CiberLATAMbywhalemate
Intelligence reportAug 1, 202618 min read

Colombia: cybersecurity landscape, July 2026

July closed with Ecopetrol, ransomware, and new rules for minors, while pressure from fraud and the public sector remained high.

Colombia: cybersecurity landscape, July 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are completed automatically with verified dated facts from within the period. Each one states its basis and counting criteria so the figures reconcile across modules. They are the recurring month-to-month reading; the later analysis develops the cases without repeating this summary.

Indicator window: 82 dated facts in July 2026 · 5 from prior months (comparative frame, not current-month volume) · 1 without confirmed date (excluded from the indicators). Facts from prior months are used only as a comparative frame in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Monthly Verified Signal Dashboard July 2026 · Colombia Top threat: Ransomware (30 of 76 incidents). Coverage: 82 dated incidents in July 2026 · 5 from prior months… VERIFIED INCIDENTS 76 period base: all counts measured from below against this total RANSOMWARE / EXTORTION 30 8 asset encryption confirmed · 5 exfiltration no encryption (simple extortion) UNCLASSIFIED INCIDENTS 18 breaches or outages without declared threat type FRAUD / PHISHING 1 documented fraud campaigns REGULATION 18 rules, resolutions, or penalties UNIQUE CVEs 1 CVE-2024-55591
Monthly Verified Signal Dashboard — Base: 76 verified dated incidents in Colombia for the period.
MONTHLY FIXED MODULE Threat axis distribution July 2026 · Colombia Each event is counted in only one axis, so the total is exactly 76. "Unclassified incidents" is the remainder. Ransomware 30 Regulation 18 Incidents 18 Unclassified 9 Fraud 1
Threat axis distribution — Each event is assigned to one axis based on its classification; the total reconciles to the 76 events in the period.
FIXED MONTHLY MODULE Sectoral Distribution of Signals July 2026 · Colombia Base: 76 incidents in the period · total 91 because 12 incidents are classified in more than one sector. Public sector / OIV 32 Others / unspecified sector… 32 Telecom 10 Finance 7 Technology 5 Energy 3 Retail / Consumer 1 Education 1
Sectoral Distribution of Signals — Heuristic sector classification by victim. One incident may affect more than one sector, so totals may exceed the base.
MONTHLY FIXED MODULE Critical Infrastructure in Colombia July 2026 · Colombia 14 of 76 facts in the period involve critical infrastructure. One fact may appear in more than one category. Public sector / government 32 Energy / utilities 3 Telecom / connectivity 10
Critical Infrastructure in Colombia — Verified facts on public sector, utilities, and essential services

Executive monthly summary for Colombia

July 2026 left a clear picture in Colombia: the Ecopetrol case dominated public debate and shaped the month’s reading around ransomware, exfiltration, and extortion. The incident, later attributed in various reports to the group The Gentlemen, exposed data tied to about 3,300 user accounts in cloud storage environments belonging to 15 companies in the group. The company said from the outset that its controls blocked encryption, so the visible impact was limited to the extraction and later disclosure of information, rather than a sustained operational disruption.

The month also showed another clear pattern, the ransomware threat did not arrive alone, but alongside more basic yet effective initial-access tactics such as internet-exposed services, poorly secured RDP, leaked credentials, and weak configurations. In technical coverage of incidents in Colombia and the region, that exposure surface appears repeatedly, along with abuse of legitimate tools, corporate printers used to print ransom notes, and native Windows encryption through BitLocker. That helps explain why the month ended with 30 incidents linked to ransomware or extortion as the primary focus.

On the regulatory front, the month carried unusual weight. The government issued Decree 0769 of 2026, which implements Law 2489 of 2025 and sets concrete obligations for digital platforms, educational institutions, and families regarding minors. The text requires privacy by default, age verification proportionate to risk, semiannual reports to MinTIC, stronger reporting channels, and even immediate referral to the Attorney General’s Office when child sexual exploitation cases are detected. This was accompanied by the final sanction from the SIC against World Foundation and Tools for Humanity, as well as legislative initiatives on minors’ use of social media.

In financial services, the tone was different but just as intense. The narrative shifted between impersonation fraud, response measures from banks and institutions, and the growing use of contextual signals and artificial intelligence to reduce account takeover attempts. There was no single case that absorbed all of the attention, but there was a sustained environment of operational pressure and defensive adaptation. The overall read for Colombia is high risk, not because of the number of isolated incidents, but because of the combination of events with reputational impact, data exposure, extortion campaigns, and a regulatory pace that forces rapid control changes.

