CiberLATAMbywhalemate

CDMX makes phishing a crime, up to 6 years

Mexico City added phishing to its local penal code, with prison, fines and higher penalties when victims are vulnerable.

Whalemate Labs · AI-assisted researchPublished:Updated 2 min read

Mexico City’s Congress approved reforms to the local Penal Code adding Article 231 Bis to classify phishing as a crime. The measure sets penalties of three to six years in prison and fines of up to 600 UMA for digital fraud carried out through deception or identity theft on technology platforms.

Mexico City’s Congress approved reforms to the local Penal Code that add Article 231 Bis and classify phishing as a crime. The measure punishes digital fraud carried out through deception or identity theft on technology platforms with prison terms of three to six years and fines of up to 600 Unidad de Medida y Actualización, according to Grupo Marmor and La Prensa.

The reform also includes aggravating factors. When digital fraud affects vulnerable groups, such as older adults, minors or people with disabilities, fines can rise by as much as 50%.

What regulatory context did the reform pass in?

The capital’s reform comes as Mexico continues to debate a future Cybersecurity Law. In a working session reported by Infobae Agencias, representatives from the financial and technology industries said the country is developing such a law and called for fraud and digital scams to be explicitly included.

In that same coverage, banking and technology voices warned that cybersecurity, fraud prevention and anti-money laundering units operate separately and do not share data, even though they work with the same information. They also proposed that the law include an integrated fraud kill chain, with initiation, execution and extraction, on the grounds that regulating only one stage leaves the other two exposed.

El Economista argued that the unresolved debate linked to the USMCA makes it likely that any future legislation will include obligations for critical infrastructure operators, incident reporting mechanisms, minimum protection standards and stronger coordination between authorities and the private sector. The same analysis tied the debate to the creation of the Digital Transformation and Telecommunications Agency, seen as an attempt to reduce institutional fragmentation by concentrating federal technology and cybersecurity policy.

What did Claudia Sheinbaum say about access to information and personal data?

Alongside that debate, President Claudia Sheinbaum said she will present a decree to guarantee access to federal government information, reserving only data tied to national security or active court cases. She also said she will seek to incorporate those criteria into the law while keeping personal data protected.

The Mexico City reform lands in a broader setting, with a criminal response already approved in the capital, a federal legislative discussion still underway and official decisions on transparency and information protection still taking shape.

How widespread is phishing in Mexico and what does reporting it require?

Noticias NEO reported that phishing in Mexico grew 202% over a recent period. The same report said that, even with the crime now defined in law, specialists consider proper digital evidence preservation essential for complaints to succeed, which adds context to how the new criminal offense may be enforced in the capital.

Sources

View all