Cyber Incident Victim: Costa Rica’s Legislative Assembly
Date:
Jul 2026
Location:
Costa Rica
Summary
Costa Rica’s Legislative Assembly detected an attempted cyberattack overnight and, following protocol, shut down its information systems to block intruders and prevent data theft. The outage disabled the Integrated Legislative System, leaving committees unable to consult bills, motions or reports and forcing the cancellation of several committee sessions; no bills were voted on and the plenary proceeded only with its political‑oversight segment before being lifted in the late afternoon. To keep proceedings transparent, the day’s agenda was published in a special edition of the official gazette. Officials from the Ministry of Science, Innovation, Technology and Telecommunications and the national CSIRT assisted the response, characterizing the activity as a contained security event with no evidence that information was compromised, altered or extracted, while investigations continue to determine the source and scope.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 0 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On the night between Monday and Tuesday of July 2026, security personnel at Costa Rica’s Legislative Assembly detected an attempt to infiltrate the institution’s information systems and, following established protocol, initiated a shutdown of several digital services to block intruders and prevent the theft of data. Congress President Yara Jiménez informed the plenary at the start of the session that the intrusion attempt had occurred between Monday night and the early hours of Tuesday morning and that the decision to disconnect the systems was taken to protect public administration continuity. After the shutdown, the Legislative Directorate published the day’s agenda in a special edition of the official gazette La Gaceta so that the matters lawmakers would consider remained a matter of public record despite the systems being offline. Jiménez requested detailed reports from the Assembly’s Security Management office and its Information Technology Department to establish the scope of the incident and the actions taken during the response. In the morning, officials from the Ministry of Science, Innovation, Technology and Telecommunications (MICITT) arrived at the Assembly to assist with the technical evaluation of the event. The Integrated Legislative System, known as SIL, which stores digital versions of bills, updated texts, motions and institutional reports that lawmakers and staff rely on daily, was among the services taken offline, leaving committees unable to consult basic documents. Seven committees were unable to meet as scheduled on the day of the outage, and their sessions for the following day were left in doubt because agendas must be published at least 24 hours in advance. The plenary proceeded only with its political‑oversight segment before Jiménez, acting on a recommendation from the Technical Services Department, lifted the session in the late afternoon rather than risk debating legislation without the required public access to the relevant files. No bills were voted on during the session.

The disclosure of the cyberattack caught many lawmakers by surprise and drew sharp criticism over the delay in informing them, with several legislators arguing they should have been notified sooner and warning that interrupting the Assembly’s digital platforms could create procedural irregularities by limiting public access to official documents and proceedings. Representative Claudia Dobles stated that public institutions have a legal and administrative obligation to report any type of attack or potential breach of public information. Members of the Frente Amplio, the Social Christian Unity Party and the National Liberation Party cautioned that agreements adopted without ordinary access to legislative documents could be exposed to later claims of nullity or unconstitutionality and urged Jiménez to release the final report from the Office of Information Security and Technology once the investigation concludes. Later on, MICITT offered a more reassuring assessment, characterizing the episode as a 'security event' detected on one of the Assembly’s servers that provides digital services to the public. The country’s Computer Security Incident Response Team, CSIRT‑CR, said the activity was detected and contained thanks to existing controls and that technical verification found no evidence that information hosted on the site had been compromised, altered or extracted. On that basis, the incident was classified as a security event rather than an information‑security breach, and MICITT said it would continue supporting the Assembly’s technical review and the safe restoration of its services. Authorities have not identified who was behind the attempt or disclosed a possible motive, noting that these questions will form part of the pending technical report. The incident occurs amid ongoing efforts by Costa Rican public institutions to harden their defenses following a series of cyberattacks on government systems in recent years.
