Blog · IT scandals · Ransomware
Ransomware knocked Argentina's immigration control offline, and the attackers demanded $4 million
On August 27, 2020, Netwalker ransomware took down the system that records entries and exits at Argentina's international border crossings, causing delays at the borders. Migraciones, Argentina's national immigration agency, restored operations from a backup and didn't pay the $4 million the attackers demanded. The attackers published data on 25,723 repatriated Argentines anyway. The backup saved operations; it didn't save the data.

What happened
At 5:45 a.m., border crossings started reporting problems. At 8 a.m., the IT team asked for permission to shut down SICAM (Sistema Integral de Captura Migratoria, the system that captures immigration records) and take its database offline to preserve it. Without that system, staff couldn't check court orders or Interpol alerts. According to the newspaper Clarín, no entries or exits were processed for almost four hours, and land crossings, Ezeiza International Airport and the Buquebus ferry terminal had to close until a temporary system was put together.
Initial forensic analysis found that the malware encrypted local files and part of the file server, but not the database. According to experts consulted by Migraciones, the attack started at headquarters and spread across the rest of the network, all the way to the border crossings. The affected machines were reinstalled by hand because of the risk of reinfection.
Netwalker demanded $4 million and set a one-week deadline. The government didn't pay. According to La Nación, the attackers published about 1.8 GB of data with the names, DNI numbers (Argentina's national ID), home addresses and phone numbers of 25,723 repatriated citizens.
Why wasn't the backup enough?
Because Netwalker used double extortion: it encrypted files and also threatened to publish what it had copied. A backup solves the first problem. Against the second, the only defense is keeping the attacker away from the data, or making sure whatever they take is worth little.
The case also showed how much access had been handed out. After a change in leadership, an internal audit found active credentials belonging to people who no longer worked at the agency, plus thousands of unjustified access grants for security forces: the Policía Metropolitana (Buenos Aires city police) alone had 19,000. Migraciones said it cut them down to 100. How the attackers got in was never confirmed: one official hypothesis was that an employee opened an executable file received by email.