Ransomware Hits Justice Ministy as Colombia Gets New President | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


Colombia’s Ministry of Justice confirmed that a ransomware attack struck part of its technology infrastructure and degraded several public-facing services on Aug. 2, just five days before the nation’s presidential handover.

The attack, which disrupted some services around illicit-drug monitoring and legal processes, came a day after Colombia’s national CERT (ColCERT) published a threat intelligence warning that ransomware groups had increased their focus on the country. While some media reports suggested that data had leaked during the Ministry of Justice compromise, then acting Minister of Justice Cielo Rusinque denied that any information had been stolen, during a Spanish-language news interview.

“Some files were encrypted,” she said, according to a translation service. “We are currently working on overcoming that encryption, [but] it has already been verified … that there was no data capture. That was the first thing I asked.”

Related:Angola’s Largest Telco Breached Hours Before IPO

Rusinque left the position during the current transition to the country’s new government last week. The South American nation is currently recovering from a 7.4-magnitude earthquake that hit the westernmost region of Chocó and surrounding territories on Aug. 10.

Colombia has been increasingly targeted by cyber adversaries, which have regularly struck government agencies and government-backed or -owned companies. In March, Colombia’s national tax authority, the Direccióon de Impuestos y Aduanas Nacionales (DIAN), suffered an alleged compromise by a hacker using the alias “ArcRaidersPlayer,” who claimed to have breached the agency. And in July, Colombia’s largest oil-and-gas company, Ecopetrol SA, acknowledged that a breach had compromised the IT networks of more than a dozen subsidiaries and had likely leaked information on at least 3,300 users.

In the past year, exploit attempts have more than tripled, and attacks on the popular Server Message Block (SMB) communication protocol for Windows, as well as specific devices, have become more common, says Arturo Torres, threat intelligence principal strategist for Latin America at Fortinet´s FortiGuard Labs.

“What stands out in Colombia during 2025 is not only the volume of malicious activity, but where that activity is increasingly concentrated,” he says. “The telemetry shows continuous activity looking for exposed and potentially vulnerable infrastructure, and automation allows this to happen at significant scale.”

Clouds and Cyberattacks in Colombia

Cyberattacks have increased across Latin America in general and in the Caribbean and northern parts of South America in particular. In early 2026, nation-state attacks rose against Colombia’s neighbor, Venezuela, for example, following the US military action to capture its former president, while China’s efforts to gather more intelligence on regional developments have also risen. Other government ministries have also been attacked in the recent path, with the Ministry of Health, the Judicial Branch, and the Superintendencia de Industria y Comercio suffering disruption when attackers hit Internet service provider IFX Networks in 2023.

Related:AI Agent Drives Espionage Attack on Thai Ministry of Finance

“Colombian public and private organizations have expanded cloud footprints faster than they’ve built cloud posture management,” says Santiago Rosenblatt, co-founder and CEO of Strike, an AI-powered penetration testing firm that operates in Latin America.

Ecopetrol suffered such an attack, according to its disclosure, as attackers accessed cloud storage environments that shouldn’t have been reachable.

While the cyberattack did not impact the company’s operations, the firm “continues to evaluate the possible exposure of corporate information that could include confidential, restricted, proprietary, or personal data, as it is not possible to ensure that this incident will not have some type of material adverse effect on the business, reputation, operational results, or financial situation of the Company,” Ecopetrol SA said in a statement in Spanish posted to social media platform X (translated with Anthropic’s Claude).

Related:Brazilian Banking Trojan Actively Spreading in Portugal

Cyberattacks on Latin America Rise

Overall, the picture in Colombia mirrors the rest of Latin America. While reconnaissance activity dropped more than 70% in 2025, exploit attempts increased 40%, Apache Log4j attacks increased 18%, and malware detection increased 42%, says Fortinet’s Torres.

Increasingly, Latin America is facing an automated and mature threat ecosystem, he says.

“Attackers can scan infrastructure, identify vulnerable services, attempt exploitation, distribute malware, leverage botnet infrastructure, and eventually monetize access through ransomware or other forms of cybercrime,” Torres says.

While cloud services pose a critical weakness for many organizations in the region, third-party business relationships — including managed service providers and partners — are the most significant systemic risk, says Strike’s Rosenblatt.

“Adversary attention is scaling faster than defensive maturity across Colombia and the region,” he says.



——————————————————–


Click Here For The Original Source.

.........................