Mining, Metals and Natural Resources, July 2026
Ecopetrol drove LATAM this month, with data exfiltration, extortion, and regulatory response; actively exploited CVEs also added pressure.
Key findings
- Ecopetrol was the month’s dominant case, with unauthorized access, data exfiltration, a blocked ransomware attempt, and follow-on extortion pressure.
- The most serious signal was not operational disruption, but exposure of data from multiple subsidiaries and thousands of user accounts.
- Initial access attributed to a privileged third party confirms the supplier attack surface remains a critical weak point in the vertical.
- July cemented a damage taxonomy in which exfiltration and extortion weigh more than effective encryption of assets.
- Campaigns involving BitLocker, printers, and exposed remote access remain plausible tactics in the region and relevant to natural resources.
- Pressure from actively exploited CVEs reinforces the need to quickly remediate exposed technologies and business systems connected to third parties.
- The compliance component, with the SEC and Colombian authorities, is already a central part of the response to high-profile incidents.
Monthly reference modules
These modules are completed automatically with the verified dated events within the period. Each one states its basis and its counting criterion, so the figures reconcile across modules. They are the recurring monthly readout; the analysis that follows develops the cases without repeating this summary.
Indicator window: 57 dated events in July 2026 · 1 without confirmed date (excluded from the indicators). Events from earlier months are used only as context for comparison in the analysis, never as volume for this period.
Monthly Executive Summary
Ecopetrol accounted for most of the July 2026 threat signal for mining, metallurgy, and natural resources in Latin America. The case combined unauthorized access, data download, a blocked ransomware attempt, extortion, and the later spread of information attributed to outside actors. Operationally, the sequence was more complex than a conventional intrusion, because the available material points to both confidentiality harm and extortion pressure, alongside coordination with authorities and a corporate effort to contain the circulation of the stolen data.
The strongest point in the case file is the exfiltration. Reuters reported unauthorized access to digital resources at about 15 companies in the group and the download of data tied to roughly 3,300 accounts. Corporate statements later cited by Yahoo Finance and Reuters insisted that no critical disruption to operations, production capacity, or essential services had been identified. That combination suggests a serious incident from an information and compliance standpoint, but not an industrial shutdown at the time it was reported.
The public development of the case unfolded in several layers. First came attribution to an unidentified external actor and mention of a blocked ransomware attempt. Later, references appeared to extortion, removal from public access of illegally copied data, and requests for the intervention of the Fiscalía and other Colombian agencies. After that, different reports cited a group claiming responsibility for the attack and saying it held as much as one terabyte of information, with references to group subsidiaries and possible sensitive business and employee data. For this report, the verifiable element is the existence of a leak with extortion pressure; the rest remains at the level of claims attributed to sources.
Alongside Ecopetrol, the month also left a background signal of risk in actively exploited vulnerabilities and intrusion campaigns reaching the region. CISA added multiple flaws to its KEV catalog during July, with references to Adobe ColdFusion, Fortinet, Microsoft SharePoint, SonicWall SMA 1000, and Oracle E-Business Suite among the names that resurfaced in specialized secondary coverage. Those records do not describe incidents in the extractive industry themselves, but they do mark an exposure surface that this sector shares with the rest of Latin American organizations, especially in environments with portals, remote collaboration, and technology exposed to third parties.
The other vector that deserves attention is ransomware. There were references to blocked attempts by cybersecurity controls at Ecopetrol and to campaigns in Colombia and Mexico where attackers printed ransom notes on corporate printers after encrypting systems with BitLocker. The material also referred to regional campaigns such as StrikeShark, associated with SharkLoader, but there the reading is of an active threat and not an incident against the vertical. Taken together, July brought a mix of exfiltration, extortion, and noise from active exploitation that makes industrial continuity, third-party access, and credential hygiene top priorities.
Qualitatively, pressure on the sector is at a high level for the month, not because of a large number of confirmed industrial incidents, but because of the severity of the dominant case, the recurring use of initial access mechanisms tied to third parties and credentials, and the coexistence of ransomware, data leakage, and exposure of critical assets to known vulnerabilities. The concentration of the signal in Colombia is also clear, although the regional context includes Chile and Peru on the mining expansion side and several countries on the threat side.
