The Ecopetrol 2026 data breach involved unauthorized access to cloud-based file-storage environments belonging to the company and approximately 15 subsidiaries. According to Ecopetrol's July 17, 2026 disclosure, an unidentified external actor unlawfully downloaded data associated with roughly 3,300 user accounts and issued extortion demands threatening to publish the extracted information.
The actor also attempted to deploy ransomware, but Ecopetrol said security controls across the company and its subsidiaries blocked that attempt. A July 20 update confirmed that the impact remained limited to file downloads. Because the company did not publish an exact intrusion start date, this record uses July 17, the first public disclosure date, for the breach date.
Confirmed Scope of the Breach
The confirmed impact is the download of corporate files from cloud-storage resources used by approximately 15 group companies, including Ecopetrol. The company described 3,300 as the number of user accounts associated with the unauthorized access, not as a count of distinct stolen identity records. The affected count in LeakData therefore represents account scope and does not mean that personal details belonging to 3,300 people were exposed.
Ecopetrol said it was continuing to classify the downloaded files and assess their criticality; its public releases did not list specific fields inside them. This entry does not invent names, email addresses, phone numbers, identity numbers, or passwords as data types. The data class is limited to the confirmed category of corporate cloud-storage files.
Elements Confirmed as Unaffected
According to the July 20 update, the identities of users associated with the 3,300 accounts were not compromised and no user access credentials were captured. The company also found no loss of information integrity despite the actor's attempts to destroy, delete, or encrypt data. Passwords and user-identity details are therefore not included among the data classes.
Ecopetrol reported no compromise in transactional technology solutions across its digital ecosystem, subsidiaries, or network of commercial and financial partners, suppliers, and customers. Operations continued without interruption. Those findings do not make the event insignificant: file confidentiality was breached, while the disclosed impact on system integrity and transactional environments remained contained.
Extortion and the Blocked Ransomware Attempt
The external actor sent extortion demands threatening to disclose unlawfully extracted information. This pattern reflects the data-theft half of double extortion, in which information is stolen before a payment demand even when encryption does not succeed. Ecopetrol's disclosure carefully distinguishes the ransomware attempt that was blocked from the file download and extortion that actually occurred.
The company did not identify the threat actor, malware, or initial access method. No confirmed attribution to a known ransomware group has been published, so this entry does not guess a group name, vulnerability, or intrusion technique. A unilateral claim on a leak site should not expand the record unless the company or a reliable investigative source verifies it.
Ecopetrol's Response
Ecopetrol said it immediately revoked unauthorized access, blocked mechanisms associated with mass downloads, and identified and contained the actor's tactics, techniques, and procedures. It pursued restrictions against external infrastructure used to store or download the information. Classification of the downloaded material and assessment of its criticality were also included in the response plan.
The company filed a criminal complaint with Colombia's Attorney General and worked with ColCERT, the specialized cybercrime directorate, the armed forces' Joint Cyber Command, and national police cybercrime units. Insurance and capital-markets teams were activated to manage investigation, remediation, and regulatory costs. By July 20 containment was in an advanced phase, although file review remained ongoing.
What Employees and Partners Should Do
Because the company said user identities and access credentials were not captured, this incident should not be used to claim that every password was stolen. Even so, teams that exchange files with Ecopetrol or its subsidiaries should inspect unusual downloads, sharing links, new-device events, and access alerts, close unnecessary public links, and apply least privilege to sensitive folders.
Authentic project, supplier, or employee details from corporate files could support targeted phishing. Independently verify messages that say “pay to prevent disclosure,” “revalidate document access,” or “install this security update.” Customers and suppliers can note that no transactional-system compromise was identified while remaining cautious about unexpected attachments and links sent in Ecopetrol's name.
How to Interpret This LeakData Record
The 3,300 value is the number of user accounts Ecopetrol associated with downloaded data; it does not mean identity information belonging to 3,300 people was stolen. The company expressly said user identities and credentials were not compromised. No files or user-level rows were imported into LeakData, so an email-search match should not be expected for this metadata-only record.
This entry covers only the cloud-file download and extortion incident disclosed in July 2026. It does not describe the blocked ransomware attempt as successful encryption or assume that undisclosed file fields were personal data. If Ecopetrol later publishes file categories, the exact intrusion date, or additional verified impact, the record should be updated only to match that new official evidence.