Costa Rica’s Conti Emergency: When Ransomware Became a National Crisis

📋 Key Takeaways
  • What happened
  • Attack anatomy
  • Impact and numbers
  • Timeline
  • Why it still matters in 2026
9 min read · 1,684 words
Educational & Ethical Use Only — This article is provided for educational and ethical cybersecurity research purposes only. The techniques described should only be used on systems you own or have explicit permission to test. Always follow responsible disclosure and the laws applicable to you. Mitigations are included so engineers can harden real systems.

On 12 April 2022, Costa Rica’s newly-installed government walked into a digital ambush: Conti ransomware hit the Ministry of Finance, encrypting systems including tax-collection and customs platforms, and within weeks the country’s presidency had declared a national state of emergency — the first time any country had formally invoked emergency powers in response to a ransomware incident. The attack crippled the treasury’s digital services for weeks during tax season, forced payroll and import-export operations onto paper workaround, and was followed by a second wave in May (Hive-ransomware-attributed intrusions against the social-security agency CCSS and other bodies) that deepened the crisis. Conti, then the most profitable ransomware brand on earth until its February internal-chat leaks and Russian-government alignment destroyed its reputation, demanded $10 million and leaked Costa Rican data, while the group’s public posture turned openly political — culminating in an infamous declaration that its aim was “to overthrow the government by means of a cyberattack.” Costa Rica refused to pay, mounted an internationally-assisted recovery (US State Department had placed a $10M bounty on Conti’s leadership days after the first attack; Microsoft, Google and others sent incident-response aid; Spain and other partners provided advisors), and the incident became the permanent reference point for ransomware-as-national-security: proof that a criminal extortion crew, with no state mandate, could put a mid-sized country into a state of emergency using commodity tooling and stolen credentials.

Quick Answer
Starting 2022-04-12, Conti ransomware intrusions crippled Costa Rica’s Ministry of Finance (tax, customs), followed by May waves (Hive-attributed) against the Social Security Fund (CCSS) and other ministries. President Rodrigo Chaves (inaugurated 2022-05-08) declared a national state of emergency on 2022-05-08 — the world’s first for a ransomware incident — authorising crisis response powers. Conti demanded $10M (later raising/extending threats via its darkweb site, claiming $80M for full non-leak of data; the group publicly declared intent to “overthrow the government by means of a cyberattack”). Costa Rica refused payment. Impacts: weeks-long tax-filing disruption during filing season, manual payroll/import workarounds (paper processes), CCSS patient-record disruption in May, aggregate incident cost to the country estimated by officials in the tens of millions of dollars per month in delays alone (official $200M+ impact statements during 2022; later academic/policy analyses framed $30M+/month knock-on costs). Response: US $10M bounty on Conti leaders (Rewards for Justice, 2022-05-05), IR support from Microsoft/Google/etc., international advisors; perpetrator identified by Costa Rica/US as Conti-linked Russian-based operators (no arrests were ever made). Meaning: ransomware graduated from enterprise risk to national-security threat — the case that justified (1) national emergency-powers playbooks for cyber, (2) no-ransom government doctrine, and (3) treating initial-access brokers and RaaS crews as strategic adversaries.

What happened

The first intrusion matured quietly: Conti operators (using stolen credentials reportedly purchased from an initial-access broker) had been inside Costa Rican networks for weeks to months before detonating, mapping the treasury’s systems and exfiltrating data for double extortion. On 12 April — Day 12 of the new Chaves administration’s actual predecessor-handover window — the encryption hit the Ministry of Finance: the tax platform (ATV), customs systems, and treasury operations went dark during income-tax filing season.

Conti demanded $10M, then publicly taunted the government on its leak site, teased a raised demand (claiming it would cost $80M to prevent full publication), and issued the political threats that made the incident historic: statements about regime change and a formal “declaration of war.” Costa Rica’s emergency declaration on 8 May — the first of its kind for ransomware anywhere — came as the second wave landed: Hive-attributed intrusions struck the Caja Costarricense de Seguro Social (CCSS, the social-security/health system), disrupting appointments and records beyond the finance ministry’s outage.

