Printers Spit Ransom Notes After BitLocker Lock

Securelist · High sophistication
Last updated July 30, 2026

Two real incidents in Colombia and Mexico show attackers using built-in Windows BitLocker to lock company drives, then printing ransom notes from office printers to pressure victims to pay. One case started from an exposed Remote Desktop (RDP) service; the other began from a misconfigured Microsoft SQL Server where credentials were found in code posted on GitHub. The attackers demanded relatively small ransoms (example: $3,000) and used “reputation” language in their messages to convince victims they would provide recovery help after payment.

How the attack worked

In both incidents described, attackers did not need custom malware to lock victims out of their data. Instead, they abused BitLocker, a legitimate Windows disk encryption feature, to lock drives after gaining a foothold in the network. In the Colombia case, initial access came through an internet-exposed RDP service. In the Mexico case, attackers exploited a misconfigured MSSQL service and used database credentials that had been published in code on GitHub. Once inside, attackers manipulated credentials, enabled BitLocker on drives holding sensitive data, and then used office printers to physically print ransom notes throughout the workplace, turning ordinary office equipment into a delivery channel for extortion messages.

Why it succeeded

The attacks relied on a mix of technical access and psychological pressure. Ransom notes used reassuring, business-like language about the attackers' "reputation" as a guarantee they would help recover data after payment, which is intended to make the extortion feel more like a transaction than a crime. The Mexico case also involved spreading encryption widely using RMM tools and group policy, escalating a single point of access into an organization-wide event. In both cases, security tooling and alerts existed, but investigation gaps meant early warning signs were not acted on in time to stop the final encryption stage.

What to watch for

  • Unexpected printer output containing threats, ransom demands, or payment instructions
  • Sudden BitLocker lock icons or prompts asking for a recovery key on drives that were not previously encrypted
  • Blue screen messages claiming a network has been "hacked," followed by credentials failing across many machines
  • Security alerts tied to RDP, MSSQL, or RMM tool activity that are generated but not fully investigated

Building resistance

Organizations can reduce exposure by closing off internet-facing RDP and misconfigured database services, and by carefully managing credentials so they are never left in code repositories. Just as important is response discipline: alerts from existing security controls need to be investigated and closed rather than left unresolved, since alert fatigue can give attackers the time needed to complete encryption. When an incident does occur, preserving logs and system state for forensic review is critical. In one of these cases, systems were restored quickly, which eliminated the evidence needed to fully understand how access occurred and to prevent a repeat attack. Training employees, especially IT, helpdesk, finance, and operations staff, to treat unexpected printer output or sudden credential failures as an active incident rather than a technical glitch can help shorten the time between compromise and response.

Key findings

  • Attackers used BitLocker (a legitimate Windows feature) to encrypt and lock corporate drives, then demanded payment for recovery.
  • In both incidents, office printers were abused to physically deliver ransom notes across the workplace.
  • Colombia case: initial access came from an internet-exposed RDP service; attackers targeted a drive with financial data and demanded $3,000.
  • Mexico case ("XEntry Team"): attackers exploited a misconfigured MSSQL service and obtained database credentials from code published on GitHub, then used RMM tools and GPO to spread encryption widely.
  • Security tooling and alerts existed in places, but investigation/response gaps (including rushed restoration) reduced the ability to collect evidence and stop the activity sooner.

Who’s being targeted

  • Commonly targeted roles: IT, Helpdesk/Service Desk, Finance, Operations, Executive leadership.
  • Affected industries: Unspecified (multiple organizations; incidents in Colombia and Mexico).
  • Attack channels: physical, email.
  • Impersonated: Extortion actor (ransomware-style operator), XEntry Team.

Red flags to watch for

  • Unexpected printer output containing threats or payment instructions
  • Sudden BitLocker lock icons on drives and prompts for a recovery key
  • Pressure to move the conversation to an external email address and pay quickly
  • A blue screen message claiming the environment is “hacked”
  • Employee credentials suddenly stop working across many machines
  • Ransom notes begin printing without any employee print job
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did attackers gain initial access in these incidents?

In one case attackers exploited an internet-exposed RDP service, and in the other they exploited a misconfigured MSSQL service and found database credentials published in code on GitHub.

Why did the ransom notes come out of office printers?

After locking drives with BitLocker, attackers used the company printers to physically distribute ransom notes across the workplace, creating urgency and visibility for the extortion demand.

Did existing security tools stop these attacks?

Security controls generated alerts and blocked some attempts, but the necessary investigation was not carried out in time, which gave attackers the opportunity to complete encryption.

What should employees do if a printer starts producing ransom notes?

Unexpected printer output demanding payment should be treated as an active security incident and reported to IT or Security immediately rather than dismissed.

Read the video transcript

Imagine you’re at your desk…and every office printer suddenly spits out the same ransom note. This really happened. In Colombia and Mexico, attackers used Windows BitLocker to lock company drives, then hijacked office printers to drop $3,000 ransom notes claiming their 'reputation' guaranteed recovery. In one case, users saw a blue screen saying 'Hacked by XEntry Team', lost access to their accounts, and hours later ransom notes started printing, pressuring them to email the extortion address and pay fast. Your move: if a printer ever spits out a ransom note or payment demand, don’t call the email on the page, call IT or Security immediately and report it as a major incident.

Similar attacks

Fake Install Guides and Helpdesk Calls Drive Attacks

Fake Install Guides and Helpdesk Calls Drive Attacks

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result “install guide,” a recruiter outreach, or a helpdesk phone call. The lures push victims to paste commands, install fake software, or reset MFA,…

July 30, 2026
Phishers Abuse DocuSign, Rewards, and “Verification”

Phishers Abuse DocuSign, Rewards, and “Verification”

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials or install remote-control tools. The common theme is trust abuse: messages and web pages look legitimate, then push users to log in, click…

July 28, 2026
Vishing Lures, Fake Identities, and Repo-Trap Attacks

Vishing Lures, Fake Identities, and Repo-Trap Attacks

This recap describes multiple real-world social-engineering-driven attacks, including vishing calls that push employees to spoofed login pages and a supply-chain trick where cloning/opening a GitHub repo in developer tools triggers malware. It also highlights an unusual case where an AI model…

August 10, 2026
Impostor Calls Target US Finance With Spoof Sites

Impostor Calls Target US Finance With Spoof Sites

Researchers reported a real campaign against large U.S. financial firms where callers pretend to be coworkers or IT to trick employees into entering passwords and multi-factor codes on spoofed websites. After access is gained, the attackers pressure victims with data-leak threats and demand large…

August 10, 2026
Fake IRS Letters and BoA Emails Push Remote Access Scams

Fake IRS Letters and BoA Emails Push Remote Access Scams

This weekly roundup includes real-world social engineering campaigns, including scammers mailing fake IRS letters to cryptocurrency holders and a phishing campaign impersonating Bank of America. The lures are designed to pressure victims into visiting a bogus compliance portal or installing remote…

August 9, 2026
Fake IT Helpdesk Calls Steal MFA at Finance Firms

Fake IT Helpdesk Calls Steal MFA at Finance Firms

A criminal group tracked as UNC6671 called employees while pretending to be their company IT helpdesk, creating urgency around “mandatory” security changes. Victims were directed to lookalike login pages to “enable passkeys” or “update MFA,” allowing attackers to steal passwords and capture…

August 7, 2026