CiberLATAMbywhalemate
Intelligence reportAug 11, 202626 min read

Logistics, Ports, Airports, Transport, Jul 2026

July saw leaks, operational stoppages from failures, and ransomware, led by Colombia and Mexico, alongside a rise in active vulnerabilities.

Logistics, Ports, Airports, Transport, Jul 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are completed automatically with verified dated facts within the period. Each one states its basis and counting criterion so the figures reconcile across modules. They are the recurring monthly readout; the analysis that follows develops the cases without repeating this summary.

Indicator window: 25 dated facts in July 2026 · 1 from previous months (comparative frame, not monthly volume) · 4 undated (excluded from the indicators). Facts from previous months are used only as a comparative frame in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Monthly Verified Signal Dashboard July 2026 · Latin America Main threat: Vulnerabilities (8 of 23 incidents). Coverage: 25 dated incidents in July 2026 · 1 of months an… VERIFIED INCIDENTS 23 period baseline: all counts measured from below based on this total RANSOMWARE / EXTORTION 5 1 asset encryption confirmed · 4 not classified determinable from the material UNCLASSIFIED INCIDENTS 3 breaches or outages without declared threat type FRAUD / PHISHING 1 documented fraud campaigns documented REGULATION 0 rules, resolutions, or sanctions UNIQUE CVEs 4 CVE-2026-15409 / CVE-2026-15410
Monthly Verified Signal Dashboard — Base: 23 verified dated incidents for Latin America.
MONTHLY FIXED MODULE Threat axis distribution July 2026 · Latin America Each event is counted on only one axis, so the total is exactly 23. "Unclassified incidents" is the remainder. Vulnerabilities 8 Unclassified 6 Ransomware 5 Incidents 3 Fraud 1
Threat axis distribution — Each event is assigned to a single axis based on its classification; the total reconciles to the 23 events in the period.
MONTHLY FIXED MODULE Sector breakdown of signals July 2026 · Latin America Base: 23 incidents in the period · total 27 because 4 incidents are classified in more than one sector. Technology 9 Public sector / OIV 8 Other / unidentified sector… 8 Telecom 2
Sector breakdown of signals — Heuristic classification by victim sector. One incident may affect more than one sector, so the total may exceed the base.
MONTHLY FIXED MODULE Geographic Distribution of Signals July 2026 · Latin America Each event is assigned to a single country or to regional coverage, so the total is exactly 23 of 23 events… Regional 17 Colombia 3 Mexico 3
Geographic Distribution of Signals — Verified period events grouped by country or regional coverage; each event is counted once.

Executive monthly summary

July closed with a mixed signal for logistics, ports, airports, and transportation in Latin America. The month was shaped by three distinct types of operational pressure: data leaks, critical service outages, and ransomware campaigns that were more visible and aggressive in their tactics. Across the material, the dominant threat was not a single malware family, but the sustained exposure of vulnerabilities and technical hygiene failures, with 8 of 23 events in the period tied to that front.

The most sensitive case in sector impact was Invima in Colombia. Analdex warned that a failure in its systems had lasted more than 24 hours and was blocking approvals, inspections, authorizations, and health certifications, with a direct effect on imports and exports at the country’s ports. That episode was not presented as a data breach, but as an operational disruption with immediate consequences for foreign trade. In an industry where document timing conditions the physical movement of cargo, this kind of degradation translates into high-cost logistics friction.

Also in Colombia, there was a leak with a third-party chain component. Bogotá’s Mobility Secretariat confirmed that it suffered a data exposure linked to a historical database managed by an external technology provider. The material does not include full technical attribution or detail on the affected volume, but it does point clearly to the risk of outsourcing and to the persistence of legacy databases that tend to accumulate data with high operational and regulatory value. Ecopetrol also confirmed that external actors published information illegally copied from 15 companies in the group. The source does not specify whether encryption occurred, so the incident should be read as data exposure with a possible extortion component, not as confirmed ransomware with downtime.

