Key Takeaways

  • Kaspersky Security Services found attackers in Colombia and Mexico exploiting exposed services and BitLocker encryption to lock down data.
  • Corporate printers were weaponized to deliver physical ransom notes, adding psychological pressure inside compromised workplaces.
  • Regional ransomware growth data reinforces the scale of the threat and the importance of structured security practices like continuous monitoring and logging.

Between May and June 2026, Kaspersky Security Services experts investigated a cluster of ransomware incidents in Colombia and Mexico. The cases combined misconfigured internet-facing systems and the abuse of legitimate administrative tools with the weaponization of corporate printers to distribute physical ransom notes.

Investigators documented that attackers used BitLocker to encrypt storage volumes and then hijacked internal printers to broadcast ransom demands. The appearance of padlock icons in Windows Explorer served as the first visible sign for users that files had become inaccessible. By bypassing the need for custom ransomware binaries, threat actors blended digital compromise with physical disruption using readily available enterprise features.

According to research published by mallory.ai, these printer-based tactics are becoming more common across Latin America. Regional threat data highlights this escalation, with Intel 471 reporting over 450 ransomware-related breach events across the region in 2025, representing a 78% increase over 2024. The World Bank also notes that disclosed cyber incidents in Latin America have grown roughly 25% annually over the past decade.

One investigated case occurred in Colombia, where attackers entered through an exposed remote access service connected to a server housing an 8 TB storage device filled with financial data. Once inside, they altered user credentials, gained persistent control, and activated BitLocker to encrypt the drive. The attackers then printed physical ransom notes on workplace printers to amplify urgency and psychological pressure.

Another incident in Mexico traced back to a misconfigured Microsoft SQL server. The attackers used exposed credentials found in publicly available code to gain initial access, weaken web server protections, and quietly maintain network access for months. Staff eventually noticed their systems displayed a blue screen stating "Hacked by XEntry Team," and their regular credentials no longer worked.

These two events reflect a broader shift toward pragmatic, tool-based ransomware operations. Gartner has repeatedly noted that threat actors prioritize speed and reliability over sophistication. Similarly, Forrester highlights that attacks using legitimate tools often evade early detection because they mimic routine administrative activity.

The digital forensic and incident response group manager at Kaspersky emphasized that exposed services, weak configurations, and legitimate tools remained the common denominators in these attacks. The inclusion of printed ransom notes merges technical disruption with tangible workplace impact, demonstrating how everyday infrastructure can be leveraged for extortion.

Guidance from NIST points to monitoring, logging, and rapid response as core practices for countering ransomware operations that rely on legitimate tools. However, consistent implementation across sprawling environments remains challenging because logs often sit in disparate systems, and alerts frequently fail to distinguish malicious behavior from routine administrative activity.

A misconfigured SQL server, an exposed remote access service, or unused printer settings provide the initial opening. Once threat actors find that opening, they escalate privileges, establish persistence, encrypt data, and apply extortion pressure. Alignment with established frameworks, such as the NIST Cybersecurity Framework or ISO-based controls, helps organizations identify these weak points and correct misconfigurations earlier.

Organizations across Latin America face an expanding threat landscape, with ransomware now representing nearly half of successful cyber incidents in the region. These investigations show that attackers do not require bespoke ransomware programs when common enterprise tools can achieve the same operational disruption.