On the morning of 18 April 2022, Costa Rica's Ministry of Finance announced that it was having technical problems and pulled its two most-used systems offline: ATV, the virtual tax administration platform, and TICA, the customs information system through which every import and export declaration in the country passes. Filing deadlines were extended. At the ports and border crossings, customs work reverted to paper — declarations completed by hand, containers queuing behind clearances that used to take minutes, and perishable cargo sitting in cold storage while brokers waited for a signature. The ministry did not initially say it had been attacked. Within a day it no longer had the option.

The intrusion had begun a week earlier. Reconstructions assembled from Conti's own leaked internal communications — analysed by researchers, not published by the Costa Rican government — place initial access on 11 April through a compromised machine on the finance ministry's network and credentials harvested from it. The operator moved laterally using Cobalt Strike beacons, enumerated domain trusts, and escalated with credential-dumping tools; roughly 672 gigabytes of data were copied out to a file-hosting service by 15 April, and the ransomware was executed on or about 16 April, with the visible collapse arriving on the night of the 17th. Three dates get collapsed into one in most accounts of this attack, and they are not the same date.

Conti posted its demand on 19 April: $10 million, in exchange for not publishing the finance ministry data it said included taxpayer records. When Costa Rica refused, the figure in the gang's own postings climbed to $20 million by late May — a number that comes from the attackers rather than from any published forensic account, and one that leaked Conti chatter suggests bore little relation to what the group would have settled for. President Carlos Alvarado's answer was flat: the Costa Rican state, he said, would not pay anything to these cybercriminals. Over the following week the gang claimed the science and technology ministry, whose site was defaced with a greeting from Conti, the meteorological institute, the state internet provider RACSA, the labour ministry and a municipal electricity board in Cartago.

Around thirty institutions were touched in all. Costa Rica's export and business chambers estimated losses to the productive sector on the order of $30 million a day while customs was down — an estimate of private-sector activity forgone, not a measure of what the incident cost the state, and the two are conflated almost everywhere this story is told. The country declared a national emergency on 8 May, hours after Rodrigo Chaves took office, the first government to do so over a cyberattack. ATV was restarted on 13 June and TICA on 24 June: a little over two months of a national tax and customs apparatus run by hand, and nothing paid.

Also that month · Somebody else's keys

Dozens of private repositories, one forgotten authorisation

GitHub published a security alert on 15 April 2022 describing an attack it had begun investigating three days earlier, after its security team spotted unauthorised access to npm production infrastructure using a compromised AWS API key. The trail led outwards rather than inwards. Someone had obtained OAuth user tokens issued to two third-party integrations — four Heroku Dashboard applications and Travis CI — and was using them to list and clone private repositories belonging to dozens of organisations that had, at some point, clicked to authorise those apps and then forgotten about it. Salesforce, which owns Heroku, said a subset of Heroku's own private repositories had been downloaded on 9 April. GitHub was precise about what it did and did not claim: that its own systems were not breached in the original attack, that it does not hold the tokens in usable form, and that the attacker had not modified any npm packages or reached user account data or credentials. Victim notifications went out in waves on 18, 22 and 27 April.

Also that month · Ten minutes apart

The substation attack that was caught in time

On 12 April, ESET and Ukraine's CERT-UA disclosed that they had interrupted an operation against a regional Ukrainian electricity provider four days earlier. The tooling was tailored to a degree that removed any doubt about intent: a binary the researchers named Industroyer2, compiled on 23 March, carrying hardcoded IEC-104 addresses matching the protection relays of the specific substation it was meant to operate. A scheduled task was set to run it at 16:10 UTC on 8 April; ten minutes later, CaddyWiper was to erase the operator workstations, with wipers prepared for Linux and Solaris hosts to lengthen the recovery. CERT-UA, working with ESET and Microsoft, removed the staged payloads before either fired, and no customers lost supply. ESET attributed the operation to Sandworm with high confidence — a researcher's assessment rather than a government finding, though later attributions agreed. The following day, CISA, the FBI, the NSA and the US Department of Energy jointly warned about a separate toolkit built to seize Schneider Electric and Omron controllers, which Dragos called PIPEDREAM and Mandiant INCONTROLLER, and which no one had yet observed in use.

India desk · April 2022

Six hours, 180 days, five years

On 28 April 2022, CERT-In issued directions under section 70B(6) of the Information Technology Act, rewriting what an Indian organisation owes the state after a security incident. The headline requirement was time: a listed incident — unauthorised access, a data breach or leak, ransomware, an attack on IoT devices — must be reported within six hours of noticing it or being made aware of it. Three quieter obligations carried further. Logs of all ICT systems had to be retained for 180 days and held within India. Data centres, virtual private server operators, cloud providers and VPN providers had to keep subscriber records — names, addresses, contact details, period of hire, IP addresses allotted — for five years after a subscription ended. And covered systems had to synchronise their clocks to NIC or NPL time servers, so logs from different organisations would line up.