The other major line in the month was ransomware with greater tactical visibility. Specialists warned about attacks in Colombia and Mexico in which attackers printed ransom notes on corporate printers after encrypting systems with BitLocker. The technique matters more than the headline: it shows enough lateral persistence to reach network peripherals and a clear intent to humiliate and apply operational pressure. In parallel, late-month coverage from ESET and Infobae confirmed a rise in ransomware in Mexico and underscored that the region continues to produce victims across multiple sectors, although the material did not identify a specific logistics, airport, or port incident within that statistic.

The technical component of the month was dominated by actively exploited vulnerabilities. CISA added several flaws to the KEV catalog during July, including CVE-2026-48282 in Adobe ColdFusion, as well as vulnerabilities in FortiSandbox, Microsoft SharePoint, SonicWall SMA 1000, and CVE-2026-56164. Reporting from F5 Labs and quasa.io offers an important read for transportation and logistics teams, because many of those attack surfaces are the ones that typically support portals, integrations, remote access, and supplier management platforms. In other words, the month was shaped not only by malware campaigns, but also by the exploitation of known and active technical exposure.

From a risk perspective, the regional signal sits at a high level. Not because of one isolated wave of extraordinary incidents, but because of the coexistence of operational failures affecting foreign trade, data leaks in agencies tied to mobility, and a ransomware layer that now combines encryption, physical pressure, and exploitation of initial access weaknesses. The material does not support any inference that activity fell from another month, because this file is the first archived period with this indicator format for Latin America. It does show that July brought a broad attack surface and sustained impact potential across the processes that support the regional logistics chain.

Distribution by axisVerified facts for the period: 23VulnerabilitiesRansomwareDisruptionsFraud/phishing8531
Signal distribution by axis — Relative weight of the documented threat axes in July, with active exploitation of vulnerabilities leading.

Regional overview for the month

July’s regional readout points to a pattern that should no longer be treated as a split between corporate cybersecurity and logistics continuity. In several incidents during the period, the main issue was not a loud intrusion but the operational fallout: systems that stop issuing documents, historical databases that are exposed, remote access that can be abused, and peripheral equipment turned into a coercion channel. For ports, airports, transport operators, and dispatch companies, that mix is especially sensitive because it turns technical incidents into delays, holds, rescheduling, and reputational costs with customers and authorities.

The clearest geographic focus was Colombia and Mexico. Colombia saw a high-impact failure at Invima, a leak tied to Bogotá’s Secretaría de Movilidad, and Ecopetrol’s confirmation about information published by outside actors. Mexico appeared in the ransomware narrative, both through Infobae’s trend coverage and through the case described by TrendTIC, where printers were used to display ransom notes. While the material does not link all of those events directly to logistics or physical transport, it does connect them to the documentary, regulatory, and support infrastructure those industries need in order to operate without friction.

The month’s qualitative severity is high because the material combines three risk classes that tend to scale well in this vertical. First, the unavailability of validation or certification services, as in the Invima case, which affects imports and exports and can block border processes. Second, exposure of historical databases or copied information, which undermines confidentiality and can create openings for extortion or later abuse. Third, mature ransomware operations, which no longer rely only on encryption but on public pressure, printed ransom notes, and the exploitation of exposed credentials or misconfigured services.

The month’s vulnerability-heavy backdrop also has sector-specific meaning. Logistics, ports, and airports depend on third-party applications, supplier integrations, remote access portals, collaboration suites, and hybrid IT and OT attack surfaces. When CISA issues multiple KEV updates in the same window, the signal is not abstract: defense teams must assume active exposure in components that often stay outside daily focus until disruption hits. July’s material showed exactly that, with mentions of FortiSandbox, SharePoint, SonicWall, and ColdFusion.

