
Colombian energy company Empresas Públicas de Medellín (EPM), one of largest public energy, water, and gas providers in the nation, providing services to 123 municipalities, suffered a BlackCat/ALPHV ransomware attack, disrupting the company’s operations and taking down online services.
The company asked about 4,000 employees to work from home because its IT infrastructure was down, and its websites were no longer accessible. EPM offered customers additional payment options and informed the neighborhood media that they were responding to a cybersecurity incident.
Later, the Prosecutor’s Office acknowledged that ransomware was responsible for the attack on EPM that resulted in the encryption of devices and data theft. The ransomware operation that launched the attack was kept a secret, though.
According to reports that claimed to have seen the encryptor sample and ransom notes from the EPM attack, hackers may have stolen corporate data during the attacks.
Although the attack’s ransom note claims that a variety of data was stolen, it should be noted that this is the exact text used in all BlackCat ransom notes and is not unique to EPM, reports said. However, new information suggests that during the attack, hackers probably stole a sizable amount of data from EPM.
A recent sample of the data-theft tool "ExMatter" from BlackCat was found to have been uploaded from Colombia to a malware analysis website by Chilean security researcher Germán Fernández. BlackCat ransomware attacks use ExMatter as a tool to steal data from corporate networks before devices are encrypted. The ransomware gang then employs this information in their double-extortion schemes. When the tool is used, it will take information from networked devices and store it on servers under the attacker’s control in folders with the name of the Windows computer from which it was taken.
Fernández discovered after examining the ExMatter tool that it uploaded the data to an unprotected remote server, making it accessible to anyone who visited. The Colombian ExMatter variant uploaded the data into a number of folders, beginning with "EPM." These computer names are consistent with the known computer naming conventions used by Empresas Pblicas de Medelln, according to Fernández. Although the total amount of stolen data is unknown, Fernández claimed that over 40 devices were listed on the website.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543