Colombia's Ministry of Justice and Law confirmed on 3 August 2026 that it was the victim of a ransomware attack that compromised part of its technological infrastructure and affected the availability of some of its services. Containment protocols were activated on detection, including the preventive isolation of compromised systems to stop propagation.
The incident lands four days before the 7 August presidential transition, and one day after Colombia's national CERT published a threat intelligence report on ransomware activity in the country.
Details remain limited, and this briefing is explicit about that boundary. What follows separates what has been officially confirmed from what has not yet been established - because in the first hours of a public-sector ransomware incident, the gap between the two is where most bad analysis is produced.
What Has Been Confirmed
Justice Minister Cielo Rusinque confirmed the incident publicly and rejected the attack on the state's technological infrastructure, stating that the government would not yield to this type of attack and would continue strengthening cybersecurity capabilities. The Attorney General's Office, the National Police, and other competent authorities were called on to advance the investigation, identify those responsible, and bring them to justice.
Minister-designate Iván Cancino separately raised the incident publicly, urging authorities to act quickly to verify the scope and purpose of the intrusion.
CONFIRMED
- The Ministry of Justice and Law was the target of a ransomware attack.
- Part of the ministry's technological infrastructure was compromised.
- Availability of some institutional services was affected.
- Cybersecurity and containment protocols were activated immediately, including preventive isolation of compromised systems.
- The response is being coordinated with the Ministry of ICT and other national authorities.
- The Fiscalía and the National Police have been asked to investigate.
What Has Not Been Established
As of publication, several determinative facts are not public. Their absence is normal at this stage of an incident and should not be filled with assumption.
NOT YET ESTABLISHED
- No ransomware group has been publicly attributed.
- No initial access vector has been disclosed.
- No ransom demand or figure has been made public.
- Data exfiltration has not been confirmed or ruled out publicly.
- The number of affected systems and the recovery timeline have not been published.
- Whether other state entities are affected has not been officially addressed.
That last point is the one worth watching. In Colombian public-sector incidents, the initial disclosure has historically understated the perimeter - not through concealment, but because shared infrastructure means the full blast radius is genuinely unknown in the first days.
"In the first 72 hours of a government ransomware incident, the most dangerous number is the one nobody has measured yet: how many other entities share the compromised infrastructure."
Why the Timing Is Operationally Significant
Two contextual facts sharpen the assessment.
The presidential transition. The attack surfaced four days before the 7 August inauguration, with a minister in office and a minister-designate incoming. Ransomware crews target transition periods deliberately. Decision authority is ambiguous, attention is elsewhere, budget approval paths are unclear, and the pressure to restore services quickly - rather than correctly - is at its peak. That is precisely the environment in which ransom payment becomes politically thinkable.
The ColCERT advisory. Colombia's national CERT published threat intelligence report IN-20260802-043 on ransomware in Colombia on 2 August 2026 - the day before the ministry confirmed its incident. Whether or not the two are connected, the sequence indicates a national threat picture already active enough to warrant a formal intelligence product.
The Precedent Colombia Already Lived
Colombia has a documented reference case for what a public-sector ransomware incident can escalate into, and it is worth stating precisely because it is the ceiling this incident should be measured against - not a description of what has happened here.
In September 2023, a ransomware attack on IFX Networks, a technology provider hosting applications and cloud infrastructure for numerous government agencies, cascaded across the Colombian state. The judicial branch, the Ministry of Health, and the Superintendency of Industry and Commerce were among the entities affected. Roughly 762 companies across Latin America were touched. Some two million judicial proceedings were suspended, and the Supreme Court halted hearings for close to a week. RansomHouse was the suspected actor.
The lesson of 2023 was not about malware. It was about concentration. A single compromised provider reached across dozens of institutions because those institutions shared infrastructure they did not individually control.
Critical Observation
- The 2023 IFX Networks incident is historical context, not the current event. The Ministry of Justice incident of August 2026 is a separate case with no confirmed link to a shared provider. It is cited here because it defines the escalation pattern Colombian state entities must plan against.
What This Class of Attack Actually Looks Like
Public-sector ransomware follows a consistent pattern regardless of which crew executes it.
- 1.Initial access through an exposed remote-access service, an unpatched edge appliance, or a phished or purchased credential.
- 2.Discovery and escalation, mapping directory services and locating file shares and backup infrastructure.
- 3.Defense evasion, disabling endpoint protection and clearing logs.
- 4.Exfiltration of sensitive records - in a justice context, case files, personnel data, and citizen records.
- 5.Encryption, typically timed for nights, weekends, holidays, or transitions when staffing is thin.
- 6.Extortion, with public pressure applied through leak sites and national media.
