Printers distributed ransom notes

Article by Nacata Security, 21/07/2026

Can you imagine arriving at work to find your computer locked with no explanation?

That is what companies in Colombia and Mexico experienced this year.

The attackers did not use sophisticated viruses or paid tools. They exploited an encryption feature already built into any Windows computer.

And to notify the victims that they had to pay, they did not send an email. They used the office’s own printers to print the ransom notes.

A reinforced door with a red digital lock, slightly ajar and opening into darkness, representing the compromised remote access and data encryption that locked out the victims.
Compromised remote access

It all started with an open door into the company’s network.

In Colombia, the attackers found a remote access point visible from the internet with insufficient protection. The device’s security software had been disabled due to compatibility issues. They got in, identified a drive containing critical financial data, and encrypted it using Windows’ built-in encryption tool. The company lost access to its information overnight.

The ransom demanded was just three thousand dollars.

A strikingly low figure for an attack of this kind. The company even considered paying it. Before investigators could analyze what had happened, the IT team restored the system, inadvertently wiping all the evidence. In Mexico, the story was different but the outcome was the same: locked systems and ransom notes coming out of the office printers.

Employees saw the message on their screens: “Hacked by XEntry Team.”

In the Mexican case, the attackers had been inside the network for three months before anyone noticed. They installed remote control tools and encrypted every drive one by one. The warning came when screens displayed that message on a blue background and credentials stopped working.

A network of glowing cables connecting servers, with an active intrusion path that has been lit up for months without anyone attending to it, symbolizing the alerts ignored during the attack in Mexico.
Months of ignored alerts

Then the printers did the rest.

Hours after the lockdown, the office printers began spitting out pages with instructions for paying the ransom. A physical tactic—unexpected and hard to ignore. These two cases share something important that goes beyond the specific method used.

The pattern repeats across the region.

The researchers who analyzed both incidents point out that this attack method is on the rise in Latin America. The attackers avoid purchasing ransomware tools or partnering with criminal groups. Instead, they use functions built into the operating system itself, which makes them harder to detect because security software does not always flag something that is part of the legitimate system as a threat.

In Mexico, the breach had been open for months with no one acting on it.

The company’s security system did issue alerts during that time. The problem was that no one investigated them. The attackers found database access credentials that had been accidentally published on a public code platform, got in, and gradually expanded their control until they had taken over everything.

A printed ransom note surrounded by identical copies, representing the regional pattern of low-cost attacks that use physical printers as an extortion channel in Latin America.
Ransom notes

The ransom notes boasted of a good payment track record.

Both in Colombia and Mexico, the printed messages included phrases promising to honor the deal if the victim paid. A strategy designed to build trust and speed up the decision. The ransom business, even on a small scale, has its own commercial logic.

Open doors and ignored alerts made it possible.

In both cases, the attackers did not need particularly advanced techniques. It was enough to find services exposed to the internet without adequate protection and for the system alerts to not be taken seriously. The combination of technical negligence and lack of human response was sufficient to compromise entire companies.

The cheapest attack can be devastating.

It does not take a large criminal budget to bring a company to a standstill. Sometimes all it takes is a door left ajar and no one watching the alarms.

What you can do

  • Close any remote internet access points that are not strictly necessary.
  • Review and act on security alerts without letting them pile up.
  • Never publish credentials or passwords in public code repositories.

How many security alerts have you left unreviewed this week?

Security is not improvised, it is audited. At Nacata Security we detect vulnerabilities and protect your company, because a single flaw can cost you everything you have built.

Related articles

Nacata Security, reach out to us anytime

How would you rate this news?

We are Nacata Security, get to know us

web: nacata.io

email: info@nacata.io

Phone: 919930793

LinkedIn: Nacata Security

Incidents

Cyberattacks that have already happened and are confirmed: hacked companies, leaked data, services down after an attack, ransoms paid.

Real cases, with names and clear consequences, explained simply so anyone understands what happened and who it affected.



RATING


7.4



Who are we?


At Nacata Security we are an offensive cybersecurity company specialized in audits and penetration testing.


We detect, assess and help mitigate the vulnerabilities of your systems, networks and applications before a real attacker exploits them, offering 360º defense tailored to each client.


We’d be glad to get in touch with you for whatever you need.