Period indicators

Indicator Value Note
Verified facts in the period 23 Base for all indicators, only facts dated within July 2026
Time window for the indicators 25 facts dated in July 2026 · 1 from earlier months (comparative frame, not monthly volume) · 4 without confirmed date (excluded from indicators) Reproduced exactly as in the file
Unclassified incidents (breaches or outages) 3 Within the verified material for the period
Cases with ransomware or extortion as the primary focus 5 Primary category, without mixing in other impact classes
Breakdown of ransomware by impact type Asset encryption confirmed: 1 · Unable to determine classification from the material: 4 The source does not allow the classification to be closed in four cases
Documented fraud or phishing cases 1 Documented fact in the period
Documented regulatory moves 0 No specific regulatory material appeared for the month
Critical CVEs mentioned 4 Reproduced according to the indicator provided
Sectors with at least one documented fact 3 One fact may affect more than one sector
Dominant threat of the month Vulnerabilities (8 of 23 facts) Main signal for the period
Facts with direct source confirmation 96% Direct confirmation according to the file
Aggregated telemetry figures excluded from volume 2 (aggregated attempts or blocks: not incidents with confirmed impact) Do not add to incidents or use as evidence of intrusion

Relevant Incidents

Invima and the document backlog at Colombia's ports

The most operationally disruptive episode for foreign trade was the failure in Invima systems reported by Analdex. According to the source, the problem had lasted more than 24 hours and prevented the issuance of approvals, inspections, authorizations, and health certificates, directly affecting imports and exports at Colombian ports. The key issue is not only how long it lasted, but the kind of dependency it disrupted. When a sanitary or document system stops responding, the bottleneck spreads to operators, freight agents, importers, exporters, and control authorities.

In logistics verticals, an interruption like this follows a specific pattern. It does not always look like a classic security incident, because it can enter through availability rather than confidentiality. Even so, the business impact is similar, containers are held up, cargo waits for validation, shipments are rescheduled, and delay costs pile up. For the port or terminal, the risk is not just lost time, but lost predictability. If a certification does not come through, the entire chain has to be recalibrated.

The material does not attribute this failure to ransomware or a confirmed intrusion. That matters. Not every outage is an attack, and this report should not force a reading that the source does not support. Even so, the lesson for sector readers is direct: document validation services must be treated as critical continuity assets, with backups, fallback procedures, and degradation testing. The impact at ports shows that the line between administrative systems and physical operations has already disappeared.

Ecopetrol and the publication of information from 15 group companies

Ecopetrol confirmed that external actors published information illegally copied from 15 companies in the Ecopetrol Group, and also said the incident had been reported on July 17, 2026. The wording matters because the source does not say the data was encrypted or describe any direct operational disruption. The case is best understood as a data exposure followed by publication by third parties, possibly linked to extortion pressure, but the material does not let us define the full mechanism.

For logistics and transportation, the case is useful by analogy. Large corporate groups with multiple subsidiaries and operating units often store information across several surfaces, from contracts to personnel data, logistics records, and supplier information. A leak affecting a holding company or large group can impact more than one legal entity and create cross-exposure. It also raises questions about the life cycle of the copied information, what kind of data was taken, where it was stored, how long it remained accessible, and what controls were in place for segmentation and retention.

Ecopetrol's public confirmation pushed the case beyond rumor and turned it into a regional reference point, even if it is not a transportation incident in the strict sense. Its value for this report lies in the structure of the harm. When a large organization manages data for multiple group companies, a single breach can trigger legal obligations, contractual reviews, and questions about access segregation. In an interconnected logistics ecosystem, that pattern is especially sensitive because suppliers, operators, and customers often share common platforms and repositories.

Bogotá's Mobility Secretariat and the leak linked to a vendor

Bogotá's Mobility Secretariat said it was the victim of a data leak tied to a historical database managed by an external technology provider. The source does not detail a technical vector, but it does point to an important risk model, the incident is not contained only within the final agency, but also in the relationship with third parties. That setup is common in urban transport, mobility, and regulated services, where historical databases and query systems are often hosted or managed by specialized vendors.

