Costa Rica’s Conti Emergency: When Ransomware Became a National Crisis
Conti encrypted the treasury during tax season, declared war on the government, and forced the world’s first ransomware state of emergency.
Conti encrypted the treasury during tax season, declared war on the government, and forced the world’s first ransomware state of emergency.
A pro-Russia statement, a furious insider, and the full Jabber archive of history’s most damaging ransomware brand — dumped for everyone to read.
OMB’s January 2022 mandate gave zero trust deadlines, named technologies, and an oversight structure — rewriting industry roadmaps worldwide.
October 2021’s FSB operation ended REvil with arrests, asset seizures, and infrastructure capture. The talent lived on elsewhere.
The Pegasus Project exposed 50,000 targeted numbers and a hard truth: modern mercenary spyware infects phones through iMessage and WhatsApp without the victim doing anything.
REvil halted the world’s largest meat processor over a holiday weekend; JBS restored from backups — and still paid $11M for leak suppression and restart insurance. The economics of ransom beyond decryption.
EO 14028 turned zero trust from slide-ware into federal procurement doctrine — MFA, SBOMs, NIST 800-207, the Cyber Safety Review Board — and reset vendor incentives industry-wide.
DarkSide entered through a no-MFA legacy VPN password, exfiltrated 100 GB, and encrypted Colonial’s IT — prompting a precautionary shutdown of 45% of East Coast fuel supply. Anatomy of the most policy-consequential ransomware ever.
ATT turned iOS advertising identifiers opt-in overnight, denial rates hit 80%+, and Meta booked a $10B impact. How one consent dialog restructured an ad economy — and pushed tracking into fingerprinting’s arms.
A remote intruder raised a Florida treatment plant’s lye setpoint from 100 to 11,100 ppm and an operator watching the screen reverted it in minutes. The incident file on shared passwords, exposed TeamViewer, and why OT security failed at a municipal water utility.
How a privacy-policy notice nobody had read moved millions of users to Signal and Telegram in a week, what WhatsApp actually changed (and what it did not), and why platform-trust collapse is a security event enterprises must plan for.
The full incident file on the SolarWinds SUNBURST supply-chain attack: how SVR-linked actors compromised the Orion build pipeline, trojanized signed updates reaching 18,000 customers, hand-picked under 100 targets including nine US federal agencies, and forged SAML tokens to persist. Includes the technical anatomy, timeline, impact numbers, and the build-pipeline hardening lessons that still define defender programs in 2026.