Ransomware gang threatens to overthrow Costa Rica government

May 16, 2022, 8:49 AM | Updated: May 19, 2022, 9:49 am

SAN JOSE, Costa Rica (AP) — A ransomware gang that infiltrated some Costa Rican government computer systems has upped its threat, saying its goal is now to overthrow the government.

Perhaps seizing on the fact that President Rodrigo Chaves had only been in office for a week, the Russian-speaking Conti gang tried to increase the pressure to pay a ransom by raising its demand to $20 million.

Chaves suggested Monday in a news conference that the attack was coming from inside as well as outside Costa Rica.

“We are at war and that’s not an exaggeration,” Chaves said. He said officials were battling a national terrorist group that had collaborators inside Costa Rica.

Chaves also said the impact was broader than previously known, with 27 government institutions, including municipalities and state-run utilities, affected. He blamed his predecessor Carlos Alvarado for not investing in cybersecurity and for not more aggressively dealing with the attacks in the waning days of his government.

In a message Monday, Conti warned that it was working with people inside the government.

“We have our insiders in your government,” the group said. “We are also working on gaining access to your other systems, you have no other options but to pay us. We know that you have hired a data recovery specialist, don’t try to find workarounds.”

Despite Conti’s threat, experts see regime change as a highly unlikely — or even the real goal.

“We haven’t seen anything even close to this before and it’s quite a unique situation,” said Brett Callow, a ransomware analyst at Emsisoft. “The threat to overthrow the government is simply them making noise and not to be taken too seriously, I wouldn’t say.

“However, the threat that they could cause more disruption than they already have is potentially real and that there is no way of knowing how many other government departments they may have compromised but not yet encrypted.”

Conti attacked Costa Rica in April, accessing multiple critical systems in the Finance Ministry, including customs and tax collection. Other government systems were also affected and a month later not all are fully functioning.

Chaves declared a state of emergency over the attack as soon as he was sworn in last week. The U.S. State Department offered a $10 million reward for information leading to the identification or location of Conti leaders.

Conti responded by writing, “We are determined to overthrow the government by means of a cyber attack, we have already shown you all the strength and power, you have introduced an emergency.”

The gang also said it was raising the ransom demand to $20 million. It called on Costa Ricans to pressure their government to pay.

The attack has encrypted government data and the gang said Saturday that if the ransom wasn’t paid in one week, it would delete the decryption keys.

The U.S. State Department statement last week said the Conti group had been responsible for hundreds of ransomware incidents during the past two years.

“The FBI estimates that as of January 2022, there had been over 1,000 victims of attacks associated with Conti ransomware with victim payouts exceeding $150,000,000, making the Conti Ransomware variant the costliest strain of ransomware ever documented,” the statement said.

While the attack is adding unwanted stress to Chaves’ early days in office, it’s unlikely there was anything but a monetary motivation for the gang.

“I believe this is simply a for-profit cyber attack,” Callow, the analyst said. “Nothing more.”

__

Associated Press writer Christopher Sherman in Mexico City contributed to this report.

Copyright © The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.

AP

(Facebook Photo/Superior Court of Arizona in Yavapai County)...
Associated Press

Arizona judge has cases reassigned following DUI arrest

The Arizona Supreme Court has ruled that all cases currently assigned to a Yavapai County Superior Court judge recently arrested on suspicion of extreme DUI will be reassigned to other judges.
19 hours ago
Haitian migrant Gerson Solay, 28, carries his daughter, Bianca, as he and his family cross into Can...
Associated Press

US, Canada to end loophole that allows asylum-seekers to move between countries

President Joe Biden and Canadian Prime Minister Justin Trudeau on Friday announced a plan to close a loophole to an immigration agreement.
4 days ago
Expert skateboarder Di'Orr Greenwood, an artist born and raised in the Navajo Nation in Arizona and...
Associated Press

Indigenous skateboard art featured on new stamps unveiled at Phoenix skate park

The Postal Service unveiled the “Art of the Skateboard" stamps at a Phoenix skate park, featuring designs from Indigenous artists.
4 days ago
(Facebook Photo/City of San Luis, Arizona)...
Associated Press

San Luis authorities receive complaints about 911 calls going across border

Authorities in San Luis say they are receiving more complaints about 911 calls mistakenly going across the border.
10 days ago
(Pexels Photo)...
Associated Press

Daylight saving time begins in most of US this weekend

No time change is observed in Hawaii, most of Arizona, Puerto Rico, the U.S. Virgin Islands, American Samoa, Guam and the Northern Marianas.
18 days ago
Mexican army soldiers prepare a search mission for four U.S. citizens kidnapped by gunmen in Matamo...
Associated Press

How the 4 abducted Americans in Mexico were located

The anonymous tip that led Mexican authorities to a remote shack where four abducted Americans were held described armed men and blindfolds.
18 days ago

Sponsored Articles

(Pexels Photo)...

Sports gambling can be fun for adults, but it’s a dangerous game for children

While adults may find that sports gambling is a way to enhance the experience with more than just fandom on the line, it can be a dangerous proposition if children get involved in the activity.
...
Fiesta Bowl Foundation

Celebrate 50 years of Vrbo Fiesta Bowl Parade magic!

Since its first production in the early 1970s, the Vrbo Fiesta Bowl Parade presented by Lerner & Rowe has been a staple of Valley traditions, bringing family fun and excitement to downtown Phoenix.
...
Quantum Fiber

How high-speed fiber internet edges out cable for everyday use

In a world where technology drives so much of our daily lives, a lack of high-speed internet can be a major issue.
Ransomware gang threatens to overthrow Costa Rica government