Menu
Browse

Cyber Incident Victim: Costa Rican Social Security Fund

Date:

Apr 2022

Location:

Costa Rica

Summary

The Caja Costarricense de Seguro Social suffered a cyberattack targeting its Human Resources portal, rendering it inaccessible to both employees and the public. This incident formed part of a broader campaign by the Conti ransomware group against multiple Costa Rican government institutions, including the Ministry of Public Education, national meteorological services, and finance ministry platforms. The Russian-linked hackers demanded a $10 million ransom from the government to halt their systematic attacks, which compromised sensitive taxpayer information and disrupted critical digital services across affected agencies. Technical teams conducted analyses to assess the impact while taking systems offline for investigation.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 3 techniques
Threat Actors Type Location
2 actors Available to members Available to members

Description

On or around April 10, 2022, during the Domingo Santo holiday period, the Caja Costarricense de Seguro Social (CCSS) experienced a cyberattack targeting its Human Resources portal. The attack was part of a broader campaign by the Russian-linked hacker group Conti against Costa Rican government institutions. The HR portal, accessible at https://rrhh.ccss.sa.cr/, became completely inaccessible to both CCSS personnel and external users following the breach. This outage prevented all online HR functions and necessitated immediate intervention by the institution’s IT department. CCSS technical experts took the system offline to conduct a forensic analysis and assess the scope of damage caused by the intrusion. The incident marked the fourth major attack by Conti within days, following breaches at the Ministry of Finance, the National Meteorological Institute, and state telecom provider Racsa.

Cyber Incident Image

Conti claimed responsibility for the coordinated attacks and escalated its ransom demand to $10 million from the Costa Rican government, threatening further disruptions if unpaid. The CCSS breach specifically impacted the HR portal’s availability but did not initially disclose evidence of data exfiltration or compromised employee records. Institutional response focused on containment through system isolation while investigators evaluated technical impacts. The attack paralleled intrusions at other agencies including the Ministry of Public Education’s Integra 2 platform and the Ministry of Finance’s ATV and Tica systems, indicating a sustained targeting of critical government infrastructure. Conti asserted it possessed one terabyte of stolen taxpayer data from the Finance Ministry, amplifying pressure on national authorities during the multi-agency crisis.

Sources
Sources available to members
2 sources