CiberLATAMbywhalemate

CDMX makes phishing a crime, up to 6 years

Mexico City added phishing to its local penal code, with prison, fines and higher penalties when victims are vulnerable.

Whalemate Labs · AI-assisted researchAug 5, 20262 min read

Mexico City’s Congress approved reforms to the local Penal Code adding Article 231 Bis to classify phishing as a crime. The measure sets penalties of three to six years in prison and fines of up to 600 UMA for digital fraud carried out through deception or identity theft on technology platforms.

What CDMX approved

The Mexico City Congress approved reforms to the local Penal Code that add Article 231 Bis and classify phishing as a crime. The measure targets digital fraud committed through deception or identity theft on technology platforms, with penalties of three to six years in prison and fines of up to 600 Units of Measurement and Update, according to Grupo Marmor and La Prensa.

The reform also includes aggravating factors. When digital fraud affects vulnerable groups, such as older adults, minors or people with disabilities, fines can rise by as much as 50%.

Regulatory context and the debate ahead

The capital’s move comes as Mexico continues to debate a future cybersecurity law. During a working session reported by Infobae Agencias, representatives from the financial and technology sectors said the country is developing such a law and urged lawmakers to explicitly include digital fraud and scams.

In that same coverage, banking and technology figures warned that cybersecurity, fraud prevention and anti-money laundering teams operate separately and do not share data, even though they work with the same information. They also proposed that the law include an integrated "fraud kill chain" covering initiation, execution and extraction, arguing that regulating only one stage leaves the other two exposed.

El Economista said the unresolved debate tied to the USMCA makes it likely that any eventual law will include obligations for critical infrastructure operators, incident reporting mechanisms, minimum security standards and stronger coordination between authorities and the private sector. That analysis also linked the debate to the creation of the Digital Transformation and Telecommunications Agency, seen as an effort to overcome institutional fragmentation by centralizing federal technology and cybersecurity policy.

The other front: access to government information and personal data

Alongside that debate, President Claudia Sheinbaum announced that she will present a decree to guarantee access to federal government information, while reserving only information tied to national security or ongoing court cases. She also said she will seek to incorporate those criteria into the law, while maintaining protection for personal data.

The Mexico City reform therefore lands in a broader setting, with a criminal response already approved in CDMX, a federal legislative discussion still unfolding and official definitions on transparency and information safeguards still taking shape.

Practical impact

Noticias NEO reported that phishing in Mexico grew 202% over a recent period. The same report said that even with the crime now classified, specialists consider proper digital evidence preservation essential for complaints to be effective, which helps frame how the new criminal offense may work in practice in the capital.

Sources

View all