Kaspersky Warns of BitLocker Ransomware Attacks Using Office Printers to Deliver Ransom Notes
Kaspersky warns of a new ransomware attack using BitLocker encryption and office printers to deliver ransom notes. Cybercriminals exploited security misconfigurations, exposing businesses to data loss, ransomware threats, and unauthorized network access.
Kaspersky researchers uncovered a new ransomware attack that targeted companies in Colombia and Mexico. Instead of utilizing complex malware, the attackers used weak security settings, vulnerable remote access services, and built-in Windows features such as BitLocker to encrypt critical company data. According to Kaspersky, the attacks occurred between May and June 2026. Victims immediately observed a padlock icon on their Windows drives, which indicated that their files had been encrypted with BitLocker. Employees were unable to access crucial files after the data was locked, and the attackers demanded a cost to recover access.
One of the more distinctive features of these attacks was the use of company printers. After gaining control of the company's network, the attackers printed ransom notes directly from the organization's printers. This allowed them to promptly notify employees that their systems had been compromised and that payment was required.
In one case in Colombia, hackers entered the network through an internet-connected remote access service that was not properly secured. They then changed user passwords and used BitLocker to encrypt an 8TB storage device containing sensitive financial information.
In another incident in Mexico, a hacking group known as the XEntry Team got access to a misconfigured Microsoft SQL Server after discovering exposed login information in publicly available code. The attackers remained hidden inside the company's systems for months before employees noticed the breach. The hack was detected when PCs flashed a blue screen with the words "Hacked by XEntry Team," preventing users from logging in.
Kaspersky researchers stated that such attacks demonstrate that attackers do not necessarily require advanced malware. Instead, they frequently rely on security vulnerabilities, weak passwords, vulnerable servers, and trusted system utilities that are already installed on Windows systems. This makes the attacks more difficult to detect because the tools used are legitimate.
To reduce the threat of ransomware attacks, Kaspersky recommends safeguarding Remote Desktop Protocol (RDP), fixing setup errors, protecting login credentials, monitoring network activity, and using advanced cybersecurity solutions like EDR and XDR. The organization also recommends that businesses frequently check for unusual activity and examine any indications of illegal access before attackers cause significant damage.
The recent incidents demonstrate that even minor security vulnerabilities can lead to major ransomware attacks. To safeguard critical company data from escalating cyber threats, organizations should assess and tighten their security settings on a regular basis.
This article is based on information from Kaspersky