The US sends $25M to Costa Rica for Conti ransomware recovery and gave $25M last month to help Albania recover from a ransomware attack allegedly caused by Iran
The U.S. government is sending $25 million to the government of Costa Rica to help the country recover from a devastating ransomware attack …
Context & Ripple Effects
Costa Rica has been in recovery mode since May 2022, when its president declared a state of emergency after Conti dumped 672GB of government data and then doubled its ransom demand to $20M, telling citizens it aimed to overthrow the government. The group itself fell apart months later after an insider betrayal, but the damage to Costa Rica's digital infrastructure lingered — and Washington's $25M grant is the outside help arriving ten months on.
The grant is also not a one-off: the U.S. gave an identical $25M to Albania just last month for a ransomware attack attributed to Iran. Two allied governments hit by ransomware, two identical checks — this reads as a deliberate instrument of cyber diplomacy, extending the posture behind the 2021 anti-ransomware program that offered rewards of up to $10M for information on state-sanctioned hackers.
First-order effects
- Costa Rica gets $25M to rebuild systems crippled by Conti — more than the $20M ransom the group demanded and the government never paid.
- Albania's recovery effort gains a committed U.S. backer, reinforcing the attribution of its attack to Iran as grounds for American support.
Second-order effects
- Ransomware crews and their state sponsors now face a changed cost calculus: hitting a U.S. partner draws American money into the target's defense rather than isolating it.
- Other donor governments and multilateral lenders face pressure to match the U.S. model, turning ransomware recovery into a competitive arena of foreign assistance.
Third-order effects
- If the pattern holds, ransomware-struck allies get treated like disaster zones — with standing aid mechanisms rather than ad-hoc grants — formalizing ransomware as a geopolitical weapon that triggers alliance obligations.
- Nation-state-linked ransomware (Conti against Costa Rica, Iran against Albania) pushes governments to treat digital extortion as a national-security incident, blurring the line between criminal and state attack.
The trend: Ransomware recovery is becoming a formal instrument of U.S. alliance policy, with Washington writing recurring checks to partners hit by state-linked extortion campaigns.