RansomHub Cyberattack Disrupts RECOPE Operations in Costa Rica
RansomHub Ransomware Attack on RECOPE: A Critical Analysis
In a significant cybersecurity incident, the RansomHub ransomware group has claimed responsibility for a cyberattack on RECOPE, the state-owned oil refining and distribution company in Costa Rica. This attack underscores the vulnerabilities faced by critical infrastructure sectors, particularly in the energy domain.
About RECOPE
RECOPE, or Refinadora Costarricense de Petróleo, S.A., is a pivotal entity in Costa Rica's energy sector. Established in 1961 and nationalized in 1974, the company is responsible for the import, refining, and distribution of petroleum products across the nation. With key facilities like the Puerto Limón refinery and an extensive pipeline network, RECOPE ensures the steady supply of gasoline, diesel, and jet fuel. The company is recognized as one of the largest in Central America, highlighting its significant market presence and operational scale.
Attack Overview
The ransomware attack was detected on November 27, prompting RECOPE to activate its contingency protocols. RansomHub claims to have exfiltrated 240 GB of sensitive data, forcing the company to switch to manual operations temporarily. Bárbara Marín Benavides, head of Communications at RECOPE, confirmed that all IT platforms were affected, and employees were instructed to avoid digital systems. Despite the disruption, RECOPE maintained customer service and supply chains, communicating effectively with stakeholders and the Costa Rican cybersecurity authorities.
RansomHub: A Formidable Threat
RansomHub, emerging in February 2024, is a Ransomware-as-a-Service (RaaS) group known for its aggressive affiliate model and double extortion tactics. The group targets high-value sectors, leveraging vulnerabilities in unpatched systems and employing sophisticated techniques like phishing and zero-day exploits. RansomHub's operations are characterized by speed and efficiency, with a focus on encrypting large datasets and exfiltrating sensitive information.
Sources
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!