Costa Rica's Ministry of Finance took its tax and customs platforms offline on 18 April 2022 and told the public it was dealing with technical problems. What had happened, according to the government's later account, was that Conti operators had entered the ministry's network the previous night using valid credentials and worked outward from a single compromised machine. The systems that stopped were the ones the economy ran through: ATV, the virtual tax administration platform through which returns are filed, and TICA, the customs information system that clears imports and exports. Filing deadlines slipped by a day, then further. The dates are worth separating: 17 April was the night the attack surfaced and 18 April the disclosure, though Advanced Intel's later reconstruction dated the first access to 11 April; the national emergency was still three weeks away.
Conti's opening demand, posted to its leak site, was $10 million. The outgoing administration of Carlos Alvarado Quesada refused, and the gang began publishing what it claimed was a terabyte of ministry data, eventually amounting to something in the region of 670 gigabytes on the leak site — a figure that comes from the attackers, not from any published forensic accounting. On 6 May the US State Department offered up to $10 million for information identifying or locating Conti's leadership, and up to $5 million more for information leading to an arrest or conviction. Two days later, on 8 May, Rodrigo Chaves Robles signed Executive Decree 43542-MP-MICITT declaring a national emergency across the public sector, on the day he was sworn in as president.
It is generally recorded as the first time any country declared a national emergency over ransomware. The gang answered on Saturday 14 May by doubling its demand to $20 million and posting that it was determined to overthrow the government by means of a cyber attack, threatening to delete Costa Rica's decryption keys within a week. Chaves said two days later that the country was at war, with twenty-seven institutions affected. The foreign-trade chamber put early losses to exporters above $125 million — an estimate of trade disrupted, not of what the incident cost the state. The quieter damage: with payroll systems down, thousands of education ministry staff were paid late, short or not at all, and were still waiting when the Constitutional Chamber ordered contingency measures on 27 May.
Then, on 19 May, eleven days after the decree, Conti's internal Tor infrastructure went offline — the admin panels used for negotiations and leak-site publishing, and the internal chat servers, though the public leak site stayed reachable a while longer. Advanced Intel, which had been reading the group's internal communications, said the sum Conti discussed among itself was under a million dollars, and described the Costa Rican campaign as a group performing its own death and subsequent rebirth. Its people dispersed into Hive, BlackCat, AvosLocker, HelloKitty, BlackByte and Karakurt. At two in the morning on 31 May, ransom notes began printing on the office printers of Costa Rica's Social Security Fund. That attack was Hive's, and on its first day alone 4,871 patients missed appointments.
Follina, and the bug report that was closed
On Friday 27 May, the Japanese research collective nao_sec flagged a Microsoft Word document that had been submitted to VirusTotal from an address in Belarus. Opening it caused Word to fetch a remote HTML template, which invoked the ms-msdt URI scheme and executed PowerShell — no macros, no warning dialogue, and in some configurations no need to open the file at all, because a preview was enough. The researcher Kevin Beaumont gave it the name it kept, Follina, after the Italian village whose dialling code, 0438, appeared in the sample. The uncomfortable part surfaced next. A researcher using the handle CrazymanArmy, of the Shadow Chaser Group, had reported the same behaviour to Microsoft in April, noting that a live sample had been seen, and had been told it was not a security related issue. Microsoft assigned CVE-2022-30190 on 30 May and published a registry workaround; the patch did not arrive until 14 June. In the interval, state-aligned operators were already using it, including a Chinese group targeting the Tibetan government-in-exile.
$150 million for a phone number
On 25 May the US Justice Department, acting on behalf of the Federal Trade Commission, filed a complaint against Twitter and announced a settlement in the same breath: $150 million in civil penalties and a compliance regime attached. The conduct at issue was narrow and precise. Between May 2013 and September 2019 Twitter asked users for phone numbers and email addresses in order to secure their accounts — two-factor authentication, password recovery — and then made that contact data available to advertisers for targeting, in breach of a consent order it had been operating under since 2011. FTC Chair Lina Khan said the alleged violations affected more than 140 million users. Twitter had disclosed the practice itself in October 2019 and characterised it as inadvertent; the settlement carried no admission of liability. The order required the company to offer authentication methods that do not require a phone number, and to tell affected users what had happened. It remains one of the clearest official statements on record that a security control repurposed for advertising has stopped being a security control.
