BitLocker Takes Companies Hostage

Article by Nacata Security, 27/07/2026

Can you imagine arriving at work and being unable to open a single company file?

That is what companies in Colombia and Mexico experienced this year.

It was not a classic ransomware attack or a sophisticated group with custom tools. The attackers used a feature already installed on Windows to encrypt data and demand a ransom.

And when they were done, they did not send a threatening email or display a pop-up message on screen. They printed the extortion notes directly from the office printers.

Image of the moment of discovery: blue screens across an open-plan office displaying the attackers' message and locked disk icons, with a chair pushed back in alarm.
Locked screens, paralyzed company

The attack began long before anyone noticed.

In the case of Mexico, the attackers gained entry through a misconfigured database service whose credentials had been accidentally published on GitHub. From that initial access, they spent three months silently exploring the network, lowering the web server’s security settings, and creating malicious files. Alerts were triggered, but no one investigated them. By the time May arrived, the attackers already controlled the entire infrastructure.

They then deployed legitimate remote management tools.

They installed ManageEngine Endpoint Central, Mesh Agent, and Tactical RMM to remotely manage devices. Using these tools, they scheduled automated tasks that activated BitLocker on every machine in the domain. Each disk received a unique key. Employees were greeted with a blue screen displaying the message Hacked by XEntry Team, and their passwords stopped working. Hours later, the printers spat out ransom notes.

In Colombia, the demand was just $3,000 for critical data.

Image of the silent intrusion: a digital tunnel representing months of undetected compromise, with commands flowing along its walls and a figure exploring the infrastructure in the shadows.
Three months without detection

A small ransom, an enormous amount of damage.

A low ransom does not mean the damage is any less severe. The Colombian company restored the system before forensic investigators could act, destroying all the evidence. The real damage goes far beyond the money.

This method is becoming a trend.

Researchers note that this is not the first time they have seen attackers use BitLocker as a weapon. A few years ago they identified ShrinkLocker using the same approach. The logic is straightforward: using tools built into the operating system avoids triggering antivirus alerts and eliminates the need to purchase ransomware from criminal groups. It is cheaper, quieter, and, as these cases demonstrate, just as effective.

Image of the escalation: a legitimate tool turned weapon, overlaid on a corporate network diagram, with torn calendar pages scattered around.
Legitimate tools, real damage

An endpoint without active protection is the perfect entry point.

In Colombia, the targeted system had its EPP disabled due to incompatibilities with other applications. This allowed the attackers to move freely and execute code without any central system raising a flag. A single unprotected device can compromise the entire network.

The logs existed, but no one was looking at them.

In Mexico, EPP alerts fired when the attackers tampered with the web server. The problem was not the technology — it was that no one investigated those warnings. Centralizing logs and responding in a timely manner is the difference between stopping an attack and discovering it only after it is too late.

The printers delivered the final message.

The fact that the attackers used the company’s own printers to deliver their ransom note speaks volumes: they already had total control. And that happened because the doors had been left open for months.

Three urgent steps

  • Protect any exposed RDP or MSSQL services with strong authentication.
  • Keep the EPP active and investigate every alert without exception.
  • Maintain offline backups and verify that you can restore them.

How many devices in your company have the EPP disabled today without anyone knowing?

Security is not improvised, it is audited. At Nacata Security we detect vulnerabilities and protect your company, because a single flaw can cost you everything you have built.

Related articles

Nacata Security, reach out to us anytime

How would you rate this news?

We are Nacata Security, get to know us

web: nacata.io

email: info@nacata.io

Phone: 919930793

LinkedIn: Nacata Security

Cyber Intelligence

The ecosystem of malicious actors and the intelligence gathered about them: APT groups and their attribution, ransomware gangs, law enforcement operations and arrests, dark web markets, threat intelligence reports and the geopolitical backdrop of cybercrime.



RATING


9.2



Who are we?


At Nacata Security we are an offensive cybersecurity company specialized in audits and penetration testing.


We detect, assess and help mitigate the vulnerabilities of your systems, networks and applications before a real attacker exploits them, offering 360º defense tailored to each client.


We’d be glad to get in touch with you for whatever you need.