Printers Spit Ransom Notes After BitLocker Lock

Securelist · High sophistication
Last updated July 30, 2026

Two real incidents in Colombia and Mexico show attackers using built-in Windows BitLocker to lock company drives, then printing ransom notes from office printers to pressure victims to pay. One case started from an exposed Remote Desktop (RDP) service; the other began from a misconfigured Microsoft SQL Server where credentials were found in code posted on GitHub. The attackers demanded relatively small ransoms (example: $3,000) and used “reputation” language in their messages to convince victims they would provide recovery help after payment.

How the attack worked

In both incidents described, attackers did not need custom malware to lock victims out of their data. Instead, they abused BitLocker, a legitimate Windows disk encryption feature, to lock drives after gaining a foothold in the network. In the Colombia case, initial access came through an internet-exposed RDP service. In the Mexico case, attackers exploited a misconfigured MSSQL service and used database credentials that had been published in code on GitHub. Once inside, attackers manipulated credentials, enabled BitLocker on drives holding sensitive data, and then used office printers to physically print ransom notes throughout the workplace, turning ordinary office equipment into a delivery channel for extortion messages.

Why it succeeded

The attacks relied on a mix of technical access and psychological pressure. Ransom notes used reassuring, business-like language about the attackers' "reputation" as a guarantee they would help recover data after payment, which is intended to make the extortion feel more like a transaction than a crime. The Mexico case also involved spreading encryption widely using RMM tools and group policy, escalating a single point of access into an organization-wide event. In both cases, security tooling and alerts existed, but investigation gaps meant early warning signs were not acted on in time to stop the final encryption stage.

What to watch for

  • Unexpected printer output containing threats, ransom demands, or payment instructions
  • Sudden BitLocker lock icons or prompts asking for a recovery key on drives that were not previously encrypted
  • Blue screen messages claiming a network has been "hacked," followed by credentials failing across many machines
  • Security alerts tied to RDP, MSSQL, or RMM tool activity that are generated but not fully investigated

Building resistance

Organizations can reduce exposure by closing off internet-facing RDP and misconfigured database services, and by carefully managing credentials so they are never left in code repositories. Just as important is response discipline: alerts from existing security controls need to be investigated and closed rather than left unresolved, since alert fatigue can give attackers the time needed to complete encryption. When an incident does occur, preserving logs and system state for forensic review is critical. In one of these cases, systems were restored quickly, which eliminated the evidence needed to fully understand how access occurred and to prevent a repeat attack. Training employees, especially IT, helpdesk, finance, and operations staff, to treat unexpected printer output or sudden credential failures as an active incident rather than a technical glitch can help shorten the time between compromise and response.

Key findings

  • Attackers used BitLocker (a legitimate Windows feature) to encrypt and lock corporate drives, then demanded payment for recovery.
  • In both incidents, office printers were abused to physically deliver ransom notes across the workplace.
  • Colombia case: initial access came from an internet-exposed RDP service; attackers targeted a drive with financial data and demanded $3,000.
  • Mexico case ("XEntry Team"): attackers exploited a misconfigured MSSQL service and obtained database credentials from code published on GitHub, then used RMM tools and GPO to spread encryption widely.
  • Security tooling and alerts existed in places, but investigation/response gaps (including rushed restoration) reduced the ability to collect evidence and stop the activity sooner.

Who’s being targeted

  • Commonly targeted roles: IT, Helpdesk/Service Desk, Finance, Operations, Executive leadership.
  • Affected industries: Unspecified (multiple organizations; incidents in Colombia and Mexico).
  • Attack channels: physical, email.
  • Impersonated: Extortion actor (ransomware-style operator), XEntry Team.

Red flags to watch for

  • Unexpected printer output containing threats or payment instructions
  • Sudden BitLocker lock icons on drives and prompts for a recovery key
  • Pressure to move the conversation to an external email address and pay quickly
  • A blue screen message claiming the environment is “hacked”
  • Employee credentials suddenly stop working across many machines
  • Ransom notes begin printing without any employee print job
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did attackers gain initial access in these incidents?

In one case attackers exploited an internet-exposed RDP service, and in the other they exploited a misconfigured MSSQL service and found database credentials published in code on GitHub.

Why did the ransom notes come out of office printers?

After locking drives with BitLocker, attackers used the company printers to physically distribute ransom notes across the workplace, creating urgency and visibility for the extortion demand.

Did existing security tools stop these attacks?

Security controls generated alerts and blocked some attempts, but the necessary investigation was not carried out in time, which gave attackers the opportunity to complete encryption.

What should employees do if a printer starts producing ransom notes?

Unexpected printer output demanding payment should be treated as an active security incident and reported to IT or Security immediately rather than dismissed.

Read the video transcript

Imagine you’re at your desk…and every office printer suddenly spits out the same ransom note. This really happened. In Colombia and Mexico, attackers used Windows BitLocker to lock company drives, then hijacked office printers to drop $3,000 ransom notes claiming their 'reputation' guaranteed recovery. In one case, users saw a blue screen saying 'Hacked by XEntry Team', lost access to their accounts, and hours later ransom notes started printing, pressuring them to email the extortion address and pay fast. Your move: if a printer ever spits out a ransom note or payment demand, don’t call the email on the page, call IT or Security immediately and report it as a major incident.

Similar attacks