July 2026, ColombiaEcopetrolJuly 17exfiltrationColCERT July 20IR supportDecree 0769July 22minorsRansomware July22 a 26campaignsEcopetrol28 to 31data leakProsecutor’sOffice 31Julyinvestigates
Colombia, July 2026: month in review — Timeline of the period’s most visible events, focused on Ecopetrol, regulation, and institutional response.

Colombia Monthly National Overview

Ransomware dominated Colombia in July, accounting for 30 of the 76 verified incidents in the period. Those incidents did not all describe the same kind of impact, and that distinction matters. There were 8 cases with confirmed asset encryption, 5 involving exfiltration without encryption, and 17 where the material does not clearly show whether encryption occurred or whether the activity was only extortion. That spread points to an ecosystem where extortion has become more common than pure system locking, and where data publication, or the threat of it, carries as much weight as technical disruption.

The Ecopetrol case is the clearest example of that shift. The company confirmed unauthorized access, data download, and a blocked ransomware attempt. Reports later emerged about information being published, attribution to The Gentlemen, and coordination with Fiscalía and MinTIC to remove leaked files. According to the company itself, the incident did not lead to a critical operational outage or immediate financial damage, but it did leave a highly visible mark on reputational exposure and data governance.

The other side of the month was regulatory. Colombia moved forward with a decree that directly affects the architecture of digital services for minors, changing the compliance agenda for platforms, schools, families and public entities. At the same time, the SIC kept a tough line on sensitive data processing with the permanent shutdown of Worldcoin in the country. The result is an environment where regulators are more active, while the implementation burden falls on organizations already under pressure from fraud, intrusion and extortion.

The qualitative risk reading for Colombia in July is high. Not because the country suffered a single systemic collapse, but because of the accumulation of incidents with real impact across multiple layers, personal data, operational continuity, the reputation of strategic companies, regulatory compliance and financial fraud. In a regional context where Colombia remains among the most attacked countries, the month reinforced an uncomfortable lesson for security teams, defense is no longer just about stopping intrusions, but about containing the value of what is taken, what is published, and what ends up in regulatory or legal dispute.

The Latin American context helps explain that pressure. In the reports cited during the month, Brazil and Mexico remained ahead of Colombia in regional volume, but the country stayed among the most closely watched by attackers and intelligence providers. That was visible in the attention drawn by Ecopetrol, the recurring mention of active ransomware groups in the region, and the scrutiny given to exposed infrastructure, both corporate and state-owned.

Colombia period indicators

Indicator Value Base / window
Verified events in the period 76 Base for all indicators. Only events dated within July 2026
Indicator time window 82 events dated in July 2026, 5 from previous months, 1 with no confirmed date Archive frame, not monthly volume
Unclassified incidents (breaches or outages) 18 Within July 2026
Cases with ransomware or extortion as the primary focus 30 Within July 2026
Confirmed asset encryption 8 Ransomware breakdown by impact type
Exfiltration without encryption (simple extortion) 5 Ransomware breakdown by impact type
Unclassifiable with the available material 17 Ransomware breakdown by impact type
Documented fraud or phishing cases 1 Within July 2026
Documented regulatory moves 18 Within July 2026
Critical CVEs mentioned 1 Within July 2026
Sectors with at least one documented event 7 Within July 2026
Dominant threat of the month Ransomware (30 of 76 events) Within July 2026
Events with direct source confirmation 66% Base: verified events in the period
Aggregated telemetry figures excluded from the volume 6 Aggregated attempts or blocks, not incidents with confirmed impact

Relevant incidents in Colombia

Ecopetrol, exfiltration and extortion attributed to The Gentlemen

The month’s most visible case was Ecopetrol. On July 17, the company reported unauthorized access to digital resources that affected cloud storage environments belonging to about 15 group companies and enabled the download of data tied to approximately 3,300 user accounts. The company itself said the ransomware attempt was blocked by internal controls and that it had not identified, at least at that point, any critical disruptions or direct financial impact.

