SYS::ONLINE
Wasteland.
Briefs1722
Issues22
SinceFeb 2026
LIVE
█ Ransomware EPM-COLOMBIA-RANSO 2026-08-06

EPM: Everest Ransomware Claim Against Colombian Electricity, Water, Sewage and Gas Provider

"The Everest ransomware and extortion group has claimed an attack on Empresas Públicas de Medellín (EPM), the state-owned utility that supplies electricity, water, sewage and natural gas to Medellín and much of…"

The Everest ransomware and extortion group has claimed an attack on Empresas Públicas de Medellín (EPM), the state-owned utility that supplies electricity, water, sewage and natural gas to Medellín and much of Antioquia. Colombian security firm A3Sec's threat intelligence team reported on 9 July 2026 that Everest had published more than 20 GB of corporate data stolen from EPM and its subsidiary CHEC on a Tor leak site, including 22 Power BI semantic models. Undercode News separately reported the Everest claim against EPM on 5 August 2026. Readers should note the sourcing carefully: as of publication no statement from EPM itself, no filing with a Colombian regulator, and no ColCERT advisory naming EPM appears among the available sources. Everything below that concerns EPM rests on third-party threat intelligence and trade reporting, not on the victim's own confirmation.

What Happened

The two accounts of the EPM incident do not line up neatly on timing, and that gap is worth stating plainly rather than smoothing over.

A3Sec, a Madrid-headquartered security vendor with operations in Colombia and Mexico, published its assessment on 9 July 2026, describing the leak as already complete: Everest had, in A3Sec's words, confirmed publication of more than 20 GB of corporate data extracted from EPM and CHEC. Undercode News reported the Everest claim against EPM nearly a month later, on 5 August 2026, framing it as a fresh incident and noting that the group had "claimed involvement in an attack against the organization." Neither source gives an intrusion date, a dwell time, or a point of entry.

The most likely reading is that these describe the same campaign at different stages of public visibility, with A3Sec catching the leak-site posting in early July and later coverage amplifying it. But that is inference, not a fact either source states. A third item in the reporting set, an Undercode News piece from 2 August, covers a vague dark-web post referencing "🇨🇴 Colombia – Data Breac…" with no named victim, no volume, and no actor. That post cannot responsibly be tied to EPM, and the outlet itself cautioned that it "should not be described as a confirmed Colombian data breach."

Critically, no source in this set documents an actual disruption to electricity, water, sewage or gas delivery. The headline risk to millions of customers is a stated concern about what a utility compromise could mean, not a reported outage. Defenders should treat the operational-impact question as open.

What Was Taken

The most specific claim comes from A3Sec, and it is unusual enough to be worth dwelling on. Rather than a conventional dump of documents, spreadsheets and credentials, Everest is reported to have released 22 Power BI semantic models in .pbix format, drawn from both EPM and CHEC. A3Sec characterised the contents as covering:

A .pbix file is not just a report. It packages the data model, the relationships between tables, the calculated measures, and often a cached extract of the underlying data. Twenty-two of them from a utility's finance and operations functions amounts to a working map of how the organisation measures itself: which customers are delinquent, how exposure is scored, and which operational thresholds matter internally. A3Sec's framing is apt here, that the impact of an attack is measured not only in downed systems but in the exposure of an organisation's strategic decision-making.

Volume is reported as "more than 20 GB" by A3Sec alone. No other source in this set provides an independent figure, a record count, or a sample. That single-source status is a real limitation, and the number should be carried with attribution rather than repeated as established fact.

Why It Matters

EPM does not sit in isolation. The Colombian energy sector has absorbed a run of pressure across mid-2026, and the pattern across incidents is more instructive than any single one.

On 17 July 2026, Ecopetrol S.A., Colombia's largest company and the source of more than 60% of national hydrocarbon production, disclosed unauthorised access to cloud-based file storage across roughly 15 subsidiaries and the unauthorised download of data tied to approximately 3,300 user accounts. The attacker was unidentified and communicated extortion demands. Notably, Ecopetrol's controls blocked deployment of an encryptor. In a 20 July follow-up the company confirmed impact was limited to file downloads, with no integrity compromise "despite the external threat actor's attempts to destroy, delete, and/or encrypt data," and no capture of user identities or access credentials. Reuters reported the company could not guarantee the breach would avoid a "material adverse" financial impact, while stating no critical operational or production disruption had been identified. Ecopetrol's disclosures are direct company statements and carry more weight than any third-party account of EPM.

Two state-linked energy entities under extortion pressure inside a four-week window is a sector-level signal. A3Sec's warning about third-party exposure sharpens it: Everest has operated since 2020 under a double-extortion model and frequently functions as an Initial Access Broker, selling footholds into breached networks. Organisations with shared infrastructure, technology integrations or VPN connectivity to EPM or CHEC face live lateral-movement and indirect-exposure risk, regardless of what EPM eventually confirms.

