The Costa Rican President Rodrigo Chaves has declared a national emergency after multiple government bodies were hit by cyber attacks from Conti ransomware group.
Conti published most of the 672 GB dump that appears to contain data belonging to the Costa Rican government agencies.
Chaves who was the economist and former Minister of Finance, became the country’s 49th and current president on May 8th and on the same day the declaration was signed into law by him. He declared a national emergency citing ongoing Conti ransomware attacks as the reason.
President Chaves added that they have signed the decree so that the country can defend itself from the criminal attack.
The country’s public health agency Costa Rican Social Security Fund (CCSS) had stated before that “a perimeter security review is being carried out on the Conti Ransomware, to verify and prevent possible attacks at the CCSS level.”
BleepingComputer observed that Conti’s data leak site had leaked 97% of the 672 GB data dump allegedly containing information stolen from government agencies
The Ministry of Finance was the first to become the victim of the attack, which has not yet fully evaluated the scope of the security incident or to what extent has taxpayers’ information, payments, and customs systems have been impacted.
Conti demanded a $10 million ransom from the Ministry which the government declined to pay.
Conti’s leak site lists the following government allegedly affected by the attack.
- The Costa Rican Finance Ministry, Ministerio de Hacienda
- The Ministry of Labor and Social Security, MTSS
- The Social Development and Family Allowances Fund, FODESAF
- The Interuniversity Headquarters of Alajuela, SIUA
On preliminary analysis of a very small subset of the leaked data, source code and SQL databases were found that appears to be from government websites.
Conti ransomware had claimed attack against Costa Rican government entities last month. Conti threat actor “UNC1756,” along with their affiliate, has claimed responsibility for the attack and the threat actor has threatened to conduct future attacks as well.
Other agencies that were impacted by Conti’s attacks include:
- Administrative Board of the Electrical Service of the province of Cartago (Jasec)
- The Ministry of Science, Innovation, Technology, and Telecommunications
- National Meteorological Institute (IMN)
- Radiographic Costarricense (Racsa)
- Costa Rican Social Security Fund (CCSS).
Conti is a Ransomware-as-a-Service (RaaS) operation linked to the Russian-speaking Wizard Spider cybercrime group, famous for other malware, including Ryuk, TrickBot, and BazarLoader).














Comments