• 2 min read
Ecopetrol says 3,300 accounts were hit in cyberattack
Ecopetrol says attackers stole data from 3,300 user accounts but failed to deploy ransomware. The company says operations and credentials were not affected.

Image: TechRadar
Ecopetrol says attackers stole data tied to 3,300 user accounts in a ransomware incident, but failed to deploy the encryptor because of the company’s security controls.
According to the company, an unidentified threat actor gained access to its IT infrastructure, exfiltrated data, and then attempted to install ransomware. Ecopetrol said the attackers were stopped before they could encrypt systems, preventing disruption to day-to-day operations.
The company added that the stolen files were pseudonymous, and said neither user identities nor account credentials were compromised.

Recommended reading
Spy malware hides in Microsoft 365 calendars
“The identity of the users of the 3,300 accounts that were illegally infiltrated was not affected, nor were the respective user access credentials captured.”
Ecopetrol also said it found no compromises affecting transactional technology systems across its digital ecosystem, its subsidiaries, or its network of commercial partners, financiers, suppliers, and clients.
The attackers still contacted the company to demand payment, though no amount was disclosed. So far, the stolen database does not appear to have been leaked, and no group has publicly claimed responsibility for the intrusion.
Ecopetrol said it removed the attackers from its systems, halted further data exfiltration, opened an internal investigation, and notified Colombian authorities, including the Attorney General’s Office and the Joint Cyber Command of the Military Forces. The investigation is ongoing.
Ecopetrol is Colombia’s state-controlled oil and gas company, with operations spanning production, refining, transportation, and exploration. It also operates in Chile, Peru, and Bolivia, and generates about $30 billion in annual revenue.
Security Editor
Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.
via TechRadar


