CiberLATAMbywhalemate

Mexico: Proofpoint Detects Mass Email Campaigns

Proofpoint saw large-scale email campaigns targeting Mexico in July and August 2026.

Whalemate Labs · AI-assisted researchPublished:2 min read

Proofpoint said it detected large-scale email campaigns targeting Mexico between July and August 2026 to steal credentials, install malware and gain unauthorized access. The lures were tied to companies and government entities, and one campaign attributed to TA2725 reached about 275,000 emails in six days.

Proofpoint said it observed large-scale email campaigns targeting Mexico in July and August 2026, with the aim of stealing credentials, installing malware and gaining unauthorized access. The malicious messages used lures tied to companies and government entities, according to ITware Latam's coverage of the company's report.

What did Proofpoint detect in Mexico?

Proofpoint observed large-scale email campaigns against Mexico during July and August 2026 aimed at credential theft, malware installation and unauthorized access. The messages relied on lures linked to companies and government entities, according to ITware Latam's coverage.

The available information does not describe a single campaign, but several operations seen during that period. The material also does not provide evidence to classify them as a confirmed APT or state-backed campaign against sectors such as government, banking or energy in Mexico.

What is known about TA2725 and TA4922?

According to ITware Latam's coverage of Proofpoint's report, TA2725 sent roughly 275,000 malicious emails targeting Mexico in a campaign that ran from July 19 to 24, 2026. The same coverage says Proofpoint also observed TA4922 expanding its operations to target Mexico for the first time.

In TA2725's case, the reported volume points to a mass email distribution campaign with significant reach in just a few days. For TA4922, the key detail is the geographic shift, since the available material says the group extended its operations to the country for the first time, without specifying how many messages were sent or what specific lures were used.

What was the scope of the activity observed?

The activity documented in the material combines phishing campaigns and malware distribution, with an explicit focus on Mexico and lures tied to businesses and government bodies. The time frame centers on July and August 2026, and the most concrete volume figure is TA2725's, with about 275,000 emails in six days, according to ITware Latam.

As far as the information provided goes, Proofpoint did not present this set of campaigns as a confirmed attack on critical infrastructure or as a state operation. The picture described by the sources is one of large-scale malicious email activity aimed at stealing credentials, installing malware and securing improper access.

Sources

View all