Regional snapshot for the month
July’s regional readout points to an attack market where data theft and extortion outweigh pure disruption. In mining, metallurgy and natural resources, that has a particular impact: personal, logistics, geology, contract, drilling and supplier relationship data all carry high value, and reputational damage can extend well beyond the technology perimeter. When an operation stays up but internal information circulates at scale, the legal and business exposure can last for weeks.
Colombia was the country with the strongest signal this month because of the Ecopetrol case and additional pressure on local companies. The available material does not show a wave of separate mining or metallurgy incidents, but rather a high-visibility intrusion that brings compliance, supply chain, forensic response and regulatory disclosure issues into play. The fact that initial access, according to the Fiscalía cited by Caracol Radio, may have come through a third party with administrator privileges fits a persistent regional pattern, where the weakest edge is often outside the industrial core and closer to the supplier ecosystem or privileged accounts.
Mexico appeared less because of the extractive industry itself and more because of the threat environment. Infobae reported a 38% rise in cyberattacks and tied that increase to a regional wave associated with StrikeShark and SharkLoader. Coverage of ransomware using BitLocker and printed notes in corporations in Colombia and Mexico reinforced the idea that extortion continues to adapt to heterogeneous environments, using legitimate or dual-use tools and staging designed to increase pressure on staff.
Chile stood out on the mining activity and exploration expansion side. La República reported on Antofagasta’s portfolio in the north of the country, while Mining Weekly noted plans to expand exploration in Encierro and Volcanes in the fourth quarter of 2026. These are not security incidents, but they do help explain why Chile’s mining perimeter remains an attractive target, more exploration means more partners, more data and more digital links to secure.
Peru also appears through mining investment, with a portfolio of 66 projects and an estimated investment of US$64.075 million. Again, the point is not that an incident occurred, but that the scale of projects and the links to permits, contractors, engineering and procurement create a larger attack surface. In environments like this, access management, identity segregation and the protection of email, collaboration and cloud storage matter as much as industrial environment defense.
Period indicators
| Indicator | Value |
|---|---|
| Verified incidents in the period | 57 |
| Indicator time window | 57 incidents dated in July 2026 · 1 with no confirmed date (excluded from the indicators) |
| Unclassified incidents (breaches or outages) | 8 |
| Cases with ransomware or extortion as the primary focus | 7 |
| Confirmed asset encryption | 1 |
| Cases that could not be classified from the available material | 6 |
| Documented fraud or phishing cases | 4 |
| Documented regulatory actions | 0 |
| Critical CVEs mentioned | 4 |
| Sectors with at least one documented incident | 6 |
| Predominant threat of the month | Unclassified (23 of 57 incidents) |
| Incidents with direct source confirmation | 96% |
Relevant Incidents
Ecopetrol, unauthorized access, exfiltration, and extortion
The month’s most significant case in the sector was Ecopetrol. The documented sequence of events points to unauthorized access to the group’s digital resources, unauthorized downloading of data tied to approximately 3,300 user accounts, and impacts on cloud storage environments at about 15 subsidiaries. Reuters and the company statements cited by Yahoo Finance agreed that a ransomware attempt was blocked by cybersecurity controls. That distinction between blocked and material damage matters, because it places the incident in the correct category: with the material available, there was no evidence of successful encryption of assets, but rather an intrusion involving exfiltration and an extortion phase.
The company itself said in separate communications that it had not identified compromise of its transactional technology solutions or any critical impact on operations, production capacity, or essential services at the time of reporting. On July 31, Infobae added that the ongoing investigation had found no evidence of essential or especially severe harm to operations, and DiarioBitcoin said no impact had been detected in digital transactions or in financial, commercial, customer, or supplier networks. That does not make the incident minor. It suggests something else, an organization can avoid an operational shutdown and still face a serious confidentiality, compliance, legal, and reputational event.
