Ransomware reached Colombia’s Ministry of Justice on 2 August 2026, affecting part of its technology estate and reducing the availability of several public-facing services, among them systems supporting illicit-drug monitoring and legal processes. The ministry says it activated containment protocols on detection and isolated affected systems to stop the spread.
Officials say files were encrypted but that no data theft was detected. No operation has claimed the attack and no entry route has been published. ColCERT, the national computer emergency response team, had published a warning the previous day that ransomware groups were increasing their focus on Colombia. The presidential handover followed on 7 August.
The Timing
A transition of government is a thin week. Attention sits elsewhere, appointments are unsettled, and the officials who would normally own an incident decision may be on their way out. Attacks timed to holidays appear repeatedly in this database — Ardent Health was encrypted on Thanksgiving morning, SickKids the week of Christmas — and a handover is a longer version of the same gap.
We are not asserting the date was chosen. Nobody has claimed the attack and no scheduling evidence has been published. The sequence is on the record and the inference is available; we are leaving it there.
A Warning With A Day To Act On It
ColCERT published its alert twenty-four hours before. That is the output a national threat intelligence function exists to produce, and it made no difference here, because nothing about a ministry’s exposure can be changed in a day.
The same pattern showed up in July, when US agencies warned water utilities about internet-facing controllers. Warnings of this kind are useful in the months before an attack, not the day before one.
What "No Data Theft" Rests On
Establishing that nothing left requires egress telemetry, retained long enough to examine. Most organisations in this database do not have it: our own audit of the corpus found 251 files where no entry route was ever established, usually for want of logs.
Almost every ransomware operation we track exfiltrates before encrypting. An organisation reporting no theft in the first days of an investigation is reporting what it can currently see, which is not the same claim. Graded medium: the operation is unidentified, the route is unpublished, and no figure for affected systems or downtime has been released.
Compiled from public reporting of Colombian officials’ statements, listed below. No operation has been identified and we are not speculating on one. No duration or record count has been published. Corrections: corrections@forensicpost.com.