Ransomware Attacks Targeting Colombia and Mexico based Businesses Examined in New Report

Cybersecurity researchers at Kaspersky have uncovered a series of ransomware assaults targeting businesses in Colombia and Mexico during May and June 2026. These operations stood out for their reliance on built-in Windows encryption tools combined with an unusual tactic: forcing the victims’ own office printers to churn out physical ransom demands.

In the examined cases, employees first realized something was wrong when padlock symbols appeared beside their drives in Windows Explorer.

This signaled that BitLocker, the native full-disk encryption feature, had locked the data.

The attackers then made it clear that payment was the only way to regain access.

One incident in Colombia began with an internet-facing remote access service that was left unprotected.

The service connected to a server holding an 8-terabyte storage unit packed with critical financial records.

Once inside, the intruders changed user passwords, activated BitLocker on the drive, and rendered the information unreadable.

To ensure the organization noticed the extortion attempt immediately, they instructed the company’s printers to produce hard copies of the ransom note and distribute them across the premises.

A separate case in Mexico involved a group identifying itself as the “XEntry team.”

Investigators determined that the attackers obtained login details that had been carelessly left in publicly available source code and used them to enter a poorly configured Microsoft SQL server.

From the database, they expanded their foothold, disabled certain web-server defenses, and maintained undetected control for several months.

The breach finally became obvious when workstations displayed a blue screen announcing “Hacked by XEntry Team,” while standard login credentials stopped working.Eduardo Chavarro Ovalle, manager of Kaspersky’s digital forensics and incident response group, described the approach as highly pragmatic.

Rather than deploying complex custom malware, the operators exploited exposed services, weak configurations, and legitimate administrative utilities already present on the networks.

Printed notes added a layer of psychological pressure, underscoring the urgency of the demands.

Although the ransom messages do not prove the incidents share a single author, overlapping language, delivery methods, and communication style leave open the possibility of a connection.

To reduce the risk of similar intrusions, Kaspersky specialists urge organizations to adopt comprehensive endpoint and extended detection platforms that provide continuous visibility and rapid response.

They also recommend services such as compromise assessments, managed detection, and professional incident response for firms that lack in-house expertise.

Strict hardening of Remote Desktop Protocol settings is essential, especially since more than 13 percent of investigated incidents stem from policy violations or configuration mistakes.

Strong application-control policies and continuous monitoring for command-and-control traffic are equally important, given that remote monitoring tools are abused in more than 20 percent of cases and attackers often employ multiple utilities in a single campaign.

These episodes illustrate how relatively simple missteps—exposed services, reused credentials, and unmonitored administrative features—can open the door to disruptive ransomware.

By treating built-in tools as potential weapons and closing obvious gaps, companies across Latin America and beyond can better protect their data and avoid the unsettling sight of their own printers delivering digital extortion demands.



Sponsored Links by DQ Promote

 

 

0 0 votes
Article Rating
Subscribe
Notify of
guest

This site uses Akismet to reduce spam. Learn how your comment data is processed.

0 Comments
Newest
Oldest Most Voted
 
0
Would love your thoughts, please comment.x
()
x
Send this to a friend