Costa Rica’s Legislative Assembly
Incident posture
Linked entities
- Victim
- Costa Rica’s Legislative Assembly
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
Costa Rica’s Legislative Assembly detected an attempted cyberattack on its servers and, following protocol, shut down its information systems to prevent intrusion, which halted access to the Integrated Legislative System and forced the postponement of committee meetings and the suspension of plenary debates on legislation. Officials from the Ministry of Science, Innovation, Technology and Telecommunications and the national CSIRT assisted in the response, confirming that the activity was contained and no data was compromised, while the Assembly pledged to release a detailed report after the investigation.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On the night between Monday and Tuesday morning, security personnel at Costa Rica’s Legislative Assembly detected an attempted intrusion into the Assembly’s information systems and, following established protocol, shut down several digital services to prevent intruders from gaining access and to protect data. Congress President Yara Jiménez informed the plenary at the start of the Tuesday session that the shutdown was enacted to safeguard the continuity of public administration. She said she had requested detailed reports from the Assembly’s Security Management office and its Information Technology Department to determine the scope of the incident and the actions taken during the response. Officials from the Ministry of Science, Innovation, Technology and Telecommunications (MICITT) arrived at the Assembly in the morning to assist with the technical evaluation. The Integrated Legislative System (SIL), which stores digital versions of bills, updated texts, motions and institutional reports, was taken offline as part of the shutdown. To keep the plenary informed, the Legislative Directorate published the day’s agenda in a special edition of the official gazette, La Gaceta. MICITT later characterized the episode as a security event detected on one of the Assembly’s servers that provides digital services to the public. The country’s Computer Security Incident Response Team, CSIRT‑CR, stated that the activity was detected and contained thanks to existing controls and that technical verification found no evidence that information hosted on the site had been compromised, altered or extracted.
Because SIL was unavailable, seven committees were unable to meet as scheduled on Tuesday and their sessions for Wednesday remained doubtful due to the requirement that agendas be published at least 24 hours in advance. No bills were voted on during the plenary; the session proceeded only with its political‑oversight segment before Jiménez lifted it in the late afternoon to avoid debating legislation without the required public access to relevant files. The sudden disclosure caught many lawmakers by surprise and drew criticism over the delay in informing them, with several legislators saying they should have been notified sooner and warning that interrupting the Assembly’s digital platforms could create procedural irregularities by limiting public access to official documents and proceedings. Representative Claudia Dobles noted that public institutions have a legal and administrative obligation to report any type of attack or potential breach of public information. Members of the Frente Amplio, the Social Christian Unity Party and the National Liberation Party cautioned that agreements adopted without ordinary access to legislative documents could be exposed to later claims of nullity or unconstitutionality and urged Jiménez to release the final report from the Office of Information Security and Technology once the investigation concludes. MICITT said that, based on the lack of evidence of data compromise, the incident was classified as a security event rather than an information‑security breach and that it would continue supporting the Assembly’s technical review and the safe restoration of its services. Authorities have not identified who was behind the attempt or disclosed a possible motive, questions that officials say will form part of the pending technical report. The incident occurs amid ongoing efforts by Costa Rican public institutions to harden their defenses after a series of cyberattacks on government systems in recent years.
Sources
Sources available to members: 1 source.