The Russia-linked Conti ransomware group launched a sweeping attack on Costa Rican government networks in April 2022, disrupting tax collection, customs, payroll, and other critical public services and prompting the government to declare a national emergency. Costa Rican officials said at least 27 institutions were attacked and several were severely affected, with the Ministry of Finance among the hardest hit; additional incidents were reported at entities including JASEC, the Sede Interuniversitaria de Alajuela, and the Instituto de Desarrollo Rural. Authorities said data was stolen and progressively leaked, while restoration of key systems took weeks, including the eventual recovery of the customs platform after roughly two months of disruption.
Conti escalated the crisis by raising its ransom demand from $10 million to $20 million, threatening to delete decryption keys, urging public pressure on the government, and later shifting tactics to target large private Costa Rican companies directly. President Rodrigo Chaves said the country was "at war" and alleged that local collaborators were aiding the extortion effort, though no proof was publicly detailed. As Costa Rica sought technical help from international partners and private-sector responders, the U.S. State Department offered rewards of up to $10 million for information identifying Conti leaders and up to $5 million for information leading to their arrest or conviction, underscoring the group's broader record of hitting more than 1,000 victims and extorting over $150 million worldwide.

TTPs, infrastructure, and targeting history in one profile.
13 events from the most recent confirmed update back to the earliest known activity.
By June 24, 2022, Costa Rica had restored its customs platform following roughly two months of disruption caused by the cyberattack. The recovery marked a significant step in reestablishing one of the country's most heavily affected government services.
By May 17, 2022, President Rodrigo Chaves publicly described the cyberattacks as a form of war or cyberterrorism and said 27 institutions had been attacked, with 9 severely affected. He also alleged that people inside Costa Rica were collaborating with Conti and announced a specialized response and assessment effort.
After Costa Rica refused to pay, Conti increased its ransom demand from $10 million to $20 million and posted threats urging public pressure on the government. The group also warned it could delete decryption keys and claimed it sought to intensify disruption.
On May 8, 2022, Costa Rica declared a national state of emergency in response to the ransomware campaign. The move elevated the incident to a national crisis and supported a broader government response effort.
On May 6, 2022, the U.S. State Department announced rewards of up to $10 million for information identifying or locating Conti leaders and up to $5 million for information leading to their arrest or conviction. The announcement explicitly referenced Conti's disruptive attacks on Costa Rican government institutions.
Costa Rican authorities confirmed attempted cyberattacks against the Ministry of Justice and the Junta de Protección Social (JPS). The disclosure showed Conti-linked activity was extending to additional public institutions beyond those previously named.
On April 26, officials said Conti had attacked the Sede Interuniversitaria de Alajuela, stealing data and altering portal content, and had also targeted Inder, which took systems offline for containment. Authorities said the number of affected public institutions had risen to eight.
On April 25, 2022, Conti announced it would stop mainly pressuring the Costa Rican government and instead target large private Costa Rican companies. The group also claimed that 80% of stolen government information had already been released.
By April 24, authorities said Conti had encrypted Jasec's accounting and human resources systems. The disclosure showed the campaign was affecting additional public-sector entities and operational functions.
On 2022-04-18, Costa Rican authorities said they were investigating whether Conti had stolen information from the National Meteorological Institute's email server. MINAE said the probe followed reports that the group claimed to have exfiltrated IMN data and was demanding payment to return it.
Costa Rican authorities reported that an attack on Jasec may have compromised customer or subscriber information. This marked one of the early publicly disclosed impacts beyond central government systems.
Around April 17-18, 2022, Conti began a major ransomware campaign against Costa Rican public institutions. The Ministry of Finance was hit hardest, disrupting tax, customs, and payroll systems and involving data theft.
In February 2022, Conti's internal messages were leaked after the group publicly supported Russia's invasion of Ukraine. The leak gave analysts new insight into the gang's operations, including indications it worked from physical offices in Russia.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
11 references tracked. Mallory keeps watching after this page renders.
swissinfo.ch
Open sourcebbc.com
Open sourcecyberscoop.com
Open sourcedw.com
Open sourceweb.archive.org
Open sourceweb.archive.org
Open sourceweb.archive.org
Open sourceweb.archive.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.