Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition

A devastating ransomware attack has hit Colombia’s Ministry of Justice just five days before the country’s presidential transition. The assault, which compromised part of its technology infrastructure, disrupted several public-facing services and raised concerns about the safety of sensitive information.

The attack occurred on August 2, with hackers encrypting some files and rendering them inaccessible to ministry personnel. Fortunately, acting Minister of Justice Cielo Rusinque has assured that no data was stolen during the breach, although it is unclear how long it will take to restore access to the affected systems. This incident follows a recent warning from Colombia’s national CERT (ColCERT), which highlighted an increase in ransomware attacks targeting critical infrastructure and government-linked organizations in the country.

The Colombian Ministry of Justice is not an isolated case; the country has been under siege from cyber adversaries in recent months. In March, the national tax authority, DIAN, was allegedly breached by a hacker using the alias “ArcRaidersPlayer,” who claimed to have compromised the agency’s systems. Meanwhile, Colombia’s largest oil-and-gas company, Ecopetrol SA, has acknowledged that its IT networks were breached in July, potentially exposing information on over 3,300 users.

The scale and frequency of these attacks are concerning, with exploit attempts more than tripling in the past year alone. According to Arturo Torres, threat intelligence principal strategist for Latin America at Fortinet’s FortiGuard Labs, this surge is largely driven by the increasing availability of exposed and vulnerable infrastructure, as well as automation that enables malicious activity on a large scale.

The Colombian government has been under pressure from various quarters, including nation-state actors and hacktivists. The country’s neighbor, Venezuela, was targeted in early 2026 with a series of nation-state attacks, following the US military action to capture its former president. Meanwhile, China’s efforts to gather intelligence on regional developments have also increased.

The attack on Colombia’s Ministry of Justice raises concerns about the country’s cybersecurity posture and its ability to protect sensitive information from cyber threats. With the expansion of cloud footprints by public and private organizations in Colombia, there is an urgent need for robust cloud security measures to prevent such breaches.

Colombia’s neighbors have also been targeted by cyber attackers in recent months. Venezuela was hit with a series of nation-state attacks, while China’s efforts to gather intelligence on regional developments have increased. The attack on IFX Networks in 2023, which disrupted several government ministries, including the Ministry of Health and the Judicial Branch, highlights the vulnerability of critical infrastructure to cyber threats.

In conclusion, the ransomware attack on Colombia’s Ministry of Justice is a stark reminder of the growing threat of cyber attacks in Latin America. As organizations expand their cloud footprints without building adequate cloud posture management, they are exposing themselves to significant risks. To mitigate these risks, it is essential for public and private organizations to prioritize cybersecurity and invest in robust security measures that can detect and prevent such breaches.


Source: Dark Reading — 2026-08-12