The public escalation was fast. On July 17, according to Reuters and Yahoo Finance, the company disclosed the unauthorized access and the blocked ransomware attempt. On July 20, it expanded the description, citing cooperation with ColCERT, the cybercrime directorate of the Fiscalía, the Joint Cyber Command, and the National Police cybercrime center. Later, on July 27 and 28, coverage from El Colombiano, Caracol Radio, El Universal, and El País added details about data leakage, the alleged involvement of privileged third parties, and the claim by a group taking credit for the attack. On July 31, Infobae and DiarioBitcoin reported new corporate efforts to stop the spread of the material and move the case into the criminal justice system.
There are two main operational takeaways. First, the exposed surface covered cloud environments and subsidiaries, not just a single isolated system. Second, initial access, according to the Fiscalía cited by Caracol Radio, may have come through a third party with administrator privileges. That combination should be especially concerning for any natural resources company that relies on contractors, integrators, and managed services. When a privileged account outside the main perimeter is the entry point, identity controls and action traceability matter more than network segmentation alone.
There is also a public communications and regulatory dimension. El País reported that Ecopetrol filed a Form 6-K with the U.S. SEC. StockTitan, based on that filing, described the incident as unauthorized access by an unidentified external actor, extortion, and a criminal complaint in Colombia. For a company with international exposure, incident management no longer ends with containing malware or restoring services. It also includes consistent language for investors, local authorities, and the capital markets.
Ransomware with BitLocker in Colombia and Mexico
The second notable block of the month was the warning about attacks in Colombia and Mexico in which attackers printed ransom notes on corporate printers after encrypting systems with BitLocker. TrendTIC presented it as a growing tactic, and Mallory.ai material described two cases attributed to the region. In the Colombian case, the source mentioned access through an exposed RDP, credential changes, encryption of an 8 TB financial volume, and ransom payment before forensic preservation. In the Mexican case, the same source referred to leaked MSSQL credentials, an exposed and misconfigured Microsoft SQL Server, use of xp_cmdshell, and remote administration tools to spread BitLocker.
Caution is required here. Mallory.ai is flagged as an uncertain attribution in the material, so its details should not be read as confirmed facts. Even so, they help contextualize the tactic reported by TrendTIC, which points to printed ransom demands after encryption. The analytical value lies in the persistence of the method, not in every operational detail of the attributed cases. For security teams in the extractive sector, the message is clear: ransomware that enters through RDP, exposed SQL, or weak credentials remains a real threat, and the printer can now be a pressure point, not just a harmless peripheral.
StrikeShark, SharkLoader, and regional intrusion pressure
Kaspersky detected the StrikeShark campaign, which uses the SharkLoader malware to infiltrate organizations in Latin America, Asia, and Europe. On July 29, Infobae added context by reporting that cyberattack cases in Mexico rose 38% and that there was a new regional wave associated with that ecosystem. There is no direct link to mining or natural resources in the material, but the campaign matters because it confirms that the region remains a target for operations with broad reach and the ability to enter through basic initial infection vectors.
From a sector perspective, these campaigns form the backdrop. Natural resources operations depend on mixed ecosystems, email, collaboration, ERP, identity, engineering records, telemetry, and third-party connections. A loader that achieves persistence or serves as the first stage for another malware family is a cross-cutting risk, even if it does not turn into a high-profile case in the vertical that same month.
Threats and active campaigns
Ransomware and extortion, exfiltration without confirmed encryption
July produced one confirmed case of exfiltration with extortion at Ecopetrol, along with several signs of ransomware pressure, but the material does not always make it possible to determine whether assets were encrypted. In the correct taxonomy, the main case belongs under data exfiltration without confirmed encryption. Reuters, Yahoo Finance, and the company’s own documentation describe unauthorized access, data downloading, and a blocked ransomware attempt. That means the incident’s value lies in the stolen information and the follow-on pressure, not in systems going offline.
The same month also saw reports of BitLocker ransomware in Colombia and Mexico. Here, encryption was mentioned, but the strongest confirmation in the material is limited to the threat pattern and the tactic of printing ransom notes on corporate printers. Because the main source of technical detail is uncertain, these cases should be treated as tactical warnings, not fully audited incidents. Even so, the takeaway for the vertical is useful: BitLocker, exposed RDP, misconfigured SQL, and abuse of administrative tools remain a high-risk combination in Latin American enterprise environments.
