Menu
Browse

Cyber Incident Victim: Colombia's Ministry of Justice

Date

Aug 2026

Location

Colombia

Status

Ongoing

Updated

2026-08-13 16:56

Timeline
Occurred
Aug 2026
Discovered
Undetermined
Disclosed
Aug 2026
Resolved
Pending
Summary

The Ministry of Justice in Colombia confirmed that a ransomware attack encrypted files on part of its technology infrastructure, disrupting services related to illicit-drug monitoring and legal proceedings. Acting officials stated that no data was exfiltrated despite the encryption, and they are working to restore the affected systems. The incident occurred shortly after a national cybersecurity alert warned of increased ransomware activity targeting the country and came during a period of governmental transition and recovery from a recent natural disaster. This event fits a broader pattern of rising cyber threats against Latin American government entities, including prior compromises of tax authorities and state‑owned energy firms.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On August 2 2026 Colombia’s Ministry of Justice confirmed that a ransomware attack had struck part of its technology infrastructure, degrading several public‑facing services including those related to illicit‑drug monitoring and legal processes. The incident occurred just five days before the nation’s presidential handover and followed a threat intelligence warning issued the previous day by Colombia’s national CERT (ColCERT) noting an increased focus of ransomware groups on the country. Acting Minister of Justice Cielo Rusinque stated in a Spanish‑language news interview that some files had been encrypted and that her team was working to overcome that encryption, while emphasizing that verification showed no data had been captured or stolen. Rusinque noted that she had left her position during the transition to the new government the prior week. The attack added to the country’s challenges as it was simultaneously recovering from a 7.4‑magnitude earthquake that had struck the western Chocó region on August 10.

Cyber Incident Image

In the broader context, Colombia had experienced other cyber incidents earlier in the year, including a claimed compromise of the national tax authority (DIAN) in March by an actor using the alias “ArcRaidersPlayer” and a July acknowledgment by Ecopetrol SA that a breach had affected the IT networks of more than a dozen subsidiaries and likely exposed information on at least 3,300 users. Fortinet’s threat intelligence principal strategist for Latin America reported that over the past year exploit attempts had more than tripled, with increased activity targeting the Server Message Block protocol and specific devices, while other observers noted rising nation‑state activity against neighboring Venezuela and heightened intelligence‑gathering efforts by China in the region. Additional disruptions had affected other Colombian ministries when attackers hit the internet service provider IFX Networks in 2023, impacting the Ministry of Health, the Judicial Branch and the Superintendencia de Industria y Comercio. The Ministry of Justice response centered on confirming the encryption, denying any data exfiltration, and stating that efforts were underway to restore the affected services. No further details about attacker identity, ransom demands, or specific remediation steps were provided in the source material.

Sources
Sources available to members
1 source