Colombia’s Ministry of Justice was hit by a ransomware attack on August 2, 2026, affecting part of its technology infrastructure and reducing the availability of several public-facing digital services. The incident happened just five days before the country’s presidential handover on August 7, when Abelardo de la Espriella was scheduled to take office. The timing placed the attack during an important period of transition for the Colombian government.

colombia-justice-ministry-government-building

The Colombian government confirmed that the attack involved ransomware, a type of malicious software that can encrypt files and disrupt access to computer systems. According to the Ministry of Justice, some of its services were affected after the attackers compromised part of the ministry’s infrastructure. Services connected to areas including illicit-drug monitoring and legal processes were among those disrupted. The incident did not mean that every system operated by the ministry was taken offline.

After detecting the attack, the ministry immediately activated its cybersecurity and containment procedures. Compromised systems were isolated as a preventive measure to stop the ransomware from spreading to other parts of the network. The ministry also began working with Colombia’s Ministry of Information and Communications Technologies and other authorities to understand the incident. Recovery efforts were focused on safely restoring affected systems and services.

encrypted-government-files-ransomware-attack

One important point is that there has been no confirmed evidence that information was stolen from the ministry. Acting Justice Minister Cielo Rusinque said that some files had been encrypted, but stated that the government had verified there was no data capture. This is significant because ransomware incidents can sometimes involve both encryption and data theft. In this case, officials have publicly described the impact primarily as an infrastructure and service-availability problem.

The attack also came at a time when Colombian organizations were already facing increased ransomware activity. A day before the Ministry of Justice incident, Colombia’s national cybersecurity response organization, ColCERT, issued a threat intelligence warning about increased ransomware activity targeting the country. Security experts have also reported growing attempts to find vulnerable infrastructure in Colombia. This suggests that government and other critical organizations remain attractive targets for cybercriminals.

colombia-government-cybersecurity-data-protection

Colombia has faced several other major cyber incidents in recent years. In 2023, attacks involving the IT provider IFX Networks disrupted services at several Colombian government institutions, including the Ministry of Health and judicial organizations. More recently, state-controlled energy company Ecopetrol disclosed a cyberattack in July 2026 in which attackers accessed cloud storage and data linked to about 3,300 user accounts. The company said its security controls blocked the attempted ransomware encryption.

The latest incident highlights the growing pressure on Colombian public infrastructure as organizations continue moving more services and information into digital and cloud-based environments. Security researchers say attackers are increasingly using automated methods to identify exposed systems and vulnerable services. Experts have also warned that third-party providers and business partners can create additional risks when their access to government or corporate systems is not properly secured.

colombia-government-ransomware-cyberattack

For the Ministry of Justice, the priority remains containing the attack, recovering affected technology and restoring services safely. Colombian authorities have also been asked to investigate the incident, identify those responsible and determine exactly how the attackers gained access. The ransomware attack shows how cyber incidents can affect government operations at sensitive moments, while also reinforcing the need for stronger protection, monitoring and response capabilities across public-sector systems.

Stay alert, and keep your security measures updated!

Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news