Colombia's Ministry of Justice confirmed that a ransomware attack struck part of its technology infrastructure on Aug. 2, disrupting public-facing services tied to illicit-drug monitoring and legal processes just days before the country's presidential transition. Acting Justice Minister Cielo Rusinque said some files were encrypted, while recovery efforts continued to restore affected systems.
Officials said the incident degraded ministry services but denied that data had been stolen, despite early reports of possible leakage. The attack came after Colombia's national CERT, ColCERT, warned that ransomware groups were increasingly targeting the country, and it adds to a broader wave of cyberattacks affecting Colombian government agencies and major state-linked enterprises amid rising exploit activity across Colombia and Latin America.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
On 2026-08-02, a ransomware attack struck part of Colombia's Ministry of Justice technology infrastructure, degrading public-facing services. The incident disrupted services tied to illicit-drug monitoring and legal processes.
One day before the Justice Ministry attack, Colombia's national CERT, ColCERT, published threat intelligence warning that ransomware groups had increased their focus on the country.
In July 2026, Ecopetrol SA acknowledged a breach that compromised the IT networks of more than a dozen subsidiaries. The company said the incident likely leaked information on at least 3,300 users and continued evaluating possible exposure of confidential and personal data.
In March 2026, Colombia's national tax authority DIAN suffered an alleged compromise that was claimed by a hacker using the alias ArcRaidersPlayer.
In 2023, attacks on IFX Networks disrupted Colombia's Ministry of Health, the Judicial Branch, and the Superintendencia de Industria y Comercio.
After the attack, acting Justice Minister Cielo Rusinque said some files were encrypted and denied that attackers captured data, despite earlier media reports suggesting a leak. Recovery efforts were underway.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.