When Ransomware Shut Down an Entire Country's Government
In 2022, ransomware hit so many Costa Rican government agencies at once that the president declared a national emergency — a response usually reserved for natural disasters.
National emergencies are usually declared for hurricanes, earthquakes, or wars. In April 2022, Costa Rica’s president declared one for a ransomware attack — a rare acknowledgment that a cyberattack can disrupt a country the same way a physical disaster can.
What actually happened
The Conti ransomware group breached dozens of Costa Rican government ministries and agencies over several weeks, disrupting tax collection, customs and foreign trade processing, and government payroll and health payment systems. The attackers reportedly demanded a $10 million ransom, later doubled, and threatened to leak stolen government data when it wasn’t paid.
Why the impact went beyond IT downtime
Foreign trade is a significant part of Costa Rica’s economy, and the customs disruption reportedly cost the country tens of millions of dollars per day in stalled imports and exports. Public health payment systems were affected too, meaning the disruption reached beyond office computers into services residents actually depend on.
Why a national emergency declaration mattered
Declaring a national emergency isn’t symbolic — it unlocks emergency funding, legal authorities, and coordination powers normally reserved for hurricanes or earthquakes. Costa Rica’s government used it specifically to justify a faster, more resourced response than normal bureaucratic processes would have allowed, treating the ransomware attack as an actual national crisis rather than an IT department’s problem.
What this means beyond Costa Rica
Most ransomware coverage focuses on individual companies. This incident is one of the clearest examples of ransomware treated explicitly as a threat to a country’s basic functioning, not just a business risk — a preview of the scale governments and critical-service providers worldwide are increasingly planning for, rather than an isolated event.
Worried this affects you?
Check whether your email address has shown up in this breach — or any other — in seconds.
Run a free breach check →Related coverage
Colonial Pipeline, Years Later: The Lesson That Actually Stuck
The 2021 ransomware attack that shut down fuel supply on the East Coast started with a single reused password. That detail still matters more than the headline did.
The Ransomware Attack That Became a Case Study in Doing It Right
Norsk Hydro got hit by ransomware that shut down plants worldwide. What made this incident different wasn't the attack — it was the response.