BOGOTÁ, COLOMBIA (By ECOPETROL, 20.Jul.2026, Words: 252) — ECOPETROL reports that the latest analyses conducted regarding the cybersecurity incident and its effects, previously disclosed on 17 Jul. 2026, indicate that the impact was limited exclusively to the downloading of files.
Accordingly, no compromise to the integrity of the information has been identified, despite the external threat actor’s attempts to destroy, delete, and/or encrypt data. The identities of users associated with the 3,300 accounts that were unlawfully infiltrated were not compromised, nor were any user access credentials captured.
ECOPETROL also confirms that no compromise has been identified in the transactional technology solutions within its digital ecosystem, those of its subsidiaries, or those of its network of commercial and financial partners, suppliers, and customers.
The company and its subsidiaries continue to carry out containment efforts, now in an advanced phase, prioritizing the following actions:
— classification of the information downloaded as a result of the incident.
— assessment and management of extortion demands and threats based on information unlawfully obtained by the external threat actor, which have been reported to the relevant authorities.
— ongoing collaboration with Colombia’s Cyber Emergency Response Team (ColCERT), given Ecopetrol’s designation as critical national infrastructure; the Specialized Directorate for Cybercrime of the Office of the Attorney General; the Joint Cyber Command of the Colombian Armed Forces (CCOCI); and the Cybercrime Center of the National Police’s Criminal Investigation Directorate (DIJIN).
The operational activities of the company and its business group continue without interruption, while efforts to monitor and address the cybersecurity incident remain ongoing.
____________________