AI
Ecopetrol Reports Cybersecurity Incident
Ecopetrol S.A. (BVC: ECOPETROL; NYSE: EC) (the "Company") announced that it has identified an unauthorized access to certain digital resources owned by the Company and its subsidiaries by an external actor who has not been identified, as well as an attempted ransomware attack that was blocked by the cybersecurity controls implemented across the Company and its subsidiaries. The unauthorized access affected cloud-based file storage environments of approximately 15 subsidiaries (including the Comp
About this update from Ecopetrol Sa
BOGOTA, Colombia, July 17, 2026 /PRNewswire/ -- Ecopetrol S.A. (BVC: ECOPETROL; NYSE: EC) (the "Company") announced that it has identified an unauthorized access to certain digital resources owned by the Company and its subsidiaries by an external actor who has not been identified, as well as an attempted ransomware attack that was blocked by the cybersecurity controls implemented across the Company and its subsidiaries. The unauthorized access affected cloud-based file storage environments of approximately 15 subsidiaries (including the Company), resulting in the unauthorized download of data associated with approximately 3,300 user accounts. The external actor communicated extortion demands, threatening to publicly disclose the information that had been unlawfully extracted. In response to this incident, the Company initiated an investigation and activated its incident response and management protocols. In addition, the Company deployed the following measures aimed at preventing the public disclosure of the unlawfully extracted information, addressing supervisory actions and/or potential financial costs associated with investigation, remediation, and regulatory compliance, as follows: a. Immediate revocation of unauthorized access to the compromised digital assets. b. Blocking of mechanisms associated with the mass download of information. c. Identification, analysis, and containment of the tactics, techniques, and procedures (TTPs) used by the malicious actor. d. Filing of a criminal complaint before the Office of the Attorney General of Colombia and deployment of cooperation activities with specialized national authorities. e. Identification of external infrastructures used for the storage or download of information to pursue restriction or blocking actions. f. Activation of support mechanisms with insurers and specialized capital markets teams to ensure the proper management of the event. g. Detailed assessment of the downloaded information and determination of its criticality. h. Enhanced monitoring of the technology infrastructure under critical alert protocols and continuous validation of preventive and detective controls. As of the date of this report, the Company has not identified any material disruption to its critical operations, production capacity, or essential services; any direct financial impact that would prevent it from continuing to conduct its business activities; or any disclosure of the information subject to the unauthorized access. However, the Company continues to assess the potential exposure of corporate information, which could include confidential, restricted, proprietary, or personal data, as it cannot guarantee that this incident will not have a material adverse effect on the Company's business, reputation, operating results, or financial condition.