← Blog

Ecopetrol Breach: 3,300 Accounts Hit in Cyberattack

Share on X

July 17, 2026: Colombian state energy giant Ecopetrol disclosed a cybersecurity incident: an attempted ransomware-style attack that led to unauthorized download of data tied to about 3,300 user accounts, then extortion threats to publish what was taken.

For a company that dominates Colombia's hydrocarbons chain, even a contained account-level theft matters—credential reuse, partner portals, and phishing that looks like internal Ecopetrol mail.

What Ecopetrol reported

In its PR Newswire release, Ecopetrol said it revoked unauthorized access, blocked mass-download paths, filed a criminal complaint with Colombia's Attorney General, and spun up insurer and capital-markets support. It had not identified material disruption to critical operations or confirmed that the stolen set had already been published—but it also said it cannot guarantee the incident will not have a material adverse effect, and continues assessing whether confidential, restricted, proprietary, or personal data was included.

Who should act

Employees, contractors, and partners with Ecopetrol digital accounts—especially if you reuse passwords elsewhere.

What you should do

  1. Rotate Ecopetrol-related credentials and enable MFA where available.
  2. Treat urgent "pay ransom / leak prevention" messages as hostile.
  3. Canonical record: Ecopetrol 2026 on BreachHistory.

Sources: Ecopetrol / PR Newswire; Yahoo Finance / Reuters wire.