The critical issue is the type of information that tends to accumulate in this class of repositories. Historical mobility databases can store personal data, vehicle records, procedures, fines, administrative movements, and user traceability. Although the note does not list specific fields, the mere existence of a leak in that context is enough to raise confidentiality and data governance concerns. In a transportation environment, public trust and service continuity also depend on the agency and its contractors maintaining a clear chain of custody.

From an operational perspective, the case highlights three recurring risks. First, excessive dependence on vendors with uneven controls. Second, historical databases that live on long after their operational need has passed. Third, the client's limited visibility into exactly what a third party is exposing. The incident does not automatically translate into disruption, but it does create an obligation to review contracts, access matrices, change logs, and joint response procedures. In urban transport, where data traceability matters as much as vehicle traceability, that point cannot be left off the agenda.

Ransomware with ransom notes printed in Colombia and Mexico

Specialists warned about a ransomware tactic seen in organizations in Colombia and Mexico in which attackers printed ransom notes on corporate printers after encrypting systems with BitLocker. The source also said that, in one of the incidents investigated in Mexico, initial access had been obtained through a misconfigured Microsoft SQL server and credentials exposed in publicly available code. That combination is especially serious because it brings together two attack layers, weak initial access and a visible pressure phase against the victim.

Printing the ransom note is not just a strange detail. It has psychological, operational, and internal coordination impact. It carries the message outside the digital perimeter and places it on an object shared by users from different departments. In transportation or logistics organizations, where printers, dispatch stations, and operational workstations often coexist in open or semi-automated spaces, the effect can be even more disruptive. The attack chain does not just encrypt, it communicates dominance within the affected environment.

The fact that BitLocker appears as the encryption mechanism also shapes the response. Many organizations associate it with legitimate disk protection functions, not malicious payloads. When an actor uses it to consolidate control over workstations or servers, the story of "just malware" falls short. The lesson is twofold, harden external access points and carefully review exposure of SQL servers, secrets in code, and reused credentials. The July material makes clear that, in campaigns like this, the weak link is still the initial configuration, not necessarily a sophisticated exploit.

Mexico and the rise in ransomware across sectors

Infobae México reported that cyberattacks in Mexico increased 38% and that ransomware affected companies across multiple sectors. That note, by itself, does not identify a confirmed incident in the logistics, port, airport, or transportation vertical, so it should not be read as a sector case. It does, however, work as regional pressure context and as a reminder that the country appears consistently in the ransomware conversation.

The readout for the vertical is cautious but relevant. Mexico concentrates a significant share of regional industrial, logistics, and transportation operations. If the broader ecosystem is seeing more attacks and ransomware remains part of the pattern, sector teams cannot assume immunity just because they belong to a different industry. Dependence on vendors, dense integration layers, and exposure to remote services are common conditions across many organizations operating in long supply chains.

In this case, the analytical value is not in the isolated number but in the broader context. The coverage points to a cross-sector escalation that can spill over to logistics operators, terminals, brokers, last-mile companies, and fleet managers. A headline does not need to mention a port or an airline for the vertical's risk environment to be affected. What matters is that the threat pattern hitting other sectors is the same one exploiting the same technical weaknesses.

Active threats and campaigns

Confirmed encryption ransomware

The only case with confirmed asset encryption in the material analyzed is the campaign described by TrendTIC, where attackers encrypted systems with BitLocker and then printed ransom notes. The coverage does not assign the incident to a company in the logistics, port, airport, or transport vertical, but it does confirm an operational and aggressive ransomware method. For the sector report, the value lies in the technique, not in a specific victim.

This method combines persistence, use of legitimate system tools, and physical pressure. BitLocker, in the attacker’s hands, suggests enough control over the environment to turn encryption into a real lockout of workstations or servers. Printing the ransom note adds a communication channel that is impossible to ignore. In organizations with shifts, dispatch centers, or control rooms, the visibility of the note can speed up internal chaos and make orderly containment harder.

