ShellCodeX
Tools โ€ข Events โ€ข News โ€ข Insights
Victim Claim

Ecopetrol

thegentlemen ๐Ÿ‡จ๐Ÿ‡ด Colombia Energy www.ecopetrol.com.co
Claimed by thegentlemen
Listed on leak site 19 Jul 2026
Reported attack date 17 Jul 2026
Group claims tracked 373
Unverified claim. This entry reproduces a listing published by the thegentlemen group on its own extortion site. Attackers routinely exaggerate or fabricate victims. Nothing here confirms that Ecopetrol suffered a breach, or what data was actually taken.

About the organisation

$33.1 Billion. www.***.com.co ECOPETROL copetrol SA is a company organized as a public limited company, of national order, linked to the Ministry of Mines and Energy. It has operations located in the center, south, east and north of Colombia, as well as abroad. It has two refineries in Barrancabermeja and Cartagena. Through its subsidiary Cenit, specialized in hydrocarbon transportation and logistics, it owns three ports for the export and import of fuels and crude oil in Coveรฑas (Sucre) and Cartagena (Bolvar) with access to the Atlantic, and Tumaco (Nariรฑo) on the Pacific. Cenit also owns most of the country's oil and multi-purpose pipelines that connect production systems with large consumption centers and maritime terminals. Ecopetrol also has a stake in the biofuels business and is present in Brazil, Mexico and the United States (Gulf of Mexico and Permian Texas). 1TB+ Stock Symbol = ECOPETROL

What the listing means

Ecopetrol appeared on the thegentlemen leak site on 19 July 2026. Groups publish a victim once negotiations stall or as pressure during them, so a listing usually means data was already exfiltrated โ€” the attack itself is dated 17 July 2026, 2 days before the listing. This group has published 134 claims in the last 30 days and remains active.

Recommended actions

  • Treat any unsolicited message referencing Ecopetrol as suspicious โ€” leaked data gets weaponised for phishing within days.
  • If you hold an account on www.ecopetrol.com.co, change that password now, update it anywhere you reused it, and enable two-factor authentication.
  • Other Energy organisations should review this group's known TTPs and validate detection coverage against them.
  • Watch for follow-on extortion: stolen data is often re-leaked or resold after the initial listing.
  • A leak-site listing is a claim made by the attacker, not a confirmed breach โ€” check the organisation's own disclosures before acting on it.

Leak-site evidence

Listing URL https://www.ransomware.live/id/RWNvcGV0cm9sQHRoZWdlbnRsZW1lbg==