The backdrop was fresh: on 10 April ransomware had reached a workstation in Oil India Limited's geological and reservoir department at Duliajan, Assam, taking the state-owned producer's online systems down while drilling and production continued. Indian outlets reported a demand of $7.5 million, or over ₹57 crore, with some converting a claimed 196-bitcoin figure to roughly ₹60 crore; those numbers came from press reporting citing police and company sources, not a company statement. The directions drew objection within days — no public consultation, six hours against the GDPR's seventy-two, and a five-year logging mandate no-log VPN businesses said they could not meet. ExpressVPN, Surfshark and NordVPN withdrew their physical servers from India rather than comply. CERT-In later gave MSMEs and cloud, VPS and VPN providers three more months. India, at that point, had no data protection statute.

AI Tech desk · April 2022

A picture, a prompt, a waitlist

OpenAI showed DALL·E 2 on 6 April 2022 and then let almost nobody touch it: a research preview behind a waitlist, generating images at four times the resolution of its year-old predecessor and editing existing ones on request. Google had set the tone two days earlier with PaLM, a 540-billion-parameter language model whose few-shot results suggested scale still had headroom, and DeepMind closed the month on 28 April with Flamingo, a visual-language model that could caption an image or answer questions about it from a handful of examples. The money moved the same week: Adept emerged from stealth with two authors of the Transformer paper aboard, and Anthropic announced a $580 million round on 29 April, led by FTX's Sam Bankman-Fried — a detail that would read differently within the year. From 2026 this looks like the generative wave assembling in plain sight: the waitlist gave way that summer to Midjourney and Stable Diffusion, and Flamingo's trick became every assistant that reads a screenshot.

Digital Guard desk · April 2022

Kaseya writes the month's biggest cheque

The month's biggest deal landed at the unglamorous end of the stack: on 11 April 2022, Kaseya agreed to buy Datto, the backup and business-continuity firm that sells through managed service providers, for $6.2 billion in cash from an investor group led by Insight Partners — a striking turn for a company whose own software had been the conduit for the REvil supply-chain attack nine months earlier. The deal completed in June. On 22 April, Sophos bought SOC.OS, a Milton Keynes alert-triage spin-out of BAE Systems, to pull third-party telemetry into its managed detection service — the direction the whole endpoint trade was drifting, from selling agents to selling operations. The squeeze on Kaspersky, meanwhile, proceeded by administrative means: in late April, Italy's new cybersecurity agency directed public bodies to diversify away from Russian-linked security software, naming Kaspersky among others. The company maintained, as throughout, that it operated independently of any government; the retreat ended, viewed from 2026, in the American sales ban of June 2024.

⏳ Time capsule — April 2022

  • The US Senate confirmed Ketanji Brown Jackson to the Supreme Court on 7 April by 53 votes to 47 — the first Black woman appointed to it.
  • Tiger Woods played the Masters from 7 to 10 April, his first PGA Tour event since a car crash thirteen months earlier; he made the cut and finished 47th, while Scottie Scheffler won his first major by three shots.
  • Emmanuel Macron defeated Marine Le Pen in the French presidential run-off on 24 April, becoming the first sitting president in twenty years to win a second term.
  • Twitter's board accepted Elon Musk's offer to buy the company for about $44 billion on 25 April; the deal did not actually close until October.
Where it stands today — 2026

The gang died, the rules did not

Conti did not survive the year. Its internal chats had been dumped online in late February 2022 by a leaker angered at its declaration of support for Russia, and by June its negotiation and leak sites were dark, its people reassembling under other names. In May the US State Department offered up to $10 million for information identifying Conti's leadership and $5 million more leading to arrests. Costa Rica became the case everyone reaches for when a government is asked whether it will pay — upstream of Royal Mail's refusal nine months later in this archive's January 2023 edition. The two teenagers charged over Lapsus$ on 1 April were tried in London the following year; one was found responsible for a run of intrusions and detained indefinitely under a hospital order.

The Indian directions outlasted almost everything else in this edition. The six-hour clock is still running in 2026, unchanged, and the DPDP Act — passed in August 2023, more than a year after CERT-In moved — did not displace it; an Indian organisation still counts its first obligation after a breach in hours rather than days. The VPN providers that left in 2022 have not returned, and reporting in mid-2026 indicated the government was weighing fresh legislation on the view that the 2022 rules never produced the compliance they demanded. Sandworm's tailored substation payload, meanwhile, became the question every grid operator is now asked: the attack that failed on 8 April 2022 is still the template.