Ransomware or extortion without a firm classification

The material also shows four cases in which the source does not allow a determination of whether there was encryption, only exfiltration, or a simple claim on a leak site. Ecopetrol, for example, confirmed the publication of information illegally copied, but did not specify whether there was encryption. In these scenarios, taxonomic caution is mandatory. A leak followed by publication should not be turned into full ransomware unless there is evidence of an impact on availability.

For the vertical, this distinction matters because it changes the response. A case of exfiltration without encryption pushes forensic, legal, and reputational crisis management. A case with confirmed encryption also requires service recovery, restoration, backup review, and spread analysis. A mere mention on a leak site requires validating whether the actor has real access, whether the publication is instrumental, or whether it is pressure without verified material compromise. The month left several examples in which the source does not close that gap.

Fraud and phishing

The period’s material documents only one fraud or phishing case within the set of indicators, but it does not provide enough detail to turn it into a robust sector campaign. Without additional elements, the most useful reading is operational, the vertical remains exposed to scams that can target administrative staff, dispatch operators, or support teams, especially when access to third-party or supplier systems is spread out.

The absence of more cases should not be read as absence of risk. In logistics and transport environments, phishing often serves as a stepping stone to other forms of intrusion, especially when combined with exposed credentials, remote access systems, and password reuse. July’s material does not expand that front with many examples, but it does leave a clear warning about the fragility of initial access in more serious campaigns.

APT and targeted intrusion

The material did not show a clearly attributable APT or hacktivist campaign tied to the logistics, port, airport, or transport axis. There are, however, events that can serve as context for monitoring, such as the publication of information from business groups and the use of exposed credentials or weak initial-access configurations. At this point, the month does not show a persistent actor specifically aimed at the vertical, but rather a continuation of opportunistic tactics with possible impact on its processes.

Critical vulnerabilities

CVE Software Exploitation Source
CVE-2026-48282 Adobe ColdFusion Under active exploitation, added to KEV on July 7, 2026 Elite Center Blog
CVE-2026-15409 SonicWall SMA 1000 Actively exploited by the Inc group, with remote code execution and root privileges F5 Labs
CVE-2026-15410 SonicWall SMA 1000 Actively exploited by the Inc group, with remote code execution and root privileges F5 Labs
CVE-2026-56164 Not specified in the provided material Added to KEV on July 14, 2026, active exploitation quasa.io

The month was dominated by active exploitation of vulnerabilities. CISA appeared repeatedly across several reports, with KEV updates in the middle and at the end of the month. For logistics teams, ports, airports, and transportation operators, the issue is not only having patches waiting, but identifying which parts of the environment connect with users, suppliers, and border operations. An integration portal, a remote console, or a supplier access gateway can be more critical than an isolated internal server.

The ColdFusion reference stands out because of its frequent use in corporate and legacy applications. SonicWall SMA 1000, meanwhile, points to an even more sensitive area, remote access. If supplier or administrator access to a critical network depends on this kind of device, exploitation stops being an abstract issue. The July material suggests attackers are still focusing on exactly those surfaces that enable remote work, administration, and operational continuity.

The buildup of KEV updates should also be read as a pattern, not a loose list. When several vulnerabilities are added within a few days, the exposure window becomes short and internal prioritization has to be more aggressive. In industries that operate 24/7, patch debt is not always resolved in a single maintenance cycle. Segmentation, compensating controls, and isolation of services that cannot be taken down immediately are needed.

Regulation and compliance

No regulatory moves were documented in the material reviewed for July. That does not mean the policy agenda disappeared from this vertical, only that this month’s file did not include a specific regulatory development to report as an indicator. In practice, the Ecopetrol, Bogotá, and Invima incidents are pushing reviews of contracts, third-party liabilities, incident notification, and data retention criteria, but those implications do not appear as a formal regulatory change within the corpus.