Subsequent coverage shifted the case from exfiltration to extortion. Different sources reported financial demands, threats to publish the material, and the appearance of leaked files on sites linked to The Gentlemen. Ecopetrol activated online takedown protocols and coordinated with the Attorney General’s Office and MinTIC. By the end of the month, the Attorney General’s Office had already opened an investigation. The key operational issue was not encryption, which did not succeed, but the full cycle of extraction, extortion pressure, and public exposure.

Bogotá Mobility Secretariat, data leak and phishing risk

The Bogotá Mobility Secretariat incident remained relevant in July because of its downstream effects. Media coverage describes a leak from a historical database managed by an external vendor, with evidence preservation, traceability review, and technical tracking of the intrusion vector. The agency said it did not have a final consolidated count of affected data and rejected claims about manipulation of traffic fines or speed camera enforcement.

The most practical consequence highlighted in the coverage is the increased risk of phishing and scams aimed at drivers, using exfiltrated data. This was not just an abstract leak, but a leak with operational value for personalized campaigns involving licenses, traffic fines, vehicles, and payments. That kind of data reuse is what turns an administrative breach into a platform for later fraud.

DIAN, scheduling incident and criminal complaint

DIAN said that in its 2026 incident there was unauthorized access to the virtual appointment scheduling system operated by an external vendor, with exposure of users’ personal data, but no compromise of tax or customs information, passwords, or credentials. The agency disabled the affected service, activated incident management protocols, and strengthened the protection of the systems involved.

The value of this case in July was not in its scale, but in the institutional response. The agency confirmed that it filed a complaint with the Attorney General’s Office over facts that could amount to extortion and other criminal conduct, and that it would also report the case to the SIC as the data protection authority. This is a useful risk signal, incidents in citizen service environments are now treated not only as technical failures, but as events with a legal and regulatory path attached.

Government and public cybersecurity procurement

There was also friction around public procurement of cybersecurity services. The Attorney General’s Office asked for explanations over alleged inconsistencies in a Colombia Compra Eficiente contract to implement cybersecurity tools in public entities. Later, the agency itself suspended the provider selection process for 30 days, responding to the Attorney General’s Office observations and thousands of comments from interested parties.

This is not a technical incident, but it is a high-value development for the month because it affects how the state buys defensive capabilities. In a period dominated by exfiltration, extortion, and fraud, a procurement suspension does not by itself change the risk, although it does affect deployment timelines and the perception of governance around cybersecurity spending.

Threats and active campaigns in Colombia

Ransomware and extortion with confirmed encryption

The clearest campaign of the month with confirmed encryption was the one attributed to XEntry Team in Kaspersky analysis and related coverage. The material describes the use of BitLocker, corporate printers to leave ransom notes, and initial access through exposed remote services. In Colombia, at least one case was reported with systems encrypted and legitimate network mechanisms used to expand the impact. The campaign did not rely on traditional encryption malware, but on abuse of native functions and weak configurations.

The other confirmed encryption case in the period was the Ecopetrol incident, although there the encryption never fully materialized because of early containment. For that reason, the case fits more cleanly under exfiltration with extortion than successful encryption. Even so, the double pressure technique, prior data theft, and threat of publication were well documented and dominated public discussion.

Ransomware and extortion with exfiltration and no encryption

Ecopetrol appears here again because the verifiable material from the month shows an attack that exfiltrated data, tried to encrypt, and was blocked. The exfiltration of about 3,300 accounts and the later leak of information from 15 companies in the group place the case on the extortion-by-data side, not on system hijacking. That distinction is essential for response teams: the priority does not end when encryption is stopped, because the second phase of the incident can remain active on forums, leak sites, and coordinated posts.

Ransomware and extortion, type undetermined

The month’s material also includes cases where the source does not specify whether there was encryption, exfiltration, or only a claim on a leak site. That was the case with several mentions of groups such as Deadlock or The Gentlemen on incident tracking and aggregation sites. These are useful intelligence signals, but by themselves they are not enough to treat them as incidents with confirmed impact. In the body of the report, they are treated as indicators of extortion pressure, not as equivalent to a proven intrusion.

Fraud and phishing

The only clearly documented case in July within this track was the increased risk of phishing against Bogotá drivers following the leak of mobility data. This was not an isolated mass phishing campaign, but a concrete offshoot of a prior incident. The pattern is classic, but effective, stolen personal and operational data, victim segmentation, and believable messages about procedures or penalties.