The government held the no-pay line with international backing: the US Rewards for Justice program’s unprecedented $10M bounty for Conti leadership identifications (5 May), incident-response and threat-intel assistance from US-based firms and platform companies, and multilateral advisors. Recovery stretched for months; some systems were rebuilt rather than restored; the tax season extension was granted by decree. No arrests were ever directly tied to the Costa Rica operations, though US indictments of Conti members in later years named the organisation’s leadership broadly.

Attack anatomy

Costa Rica April-May 2022 attack chain:

  RECON & ACCESS
    purchased stolen credentials /
    initial-access broker entry
    (reportedly linked to a
    contractor-compromise chain)
    weeks-to-months dwell before
    detonation

  ESCALATION & STAGING
    Cobalt-Strike-class post-exploit
    lateral movement across ministry
    networks
    data exfiltration at scale
    (double-extortion staging)

  DETONATION (2022-04-12)
    Conti encryptor deployed ministry-
    wide: finance taxation (ATV),
    customs, treasury ops
    during income-tax filing season

  EXTORTION POSTURE
    $10M initial demand (2022-04)
    public darkweb taunts + gradual
    data leaks
    May: "overthrow the government"
    declarations; $80M non-leak claim

  SECOND WAVE (May)
    separate Hive-attributed intrusions:
    CCSS (social security/health)
    + other agencies
    (investigators assessed opportunism
    by an affiliated/separate crew
    exploiting strained defenders)

  RESPONSE
    2022-05-08 national emergency
    declaration (first for ransomware)
    no-ransom doctrine held
    US $10M RFJ bounty (2022-05-05)
    IR aid (Microsoft, Google, others)
    months-long recovery; decree-based
    tax deadline extensions
data-hmmnm-seam="2">

Impact and numbers

Metric Value
First encryption 2022-04-12, Ministry of Finance (tax/customs/treasury)
Ransom demand $10M initial; $80M non-leak claim in May
Emergency declaration 2022-05-08, nationwide — first ever for ransomware
Second wave May 2022: CCSS/social security (Hive-attributed) + other bodies
Disruption Weeks of tax-platform outage during filing season; manual customs/payroll workarounds; CCSS record disruption
Cost estimates Officials cited tens of millions/month in knock-on losses; 2022 statements referenced $200M+ aggregate impact
US response $10M Rewards-for-Justice bounty on Conti leadership (2022-05-05); IR/intel assistance
Payment None — national no-ransom doctrine held
Arrests None directly for the Costa Rica ops; Conti broadly indicted later
data-hmmnm-seam="3">

Timeline

Date Event
2022 early Pre-attack dwell: Conti inside finance-ministry networks (stolen-credential/contractor-class entry), exfiltrating
2022-04-12 Encryption detonates: Finance Ministry crippled during tax season; $10M demand
2022-04→05 Public taunts/data leaks; US advisors arrive; recovery begins amid outage
2022-05-05 US State Dept offers $10M bounty for Conti leadership intelligence
2022-05-08 President Chaves declares national state of emergency (first for ransomware); second wave hits CCSS (Hive-attributed) continues through May
2022-05→08 Stockpiled leaks continue; systems rebuilt over months; tax deadlines extended by decree
2022→2024 Conti brand dissolves (February leaks + sanctions pressure), crews rebrand; no direct arrests for Costa Rica ops
data-hmmnm-seam="4">

Why it still matters in 2026

Because every national cyber-emergency since has cited it. Costa Rica proved ransomware could produce an Article-of-war-scale crisis response without a single state actor in the kill chain — no reconnaissance satellites, just an initial-access broker, a Cobalt Strike licence, and a crew willing to make political demands. The precedent calcified into doctrine: the White House’s joint-advisory stance that critical-infrastructure ransomware is a national-security event, the escalating no-ransom orthodoxy among allies (formalised in varying degrees by 2023–2025 policy statements and the ransomware-payment reporting regimes), and emergency-powers frameworks that now include cyber triggers explicitly. It also closed Conti’s story arc with historical irony: the crew that put a country under emergency declaration was already dead-brand-walking — February’s-chat-leaks (which a Costa Rica-focused campaign helped make famous) had shredded its operational security, and its members scattered into Hive, Quantum, Black Basta and the successor ecosystem that 2026 defenders still fight. For mid-sized nations, Costa Rica remains the planning scenario: months of degraded treasury operations, an assist-package dependency on larger allies, and the discovery that emergency declarations cannot reboot a tax authority — only resilience investment (segmentation, offline backups, rehearsed restoration) can. The first country hit by a cyber-emergency became the textbook argument for not being the second.

