Ransomware Hit Colombia's Justice Ministry Five Days Before a New President Took Office
Files were encrypted, services went down, and ColCERT had warned about exactly this kind of attack the day before. Here is what happened, and why Colombia keeps ending up in the crosshairs.

Key points
- Ransomware, meaning malicious software that scrambles files until a payment is made, struck Colombia's Ministry of Justice on 2 August 2025, five days before a presidential handover.
- The then-acting Minister of Justice Cielo Rusinque said on record that no data was stolen, only files were encrypted.
- Colombia's national cyber-emergency team, ColCERT, had published a warning about rising ransomware threats against Colombian targets the day before the attack hit.
- Separately, oil-and-gas giant Ecopetrol SA confirmed in July 2025 that a breach across more than a dozen of its subsidiaries likely exposed information on at least 3,300 users.
- Exploit attempts across Latin America rose 40 percent in 2025, and malware detections climbed 42 percent, according to Fortinet's FortiGuard Labs.
Colombia's Ministry of Justice confirmed it was hit by ransomware on 2 August 2025, scrambling files across part of its technology systems and knocking several public-facing services offline. The disruption affected tools used for illicit-drug monitoring and legal processes. Timing was sharp: the attack landed five days before the country handed power to a new government.
Did the criminals steal any data?
The acting minister said no. Cielo Rusinque, who held the role at the time, gave an interview in Spanish in which she confirmed files had been encrypted but said her team verified there was no data theft. "Some files were encrypted," she said. "We are currently working on overcoming that encryption, but it has already been verified that there was no data capture. That was the first thing I asked."
Some media reports had suggested data leaked. Rusinque's public denial, on the record, is the official government position. She has since left the role as part of the transition to the new administration.
How did this happen, and why Colombia?
ColCERT, Colombia's national computer emergency response team, published threat intelligence the day before the attack warning that ransomware groups were focusing more attention on Colombian targets. That warning arrived too late, or was not acted on fast enough, to stop what followed.
This was not an isolated bad week. Colombia's national tax authority faced an alleged breach in March 2025. Ecopetrol SA, the country's largest oil-and-gas company, disclosed in July that attackers broke into cloud storage, meaning internet-based file servers, across more than a dozen subsidiaries, likely exposing personal data on at least 3,300 people. Ecopetrol said it "continues to evaluate the possible exposure of corporate information" and could not rule out a material impact on its business or reputation.
| Incident | Date | Impact |
|---|---|---|
| IFX Networks (ISP) attack affecting Health Ministry, Judicial Branch | September 2023 | Widespread government service disruption |
| DIAN tax authority alleged breach | March 2025 | Claimed by hacker alias "ArcRaidersPlayer" |
| Ecopetrol SA cloud breach | July 2025 | 3,300-plus users across 12-plus subsidiaries |
| Justice Ministry ransomware | 2 August 2025 | Files encrypted; services degraded |
Fortinet's Latin America threat intelligence lead Arturo Torres says exploit attempts across the region rose 40 percent in 2025, Apache Log4j attacks, a type of attack that exploits a well-known flaw in a widely used software tool, rose 18 percent, and malware detections climbed 42 percent. Attackers are increasingly automated, he says, scanning for weak points at scale without much human effort on their end.
Santiago Rosenblatt, co-founder and CEO of penetration-testing firm Strike, which tests organisations' defences in Latin America, points to cloud security as a particular gap. "Colombian public and private organisations have expanded cloud footprints faster than they've built cloud posture management," he says. Third-party suppliers and managed service providers, meaning outside companies that run IT systems on behalf of clients, carry the biggest systemic risk in the region, he adds.
What should ordinary Colombians affected by these incidents do?
The Justice Ministry said no personal data was taken in the ransomware attack, so citizens whose cases sit within its systems have no confirmed exposure to act on right now. Ecopetrol users are a different matter. If you are one of the roughly 3,300 people whose information may have been exposed in that breach, watch for unexpected emails or calls asking you to confirm personal details, change passwords on any account that shares credentials with Ecopetrol services, and consider placing a fraud alert with Colombia's financial regulators if you notice unusual account activity.
More broadly, the pattern across these incidents, first reported on by Dark Reading, points to a government sector that is expanding digital services faster than it is securing them. That gap tends to narrow only after incidents that are expensive enough to force change.



