Colombia Justice Ministry Hit With Ransomware
Ransomware disrupted Colombia's Ministry of Justice days before the presidential transition, part of a documented pattern of attacks on Latin American government institutions.
Ransomware hit Colombia’s Ministry of Justice (Ministerio de Justicia y del Derecho) in the days surrounding the country’s presidential transition, according to Dark Reading. The attack follows a documented escalation of ransomware activity across Latin American government and critical infrastructure targets.
No ransomware group has publicly claimed responsibility as of this writing. Attribution: unconfirmed — treat accordingly.
What’s confirmed
- Target: Colombia’s Ministry of Justice
- Timing: days before or around the August 2026 presidential transition
- Pattern: researchers characterize this as part of sustained, increasing ransomware activity against Latin American government institutions and critical infrastructure
- Official statement on operational impact: not yet released
What’s not confirmed
- Ransomware variant or operating group
- Whether data was exfiltrated
- Whether a ransom demand was issued
- Scope of operational disruption to judicial processes
Context
Colombia has faced repeated cyberattacks against state institutions. This incident reflects a broader documented trend — municipalities, national ministries, utilities, and infrastructure operators across Latin America have drawn consistent ransomware attention.
Transition periods represent a recognized risk window. A ministry managing judicial data, criminal records, and legal processes is high-value. Institutional continuity is under stress during any administration handover — access control reviews, personnel changes, and divided operational attention are all factors.
Analysis: whether the timing against Colombia’s transition is deliberate targeting or opportunistic is unconfirmed. The overlap is notable. Flag it as a hypothesis, not a conclusion, until attribution is established.
What to watch
- Official statement from Colombia’s Ministry of Justice or COLCERT (Colombia’s national CSIRT)
- Ransomware group claim on public leak sites
- Whether judicial operations were disrupted through the transition window
- CISA or regional CERT advisories on any associated vulnerability or initial access vector
Related coverage: Gunra Ransomware Crew Draws FBI Advisory, Storm-1175 StormEncryptor: China-Linked Ransomware Targets Critical Infrastructure, DeadLock Moves Extortion Infra to Polygon Blockchain
Found this useful? Share it.