The Gentlemen’s claim in the Ecopetrol case fits more closely with extortion and public pressure than with verified-encryption ransomware. The group said it had up to a terabyte of information and reportedly issued an ultimatum. As far as the available material goes, the firm evidence is the data leak and the associated threat, not system unavailability caused by encryption. That is why the report does not group everything under "ransomware," because doing so would erase differences that matter to a CISO.
Fraud and phishing
The month’s material includes four documented fraud or phishing cases, but the provided set does not show a broader sector narrative that would support treating them as a single campaign targeting mining, metallurgy, or natural resources. Even so, the data is useful because these tactics are often the first step toward more complex incidents. In organizations with distributed operations and heavy reliance on vendors, credential fraud, executive impersonation, and phishing aimed at finance or procurement staff remain plausible entry points.
The preventive reading is straightforward. When pressure centers on employee information, payroll, banking data, or credentials, the line between leakage, social engineering, and fraud becomes blurry. If the organization also operates multiple subsidiaries, as in the Ecopetrol case, the risk of cross-company impersonation within the group rises. In that environment, phishing-resistant authentication and out-of-band verification are not a luxury, they are a minimum barrier.
APT, industrial espionage and hacktivism
The material did not provide robust attribution to a state-linked APT or a clearly tied hacktivist campaign in the vertical. There are indications of interest in sensitive business, employee, and operational information, especially in the Ecopetrol case. The Gentlemen, according to the coverage, may have offered or hinted at access to internal files from several companies in the group. But that is not enough to classify the case as state industrial espionage or as APT in the strict sense.
What the month does show is that industrial espionage does not require a sophisticated campaign to cause harm. Exfiltration of drilling data, payroll records, medical data, or credentials, if any of what was circulated proves authentic, would have a direct impact on competition, litigation, labor relations, and vendor negotiations. For that reason, the response should not stop at the technical containment of the incident. It should also consider what information, even if it was not widely published, may have ended up in the hands of third parties.
Critical vulnerabilities
| CVE | Software | Exploitation | Source |
|---|---|---|---|
| CVE-2026-48282 | Adobe ColdFusion | Added by CISA to KEV on July 7, 2026, with active exploitation reported in summarized coverage | Elite Center Blog |
| CVE-2026-15409 | SonicWall SMA 1000 | Active exploitation reported by F5 Labs, tied to Inc RaaS and remote code execution with root privileges | F5 Labs |
| CVE-2026-15410 | SonicWall SMA 1000 | Active exploitation reported by F5 Labs, tied to Inc RaaS and remote code execution with root privileges | F5 Labs |
| CVE-2026-46817 | Oracle E-Business Suite | Privilege management vulnerability added to KEV by CISA, according to Device Security Lab summary | Device Security Lab |
The material did record critical CVEs that were actively exploited, so the absence note does not apply here. The practical takeaway for this sector is that exposed collaboration surfaces, business applications, and edge appliances remain a recurring entry point. In environments with subsidiaries, contractors, and remote access, a product that lands in KEV quickly becomes a business issue, not just a patching issue.
Beyond the four CVEs listed above, several reports said CISA added other actively exploited vulnerabilities over the course of the month, including components from Fortinet, Microsoft SharePoint, WordPress Core, Langflow, DD-WRT and SonicWall SMA 1000. The point is not the brand count, but the pattern: attackers exploit patching windows in widely deployed technologies with broad reach. For a natural resources company, that means reviewing not only what runs in the plant, but also what supports identity, communications and access.
Regulation and compliance
July showed no broad regulatory movement in the vertical, and the documented regulatory movement indicator remains at zero. That did not make it a light month for the companies affected. In Ecopetrol, the filing of Form 6-K with the SEC opened a disclosure channel for investors in the United States, while coordination with Fiscalía, MinTIC, ColCERT, the Policía Nacional, and other Colombian authorities also placed the case in the criminal and public administration sphere.
