CiberLATAMbywhalemate

Mexico, Colombia Hit by BitLocker Ransomware

Kaspersky found BitLocker-based ransomware in Mexico and Colombia, with ransom notes printed from corporate printers.

Whalemate Labs · AI-assisted researchJul 31, 20263 min read

Kaspersky reported ransomware attacks in Colombia and Mexico in which attackers encrypted systems with BitLocker and used corporate printers to leave ransom notes. In Colombia, one of the initial entries came through an Internet-exposed remote access service tied to a server holding 8 TB of financial data.

Kaspersky reported a series of ransomware attacks in Colombia and Mexico that used an unusual tactic, the attackers encrypted systems with BitLocker and used the victims' corporate printers to print ransom notes.

Colombia, entry through an exposed remote service

In one of the incidents investigated in Colombia, the attackers got into the network through a remote access service exposed to the Internet. That access was linked to a server storing 8 TB of financial information, according to the report published by Noti.mx based on Kaspersky's analysis.

The material does not publicly identify the affected organization, but it does identify the entry point and the amount of data tied to the compromised server. The sequence described shows that the BitLocker encryption came after that initial access, without detailing the use of specialized malware to carry out the lockout.

Mexico, misconfigured SQL and leaked credentials

In the incidents observed in Mexico, the report says the attackers exploited a misconfigured SQL server and credentials leaked in public code. With that combination, they were able to maintain prolonged access to the compromised environments and later encrypt the data with BitLocker.

The same investigation says the ransom demands were also printed on paper. Using corporate printers to distribute the notes was meant to increase pressure on victims and make the message visible inside the operation.

Kaspersky, according to Noti.mx's coverage, said the attackers abused poorly configured remote services and exposed credentials, without needing to deploy specialized malware for the encryption. The method relied more on the access gained and on legitimate tools already in the environment than on a complex malicious payload.

A regional pattern that keeps growing

The case fits into a broader trend across Latin America. Infobae, citing FortiGuard Labs' Threat Landscape Report 2026, said the region suffered 843.3 billion hacking attempts during 2025, with Brazil as the most affected country, followed by Mexico and Colombia. The same article linked part of the escalation in Mexico to StrikeShark, an operation associated with attacks against governments and companies.

ESET, in its first-half 2026 analysis published in WeLiveSecurity, reported that Brazil had more than 100 victims, Mexico nearly 80, Argentina 39 and Colombia 33. The firm's telemetry also detected 195 ransomware instances in Brazil between January and May 2026, including nine ransomware-as-a-service families.

ADN Radio, citing an ESET Latin America researcher, also described the evolution of groups such as DragonForce toward cartel-like models, with about 600 victims in more than 60 countries, including Brazil, Argentina, Colombia and Mexico. That picture reinforces the sustained pressure on governments and public agencies across the region.

Sources

View all