empresas del grupo afectadas y hackers están extorsionando tras robar datos de 3.300 cuentasEl Colombiano
- Así funciona The Gentlemen, el grupo de ransomware que robó los datos de EcopetrolInfobae
- Ecopetrol Breach: 3,300 Accounts Hit, Ransomware BlockedGBlock.app
- Ransomware attemptICSStrive
- Deadlock Ransomware Strikes Hardware Asesorias Software Ltda in ColombiaDexpose.io
- 136 victims for Colombia - Ransomware.liveRansomware.live
- Colombia's Ecopetrol says cyberattack stole data tied to ...Reuters
- Thegentlemen ransomware claims EcopetrolTechWalrus
- The Gentlemen ransomware lists Colombia's Ecopetrol and a US Navy command | IntelFusionsIntelFusions
- Gobierno desmiente denuncias sobre supuestos hechos ...Colombia Compra Eficiente
