THE article examines a new extortion scheme involving cybercriminals exploiting vulnerabilities in corporate printers and the BitLocker encryption system to demand ransoms from organizations. It details two incidents: one in Colombia where attackers exploited an exposed RDP service to encrypt data and issue ransom notes via printers, and another in Mexico involving a misconfigured MSSQL service that allowed attackers to manipulate systems and encrypt data.
Key findings highlight the importance of securing remote access services and monitoring network traffic to prevent such attacks, with a recommendation for strict application control and incident response procedures.