← Back to Feed

A new extortion cocktail: office printers, small ransoms, and BitLocker

July 21, 2026 · Kaspersky (Securelist) · Severity: MEDIUM

Attackers in Latin America are exploiting misconfigured office printers and BitLocker encryption to extort small ransoms from businesses. Kaspersky investigated two incidents in Colombia (June) and Mexico (May), where attackers compromised systems via exposed RDP services, encrypted critical data with BitLocker, and printed ransom notes demanding payments as low as $3,000. In the Colombia case, attackers targeted an 8 TB financial data drive, locking it until the victim considered paying. The attacks highlight poor security practices, such as leaving RDP services internet-exposed, enabling unauthorized access. This trend reflects a shift toward low-profile, high-impact attacks leveraging built-in tools like BitLocker, avoiding traditional ransomware detection. Similar to past threats like ShrinkLocker, attackers exploit misconfigurations to encrypt data discreetly. The incidents underscore the risks of unsecured remote access and the growing use of unconventional methods, like printer abuse, for extortion. Victims’ haste to restore systems often destroys forensic evidence, complicating investigations. Businesses must secure RDP, enforce strong credentials, and monitor for unusual printer or BitLocker activity to mitigate such threats.

Recently, our teams in Latin America investigated a series of incidents involving misconfiguration, the deployment of BitLocker, and the exploitation of corporate printers. Attackers used the devices to notify organizations that their infrastructure had been compromised and they had to pay a ransom to recover their data.

This article analyzes two incidents that occurred in June in Colombia and in May in Mexico. We highlight the similarities in the attackers’ communications and outline emerging trends in ransom amounts.

Initial sign of an attack

In both cases, the affected users initially noticed a padlock icon next to their drives in Windows Explorer. This indicated that the drive was encrypted with BitLocker, blocking access to its contents.

Drive icon indicating that the drive is locked

Drive icon indicating that the drive is locked

A recovery key was required to unlock the drive.

Attempt to access the disk's contents and the prompt for the BitLocker recovery key

Attempt to access the disk’s contents and the prompt for the BitLocker recovery key

This is not the first time we have seen such threats; a few years ago, our team discovered a threat known as ShrinkLocker, which utilized BitLocker to achieve its goals.

First case: abusing RDP to encrypt data

One of the incidents occurred in Colombia in June. The attackers exploited an internet-exposed RDP service on a machine connected to an 8 TB storage device containing mission-critical data. After taking control of the system and manipulating user credentials, the attackers enabled BitLocker exclusively on the drive that primarily stored financial data. Once the encryption was complete, they locked the drive and used the company’s printers to produce ransom notes.

Ransomware note

Ransomware note

Unfortunately, it was not possible to obtain evidence in the case due to the company’s rush to restore the encrypted disk. The communication with the attackers revealed a demand for just $3,000, and the company considered paying the ransom. After that, the system was restored before the forensic team could take any action, eliminating the evidence needed to assess the incident.

Attacker's reply to the victim's email sent to the address in the printed ransom note

Attacker’s reply to the victim’s email sent to the address in the printed ransom note

This attack was made possible by an internet-facing remote desktop service (RDP) with additional open ports, which employees used to access corporate information. By exploiting this network exposure and misconfiguration, attackers breac

Key Takeaways

  • Attackers use BitLocker to encrypt drives and demand small ransoms.
  • Compromised office printers display ransom notes to notify victims.
  • Incidents in Colombia and Mexico show emerging extortion trends.
☕ Buy a Coffee