CiberLATAMbywhalemate

Ecopetrol rules out credential theft after breach

The company said the incident only involved file downloads and did not affect 3,300 accounts or their credentials.

Whalemate Labs · AI-assisted researchJul 21, 20261 min read

Ecopetrol said its latest review found that a cyberattack only involved the download of company files. The company also ruled out any impact on the identity of 3,300 accounts or on their login credentials.

Ecopetrol said its latest review found that a cyberattack only involved the download of company files. The company also ruled out any impact on the identity of 3,300 accounts or on their login credentials.

Confirmed scope

The update, released by the company, narrows the incident to a file exfiltration. Based on that analysis, Ecopetrol said there is no evidence that the users linked to those 3,300 accounts were affected, or that their access data was exposed.

The key point in the statement is that the episode did not lead to any operational disruption, according to the company. That distinction matters because the company’s first statement focused on defining the technical event rather than describing a broader business impact.

What was ruled out

Ecopetrol specified two areas that, according to its most recent review, were not compromised. First, the identity of the users tied to the 3,300 accounts mentioned. Second, the access credentials.

The available information does not provide details on the method used, the origin of the attack, or the type of files downloaded. It also does not include any public attribution to a possible responsible party in the material provided. The company limited itself to sharing the results of its analysis and narrowing the scope of the incident.

Coverage from El Espectador and La República matches that same point, while the corporate report published in Yahoo Finance is also part of the available sources on the event.

Sources

View all