Financial coverage also showed strong pressure from identity fraud, although the material for the period focuses more on prevention and response than on a single case. Banks and fintechs appear forced to sharpen detection engines, rely on contextual signals, and respond to a rise in impersonation attempts and account takeovers. That does not point to one campaign, but it does point to a persistent threat class.

APT and operational relay networks

On the advanced-threat front, the strongest signal came from ColCERT with its alert on the CHARLIE/ORB3 operational relay network. The material attributes its use to APT5 and APT15, with infrastructure that works as a covert channel for tactical operations and with specific recommendations for segmentation, phishing-resistant MFA, and access controls. This is a relevant finding for telecommunications, closer to support infrastructure for espionage or persistence than to an incident with immediate mass impact.

Critical vulnerabilities with impact in Colombia

CVE Software Exploitation Source
CVE-2024-55591 Fortinet FortiGate and FortiProxy Authentication bypass exploited by the group The Gentlemen, with combined use of valid credentials, brute force against SSL VPN and RDP ColCERT, cited in IntelFusions and Scrutex

The only critical CVE mentioned in the material analyzed was CVE-2024-55591. The fact that the monthly indicator shows 1 does not mean there are no other critical vulnerabilities in the region, only that in the July material this was the single concrete, verifiable reference.

Regulation and compliance in Colombia

Decree 0769 of 2026, protections for minors and technical obligations

The decree signed in July by the national government is the month’s most significant regulatory text, by both the number of mentions and its regulatory density. It implements Law 2489 of 2025 and sets out default privacy obligations, age verification proportional to risk, semiannual reports to MinTIC, parental controls, complaint channels, and interagency coordination. It also explicitly bans measures that amount to prior censorship, mass monitoring of private communications, or weakening of end-to-end encryption.

The compliance implications are substantial. The decree does not stop at broad principles, it pushes platforms, schools, and families to adopt specific controls. It also requires reporting every six months and the integration of mechanisms to escalate serious cases to Fiscalía and ICBF. In practice, that means documenting processes, updating Terms and Conditions, reviewing age-gating flows, and adjusting how minors’ data is handled.

SIC, Worldcoin and sensitive data processing

The SIC made final the permanent shutdown of World Foundation and Tools for Humanity’s sensitive data processing operation in Colombia, and ordered the deletion of all data collected in the country, including iris codes. The decision reinforces a strict enforcement line on biometrics and sensitive data processing. For any organization working with identity verification, biometrics, or high-risk profiles, the message is clear, using sensitive data without sufficient legal basis, proportionality, and controls can end in a complete shutdown.

Identity theft and the shifting burden of proof

Law 2573 of 2026 and related coverage also mark a change in approach. When a person claims identity theft in loans or other obligations, the entity must suspend collections, provide supporting records, and show what mechanisms it used to verify identity. In practice, this redistributes the burden of proof and forces banks, merchants, and operators to better document onboarding and authentication decisions.

Public procurement of cybersecurity

A review of Colombia Compra Eficiente’s procurement process exposed the political and technical sensitivity of cybersecurity contracting for state entities. The Procuraduría stepped in, the agency suspended the process, and questions emerged about the sequence, the tender documents, and the governance of the framework agreement. Beyond the contract dispute, the episode shows that buying digital defense is now subject to public scrutiny on par with a major public works project or a strategic purchase.

Most affected sectors in Colombia

The business sector was under the heaviest pressure, both by volume and by case value. Ecopetrol drew the most attention, but it was not an isolated incident. Data exposure, extortion, and leaks also surfaced in technology infrastructure, service providers, and highly digitized companies. The pattern is consistent: where there is cloud storage, remote services, or outside vendors with broad privileges, the attack surface grows.

The public sector also had a busy month. DIAN, Bogotá’s Mobility Secretariat, and Colombia Compra Eficiente each raised different concerns, but all pointed to the same tension between citizen service, data exposure, and response capacity. In some cases there was exfiltration, in others questions about procurement, and in others a clear need for coordination with criminal or data protection authorities.

In financial services, the pressure was more diffuse but still very present. The focus was on fraud, impersonation, mule accounts, and more sophisticated access techniques supported by AI. That scenario is forcing institutions to improve contextual detection, review onboarding processes, and maintain a fast response capability when faced with false identity or impersonation claims.

There was also a regulatory component affecting the telecom sector and digital platforms, mainly because of obligations under Decreto 0769. Although this was not one of the sectors most exposed by incidents in July, it is among those that will need to invest the most in compliance during the second half of the year.

