If you own or otherwise manage a website or computer network in Costa Rica, you may want to ensure that your security systems and protocols are solid and up-to-date. Hacking and network security skills are in high demand in Costa Rica at this time, and many employers are asking job candidates that they bring factual proof of their exploits before they are hired, which means that they may target you just to get the job.
As recently reported by the Costa Rica Star, an online news publication owned by the University of Costa Rica (Spanish initials: UCR) suffered a massive distributed denial of service (DDOS) attack following the publication of a public opinion poll on the sentiment of voters. The news sparked controversial comments about the possibility of the attack having been carried out by hackers under the employ of a political party. Other publications that have suffered similar attacks in Costa Rica include El Pais, an online news daily that is often the voice of the opposition.
To think that hackers in Costa Rica are being hired to either conduct attacks or to strengthen security systems is not far-fetched. In late November, the National University of Costa Rica (UNA) celebrated the International Information Security Day with a series of workshops and lectures at the Chorotega Campus in Nicoya, province of Guanacaste. Some of the most heavily attended and vibrant lectures were on subjects such as:
- Network intrusions
- Network security exploitation
- Hacktivism
- “Man in the middle” attacks
- Breach of privacy in online social networks
At websites such as La Web del Programador, requests for hackers to perform freelance assignments in Costa Rica are not unusual, and many of them ask for proof of a recent exploit along with a resume or curriculum vitae. The prospective hacker may tell the employer “I am going to deface the homepage of “www.*****.com” or “I will give you the admin password of www.*****.com” to increase their chances of getting hired.
Hacking skills are not just being asked of freelancers for the purpose of carrying out nefarious work. At IBM Costa Rica, you need hacking skills to get a cushy job as a Security Information and Event Management (SIEM) threat analyst. The employment of hackers in Costa Rica dates back to 2012, when an article by Pablo Fonseca of La Nacion profiled the daily routine of Yere Cespedes, an employee of Deloitte in the trendy Barrio Dent in San Jose. Back then, the Deloitte consultancy employed five hackers to study network vulnerabilities and possible exploits.
In late 2012, a curious message appeared on the Facebook and Twitter feeds of presidential candidate Johnny Araya, who recently abnegated his political campaign:
“Posted by hacker: Don Johnny, yous should do a better job at protecting your social media pages and improve your security because next time I could publish your personal and confidential information, WikiLeaks-style. Also, do not take credit for doing things that you should be doing anyway.”
Candidate Araya was still Mayor of San Jose when the attack above took place. Whereas in the past such attacks in Costa Rica were often credited to politically-motivated hackers, these days it is not unreasonable to believe that the motivation of the attacker was monetary, meaning that he or she was paid to do it.




