Mexico SABG flags IMSS and SAT data lapses
Mexico’s anti-corruption office found data protection failures at public agencies, including IMSS, SHF and SAT, and ordered fixes.
Mexico’s anti-corruption and good government ministry said it found personal data protection failures at nine national health institutes, IMSS, the Sociedad Hipotecaria Federal and SAT. The cases included a clinical records system without the required security certification, a published IMSS database, ransomware against SHF, and the extraction of a SAT taxpayer’s data.
Mexico’s anti-corruption and good government ministry said it found personal data protection failures at nine national health institutes, IMSS, the Sociedad Hipotecaria Federal and SAT. The cases included a clinical records system without the required security certification, a published IMSS database, ransomware against SHF, and the extraction and disclosure of a SAT taxpayer’s information.
What did SABG detect in the public sector?
The agency identified failures in public bodies tied to the handling of personal data and ordered specific corrective measures. In the case of nine national health institutes, it ordered policy fixes, system updates and staff training within 40 business days.
The report also included IMSS, SHF and SAT among the violations it found. According to the authority, one case involved a clinical system without the required security certification, while another led to the publication of an IMSS database.
What figures did the authority report between September and June?
SABG said that between September 1, 2025 and June 30, 2026, it opened 122 investigations and carried out 60 inspections in the public sector related to personal data protection. In the private sector, it received 294 matters and closed 298.
It also received 76 matters tied to sanctions against companies and resolved 71, with fines totaling 118.5 million pesos for personal data-related violations. The figures are part of the ministry’s official recent activity report.
What other incidents were mentioned?
The authority also cited a ransomware attack against the Sociedad Hipotecaria Federal and the extraction and disclosure of a SAT taxpayer’s information. In both cases, the incidents were recorded as violations related to personal data protection.
The source material also includes a Milenio report about a cyberattacker identified as "Eternal," who offered databases allegedly tied to Telcel users, the Civil Registry, Nuevo Leon’s state payroll, IMSS workers, REPUVE vehicles and state water systems. That report said SABG issued two alerts related to that activity, although the available result does not confirm that those databases actually came from the institutions named.
The same Milenio coverage added that one SABG alert was linked to a Telegram post dated September 22 offering more than 12.9 million records allegedly tied to different call centers. The figure and attribution were presented by the outlet as part of the report on the attacker’s activity, not as independent technical confirmation.
Sources
- IMSS, SAT y SHF: SABG detecta fallas en datos personales; estos son los casoselimparcial.com· El Imparcial
- Ciberatacante que vende bases de datos por miles de pesos en Méxicomilenio.com· Milenio
- Filtran datos en el IMSS, SAT e Hipotecaria Federaleleconomista.com.mx· El Economista



