Costa Rica's president declares a state of emergency after the Conti ransomware group published 672GB of data that appears to be from government agencies
The Costa Rican President Rodrigo Chaves has declared a national emergency following cyber attacks from Conti ransomware group on multiple government bodies.
Context & Ripple Effects
The data publication turned Conti's intrusion into a national governance crisis: Rodrigo Chaves responded with an emergency declaration rather than treating the incident as an isolated agency breach. Related coverage shows the disruption went on to cripple Costa Rica's digital infrastructure for months.
Conti later paired the attack with a doubled $20 million ransom demand and an appeal for citizens to pressure the government, making the leak part of a coercive campaign against the state rather than simply a data-theft event.
First-order effects
- Costa Rican government agencies face immediate exposure from the published data, while the emergency declaration elevates containment and continuity work across the affected public sector.
- Conti gains leverage by combining the disclosure with public pressure for payment, directly confronting Chaves's government with a ransom decision under disrupted conditions.
Second-order effects
- The group's demand and public messaging force Costa Rica to manage the attack as both a cybersecurity response and a political communications problem, rather than leaving affected agencies to respond independently.
- The months-long disruption documented later made recovery an external-support issue as well: the US ultimately sent Costa Rica funding for Conti ransomware recovery.
Third-order effects
- Ransomware against government systems is becoming a national-resilience risk when attackers can disrupt digital services, expose agency data, and seek to mobilize public pressure in the same campaign.
- The Costa Rica episode indicates that recovery capacity and outside assistance can become part of the cost of resisting extortion, shifting the burden beyond the initially breached agencies.
The trend: Ransomware groups are escalating from encrypted systems and stolen files toward coordinated coercion campaigns aimed at governments' operational continuity and public legitimacy.