CiberLATAMbywhalemate

Banxico reports eight bank cyber incidents in 2026

Banxico logged eight cyber incidents at banks between January and May 2026, twice the total recorded in all of 2025.

Whalemate Labs · AI-assisted researchPublished:3 min read

Between January and May 2026, Mexico’s central bank recorded eight cyber incidents at financial institutions, double the total for all of 2025, according to a note republished by MSN based on information attributed to Banxico. The figure comes as the sector faces new biometric rules, security certifications and regulatory penalties.

Between January and May 2026, Mexico’s central bank recorded eight cyber incidents at financial institutions, a figure that is reported as twice the total for all of 2025, according to a note republished by MSN based on information attributed to Banxico. The figure comes amid new regulatory requirements for the sector, reporting on security gaps at banks and a sanctions framework that reaches financial and vulnerable activities.

What do the reports show about the financial sector?

Banxico counted eight cyber incidents between January and May 2026, according to the material republished by MSN. The comparison with all of 2025 shows a clear jump in just five months, in an ecosystem where the CNBV also oversees 5,381 entities, according to El Heraldo de México.

That broad supervisory universe brings compliance obligations, including measures to protect security and financial information. At the same time, an analysis cited by Expansión found that 42% of Mexico’s leading financial institutions have gaps in basic email security measures, increasing exposure to identity spoofing attacks.

What new requirements are appearing for entities?

The CNBV has set technical requirements for fingerprint collection and facial biometrics, including verification and safeguarding processes for that information in customer identification, according to Itsitio México. On that same front, Milenio reported that Paycaster received operating authorization in Mexico in 2026 from Banxico and the CNBV.

Milenio also said Paycaster has certification under the international PCI DSS 4.0.1 standard for data and information protection in card operations. Those kinds of approvals and certifications form part of the control framework the sector must meet to operate.

What happens if obligations are not met?

The LFPIORPI sets out violations and fines in Articles 53 and 54, with sanctions calculated in UMA for failing to file notices, filing them late, submitting incomplete information, or failing to keep documentation for ten years, according to Siempre Al Día. The framework applies to a range of vulnerable activities, including certain financial services.

The sanctions regime adds to technical requirements and CNBV oversight of thousands of entities. In practice, Mexico’s financial sector is facing more regulatory pressure, more exposure to basic failures, and a rising number of incidents reported by the central bank.

Sources

View all