● Ransomware

Cybercriminals Deploy Office Printers and BitLocker in New Extortion Scheme

July 23, 2026 · snewle
Cybercriminals Deploy Office Printers and BitLocker in New Extortion Scheme

A novel extortion scheme combining compromised office printers, Windows BitLocker encryption, and targeted ransom demands has been identified by cybersecurity researchers. The attack methodology represents an unusual approach to data extortion, exploiting legitimate Windows encryption features after gaining initial access through networked office equipment.

The campaign involves attackers leveraging vulnerable or misconfigured office printers as entry points into corporate networks. Once inside, threat actors deploy Windows’ built-in BitLocker encryption tool to lock victims out of their own data, demanding relatively small ransom payments to restore access. This approach differs from traditional ransomware by utilizing native operating system features rather than custom malware.

How Are Attackers Gaining Initial Access?

The attack begins with compromised office printers serving as the initial infiltration vector. Networked printers, often overlooked in security audits, provide attackers with a foothold inside corporate environments. From this position, threat actors can move laterally across networks to reach critical systems and data.

In one documented case, attackers abused Remote Desktop Protocol connections to gain deeper access to victim systems. This allowed them to execute the encryption phase of their attack, activating BitLocker on targeted drives and effectively locking legitimate users out of their own files and systems.

Who Is Behind These Attacks?

Researchers identified at least one threat group involved in these operations, tracked as the XEntry Team. This actor appears to be actively exploiting the printer-to-BitLocker attack chain to extort victims. The relatively small ransom demands suggest these campaigns may be targeting small to medium-sized organizations rather than major enterprises.

What Defense Measures Are Recommended?

Security experts emphasize that backups remain the most powerful and cost-effective defense against ransomware and extortion attacks. Organizations maintaining regular, isolated backup copies of critical data can restore their systems without negotiating with attackers, regardless of the encryption method used.

The research highlights that no security measure provides absolute protection, as administrators and IT professionals can make mistakes and antivirus solutions may fail. However, proper backup strategies ensure that even successful attacks don’t result in permanent data loss or force organizations into paying extortionists for access to their own information.

The emergence of this attack technique underscores the importance of securing all network-connected devices, including peripheral equipment like printers that may not receive the same security attention as servers and workstations.

Source: Securelist