Extortion at Ecopetrol: Why Critical Infrastructure Requires On-Premises Air-Gapped Observability

Russ Warner
,
President & COO
Calendar grid icon with the month of August 2023 displayed, showing days Sunday to Saturday.

I was in Bogotá, Colombia this week and learned of a major cybersecurity incident that hit Ecopetrol, the country's largest oil and gas company.. 

The breach, linked to a ransomware-as-a-service group known as "The Gentlemen," involved the exfiltration of data from roughly 3,300 user accounts via compromised cloud storage. 

While Ecopetrol successfully blocked the encryption of its systems, the attackers eventually leaked the data after the company refused to pay an extortion demand.

This incident serves as a stark reminder of the hidden vulnerabilities found in centralized cloud repositories. When critical infrastructure operators rely on external clouds for their data, they open themselves up to third-party exposure and external attack surfaces.

Catching Exfiltration Before It Happens (Full-Stack Intelligence)

To stop an attack like the one seen at Ecopetrol, operators need more than simple "up or down" alerts; they need to see subtle behavioral changes that hint at lateral movement or data theft. 

Komodo Eye analyzes message volume trends and identifies abnormal patterns, such as sudden spikes in data transfers or flapping links.

The system detects when performance begins to trend in a dangerous direction before a total failure occurs.

 

And, it scans millions of logs for "rare events"—messages that might only appear a few times a year. These rare indicators act as an early warning system, allowing engineers to catch the first subtle signs of a breach during the initial reconnaissance phase.

Unifying IT & OT Without Compromising Boundary Security

Komodo Eye provides a unified view that spans from Layer 0 (physical power and environment) all the way to Layer 5 (application logic).


This allows operators to see the entire "path" of an attack—from a server in the data centre down to an industrial controller at the edge—within a single operational picture.

Komodo Eye uses a granular Role-Based Access Control (RBAC) system to define exactly what each user can see and do, such as restricting a technician’s view to only specific geographic sites or device types. 

This ensures that while you have complete situational awareness, you never compromise the segmentation that keeps your most critical assets safe.

Eliminating the SaaS & Cloud Attack Surface

Komodo Eye is installed 100% on-premises and air-gapped, and operates with zero internet connectivity, ensuring there are no external attack pathways for hackers to exploit.

Because the system is installed directly within your private data center, all logs and telemetry remain inside your isolated IT and OT zones. This eliminates the entire class of risks associated with SaaS and cloud-integrated tools, keeping your "source of truth" hidden from the public web.

Conclusion: Sovereignty Over Convenience

In an era where cyber threats are adaptive and AI-assisted, critical infrastructure operators must prioritize data sovereignty over the convenience of the cloud. 

Leaving your network telemetry in a vulnerable cloud repository is an unnecessary risk. By moving to an on-premises, air-gapped solution, you reclaim control over your data and ensure that your monitoring remains operational even if external clouds are hit.