The sequence helps explain how major incidents are handled in the region. Internal controls and technical containment come first. Then comes forensic preservation, reporting, and cooperation with authorities. After that, market disclosure enters the picture, and for companies with international exposure, so do materiality and consistency in the facts being disclosed. The month’s experience shows that this transition can no longer be improvised: if information spreads before the company has organized its own account, reputational costs rise.
It is also worth watching what did not appear. There was no documented wave of specific regulation for mining, metallurgy, or natural resources in Latin America in the source material. Even so, the lack of that front does not reduce the importance of corporate disclosure, interagency coordination, or response procedures for extortion and data leaks. For companies with listed securities or subsidiaries in multiple countries, that triangle of operations, forensics, and compliance is part of the incident, not a side task.
Countries and most affected subsegments
Colombia
Colombia was the center of gravity in July. Ecopetrol drew most of the attention and pulled its corporate group, subsidiaries, and supplier and customer ecosystem into a discussion about exfiltration, extortion, credentials, and compliance. Reuters, Infobae, El Colombiano, El Universal, El País, Caracol Radio and DiarioBitcoin converged on the same point: there was a serious incident, with data downloaded, and no public evidence of critical operational disruption at the time of reporting.
The material also shows that Colombia faces broader cyber pressure. Infobae cited more than 3,000 weekly cyberattacks against Colombian companies, although that figure comes from telemetry and not incident reporting, so it serves only as context. Added to that are references to ransomware incidents in the country and the presence of a significant mining base in other events during the period. The combination points to an environment where risk is not limited to the energy or extractive sectors, but spreads across the full value chain.
Mexico
Mexico stands out as another relevant point because of the escalation in cyberattacks and its role in the regional ransomware context. Infobae’s figure showing a 38% increase in cyberattacks, along with references to StrikeShark and SharkLoader, suggests broad pressure on Mexican companies. While the material does not show a mining or natural resources incident comparable to Ecopetrol’s, it does flag exposure in a large market with multiple sectors and heavy use of shared corporate infrastructure.
From an industry perspective, that matters because extractive and metals companies in Mexico often rely on extensive supply chains and mixed technology dependencies. If initial access comes through leaked credentials, exposed RDP, or abuse of business applications, the gap between a generic attack and an industrial incident gets much smaller.
Chile
Chile was more of a context story than an incident story. La República reported new prospects in the north of the country and Antofagasta’s exploration pipeline, while Mining Weekly noted plans for environmental approval to expand exploration in Encierro and Volcanes. None of that is a cybersecurity fact, but it does indicate business activity that widens the exposure surface. More exploration, more permits, and more partners also mean more identities, more documents, and more digital exchange points.
The absence of a verifiable Chilean incident in the material should not be read as absence of risk. In a subsegment heavy in geodata, engineering, and community relations, protecting sensitive information matters just as much as protecting industrial systems.
Peru
Peru appeared on the investment side of mining. The pipeline of 66 projects worth US$64.075 billion indicates a substantial amount of activity that, by itself, multiplies exposure to third parties, studies, permits, and collaboration platforms. This is not an incident, but it does help explain why attackers see value in this vertical: where there are more projects, more data moves around, and there are more opportunities for impersonation, intrusion, and intellectual property theft.
Energy and oil subsegment
Although the report’s focus includes mining, metals, and natural resources in a broader sense, July was dominated by oil and related services in the Ecopetrol case. That matters because risk is not confined to mines or smelters. Energy and extraction companies share with mining the intensive use of subsidiaries, contractors, logistics, financial systems, and document platforms. The case shows how an incident at a holding company with multiple subsidiaries can affect operations, legal, compliance, and communications at the same time.
Exploration and project pipeline
The Chile and Peru findings suggest that the exploration subsegment continues to grow, and with it the size of the digital attack surface. In exploration, the value of a file or database is not only in day-to-day operations, but also in future competitive advantage. That is why industrial espionage and extortion can have lasting impact even without visible disruption.
Trends and signals to watch
There is no historical comparative baseline, because this is the first archived period with this indicator format for Latin America. Even so, the month offers clear signals to monitor in August and in the months ahead.