An airline grounded, a month before the clock started
SpiceJet's systems were hit late on the night of Tuesday 24 May 2022, and the consequences appeared at the departure gates next morning. Flights were held across the airline's network; passengers described waits of two to five hours, a booking system that would not load and a call centre that would not answer. The airline's account, posted that morning, described an attempted ransomware attack that had impacted and slowed down morning flight departures; its IT team, it said, had contained the situation and flights were operating normally. The word attempted did a lot of work, and no technical account was ever published to support it. On 27 May it told the stock exchanges that its 30 May board meeting to approve the year's results was postponed, because the attack had disrupted the audit.
The timing mattered twice. CERT-In had issued its cyber security directions on 28 April 2022 — six hours to report a listed incident, 180 days of rolling ICT logs, five years of subscriber records for VPN and virtual-server providers — and they did not take effect until 27 June. SpiceJet's incident fell in the gap: a listed incident at a company of national consequence, disclosed when and how the company chose. Through May the objections mounted — on the reporting window, on log retention, above all on the VPN provisions — and in mid-May CERT-In published frequently asked questions clarifying that enterprise VPNs were out of scope and logs could be held outside India. It did not settle the argument. Several international VPN operators withdrew their Indian servers instead, and the deadline for smaller entities was later pushed to September.
Open weights and generalist agents
On 3 May 2022 Meta released OPT-175B, a 175-billion-parameter language model whose weights and training code went to researchers under a non-commercial licence — by Meta's own account the first model of that size opened to the wider research community, and the start of the open-weights line that became Llama. Google answered all month. At I/O on 11 May Sundar Pichai introduced LaMDA 2 and the AI Test Kitchen, an app that would let the public prod a dialogue model and report what it got wrong — the same LaMDA that would shortly persuade a Google engineer of its sentience, and later underpin Bard. DeepMind's Gato paper followed on 12 May: a single network trained across hundreds of tasks, from Atari to stacking blocks with a robot arm, titled "A Generalist Agent" — the noun the industry later adopted wholesale. And on 23 May Google Research showed Imagen, a text-to-image model that human raters, in Google's own tests, preferred to DALL-E 2 — shown but not released, on misuse grounds, months before open-weights image generators made that caution moot.
$61 billion, with an endpoint attached
On 26 May 2022 Broadcom announced its agreement to buy VMware for roughly $61 billion in cash and stock — one of the largest technology acquisitions on record, and, almost in passing, a change of ownership for Carbon Black, the endpoint business VMware had bought in 2019. Broadcom already owned Symantec's enterprise arm, and the immediate question was whether Carbon Black would be sold, starved or absorbed. The answer took years: the deal closed in November 2023 after clearances from regulators in around a dozen jurisdictions, a sale of Carbon Black was weighed and shelved, and the unit ended up folded in beside Symantec under Broadcom's enterprise security division. At the other end of the market, SentinelOne announced on 4 May 2022 that its acquisition of Attivo Networks had closed — $616.5 million in cash and stock for a specialist in identity security and lateral-movement protection, on the argument that stolen credentials had become the endpoint's soft flank. Identity threat detection, a niche then, is a routine line on endpoint platforms now.
⏳ Time capsule — May 2022
- The Event Horizon Telescope collaboration published the first image of Sagittarius A*, the black hole at the centre of the Milky Way, on 12 May.
- Ukraine's Kalush Orchestra won the Eurovision Song Contest in Turin on 14 May with "Stefania".
- Finland and Sweden formally submitted their applications to join NATO on 18 May, ending decades of non-alignment.
- Top Gun: Maverick opened in cinemas on 27 May, thirty-six years after the original.
The brand died; the people did not
Costa Rica's recovery was measured in months, not weeks: the tax platform restarted on 13 June, the customs system on 24 June, close to two months after the first machine was touched. The durable legacy is the exit itself. Conti demonstrated that a ransomware brand under sanction is a liability, and that the fix is to dissolve loudly and reappear quietly under other names — the route taken by every collapse this archive has covered since, from LockBit after Operation Cronos to ALPHV's exit with its affiliates' money. Hive, the biggest beneficiary of the dispersal and the group behind the 31 May hospital attack, was infiltrated by the FBI from July 2022 and taken apart in January 2023 — a story told in this archive's January 2023 edition.
Follina's other legacy is procedural. A researcher reported the behaviour, was told it was not a security issue, and was vindicated six weeks later by a live sample uploaded from Belarus — a sequence still cited whenever vendor triage is argued about. And the two thresholds crossed that month have not been uncrossed. A national emergency over a ransomware attack is no longer unheard of, and in India the six-hour rule that SpiceJet missed by a month became the reporting baseline against which every incident since has been measured, and every delay in disclosing one.