Colombia's Ministry of Justice and Law confirmed publicly that a ransomware attack compromised part of its technology infrastructure and degraded the availability of several public-facing services in the first days of August 2026, days before the country's Aug. 7 presidential handover. Then acting Justice Minister Cielo Rusinque confirmed the incident, said files had been encrypted, and denied that any data was stolen. No threat group has claimed the attack, no ransom demand has been made public, and the intrusion vector remains unstated by the ministry. The incident landed one day after Colombia's national CERT (ColCERT) published a threat intelligence warning that ransomware operators had sharply increased their focus on the country.
What Happened
Accounts differ on the exact day. Dark Reading, SC Media, and Undercode News all date the attack to Aug. 2; the Colombian outlets that covered the ministry's own communiqué (Infobae, Semana, Cambio, El Universal) and the DATAENFORCE briefing describe the ministry confirming and detecting the incident on the morning of Monday, Aug. 3. The most consistent reading is an attack executed on or around Aug. 2 that was detected, contained, and publicly disclosed on Aug. 3. The same discrepancy propagates into the timing framing: Dark Reading and SC Media call it five days before the presidential handover, while DATAENFORCE says four days. Both are describing the same Aug. 7 transition.
What the sources agree on is the response. Per the ministry's statement, reproduced by Semana, Infobae, and Cambio, cybersecurity, containment, and preventive isolation protocols were activated as soon as the anomaly was detected, with compromised systems pulled offline to stop the malware spreading. The ministry said it was working with MinTIC, Colombia's ICT ministry, and other specialised authorities to contain damage, delimit the scope of the attack, and restore systems safely.
Rusinque publicly rejected the attack and called on the Fiscalía General de la Nación (Attorney General's Office) and the National Police to investigate with maximum speed, identify those responsible, and bring them to justice. "No cederemos ante este tipo de ataques y continuaremos fortaleciendo nuestras capacidades de ciberseguridad para proteger la información institucional," she said, per Cambio: we will not yield to this type of attack, and we will continue strengthening our cybersecurity capabilities.
The disclosure was, notably, not first made by the outgoing government. El Universal and Semana report that incoming minister designate Iván Cancino flagged the incident first on Instagram, writing that an attack had apparently occurred against ministry systems and asking authorities to move quickly to verify who was responsible and what the attack's purpose was. The ministry's formal confirmation, posted to the @MinjusticiaCo account on X, followed.
On service impact, Dark Reading and SC Media report disruption to services tied to illicit-drug monitoring and legal processes. Cambio provides the most operational detail available in these sources: the ministry moved to receiving and filing documents in person while systems recovered, and named the Sistema de Información de Casas de Justicia (SICJ) among the platforms taken down but served through alternate channels. Some applications remained active throughout.
What Was Taken
Nothing, according to the victim. This is the single most contested point in the reporting, and the sources split cleanly.
Rusinque, in a Spanish-language broadcast interview quoted by Dark Reading, was explicit: "Some files were encrypted. We are currently working on overcoming that encryption, [but] it has already been verified ... that there was no data capture. That was the first thing I asked." SC Media and Undercode News both echo this denial, and both note that earlier reports had suggested data leakage. None of the eight sources here names the outlet that made the exfiltration claim, quantifies it, or points to a leak site listing. There is no record count in evidence, in either direction.
Treat the no-exfiltration claim as the ministry's position rather than as an independently verified finding. It was made within days of detection, by an official who left the post during the transition the following week, and before any public forensic conclusion. DATAENFORCE's briefing, written on Aug. 3, is explicit that details remain limited and draws a hard line between what was officially confirmed (that ransomware struck, that part of the infrastructure was compromised, that services degraded, that containment ran) and what was not. Modern ransomware operations overwhelmingly stage data before encrypting, so an early "no data capture" statement is a claim that should age under scrutiny, not a closed question. Absent a claim post, a ransom note, or a completed incident report, the honest position is that exfiltration is unconfirmed in both directions.
Why It Matters
A justice ministry is not an ordinary government target. The systems in scope touch legal proceedings, case management, and illicit-drug monitoring, which in Colombia's context means data of direct interest to organised crime as well as to anyone conducting political reconnaissance. Even a pure availability event against those systems has downstream effects on legal timelines and casework.
