Desk live·
ForensicPost
Ransomware/Public sector/File 26-0802b

Colombia’s Justice Ministry Hit by Ransomware Five Days Before Presidential Handover

Ransomware encrypted files at Colombia’s Ministry of Justice on 2 August, cutting availability of drug-monitoring and legal services. The national CERT had warned about rising ransomware activity in the country the day before.

Constructed geometry · not a chart of case data
JurisdictionColombiaBogotáthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetMinistry of Justice, Colombia
ActorUnattributed
D. Kennedy9 min readConfidence: medium2 sources reviewed

Ransomware reached Colombia’s Ministry of Justice on 2 August 2026, affecting part of its technology estate and reducing the availability of several public-facing services, among them systems supporting illicit-drug monitoring and legal processes. The ministry says it activated containment protocols on detection and isolated affected systems to stop the spread.

Officials say files were encrypted but that no data theft was detected. No operation has claimed the attack and no entry route has been published. ColCERT, the national computer emergency response team, had published a warning the previous day that ransomware groups were increasing their focus on Colombia. The presidential handover followed on 7 August.

The Timing

A transition of government is a thin week. Attention sits elsewhere, appointments are unsettled, and the officials who would normally own an incident decision may be on their way out. Attacks timed to holidays appear repeatedly in this database — Ardent Health was encrypted on Thanksgiving morning, SickKids the week of Christmas — and a handover is a longer version of the same gap.

We are not asserting the date was chosen. Nobody has claimed the attack and no scheduling evidence has been published. The sequence is on the record and the inference is available; we are leaving it there.

A Warning With A Day To Act On It

ColCERT published its alert twenty-four hours before. That is the output a national threat intelligence function exists to produce, and it made no difference here, because nothing about a ministry’s exposure can be changed in a day.

The same pattern showed up in July, when US agencies warned water utilities about internet-facing controllers. Warnings of this kind are useful in the months before an attack, not the day before one.

What "No Data Theft" Rests On

Establishing that nothing left requires egress telemetry, retained long enough to examine. Most organisations in this database do not have it: our own audit of the corpus found 251 files where no entry route was ever established, usually for want of logs.

Almost every ransomware operation we track exfiltrates before encrypting. An organisation reporting no theft in the first days of an investigation is reporting what it can currently see, which is not the same claim. Graded medium: the operation is unidentified, the route is unpublished, and no figure for affected systems or downtime has been released.

How we reported this

Compiled from public reporting of Colombian officials’ statements, listed below. No operation has been identified and we are not speculating on one. No duration or record count has been published. Corrections: corrections@forensicpost.com.

Sources
  1. Ransomware Hits Justice Ministry as Colombia Gets New PresidentDark Reading
  2. Colombia’s Ministry of Justice hit by ransomware attackSC Media
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary