On 12 April 2022, Costa Rica’s newly-installed government walked into a digital ambush: Conti ransomware hit the Ministry of Finance, encrypting systems including tax-collection and customs platforms, and within weeks the country’s presidency had declared a national state of emergency — the first time any country had formally invoked emergency powers in response to a ransomware incident. The attack crippled the treasury’s digital services for weeks during tax season, forced payroll and import-export operations onto paper workaround, and was followed by a second wave in May (Hive-ransomware-attributed intrusions against the social-security agency CCSS and other bodies) that deepened the crisis. Conti, then the most profitable ransomware brand on earth until its February internal-chat leaks and Russian-government alignment destroyed its reputation, demanded $10 million and leaked Costa Rican data, while the group’s public posture turned openly political — culminating in an infamous declaration that its aim was “to overthrow the government by means of a cyberattack.” Costa Rica refused to pay, mounted an internationally-assisted recovery (US State Department had placed a $10M bounty on Conti’s leadership days after the first attack; Microsoft, Google and others sent incident-response aid; Spain and other partners provided advisors), and the incident became the permanent reference point for ransomware-as-national-security: proof that a criminal extortion crew, with no state mandate, could put a mid-sized country into a state of emergency using commodity tooling and stolen credentials.
Starting 2022-04-12, Conti ransomware intrusions crippled Costa Rica’s Ministry of Finance (tax, customs), followed by May waves (Hive-attributed) against the Social Security Fund (CCSS) and other ministries. President Rodrigo Chaves (inaugurated 2022-05-08) declared a national state of emergency on 2022-05-08 — the world’s first for a ransomware incident — authorising crisis response powers. Conti demanded $10M (later raising/extending threats via its darkweb site, claiming $80M for full non-leak of data; the group publicly declared intent to “overthrow the government by means of a cyberattack”). Costa Rica refused payment. Impacts: weeks-long tax-filing disruption during filing season, manual payroll/import workarounds (paper processes), CCSS patient-record disruption in May, aggregate incident cost to the country estimated by officials in the tens of millions of dollars per month in delays alone (official $200M+ impact statements during 2022; later academic/policy analyses framed $30M+/month knock-on costs). Response: US $10M bounty on Conti leaders (Rewards for Justice, 2022-05-05), IR support from Microsoft/Google/etc., international advisors; perpetrator identified by Costa Rica/US as Conti-linked Russian-based operators (no arrests were ever made). Meaning: ransomware graduated from enterprise risk to national-security threat — the case that justified (1) national emergency-powers playbooks for cyber, (2) no-ransom government doctrine, and (3) treating initial-access brokers and RaaS crews as strategic adversaries.
What happened
The first intrusion matured quietly: Conti operators (using stolen credentials reportedly purchased from an initial-access broker) had been inside Costa Rican networks for weeks to months before detonating, mapping the treasury’s systems and exfiltrating data for double extortion. On 12 April — Day 12 of the new Chaves administration’s actual predecessor-handover window — the encryption hit the Ministry of Finance: the tax platform (ATV), customs systems, and treasury operations went dark during income-tax filing season.
Conti demanded $10M, then publicly taunted the government on its leak site, teased a raised demand (claiming it would cost $80M to prevent full publication), and issued the political threats that made the incident historic: statements about regime change and a formal “declaration of war.” Costa Rica’s emergency declaration on 8 May — the first of its kind for ransomware anywhere — came as the second wave landed: Hive-attributed intrusions struck the Caja Costarricense de Seguro Social (CCSS, the social-security/health system), disrupting appointments and records beyond the finance ministry’s outage.
The government held the no-pay line with international backing: the US Rewards for Justice program’s unprecedented $10M bounty for Conti leadership identifications (5 May), incident-response and threat-intel assistance from US-based firms and platform companies, and multilateral advisors. Recovery stretched for months; some systems were rebuilt rather than restored; the tax season extension was granted by decree. No arrests were ever directly tied to the Costa Rica operations, though US indictments of Conti members in later years named the organisation’s leadership broadly.
Attack anatomy
Costa Rica April-May 2022 attack chain:
RECON & ACCESS
purchased stolen credentials /
initial-access broker entry
(reportedly linked to a
contractor-compromise chain)
weeks-to-months dwell before
detonation
ESCALATION & STAGING
Cobalt-Strike-class post-exploit
lateral movement across ministry
networks
data exfiltration at scale
(double-extortion staging)
DETONATION (2022-04-12)
Conti encryptor deployed ministry-
wide: finance taxation (ATV),
customs, treasury ops
during income-tax filing season
EXTORTION POSTURE
$10M initial demand (2022-04)
public darkweb taunts + gradual
data leaks
May: "overthrow the government"
declarations; $80M non-leak claim
SECOND WAVE (May)
separate Hive-attributed intrusions:
CCSS (social security/health)
+ other agencies
(investigators assessed opportunism
by an affiliated/separate crew
exploiting strained defenders)
RESPONSE
2022-05-08 national emergency
declaration (first for ransomware)
no-ransom doctrine held
US $10M RFJ bounty (2022-05-05)
IR aid (Microsoft, Google, others)
months-long recovery; decree-based
tax deadline extensions
Impact and numbers
| Metric | Value |
|---|---|
| First encryption | 2022-04-12, Ministry of Finance (tax/customs/treasury) |
| Ransom demand | $10M initial; $80M non-leak claim in May |
| Emergency declaration | 2022-05-08, nationwide — first ever for ransomware |
| Second wave | May 2022: CCSS/social security (Hive-attributed) + other bodies |
| Disruption | Weeks of tax-platform outage during filing season; manual customs/payroll workarounds; CCSS record disruption |
| Cost estimates | Officials cited tens of millions/month in knock-on losses; 2022 statements referenced $200M+ aggregate impact |
| US response | $10M Rewards-for-Justice bounty on Conti leadership (2022-05-05); IR/intel assistance |
| Payment | None — national no-ransom doctrine held |
| Arrests | None directly for the Costa Rica ops; Conti broadly indicted later |
Timeline
| Date | Event |
|---|---|
| 2022 early | Pre-attack dwell: Conti inside finance-ministry networks (stolen-credential/contractor-class entry), exfiltrating |
| 2022-04-12 | Encryption detonates: Finance Ministry crippled during tax season; $10M demand |
| 2022-04→05 | Public taunts/data leaks; US advisors arrive; recovery begins amid outage |
| 2022-05-05 | US State Dept offers $10M bounty for Conti leadership intelligence |
| 2022-05-08 | President Chaves declares national state of emergency (first for ransomware); second wave hits CCSS (Hive-attributed) continues through May |
| 2022-05→08 | Stockpiled leaks continue; systems rebuilt over months; tax deadlines extended by decree |
| 2022→2024 | Conti brand dissolves (February leaks + sanctions pressure), crews rebrand; no direct arrests for Costa Rica ops |
Why it still matters in 2026
Because every national cyber-emergency since has cited it. Costa Rica proved ransomware could produce an Article-of-war-scale crisis response without a single state actor in the kill chain — no reconnaissance satellites, just an initial-access broker, a Cobalt Strike licence, and a crew willing to make political demands. The precedent calcified into doctrine: the White House’s joint-advisory stance that critical-infrastructure ransomware is a national-security event, the escalating no-ransom orthodoxy among allies (formalised in varying degrees by 2023–2025 policy statements and the ransomware-payment reporting regimes), and emergency-powers frameworks that now include cyber triggers explicitly. It also closed Conti’s story arc with historical irony: the crew that put a country under emergency declaration was already dead-brand-walking — February’s-chat-leaks (which a Costa Rica-focused campaign helped make famous) had shredded its operational security, and its members scattered into Hive, Quantum, Black Basta and the successor ecosystem that 2026 defenders still fight. For mid-sized nations, Costa Rica remains the planning scenario: months of degraded treasury operations, an assist-package dependency on larger allies, and the discovery that emergency declarations cannot reboot a tax authority — only resilience investment (segmentation, offline backups, rehearsed restoration) can. The first country hit by a cyber-emergency became the textbook argument for not being the second.
Detection and hardening takeaways
- Dwell-time detection is the whole game. Conti sat inside Costa Rican networks for weeks-month ahead of detonation; credential-stuffing/broker-sourced entry leaves telemetry (impossible travel, new-device MFA fatigue patterns, unusual VPN sessions capable of paging humans); ransomware encryption is the last five minutes of an intrusion that was detectable for months.
- Segment government estates like critical infrastructure. The treasury outage spread because ministry networks were flat enough for one entry to reach taxation, customs, and treasury operations; zero-trust segmentation between agencies turns “country emergency” into “bad week for one ministry.”
- Rehearse restoration, not just backup. Costa Rica’s multi-month recovery wasn’t a backup-capacity problem — it was restoration-process maturity (dependency mapping, staged rebuilds, degraded-mode operations manuals) that separates a two-week outage from a season-long one.
- Hold the no-pay line with pre-planned support. Refusing ransom requires (a) political pre-commitment, (b) data-leak contingency planning, and (c) international IR relationships already in place — Costa Rica managed all three under fire; improvising them mid-crisis is how wavering becomes payment.
- Monitor the broker economy targeting you. The entry path was reportedly credential-based via an access broker; governments (and enterprises) benefit from threat-intel programs that track which of their contractors’ credentials circulate in stealer logs and broker listings — the intrusion’s first domino was on sale before the attacker committed.
FAQ
Why did Conti target Costa Rica?
Mixed motives, mostly opportunity plus ideology-tinged spite. The initial intrusion was criminal-economics (a mid-sized government with cyber-mature-enough-to-extort digital treasury systems); the escalation to “overthrow” rhetoric came after (a) the February 2022 leaks had made Conti publicly radioactive, (b) the government refused to negotiate, and (c) the crew’s Russian-nationalist posture made attacking a Western-aligned state politically satisfying. No evidence has emerged of Russian-state direction — the consensus assessment is criminal actors adopting political branding.
What actually is a “state of emergency” for ransomware?
In Costa Rica’s case, invocation of the national emergency law unlocking expedited procurement, inter-agency coordination, and international assistance without normal legislative lead time. It did not involve martial powers or internet shutdowns — the practical content was budget-fluidity and hierarchy-cutting for the response. The significance was categorical: a head of state formally classifying a criminal ransomware incident as a national emergency, which lowered the doctrinal barrier for other governments to do the same (subsequent national cyber-emergies — Vanuatu 2022, various colonial-pipeline-style declarations — reference it).
Did refusing to pay work out?
As policy, yes: the country survived without payment, the leaked data’s damage proved survivable, and the no-ransom stance earned international response support that money can’t buy (the US bounty on the attacker arrived because Costa Rica held the line). As accounting, it was expensive — months of disruption whose costs plausibly exceeded the ransom demand — which is exactly the tradeoff governments must pre-decide: paying funds the next attack and doesn’t guarantee deletion; not paying requires pre-invested resilience to be affordable. Costa Rica became the standing case study for the second path.