The timing is the second half of the story, and every source lands on it. A presidential handover is the highest-friction window in a government's calendar: authority is ambiguous, senior officials are leaving, incoming officials have no operational history with the systems they are inheriting, and incident response decisions cross an administrative boundary. Rusinque left the post during the transition the week after the attack, meaning the official who fronted the initial denial was not the official who owns the recovery. Undercode News frames this generally, and correctly: transitions, restructurings, and periods of national uncertainty create windows because defenders are distracted and responsibilities are in flux. Colombia was simultaneously responding to a 7.4-magnitude earthquake that struck Chocó on Aug. 10, compounding the demand on national crisis capacity.
The regional pattern is the third layer. ColCERT's warning, published a day before the attack, specifically flagged rising ransomware interest in Colombia. Dark Reading notes prior incidents including an alleged March compromise of the national tax authority DIAN by an actor using the alias "ArcRaid," and SC Media adds state oil and gas company Ecopetrol to the list. SC Media reports that experts are seeing a significant increase in exploit attempts and a growing concentration of malicious activity against vulnerable infrastructure in Colombia, attributed to automated and increasingly mature criminal ecosystems abusing cloud service vulnerabilities and third-party relationships. This is not a one-ministry problem; it is a sustained campaign posture against Latin American public sector and critical infrastructure targets.
The Attack Technique
Unknown, and none of these eight sources claims otherwise. There is no named ransomware family, no affiliate or group attribution, no initial access vector, no dwell time estimate, and no published indicators of compromise. The only technical fact confirmed by the victim is that file encryption occurred on at least part of the estate, and that recovery work focused on overcoming that encryption, which suggests decryption or restoration was still in progress rather than complete at the time of Rusinque's interview.
What the ministry's own account does reveal is defensive posture rather than attacker tradecraft: detection triggered containment protocols, and compromised systems were preventively isolated to prevent propagation. That the ministry could isolate segments and keep some applications running while others went dark implies some degree of segmentation, though the sources do not describe the architecture.
For context on plausible entry paths rather than confirmed ones, SC Media's regional framing points at exploitation of cloud service vulnerabilities and abuse of third-party relationships as the dominant patterns driving the Latin American surge. Applied to this incident, that is a hypothesis, not a finding. Anyone attributing this attack to a specific group or vector right now is working ahead of the evidence.
What Organizations Should Do
- Harden the transition window. Treat leadership changes, machinery-of-government moves, and major reorganisations as elevated-risk periods with a named incident commander whose authority explicitly survives the handover. Document who can authorise isolation, ransom decisions, and public statements on both sides of the changeover date, before the date arrives.
- Do not certify "no data was stolen" early. Availability impact is visible in hours; exfiltration is not. Until egress telemetry, cloud storage access logs, and outbound volume baselines have been reviewed by responders, the accurate public statement is "we have found no evidence of exfiltration to date and the investigation continues." Premature denials cost credibility if a leak site post appears later.
- Act on national CERT advisories within days, not quarters. ColCERT warned of intensifying ransomware targeting of Colombia one day before this attack. Build a process that converts a national CERT bulletin into a concrete hunt task, a patch sprint, and an exposure review with a deadline attached.
- Pre-build manual continuity paths for citizen-facing services. The ministry fell back to in-person document filing and published alternate routes for downed systems such as the SICJ. That fallback works only if it is designed and staffed in advance. Identify your top public services, define the offline process for each, and rehearse it.
- Segment so that isolation is a scalpel, not an axe. Preventive isolation worked here at least partially. Validate that you can sever a compromised segment without severing everything, and test it, especially where a single ministry or business unit hosts multiple unrelated public services.
- Assume identity and third-party access are the way in. Given the reported regional pattern of cloud vulnerability exploitation and supplier abuse, enforce phishing-resistant MFA on all remote and administrative access, inventory every third party with network or cloud access, and time-box their privileges.
- Protect and test backups against an encryption-first adversary. Keep immutable, offline copies of case management and records systems, and measure restore time against the actual service-level expectation for legal processes, not a theoretical RTO.
Sources: Ransomware Hits Justice Ministy as Colombia Gets New President | Colombia’s Ministry of Justice hit by ransomware attack brief SC... | Ataque cibernético contra el Ministerio de Justicia: se reportan fa... | Ransomware Hits Colombia's Ministry of Justice: What Is Confirmed,... | Colombia’s Justice Ministry Hit by Ransomware as a Political Transi... | Gobierno Petro denuncia ataque cibernético contra MinJusticia; mini... | MinJusticia, víctima de un ciberataque: qué pasó y cuáles servicios... | Ministerio de Justicia sufre ciberataque con ransomware, confirma I...