The lack of regulatory change also has a tactical reading. When pressure comes from operational incidents and data exposure, many organizations respond first from the standpoint of continuity and only later from compliance. For transportation and logistics, that can be a mistake, because documentary compliance and operational compliance usually go hand in hand. If a certification system goes down, operations are delayed, and traceability, auditing, and obligations to authorities or customers are also put at risk.

Countries and most affected subsegments

Colombia

Colombia was the most visible country in the month within the vertical’s material. Three distinct signals appeared, each in a different layer of risk. The Invima failure directly affected ports and foreign trade. Bogotá’s Mobility Secretariat confirmed a data leak tied to a third-party provider. Ecopetrol acknowledged the publication of information illegally copied from 15 companies in the group. The common denominator is not a single attack vector, but the exposure of critical systems, legacy databases, and third-party chains.

For readers in the sector, Colombia illustrates a common condition in the region: logistics operations depend on regulatory platforms and data systems that are not strictly "at the terminal," but do determine whether cargo moves or gets held up. The sensitivity lies both in the interface with the state and in the reliance on vendors to host or manage historical databases. That combination creates high-friction risk, even when each incident has a different technical nature.

Mexico

Mexico appears this month through the ransomware narrative and broader coverage of cyberattack escalation. TrendTIC placed there one of the cases where ransom notes were printed and a misconfigured SQL database with exposed credentials was exploited. Infobae México, meanwhile, reported a 38% increase in cyberattacks and said ransomware affected companies across different sectors. While the material does not identify a specific logistics or transportation incident in Mexico, it does confirm that the threat environment is active and that the country remains one of the region’s most exposed hubs.

For transportation and logistics, that reading is especially sensitive because of the country’s weight in manufacturing, cross-border trade, and distribution networks. When the broader ecosystem is under pressure from ransomware and attacks that exploit weak initial access, vertical operators cannot assume they are off the radar. Exposure to remote services, vendors, and legacy applications makes Mexico a priority monitoring focus.

Brazil, Argentina, and other countries in the regional context

Late-month material placed Brazil and Mexico as leaders in ransomware incidence in coverage citing ESET. Those figures do not correspond to a vertical-specific incident, but they help frame regional pressure. References also appear to Argentina and other countries in the distribution of victims reported by the cited company. The correct reading is that the regional map remains broad and that ransomware is not confined to a single country or a single industry.

As for subsegments, the material touches at least three: ports, urban mobility, and energy/group companies. The port case is the one most directly tied to the report’s focus because of the effect of Invima. Urban mobility appears through Bogotá. Ecopetrol’s corporate group adds the dimension of enterprise and third-party exposure. The absence of a concrete airport incident does not reduce the month’s relevance, it only shows that the visible signal came through other arteries of the logistics chain.

There is no comparable baseline because this is the first archived period with this indicator format for Latin America. For that reason, it would be wrong to invent a month-over-month trend. What can be identified are signals that deserve follow-up in the next reports.

The first is the persistence of unclassified disruptions in critical services. The Invima case showed that a failure can stop essential foreign trade documents without the source determining whether there was a cyberattack. That operational ambiguity is, by itself, a problem. For teams in the sector, the next step is not to wait for a perfect forensic confirmation, but to make sure manual or alternate processes exist before a shutdown.

The second signal is the consolidation of ransomware with visible pressure. Printed ransom notes, the use of BitLocker and the exploitation of misconfigured SQL point to a campaign intended to maximize psychological and operational impact. If these techniques are repeated across organizations in the sector, the response should include not only backup and restoration, but also the ability to physically isolate printers, review print queues and segment administrative access.

The third signal is critical dependence on third parties. Bogotá made clear that a historical database in a vendor's hands can end up exposed. In logistics and transportation, where much of the operation rests on integrators, dispatch software, payment platforms and tracking systems, the digital supply chain is just as sensitive as the physical one. The next major incident may not come through the main system, but through the partner with the weakest security maturity.

