Ransomware forced Costa Rica's state fuel company RECOPE to sell fuel manually

Organization
Refinadora Costarricense de Petróleo (RECOPE)
Exploit
Ransomware
Industry
Energy & Utility

Refinadora Costarricense de Petróleo, the state-owned company that imports, refines and distributes fuel across Costa Rica and operates pipelines running from the Caribbean coast to the Pacific, detected a ransomware incident on the morning of Wednesday November 27, 2024.

The attack took down the digital systems RECOPE used to process fuel payments. The company reverted to manual sales, extending hours at its tanker terminals into the night and filling 203 trucks by hand while working with Costa Rica's Ministry of Science, Innovation, Technology and Telecommunications on the response. RECOPE president Karla Montero said operations would remain manual until the systems were confirmed safe, and management said inventories were sufficient to meet demand. No fuel shortage resulted, although public concern prompted a spike in purchases.

Cybersecurity responders from the United States arrived on Thanksgiving Day to help restore systems. The Record later reported that the deployment was the first use of the State Department's Foreign Assistance Leveraged for Cybersecurity Operational Needs program, known as FALCON, delivered within roughly 36 hours at a cost of about 500,000 dollars and lasting around 10 days on site.

RansomHub was identified as responsible. According to The Record, the group gained access through a phishing email, remained in RECOPE's network for several months and demanded 5 million dollars, which Costa Rica refused to pay. Kaspersky's ICS CERT also attributed the incident to RansomHub.

Sources