The comparison with the previous month shows a clear shift in the nature of the signal. In the prior report, incidents dominated, with 45 such events. In July, the focus shifted to ransomware, with 30 of 76 events. This is not just a change in label, but in threat dynamics. Attention moved from broader intrusion or leak events to campaigns centered on extortion pressure and data publication.

The number of documented fraud or phishing cases also fell, from 18 the previous month to 1 in July. That does not mean fraud declined in the country, only that the July material documented it less as concrete cases and more as structural context. At the same time, regulatory moves decreased from 26 to 18, but the quality of those changes was different: July produced rules and decisions with greater operational weight, such as Decree 0769 and the SIC decision on Worldcoin.

The drop in critical CVEs mentioned, from 9 to 1, should not be read as a general technical reprieve either. It simply means that in the July material analyzed, only one explicit and verifiable critical vulnerability appeared. That calls for caution, since absence of mention does not mean absence of exploitation in the country or across the region.

Another strong signal is the consolidation of extortion campaigns that combine data theft, public pressure and leak channels. Ecopetrol is the emblematic case, but it is not the only context pointing in that direction. The material on The Gentlemen, XEntry Team and Deadlock shows that attackers continue to find returns in double-extortion models, sometimes without needing to deploy traditional encryption malware.

Ransomware in Colombia, July 2026Base: 30 incidents with ransomware or extortion as the primary focusConfirmed encryptionExfiltration without encryptionCannot determine classification851708162430
Colombia, July 2026: ransomware classification — Distribution of the ransomware theme based on verified material from the month.

Security guidance for teams in Colombia

Organizations operating in Colombia should start from a simple assumption: ransomware containment is no longer enough if exfiltration and the later public exposure of data are not also controlled. That means tightening cloud storage monitoring, reviewing third-party permissions, auditing administrative access, and preparing rapid procedures to remove leaked information. In incidents like Ecopetrol, stolen data retains value even when encryption is not completed.

Remote access surfaces also need to be hardened. This month’s evidence again points to RDP, exposed services, RMM tools, and weak credentials as core parts of the attack chain. The priority is to reduce direct internet exposure, require phishing-resistant MFA, and review which management services remain accessible without real segmentation.

In environments with BitLocker or native encryption mechanisms, recovery keys should be centralized, with alerts when unusual activations appear. The campaign attributed to XEntry Team offers a very specific lesson, if an attacker is living inside the network, hardening administration is just as important as antimalware.

For fraud teams, the month reinforces the value of contextual signals. Device, geolocation, time of use, transaction history, and session behavior provide more value than standalone authentication once an attacker already has credentials or is using deepfakes and impersonation. In the financial sector, defense depends on correlating context, not just adding friction for the user.

Legal and compliance teams also need speed. Decree 0769, the sanction against Worldcoin, and Law 2573 point in the same direction, tighter scrutiny of data handling, minors, biometrics, and impersonation. This is not only a privacy issue, it is an operational design issue. Teams should review retention policies, consent flows, reporting procedures, and response times for incidents involving personal data.

Finally, public-sector and private-sector organizations with high external exposure should rehearse data publication scenarios. Preparation is not limited to restoring systems. They need to know how to verify leaks, coordinate with authorities, respond to the press, protect third parties, and reduce the potential for fraud reuse of exfiltrated information.

Material limitations

This report covers only facts dated within July 2026 and uses the supplied file as its sole reference base. The comparative framework block contains facts from earlier months and was used only to assess changes, never as part of the period total. The undated item was excluded from the indicators and could only be used as qualitative context if mentioned.

A zero indicator, especially for critical CVEs, means it did not appear in the material analyzed for the month, not that there were no critical vulnerabilities exploited in Colombia or in the region. The same applies to fraud, uncategorized incidents, or sectors: the value reflects what the file documented, not the complete absence of activity.

The declared time window for the indicators includes 82 facts dated in July 2026, 5 facts from earlier months used as a comparative framework, and 1 fact without a confirmed date excluded from the counts. The indicators reproduced in this report correspond only to the verified facts from the period, using the base already calculated in the material provided.

Sponsored content, advertorials, social media posts, and LinkedIn references were excluded as trend evidence. Aggregated telemetry was also avoided as if it were confirmed-impact incidents. Counts of attempts, blocks, and scans are considered only when the material explicitly presents them as activity volume, not as verified intrusion.

Sources