data-hmmnm-seam="5">

Detection and hardening takeaways

  • Dwell-time detection is the whole game. Conti sat inside Costa Rican networks for weeks-month ahead of detonation; credential-stuffing/broker-sourced entry leaves telemetry (impossible travel, new-device MFA fatigue patterns, unusual VPN sessions capable of paging humans); ransomware encryption is the last five minutes of an intrusion that was detectable for months.
  • Segment government estates like critical infrastructure. The treasury outage spread because ministry networks were flat enough for one entry to reach taxation, customs, and treasury operations; zero-trust segmentation between agencies turns “country emergency” into “bad week for one ministry.”
  • Rehearse restoration, not just backup. Costa Rica’s multi-month recovery wasn’t a backup-capacity problem — it was restoration-process maturity (dependency mapping, staged rebuilds, degraded-mode operations manuals) that separates a two-week outage from a season-long one.
  • Hold the no-pay line with pre-planned support. Refusing ransom requires (a) political pre-commitment, (b) data-leak contingency planning, and (c) international IR relationships already in place — Costa Rica managed all three under fire; improvising them mid-crisis is how wavering becomes payment.
  • Monitor the broker economy targeting you. The entry path was reportedly credential-based via an access broker; governments (and enterprises) benefit from threat-intel programs that track which of their contractors’ credentials circulate in stealer logs and broker listings — the intrusion’s first domino was on sale before the attacker committed.

FAQ

Why did Conti target Costa Rica?

Mixed motives, mostly opportunity plus ideology-tinged spite. The initial intrusion was criminal-economics (a mid-sized government with cyber-mature-enough-to-extort digital treasury systems); the escalation to “overthrow” rhetoric came after (a) the February 2022 leaks had made Conti publicly radioactive, (b) the government refused to negotiate, and (c) the crew’s Russian-nationalist posture made attacking a Western-aligned state politically satisfying. No evidence has emerged of Russian-state direction — the consensus assessment is criminal actors adopting political branding.

What actually is a “state of emergency” for ransomware?

In Costa Rica’s case, invocation of the national emergency law unlocking expedited procurement, inter-agency coordination, and international assistance without normal legislative lead time. It did not involve martial powers or internet shutdowns — the practical content was budget-fluidity and hierarchy-cutting for the response. The significance was categorical: a head of state formally classifying a criminal ransomware incident as a national emergency, which lowered the doctrinal barrier for other governments to do the same (subsequent national cyber-emergies — Vanuatu 2022, various colonial-pipeline-style declarations — reference it).

Did refusing to pay work out?

As policy, yes: the country survived without payment, the leaked data’s damage proved survivable, and the no-ransom stance earned international response support that money can’t buy (the US bounty on the attacker arrived because Costa Rica held the line). As accounting, it was expensive — months of disruption whose costs plausibly exceeded the ransom demand — which is exactly the tradeoff governments must pre-decide: paying funds the next attack and doesn’t guarantee deletion; not paying requires pre-invested resilience to be affordable. Costa Rica became the standing case study for the second path.

data-hmmnm-seam="end">

Prabhu Kalyan Samal

Application Security Consultant at TCS. Certifications: CompTIA SecurityX, Burp Suite Certified Practitioner, Azure Security Engineer, Azure AI Engineer, Certified Red Team Operator, eWPTX v3, LPT, CompTIA PenTest+, Professional Cloud Security Engineer, SC-900, SC-200, PSPO I, CEH, Oracle Java SE 8, ISP, Six Sigma Green Belt, DELF, AutoCAD. Writing about ethical hacking, security tutorials, and tech education at Hmmnm.