The first is the consolidation of exfiltration with extortion as the dominant form of harm in the vertical, at least in the documented cases. Ecopetrol showed that data loss and public pressure can be more visible than encryption. The second is the persistence of initial access gained through third parties, credentials and exposed environments, something that appeared both in the Colombian investigation narrative and in attributed descriptions of ransomware in the region.
The third signal is the growing weight of compliance. When an incident reaches subsidiaries, user accounts, employee data and cloud environments, the debate stops being purely technical. In companies with stock market exposure or international contractual obligations, the line between cybersecurity, investor relations and regulatory reporting becomes blurred. July made that especially clear.
The fourth signal is tactical. The month left traces of ransomware that tries to adapt to the local corporate environment with printers, BitLocker, exposed RDP and SQL abuse. No exotic tool is needed to cause damage if the network has weak credentials or services published without control. The fifth signal is structural, actively exploited vulnerabilities continue to affect widely used technologies, from collaboration applications to edge appliances and business suites.
Security team recommendations
First, prioritize review of the third-party attack surface and privileged accounts. The Ecopetrol case, according to the investigation cited by Caracol Radio, points to initial access through a third party with administrator privileges. That means vendors, remote access, shared credentials, inherited privileges, and service accounts need to be audited. In a group with subsidiaries, the inventory of who can access what cannot be left scattered across spreadsheets or informal approvals.
Second, strengthen cloud storage protection and the classification of sensitive information. The month showed unauthorized data downloads in environments at roughly 15 subsidiaries. If the organization does not know where critical information lives, it cannot accurately measure what was lost or what legal exposure exists. Labeling, segregation, clear retention rules, and controls on copies and external sharing are needed.
Third, harden the remote access path. Exposed RDP, exposed or misconfigured SQL, and abuse of administrative tools appear as recurring patterns in the region. Phishing-resistant multifactor authentication, geographic and time-based restrictions, removal of legacy access, and monitoring for anomalous activity should be treated as baseline controls, not optional improvements.
Fourth, prepare a specific response for extortion and leak scenarios. The Ecopetrol case showed that an incident does not end when a ransomware attempt is blocked. The damage can shift to public circulation of files, negotiations with attackers, intervention by authorities, and handling internal claims. It is advisable to have communication scripts, forensic preservation workflows, and criteria for deciding what is reported, when, and to whom.
Fifth, review the security of printing and peripheral devices. The tactic of printing ransom notes is not central because of the paper, but because of the message, the attacker wants to make an impact outside the SOC and the admin console. Printers should be inventoried, segmented, and authenticated, with centralized logs. If they can receive jobs from compromised workstations without control, they can also amplify attacker pressure.
Sixth, speed up patching for technologies that appear in KEV. July included several references to Adobe ColdFusion, Fortinet, Microsoft SharePoint, SonicWall SMA 1000, and Oracle E-Business Suite. A slow remediation schedule, especially in internet-facing systems, leaves a window attackers already know how to exploit. In natural resources, where there is dependence on portals, integrations, and contractors, patching delays often multiply risk.
Seventh, practice exfiltration scenarios without encryption. Many playbooks are still built around full outage. July suggests a different scenario, operations continue, but sensitive data leaves the environment. That requires detection, containment, scope analysis, and legal coordination capabilities that are very different from a simple restore.
Material limitations
This report was built exclusively from the material provided for July 2026 and within the thematic scope of mining, metallurgy, and natural resources in Latin America. No internet access or sources outside the authorized list were used. Facts from prior months were left out of the reporting period and are used only as context when the source material allows it. There is also one undated fact, which is not included in any count or indicator; if mentioned, it should be understood as qualitative context, not as monthly volume.
The declared time window for the indicators is 57 dated facts in July 2026, with 1 undated fact excluded. That base should be read as a snapshot of the month, not as aggregated sector telemetry. Blocked attempts, scans, or detections were not counted as incidents. When vendor telemetry or weekly averages were cited, they were used only as context and not as evidence of a successful intrusion.
