RansomHub Cyberattack Disrupts RECOPE Operations in Costa Rica

Incident Date: Dec 12, 2024

Attack Overview
VICTIM
RECOPE - Refinadora Costarricense de Petróleo
INDUSTRY
Energy, Utilities & Waste
LOCATION
Costa Rica
ATTACKER
Ransomhub
FIRST REPORTED
December 12, 2024

RansomHub Ransomware Attack on RECOPE: A Critical Analysis

In a significant cybersecurity incident, the RansomHub ransomware group has claimed responsibility for a cyberattack on RECOPE, the state-owned oil refining and distribution company in Costa Rica. This attack underscores the vulnerabilities faced by critical infrastructure sectors, particularly in the energy domain.

About RECOPE

RECOPE, or Refinadora Costarricense de Petróleo, S.A., is a pivotal entity in Costa Rica's energy sector. Established in 1961 and nationalized in 1974, the company is responsible for the import, refining, and distribution of petroleum products across the nation. With key facilities like the Puerto Limón refinery and an extensive pipeline network, RECOPE ensures the steady supply of gasoline, diesel, and jet fuel. The company is recognized as one of the largest in Central America, highlighting its significant market presence and operational scale.

Attack Overview

The ransomware attack was detected on November 27, prompting RECOPE to activate its contingency protocols. RansomHub claims to have exfiltrated 240 GB of sensitive data, forcing the company to switch to manual operations temporarily. Bárbara Marín Benavides, head of Communications at RECOPE, confirmed that all IT platforms were affected, and employees were instructed to avoid digital systems. Despite the disruption, RECOPE maintained customer service and supply chains, communicating effectively with stakeholders and the Costa Rican cybersecurity authorities.

RansomHub: A Formidable Threat

RansomHub, emerging in February 2024, is a Ransomware-as-a-Service (RaaS) group known for its aggressive affiliate model and double extortion tactics. The group targets high-value sectors, leveraging vulnerabilities in unpatched systems and employing sophisticated techniques like phishing and zero-day exploits. RansomHub's operations are characterized by speed and efficiency, with a focus on encrypting large datasets and exfiltrating sensitive information.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.