Justice-sector data raises the stakes at stage four. Case files, judicial records, and personnel information carry consequences that outlast any outage: witness exposure, procedural challenges to evidence integrity, and long-tail privacy harm to citizens who were never parties to the security decision.
Detection Opportunities
- Off-hours and impossible-travel authentication against remote-access infrastructure.
- A single account enumerating or reading case-file repositories at volume.
- Living-off-the-land tooling running in administrative context.
- Sustained outbound transfers to unfamiliar hosting or cloud storage.
- Attempts to disable endpoint protection, delete shadow copies, or reach backup servers.
- Credential anomalies on government mobile fleets, which are increasingly the softest path to a valid session.
Where DATAENFORCE Technology Changes the Outcome
DATAENFORCE builds for sovereign and government environments in Colombia and internationally, and this incident maps directly onto the layers the portfolio was designed to cover.
[VALIANT](/en/products/valiant) is the anti-ransomware and data-extortion layer. It intercepts payload execution and the pre-encryption behaviours that precede it - shadow-copy deletion, backup enumeration, mass file modification. Preventing the detonation is what converts an incident into an alert instead of a service outage and a public statement.
[OSPREY](/en/products/osprey) addresses the half of the attack that persists even when encryption is stopped. It baselines behaviour per identity and role and surfaces the bulk reads, staging, and outbound transfers that constitute exfiltration. In a justice ministry, that is the difference between a recoverable availability incident and the permanent public exposure of case files.
[DAEDALUS](/en/products/daedalus) analyses malware, phishing, and smishing - the entry stage where most public-sector intrusions actually begin, long before any ransomware component is deployed.
[PROXIMITY](/en/products/proximity) and [VANGUARD](/en/products/vanguard) cover the government mobile estate: sovereign Android fleet management and device-level data protection. Ministerial mobile devices hold credentials, session tokens, and documents, and they are consistently the least monitored asset class in government networks.
[INFOTRACK](/en/products/infotrack) governs document tracking and information lifecycle. When a justice institution must answer which case files moved and who touched them, document-level visibility turns a months-long forensic reconstruction into an auditable record - and it supports the notification obligations that follow.
Recommended Countermeasures
- Enforce phishing-resistant MFA across every remote-access and privileged account in the ministry and its dependencies.
- Inventory and contractually bind shared infrastructure providers - the 2023 lesson was that provider risk is state risk.
- Maintain offline, immutable, tested backups unreachable from the production domain.
- Segment so that one compromised endpoint cannot reach case-file repositories.
- Deploy behavioural detection targeting the pre-encryption window rather than payload signatures.
- Pre-authorise incident decision rights that survive a ministerial transition, so that authority is never ambiguous mid-incident.
Executive Takeaways
- Isolation contained the propagation. It does not answer whether data left first.
- Transition periods are targeted deliberately; decision authority must be pre-assigned, not improvised.
- Shared government infrastructure converts one intrusion into many incidents - map that dependency before it is tested.
- Judicial data exposure outlasts any outage; exfiltration detection is the control that matters most in this sector.
- Treat the ColCERT advisory as an operational input, not a document to file.
Strategic Assessment
The Ministry of Justice acted correctly on the information available: it detected, isolated, escalated to law enforcement, and disclosed publicly on the same day. That is a materially better posture than Colombia demonstrated in 2023.
The open question is not containment. It is whether data left before isolation, and whether the compromised infrastructure is shared with other entities of the state. Those two answers will determine whether this is remembered as a contained ministerial incident or the first confirmed node of something wider.
Colombian state entities should treat the next several days as an active threat window - particularly those sharing providers, identity infrastructure, or network paths with the ministry, and particularly across the 7 August transition.
For the corporate-sector counterpart to this pattern, see our analysis of the Ecopetrol ransomware incident of July 2026, where the encryption was blocked and the data was taken anyway.
Sources
- Ministerio de Justicia confirma ataque cibernético con ransomware - Noticias RCN
- Ministro designado Iván Cancino denuncia presunto ataque cibernético contra sistemas del Ministerio de Justicia - El Heraldo
- COLCERT IN-20260802-043 Informe de inteligencia de amenazas: ransomware en Colombia
- Several Colombian government ministries hampered by ransomware attack (September 2023 precedent) - The Record
About this report
This briefing reflects publicly available information as of 3 August 2026, the day the Ministry of Justice and Law confirmed the incident. Details are incomplete by nature at this stage; sections marked as not established are explicitly unconfirmed and should not be treated as findings. The September 2023 IFX Networks incident is included as historical precedent only and has no confirmed connection to the current event. DATAENFORCE has not conducted forensic work on this incident and makes no claim about the ministry's internal security posture. This is a strategic briefing for public-sector security leaders, not legal or incident-specific advice. It will be updated as verified information becomes available.