Ecopetrol Data Breach

Alleged

Ransomware claim involving Ecopetrol.

Published: Jul 19, 2026 The Gentlemen
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Ecopetrol
Industry
Energy
Threat Actor
The Gentlemen
Date of Incident
Jul 19, 2026

Executive Summary

Ecopetrol, an energy organization based in Colombia, has been listed as a victim on The Gentlemen ransomware group’s dark web leak portal, with the entry published on July 19, 2026. The listing was identified through SOCRadar’s Dark Web Monitoring service. The company operates in the energy space, according to the sector classification captured at the time of listing. The entry places Ecopetrol among the most recent additions to The Gentlemen’s victim population. In the 60 days leading up to this listing, The Gentlemen claimed 133 other victims on its leak portal. The group has primarily targeted the business services, manufacturing, and healthcare sectors, with a significant concentration of victims in the United States, Germany, and France. Other recent victims listed by The Gentlemen that share similarities with Ecopetrol include Energon, MBT Energy, Kosmos, and Suburban Water. Ecopetrol’s profile aligns with the group’s pattern of opportunistic attacks on energy companies and mid-market targets, rather than indicating a deviation from their usual modus operandi.

Technical Analysis

Initial-access correlation against SOCRadar’s stealer-log telemetry revealed a significant exposure for the ecopetrol.com.co domain. The analyzed sample included 8 records linking employee credentials to organizational systems, 4 records showing corporate users active on third-party services, and 12 records associated with customer, supplier, or external accounts on organizational systems. Critical endpoints identified included the Microsoft Entra ID SAML endpoint, an on-premises ADFS federation service, corporate webmail, an internal back-office/ERP portal, and an HR/personnel management portal. The observed credential profile is mixed, with sample freshness ranging from June 2024 to July 2026, and a notable long-tail persistence indicating that some credentials may not have been rotated. For ransomware groups like The Gentlemen, credentials harvested by infostealers represent a well-established initial access vector. Threat actors or initial-access brokers commonly source recent logs from underground marketplaces, validate corporate credentials, and then use them to gain access to systems such as Microsoft 365, VPNs, or remote-access portals before deploying ransomware. While the stealer-log data presented here does not definitively confirm that these specific credentials were exploited by The Gentlemen, the observed pattern is highly consistent with the typical attack kill chain for this type of incident. CTI teams should prioritize actions such as credential rotation, implementing multi-factor authentication, and conducting thorough endpoint reviews for the exposed accounts, treating this exposure as an active risk rather than a historical event.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.