There is also a physical dimension that shapes how resilient EPM actually is. In a separate July 2026 report, the utility said cable theft and vandalism had caused close to COP 25,000 million in damage to its underground energy network so far in 2026, that it spent over COP 7,200 million on repairs across 2024 and 2025, and that more than 763,000 customers experienced service interruptions from those incidents, averaging 24.6 hours per event. A network already absorbing repeated physical degradation has less headroom to absorb a cyber event on top of it.

The Attack Technique

Initial access remains unknown. No source in this set identifies an exploited vulnerability, a phishing campaign, a compromised credential, or a third-party entry point for the EPM intrusion.

What can be said about the actor's tradecraft comes from A3Sec's profile and from the shape of the leak. Everest runs double extortion: exfiltrate first, encrypt second, and publish on a Tor leak site to force payment. Whether encryption was actually deployed at EPM is not stated anywhere in the available reporting, and the absence of any documented service disruption is at least weakly consistent with a theft-and-extort operation rather than a destructive one. The group's parallel role as an Initial Access Broker means an EPM intrusion may have originated in purchased access, and may equally end with residual access being resold.

The Ecopetrol case, which is far better documented, offers a useful contrast in technique and outcome. There the actor targeted cloud-based file storage across a subsidiary estate, performed mass downloads, attempted destruction and encryption, and failed at the encryption stage because controls held. Ecopetrol responded by revoking unauthorised access, blocking mass-download mechanisms, analysing the TTPs, filing a criminal complaint with the Attorney General's Office, and identifying external infrastructure used to stage the stolen data. That sequence, cloud file stores as the target and bulk exfiltration as the objective, is the sector's demonstrated pattern in 2026. Its relevance to EPM is analogous, not evidentiary.

What Organizations Should Do

For Colombian critical infrastructure operators and anyone connected to EPM, CHEC or the wider Grupo EPM supply chain:

  1. Audit your perimeter against EPM and CHEC connectivity. A3Sec's guidance is to formally request confirmation of security status from any partner sharing infrastructure with the affected entities, and to review event logs for anomalous connections across the relevant window. Start no later than early July 2026.
  2. Revoke shared secrets on suspicion, not confirmation. Rotate credentials, VPN certificates and API keys shared with the affected entities now. Waiting for EPM to confirm scope converts an inexpensive precaution into an incident.
  3. Treat BI platforms as crown-jewel data stores. The reported theft of 22 .pbix files illustrates that analytics platforms concentrate exactly the material an extortionist wants. Apply the same access controls, egress monitoring and export restrictions to Power BI, Tableau and equivalents that you apply to your ERP or data warehouse, and alert on bulk model exports.
  4. Instrument cloud file storage for mass-download behaviour. Ecopetrol's stated response included blocking mechanisms associated with mass information download. Detection thresholds on bulk retrieval from SharePoint, OneDrive, S3 and equivalent stores, tuned per subsidiary, would have shortened that incident.
  5. Enforce MFA and active EDR/SIEM coverage without exception. A3Sec's recommendation is strict MFA plus continuous monitoring. In practice the gaps are usually service accounts, legacy VPN endpoints and subsidiary estates outside the parent's tooling, which is precisely where a 15-subsidiary cloud footprint gets breached.
  6. Segment IT from OT and rehearse the disconnect decision. With no confirmed operational impact at EPM, the open question for every utility is whether an IT-side compromise could reach control systems. Know your boundary, verify it holds, and decide in advance who is authorised to sever it.
  7. Engage national authorities early. Ecopetrol coordinated with ColCERT under its critical national infrastructure designation, alongside the Attorney General's cybercrime directorate, the Joint Cyber Command (CCOCI) and the National Police's DIJIN. Colombian operators should have those escalation paths established before they are needed.

Where the sources conflict, this brief has said so. The EPM claim is credible and specific but rests on third-party intelligence; the Ecopetrol details are company-confirmed. Treat the two accordingly until EPM speaks for itself.

Sources: Ransomware Attack Targets Colombia’s EPM, Threatening Critical Elec... | Ecopetrol confirms ransomware attempt, data stolen from 3,300 accou... | Brecha en Infraestructura Crítica: Filtran modelos de inteligencia... | Ecopetrol Reports Cybersecurity Incident | Colombia Data Breach Claim Raises Fresh Cybersecurity Concerns — Da... | Ecopetrol Continues to Implement Monitoring and Protection Measures... | Colombia’s Ecopetrol says cyberattack stole data tied to 3,300 acco... | EPM alerta: el robo a la red eléctrica nos afecta a todos - Valor&N...