Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition

Colombian Justice Ministry Hit by Ransomware Attack Just Days Before Presidential Transition

A devastating ransomware attack struck Colombia’s Ministry of Justice on August 2, crippling several public-facing services and raising concerns about the country’s ability to protect its critical infrastructure. The attack, which occurred just five days before the presidential handover, is the latest in a series of high-profile cyberattacks that have targeted government-linked organizations in Colombia.

The attackers used ransomware to encrypt some files on the Ministry’s technology infrastructure, disrupting services related to illicit-drug monitoring and legal processes. While there are reports of data leaks, Acting Minister of Justice Cielo Rusinque has denied any information had been stolen, stating that “some files were encrypted” but no data capture occurred.

This attack is not an isolated incident in Colombia. The country’s critical infrastructure has been under siege by cyber adversaries for months. In March, the national tax authority, DIAN, was allegedly compromised by a hacker using the alias “ArcRaidersPlayer,” who claimed to have breached the agency. And just last month, Ecopetrol SA, the largest oil-and-gas company in Colombia, acknowledged that a breach had compromised the IT networks of more than a dozen subsidiaries and likely leaked information on at least 3,300 users.

The situation is alarming because it highlights the increasing sophistication and frequency of ransomware attacks in Latin America. According to Arturo Torres, threat intelligence principal strategist for Latin America at Fortinet’s FortiGuard Labs, “the volume of malicious activity has more than tripled in the past year, with a significant concentration on exposed and potentially vulnerable infrastructure.” He adds that automation allows these attacks to happen at scale.

The cyberattack on Colombia’s Ministry of Justice is also part of a larger trend affecting Latin America. Nation-state attacks have risen against neighboring countries, such as Venezuela, following US military action to capture its former president. China has also increased efforts to gather intelligence on regional developments, further exacerbating the security threat in the region.

Colombian public and private organizations have expanded their cloud footprints rapidly without adequately building cloud posture management, making them vulnerable to attacks like Ecopetrol’s recent experience. Attackers accessed cloud storage environments that shouldn’t have been reachable, compromising sensitive information.

The takeaway from these incidents is clear: critical infrastructure in Latin America is under siege by cyber adversaries. It’s crucial for governments and organizations to invest in robust cybersecurity measures, including threat intelligence, incident response planning, and employee education on safe online practices. By doing so, they can reduce the risk of devastating ransomware attacks like this one and protect sensitive information from falling into the wrong hands.


Source: Dark Reading — 2026-08-12