Funksec Targets Aquamaná ESP in Major Ransomware Breach
Ransomware Attack on Aquamaná ESP: A Closer Look at Funksec's Latest Target
The ransomware group Funksec has recently claimed responsibility for a cyberattack on Aquamaná ESP, a municipal public utility company based in Villamaría, Caldas, Colombia. This incident, discovered on January 20, 2025, underscores the vulnerabilities faced by public service entities in the digital age.
About Aquamaná ESP
Aquamaná ESP is a key player in the Energy, Utilities & Waste sector, providing essential services such as water supply, sewage management, and waste disposal to the local community. Established in 1996, the company has a mission to ensure quality, continuity, and coverage of public services while preserving natural resources. With a proactive approach to environmental challenges, Aquamaná ESP stands out for its commitment to technological innovation and sustainable financial efficiency. Despite its significant role, the company’s digital infrastructure appears to have been vulnerable to cyber threats, as evidenced by the recent breach.
Details of the Attack
The attack on Aquamaná ESP involved the defacement of its website and potential data exfiltration, although the full extent of the data leak remains unspecified. Funksec, known for its double extortion tactics, likely used a combination of data encryption and exfiltration to pressure the company. This incident highlights the critical need for enhanced cybersecurity measures in public utility companies, which are increasingly becoming targets for cybercriminals.
Funksec: An Emerging Threat
Funksec is a relatively new ransomware group that emerged in late 2024. It distinguishes itself through a combination of technical sophistication and political motivations, often targeting organizations across various sectors, including media, IT, and public services. The group employs a double extortion strategy, encrypting files and threatening to leak exfiltrated data. Funksec's operations are facilitated through a Tor-based data-leak site, where they also offer free DDoS tools, indicating a broader attack capability.
Sources
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!