Cyber Incident Victim: Costa Rican Social Security Fund
Date:
May 2022
Location:
Costa Rica
Summary
The Caja Costarricense de Seguro Social experienced a cyberattack that prompted the preventive shutdown of all systems to contain the incident. While critical databases related to education, pensions, payroll, and medical records remained uncompromised, restoration efforts for affected services were underway with specialized teams and third-party support, though no timeline for full recovery was established. The organization committed to providing updates as investigations progressed.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On May 31, 2022, during the early morning hours, the Caja Costarricense de Seguro Social (CCSS) experienced a cybersecurity breach. The organization’s Director of Information and Communication Technologies, Roberto Blanco Topping, confirmed the incident and initiated immediate technical analyses to assess the intrusion. Blanco stated that critical databases—including Edus (education system), Sicere (revenue collection), payroll, and pension systems—remained uncompromised, indicating the attackers did not penetrate these core datasets. As a precautionary measure, CCSS administrators proactively shut down all operational systems to prevent further unauthorized access or damage. Restoration efforts focused on reactivating critical services first, though Blanco emphasized no definitive timeline existed for full operational recovery due to the ongoing forensic investigation. Technical teams collaborated with specialized internal personnel and an unnamed third-party entity to evaluate the breach’s pathway and develop a recovery strategy.

The incident disrupted multiple CCSS services, though the full scope of impacted systems remained unconfirmed at the initial disclosure. Response priorities centered on isolating compromised infrastructure while preserving unaffected databases. Blanco’s public update confirmed no evidence of data exfiltration from financial or pension systems, mitigating immediate concerns about large-scale financial fraud or identity theft. The preventive system-wide shutdown extended service interruptions beyond directly targeted systems, reflecting a containment strategy favoring operational paralysis over risk escalation. CCSS committed to providing further public updates once investigators established additional factual details about the attack vector, duration, or perpetrator methodology. Restoration work continued without confirmation of when standard operations would resume.
