Kaspersky researchers investigated two BitLocker-based extortion incidents in Latin America — one in Colombia exploiting an exposed RDP service, another in Mexico via a misconfigured MSSQL server with credentials leaked on GitHub. In the Mexico case, attackers operated undetected for three months, deployed multiple RMM tools (ManageEngine Endpoint Central, Mesh Agent, Tactical RMM), used xp_cmdshell for OS-level command execution, and ultimately pushed GPO-based BitLocker encryption across the entire domain. Both attacks used office printers to deliver ransom notes and demanded relatively small sums. Key takeaways include the danger of exposed RDP/MSSQL services, disabled endpoint protection, ignored security alerts, and the growing trend of abusing built-in Windows tools instead of traditional ransomware payloads.