Sinaloa: Possible Data Leak Reported
Officials in Sinaloa reported a possible leak of medical records, payroll data and bank accounts. No public technical findings are available.
Local authorities and media in Sinaloa reported a cyberattack against the Culiacán city government and the state government, with possible impact on medical records, payroll data and bank accounts. As of July 23, there were no public technical findings confirming the origin or scope of the breach.
Authorities and local media in Sinaloa reported a cyberattack against the Culiacán city government and the state government. According to a council member cited by the press, more than 4,000 citizen medical records may have been compromised, along with payroll information and bank accounts belonging to workers and taxpayers.
Reported scope in Sinaloa
Debate reported that the compromised information would no longer be limited to patients in the health area, but would cover the entire Culiacán city employee database, including the full payroll and the bank accounts of employees and taxpayers. In the same coverage, the Culiacán city government said in briefings that its technical teams were reviewing systems and had not yet detected alerts that would formally confirm a breach.
El Sol de Sinaloa added that, as of July 23, there had already been seven reports of possible cyberattacks against public systems in the state during July. According to that review, the allegations involved medical records, payrolls, taxpayer rolls, property information and port records. The outlet also said there were no public technical findings confirming the origin or scope of the possible breaches.
What is known, and what remains unconfirmed
Based on the material available, there is no public confirmation that the incident in Sinaloa was ransomware, and there is no official technical attribution for the attack. Local coverage refers to possible leaks and systems under review, but not to a closed forensic conclusion.
In parallel, Kaspersky and an analysis circulated by Latin American media described ransomware cases in Mexico with a different profile. In one of them, attackers exploited a misconfigured Microsoft SQL server to gain elevated privileges, deploy web shells, evade EPP alerts and encrypt critical drives with BitLocker, while printing ransom notes on office printers. The victim organization was not publicly identified or linked to the health sector.
TrendTIC also reported a case in Mexico attributed to a group calling itself XEntry Team, which allegedly gained initial access through a misconfigured Microsoft SQL server and credentials exposed in public code, then encrypted systems with BitLocker and printed ransom notes on corporate printers. That account also does not identify the victim as a hospital or another health organization.
Taken together, those reports show a clear contrast. In Sinaloa, there is a case with alleged exposure of medical records and administrative data, but no official confirmation of the type of attack. Separately, there are ransomware cases in Mexico with specific technical vectors, although no public link to health providers.
Sources
- Hackeo en Sinaloa: Habrían sido filtrados datos de 4000 pacientes, cuentas bancarias y másdebate.com.mx· DebateUnverified URL
- Errores de configuración que alimentan el ransomware: lecciones de Colombia y Méxicocarmona.mx· Carmona.mx
- Expertos alertan sobre una creciente táctica de ransomware: hackers imprimen demandas de rescate durante ataques en América Latinatrendtic.cl· TrendTIC
- Suman siete reportes de posibles ciberataques a sistemas públicos de Sinaloa en juliooem.com.mx· El Sol de Sinaloa



