Hackers en México e impresoras: nueva táctica de ransomware

· 3 min read · Cybersecurity
Colombia and Mexico face a new ransomware tactic

Cybercriminals in Mexico and Colombia are using BitLocker and corporate printers to demand ransoms, exploiting deficient configurations.

Cybersecurity experts have raised alarms in Latin America after detecting an unusual and aggressive ransomware tactic targeting organizations in Mexico and Colombia. Investigations conducted between May and June 2026 revealed that cybercriminal groups are compromising corporate infrastructure through misconfigurations and exposed credentials, then encrypting data using native operating system tools like Microsoft BitLocker. The most unusual aspect of this maneuver is that, after encrypting critical information, the attackers seize control of the victim's corporate printers to physically print ransom demands.

In the analyzed cases, initial access did not require sophisticated malware but rather the abuse of vulnerabilities and misconfigured remote services. In Colombia, attackers gained access through an internet-exposed service connected to an 8 TB storage containing financial information, while in Mexico, the group known as "XEntry Team" exploited a misconfigured SQL server with leaked credentials in public code, maintaining a silent presence for months. Once inside, they disabled web server protections and executed the extortion physically in the offices.

This methodology, described by specialists as high-impact psychological pressure, reflects the trend of misusing legitimate tools (RMM and RDP) already present within corporate networks. Given that more than 13% of incidents in the region correspond to policy violations and human configuration errors, experts recommend a series of key measures to prevent these intrusions:

  • Unified real-time protection: Implement advanced solutions with investigation, detection, and managed response capabilities (EDR and XDR) to continuously monitor infrastructure.
  • Specialized support against evasive threats: Adopt security tools that help investigate complex incidents and provide necessary technical support in case of lacking specialized internal personnel.
  • Strict adjustment of Remote Desktop Protocol (RDP): Configure these accesses according to global best practices to close the door to unauthorized access, a breach responsible for a large part of current vulnerabilities.
  • Application control and C2 traffic monitoring: Prioritize strict policies for program execution on the network and actively monitor traffic for command and control (C2) communications, especially considering that more than 20% of attacks abuse remote monitoring tools (RMM).
  • Centralized log management: Protect and centralize system logs to monitor security alerts and immediately investigate any sign of unusual access or activity.

From the perspective of next+'s strategic consulting team, these incidents highlight that cybersecurity is no longer just a challenge of sophisticated software, but of operational hygiene and digital infrastructure governance. The fact that native tools like BitLocker and peripheral devices like printers are used as extortion weapons confirms that the attack surface in modern companies is highly fragmented. For senior management in Latin America, the priority must be to close the gap of deficient configurations and exposed accesses. In an environment where brands operate omnichannel ecosystems and handle enormous volumes of sensitive data, business continuity and customer trust depend on rigorously auditing internal architecture before their own resources become the greatest corporate risk.

Related articles