In particular, an indicator at zero means it did not appear in the material analyzed this month, not that it did not occur in the region. This is especially true for CVEs and regulatory moves. In this period, critical CVEs did appear in the material, so they were reported. If in another month a CVE indicator were zero, the correct reading would be no record in the corpus, not no vulnerabilities exploited in Latin America.
The material excluded consumer social media and sponsored posts, and sources outside the authorized list were not used as evidence. Any claim attributed by a source marked as uncertain was also treated cautiously, especially in Mallory.ai cases. When a source did not specify whether encryption was involved, or when the technical attribution was not confirmed by primary material, the report stated that explicitly to avoid overstating the event or mixing different taxonomies.
Graphic appendix
The month’s events show a concentrated sequence between July 17 and July 31, with Ecopetrol at the center of the densest activity. The timeline below summarizes that concentration and helps show how the case moved from unauthorized access and the blocking of an attempted ransomware attack to extortion, data disclosure, and regulatory and criminal response.
Sources
- La Fiscalía investiga el ciberataque contra Ecopetrol: se habría infiltrado información sensibleInfobae
- Ecopetrol intenta frenar difusión de información extraída tras hackeo a sus sistemasDiarioBitcoin
- Un ciberataque a Ecopetrol expone información del negocio y de sus empleadosEl País América Colombia
- Así se orquestó el ciberataque a Ecopetrol: Fiscalía investigaCaracol Radio
- ¿Ciberataque a Ecopetrol? Publican información de 15 empresas del grupo y la compañía pide intervención de las autoridadesEl Colombiano
- Colombia's Ecopetrol says cyberattack stole data tied to ...Reuters
- Ecopetrol Reports Cybersecurity Incident - Yahoo FinanceYahoo Finance / PRNewswire
- Casos de ciberataques aumentan 38% en México, empresas registran escalada en diversos sectoresInfobae
- Se encuentran 99 nuevos yacimientos de exploración en el norte de Chile para extraer cobreLa República
- Empresas en Colombia enfrentan más de 3.000 ciberataques semanales y pérdidas millonariasInfobae
- Weekly CISA KEV Updates: 28 July 2026Hackerstorm
- Boletín Semanal de Ciberseguridad, 25-31 de julioTelefónica Tech
- Andean Precious Metals en Noosa 2026: Cerro Bayo gana escalaInvesting.com México
- Weekly Threat Bulletin – July 22nd, 2026F5 Labs
- Expertos alertan sobre una creciente táctica de ransomwareTrendTIC
- Attackers Abuse BitLocker and Office Printers in Latin AmericaMallory.ai
- Ecopetrol Continues to Implement Monitoring and Protection Measures in Response to Cybersecurity IncidentYahoo Finance / PR Newswire
- Vulnerability Summary for the Week of July 20, 2026CISA
- Cyber incident hits Ecopetrol S.A. (NYSE: EC), affecting cloud-based file storage and prompting criminal complaintStockTitan
- Security News Daily Report 2026-07-16|Device Security LabDevice Security Lab
- Ep.697 - RadioCSIRT Flash info cybersécurité du jeudi 16 juillet 2026YouTube / RadioCSIRT
- Cobre para la transición energética: nuevos proyectos se expanden en ecosistemas sensibles y tierras comunitarias de Colombia y ArgentinaMongabay
- CISA Adds Four Known Exploited Vulnerabilities to Catalog on July 14Quasa.io
- Resumen de noticias sobre ciberseguridad – 10 de julio de 2026Integrity360
- CVE críticos julio 2026: ColdFusion, Ivanti y Fortinet | Elite Center BlogElite Center Blog
- Cartera de Proyectos de Inversión Minera 2026: Perú impulsará 66 proyectos por más de US$64.075 millonesLa República
- Weekly CVE Report: 6 Exploited Bugs Hit CISA KEVSecurityOnline
- Antofagasta to seek enviro approval for Encierro, Volcanes exploration in fourth quarterMining Weekly
- Incremento del RansomwareGlobal IT Media
- Ciberataque a Ecopetrol: filtran información de 15 empresas del grupoEl Universal
