LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surface
Recent BreachesData breach tracker

Recent Breaches › Ecopetrol Listed by thegentlemen Ransomware Group

HIGH severityConfirmedHow we verify

Ecopetrol Listed by thegentlemen Ransomware Group: What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·July 19, 2026
Ecopetrol Listed by thegentlemen Ransomware Group

Occurred July 2026 · publicly disclosed July 19, 2026.

HIGH
Severity
1
Data types exposed
July 19, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Ecopetrol was listed by thegentlemen ransomware group on July 19, 2026, after internal files were exfiltrated in a ransomware attack. An undisclosed number of people may have been affected; check the company’s notices and monitor accounts for unusual activity.

Severity & verification
HIGH severityConfirmed
Contact / identity PII exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the Ecopetrol Listed by thegentlemen Ransomware Group breach?
See every leak tied to your email — not just this one. 15-second check, no card, no account.

On July 19, 2026, the Colombian energy company Ecopetrol was listed by the ransomware group known as thegentlemen. Public reporting describes the incident as a ransomware attack in which internal files were exfiltrated. The number of people affected remains unknown, and broader technical detail about timing, intrusion method, and full scope has not been disclosed in available accounts.

The listing itself is a claim published by the group. What is confirmed in the public record is limited: Ecopetrol appears on the group's leak-site material in connection with alleged theft of internal files. For an organisation of national scale in oil, gas, and energy logistics, any confirmed exposure of internal material carries operational and privacy consequences that warrant careful, factual attention rather than speculation.

Inside the incident

According to the reported summary, Ecopetrol was named by thegentlemen in connection with a ransomware attack involving exfiltration of internal files. The date associated with public reporting of the listing is July 19, 2026. No verified figure has been given for the number of individuals whose personal data may have been involved. Specifics such as the initial access vector, the duration of unauthorised access, the volume of data taken, or whether systems were encrypted in addition to data theft have not been detailed in the material provided.

Ransomware incidents of this type typically involve both the threat of data publication and pressure on the victim organisation. In this case, the public facts stop at the group's claim that internal files were removed. Independent confirmation of the full contents, the success of any recovery efforts, or the status of negotiations—if any occurred—is not part of the available record. Readers should treat the leak-site listing as an unverified assertion by the actors until corroborated by the company or by regulators.

Who is thegentlemen?

thegentlemen is a ransomware group that, like other actors in this category, is known publicly for double-extortion tactics: encrypting or disrupting systems while also stealing data and threatening to publish it if demands are not met. Such groups commonly operate leak sites where they list claimed victims and, in some cases, release samples or larger archives to increase pressure. Their tooling, affiliate models, and exact naming conventions can evolve, and public documentation of any single group's full history is often incomplete.

For this incident, the only specific claim tied to Ecopetrol in the given facts is the listing itself and the assertion that internal files were exfiltrated. No additional statements, ransom figures, or sample-file descriptions unique to this victim are included in the source material. Therefore no further claims by the group about Ecopetrol should be treated as established fact. Attribution rests on the group's own publication of the victim's name; it has not been independently verified here.

Ecopetrol and its sector

Ecopetrol is described in the reported material as a public limited company of national order, linked to Colombia's Ministry of Mines and Energy. It maintains operations across the centre, south, east, and north of Colombia as well as abroad, and operates refineries in Barrancabermeja and Cartagena. Through its subsidiary Cenit, which specialises in hydrocarbon transportation and logistics, it is associated with port facilities used for the export and import of fuels and crude oil, including sites with Atlantic and Pacific access. The same summary references a figure of $33.1 billion in a corporate context, underscoring the organisation's scale within the national energy economy.

Companies in the oil, gas, and energy-logistics sector routinely hold a mix of operational, commercial, and personal data. That can include employee and contractor records, technical and engineering documentation, commercial contracts, logistics and shipping data, and systems information tied to critical infrastructure. A breach affecting such an organisation matters because disruption or leakage can affect not only corporate confidentiality but also supply-chain partners, workers, and, in extreme cases, continuity of energy-related services. The national linkage and geographic footprint described above make the potential blast radius larger than that of a purely local private firm.

What was likely exposed

The facts name the exposed material only as "internal files exfiltrated in a ransomware attack." No inventory of file types, no count of records, and no confirmation of whether customer, employee, or purely technical data were included have been supplied. The number of people affected is explicitly unknown.

Organisations of Ecopetrol's type typically maintain human-resources files, vendor and partner information, operational reports, network and industrial-control documentation, and commercial correspondence. It is reasonable to expect that some combination of those categories could exist among "internal files," yet it would be inaccurate to state that any specific category was confirmed stolen. Exact contents remain unconfirmed. Until Ecopetrol or competent authorities publish a clearer accounting, any description of personal identifiers, financial details, or industrial secrets should be treated as hypothetical rather than established.

What's at stake

For individuals whose information may have been among the internal files, risks include targeted phishing, identity misuse, or social-engineering attempts that reference genuine internal context. Employees, contractors, and partners are often the first populations exposed when corporate file shares are taken. Because the headcount of affected people is unknown, the practical advice is precautionary rather than panic-driven: monitor accounts, treat unexpected messages with heightened scepticism, and watch for unusual activity on financial or government services.

For the organisation, stakes include operational confidentiality, regulatory and contractual obligations, reputational harm, and possible follow-on intrusion attempts that reuse stolen credentials or knowledge of internal systems. Energy-sector entities also face heightened scrutiny around critical-infrastructure resilience. None of these outcomes is proven solely by a leak-site listing; they are the concrete categories of harm that follow when internal material is confirmed to have left an organisation's control. Public detail on whether any of those harms has already materialised in this case remains limited.

If your data was in this breach

If you have a past or present relationship with Ecopetrol—as an employee, contractor, supplier, or partner—treat the incident as a prompt to tighten ordinary security hygiene. Change passwords on work-related and personal accounts that may have shared credentials, enable multi-factor authentication where it is available, and be alert for phishing that references the company, invoices, or internal projects. Review financial and credit activity for unfamiliar activity over the coming months. Keep records of any suspicious contact.

Because the precise contents of the exfiltrated files are unconfirmed and the number of people affected is unknown, there is no public list against which to check a name. You can still run a free exposure scan of your email address to see whether your information has already appeared in other known breach datasets; that step does not confirm or deny involvement in this specific incident, but it helps you understand your wider exposure and prioritise further protections.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyEcopetrol security record
64/100
DoxxScan™ · Moderate doxx risk
C- 60Below-average record

1 reported incident on record.

See Ecopetrol’s full breach history →

More recent breaches

Advanced Marketing Listed by thegentlemen Ransomware GroupJuly 25, 2026Vicenzi Group Listed by thegentlemen Ransomware GroupJuly 11, 2026Fortray Listed by thegentlemen Ransomware GroupJuly 11, 2026Internet Ag Listed by thegentlemen Ransomware GroupJuly 11, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Ecopetrol Listed by thegentlemen Ransomware Group →

Source: Ecopetrol S.A. (via PR Newswire) / Reuters

Verified breach

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram