Ecopetrol, Colombia's state-linked energy company, confirmed a ransomware-related intrusion after attackers accessed its IT infrastructure and stole pseudonymous data associated with 3,300 user accounts. Reporting tied the incident to the threat group thegentlemen, with claims that more than 1 TB of data was involved in the compromise of the company, which operates refineries, pipelines, ports, and international energy assets.
The company said the attackers attempted to deploy an encryptor, but security controls blocked the encryption phase and prevented disruption to transactional systems and partner networks. Ecopetrol stated that no user identities or credentials were compromised, that the threat actors were removed from its environment, and that an internal investigation is underway; Colombian authorities, including the Attorney General's Office and the Military Forces' Joint Cyber Command, were also notified.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
Ecopetrol stated it had removed the attackers from its environment, opened an internal investigation, and notified Colombian authorities including the Attorney General's Office and the Military Forces' Joint Cyber Command. The company also said no user identities or credentials were compromised.
Ecopetrol confirmed that attackers accessed its IT infrastructure and stole pseudonymous data from 3,300 user accounts. The company said an attempted encryptor deployment was blocked by security controls, preventing disruption to transactional systems and partner networks.
The Ecopetrol incident was publicly discovered or reported on July 19, 2026 at 10:13 UTC, identifying the Colombian energy company as a victim of thegentlemen.
Ecopetrol was reportedly breached in a ransomware attack attributed to thegentlemen. The incident was dated July 17, 2026, and more than 1 TB of data was said to be involved.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.