AP

Cyber attack causes chaos in Costa Rica government systems

Apr 22, 2022, 9:45 AM | Updated: 10:15 am

SAN JOSE, Costa Rica (AP) — Nearly a week into a ransomware attack that has crippled Costa Rican government computer systems, the country refused to pay a ransom as it struggled to implement workarounds and braced itself as hackers began publishing stolen information.

The Russian-speaking Conti gang claimed responsibility for the attack, but the Costa Rican government had not confirmed its origin.

The Finance Ministry was the first to report problems Monday. A number of its systems have been affected from tax collection to importation and exportation processes through the customs agency. Attacks on the social security agency’s human resources system and on the Labor Ministry, as well as others followed.

The initial attack forced the Finance Ministry to shut down for several hours the system responsible for the payment of a good part of the country’s public employees, which also handles government pension payments. It also has had to grant extensions for tax payments.

Conti had not published a specific ransom amount, but Costa Rica President Carlos Alvarado said, “The Costa Rican state will not pay anything to these cybercriminals.” A figure of $10 million circulated on social media platforms, but did not appear on Conti’s site.

Costa Rican businesses fretted over confidential information provided to the government that could be published and used against them, while average citizens worried that personal financial information could be used to clean out their bank accounts.

Allan Liska, an intelligence analyst with security firm Recorded Future, said that Conti was pursuing a double extortion: encrypting government files to freeze agencies’ ability to function and posting stolen files to the group’s extortion sites on the dark web if a ransom wasn’t paid.

The first part can often be overcome if the systems have good backups, but the second is trickier depending on the sensitivity of the stolen data, he said.

Conti typically rents out its ransomware infrastructure to “affiliates” who pay for the service. The affiliate attacking Costa Rica could be anywhere in the world, Liska said.

A year ago, a Conti ransomware attack forced Ireland’s health system to shut down its information technology system, cancelling appointments, treatments and surgeries.

Last month, Conti pledged its services in support of Russia’s invasion of Ukraine. The move angered cybercriminals sympathetic to Ukraine. It also prompted a security researcher who had long been surveilling Conti to leak a massive trove of internal communications among some Conti operators.

Asked why Central America’s most stable democracy, known for its tropical wildlife and beaches, would be a target of hackers, Liska said the motivation usually has more to do with weaknesses. “They’re looking for specific vulnerabilities,” he said. “So the most likely explanation is that Costa Rica had a number of vulnerabilities and one of the ransomware actors discovered these vulnerabilities and was able to exploit it.”

Brett Callow, a ransomware analyst at Emsisoft, said he looked at one of the leaked files from the Costa Rican finance ministry and “there doesn’t seem to be much doubt that the data is legit.”

On Friday, Conti’s extortion site indicated it had published 50% of the stolen data. It said it included more than 850 gigabytes of material from Finance Ministry and other institutions’ databases. “This is all ideal for phishing, we wish our colleagues from Costa Rica good luck in monetizing this data,” it said.

That seemed to contradict Alvarado’s assertion that the attack was not about money.

“My opinion is that this attack is not a money issue, but rather looks to threaten the country’s stability in a transition point,” he said, referring to his outgoing administration and the swearing in of Costa Rica’s new president May 8. “They will not achieve it.”

Alvarado did allude to the possibility that the attack was motivated by Costa Rica’s public rejection of Russia’s invasion of Ukraine. “You also can’t separate it from the complex global geopolitical situation in a digitalized world,” he said.

__

AP writer Frank Bajak in Boston contributed to this report. Sherman reported from Mexico City.

Copyright © The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.

AP

Republican presidential candidates, from left, former Arkansas Gov. Asa Hutchinson, former New Jers...

Associated Press

3rd Republican presidential debate is set for Nov. 8 in Miami, with the strictest qualifications yet

The third Republican presidential debate will be held in Miami on Nov. 8, a day after several states hold off-year elections.

3 days ago

During the equinox, the Earth’s axis and its orbit line up so that both hemispheres get an equal ...

Associated Press

The fall equinox is here. What does that mean?

The equinox arrives on Saturday, marking the start of the fall season for the Northern Hemisphere. But what does that actually mean?

3 days ago

Ray Epps Ray Epps, an Arizona man who became the center of a conspiracy theory about Jan. 6, 2021, ...

Associated Press

Ray Epps, an Arizona man who supported Trump, pleads guilty to Capital riot charge

Ray Epps, the target of a conspiracy theory about the Jan. 6, 2021, attack, pleaded guilty on Wednesday to a misdemeanor charge.

5 days ago

Former President Donald Trump repeatedly declined in an interview aired Sunday, Sept. 17, 2023, to ...

Associated Press

Trump refuses to say in a TV interview how he watched the Jan. 6 attack unfold at the US Capitol

Former President Donald Trump repeatedly declined in an interview aired Sunday to answer questions about whether he watched the Capitol riot.

8 days ago

This frame grab from video, provided by the Mexican government, shows Ovidio Guzman Lopez being det...

Associated Press

Mexico extradites son of ‘El Chapo,’ Ovidio Guzman Lopez to US

The son of notorious cartel leader Joaquin “El Chapo” Guzmán, Ovidio Guzman Lopez was extradited to the U.S. on Friday.

9 days ago

impeachments in US history...

Associated Press

A look at notable impeachments in US history, including Texas Attorney General Ken Paxton

Texas Attorney General Ken Paxton was acquitted Saturday on during his impeachment trial. Here's a roundup of impeachments in U.S. history.

9 days ago

Sponsored Articles

Home moving relocation in Arizona 2023...

BMS Moving

Tips for making your move in Arizona easier

If you're moving to a new home in Arizona, use this to-do list to alleviate some stress and ensure a smoother transition to your new home.

...

DAY & NIGHT AIR CONDITIONING, HEATING AND PLUMBING

Here are the biggest tips to keep your AC bill low this summer

PHOENIX — In Arizona during the summer, having a working air conditioning unit is not just a pleasure, but a necessity. No one wants to walk from their sweltering car just to continue to be hot in their home. As the triple digits hit around the Valley and are here to stay, your AC bill […]

...

SANDERSON FORD

Thank you to Al McCoy for 51 years as voice of the Phoenix Suns

Sanderson Ford wants to share its thanks to Al McCoy for the impact he made in the Valley for more than a half-decade.

Cyber attack causes chaos in Costa Rica government systems