The fourth signal is the centrality of actively exploited vulnerabilities. The repeated references to KEV and to flaws under exploitation confirm that the time between publication and abuse remains short. In a sector that cannot stop operations every day, this requires prioritizing inventory, external exposure and remote services. A generic patching policy is not enough if it is not clear which asset is connected to which critical process.

Security team guidance

July’s recommendations should start with operational continuity, not prevention alone.

First, review the document workflows that support port, healthcare and mobility operations. If a validation or certification fails, the business stops even if the traditional perimeter stays up. That means mapping manual fallback processes, contingency owners and restart criteria for approvals, inspections and authorizations.

Second, harden relationships with vendors that manage legacy databases or lookup platforms. The Bogotá breach shows that a third party is not a contract detail, it is part of the attack surface. Contracts should include monitoring, logging, segregation, early notification and periodic access testing obligations. It is also wise to limit how long information is kept once it no longer adds operational value.

Third, prioritize external exposure of remote access, SQL, admin consoles and partner portals. The case described by TrendTIC shows that poor configuration and exposed credentials are still enough to open the door. A live inventory, code secret review, MFA where possible and shutting down unnecessary services remain high-return controls.

Fourth, treat printers, print queues and peripheral devices as part of the operational perimeter. If attackers used printers to deploy ransom demands, the organization needs visibility into who prints, from where and under which rules. In dispatch offices, customer service and fleet control, this may look minor until it becomes a channel for public pressure.

Fifth, speed up remediation for actively exploited vulnerabilities. References to ColdFusion, SonicWall, SharePoint, FortiSandbox and other KEV flaws show the issue is not theoretical. Teams should maintain priority lists based on real exposure, not CVSS alone. If an asset is exposed to the internet or serves as a vendor access point, patching cannot wait for the normal monthly cycle.

Sixth, segment credentials, access and backups with ransomware and confirmed encryption in mind. When an attacker has already executed code and encrypted with BitLocker, the difference between a manageable recovery and a prolonged crisis usually comes down to prior segmentation and backup quality. Backups should be tested with restore scenarios that include document and print systems, not just core servers.

Seventh, strengthen legal and communications response for cases involving data publication without clear encryption. Ecopetrol shows that not every incident fits the same template. When the source says information was illegally copied, the crisis team must be able to handle notification, investigation, evidence preservation and public messaging without forcing a technical classification that does not yet exist.

Material limitations

This report was prepared exclusively from the material provided in the July 2026 file. No internet or external sources were used, and no information was added that does not appear in the authorized list of sources for citation. By design, that limits the ability to reconstruct some incidents down to their full technical detail, especially in cases where the source confirms the release of data or a service outage but does not specify whether there was encryption, exfiltration, or both.

The time window for the period is the one stated in the indicators. Only facts dated within July 2026 are included in the month’s volume. The only fact from earlier months is kept only as comparative context and must be read with its explicit month. The four undated facts are excluded from the indicators and are used, if at all, as qualitative context, always making clear that their date is unconfirmed.

An indicator of 0 does not mean the phenomenon does not exist in the region, only that it did not appear in the material analyzed for this month. This is especially true for critical CVEs and regulatory moves. A 0 in regulation does not mean there is no regulatory or compliance debate in the region, and a specific count of critical CVEs does not rule out other vulnerabilities exploited outside this corpus.

Aggregated telemetry elements, such as automated attempts or blocks and vendor averages, are also excluded from the volume. If they are mentioned, they should be understood as background noise and not as confirmed intrusion. In July, that boundary is important to avoid mixing scales, hack attempts, detections, or statistical aggregates are not the same as incidents with verifiable impact on logistics, ports, airports, or transport.

Sources excluded by editorial rule also define what can be stated. Social media posts for consumers, sponsored content, and commercial press releases that are not in the list of available sources for citation were not used. When a note presents a claim attributed to a company or vendor telemetry, the report keeps it as such and does not turn it into an absolute trend if there is no stronger support in the authorized material.

Sources