Mexico: cybersecurity landscape, July 2026
Ransomware dominated July in Mexico, with 105 verified incidents, 55 extortion cases, and 19 critical CVEs mentioned.
Key findings
- Ransomware was the leading threat in Mexico, accounting for 55 of 105 verified incidents and rising sharply from the previous month.
- The public sector concentrated the most sensitive cases due to reputational and data impact, with León, Sinaloa, and the Presidency as the main focal points.
- Mexico City moved to classify phishing as an autonomous crime, while regulatory pressure grew over biometrics and data processing.
- Technical activity showed abuse of weak configurations, exposed services, and leaked credentials more than mass CVE exploitation for local intrusion.
- There were 19 critical CVEs mentioned, several with active exploitation, increasing the urgency of patching exposed systems.
- Most ransomware cases could not be determined with precision as to whether there was encryption, exfiltration, or only publication on a leak site.
- Exposure of sensitive data, especially health, citizenship, and financial data, raised secondary risk from fraud, extortion, and identity theft.
Monthly reference modules
These modules are completed automatically with verified dated facts within the period. Each one states its source basis and counting criterion, so the figures reconcile across modules. They are the recurring month-to-month reading; the analysis that follows develops the cases without repeating this summary.
Indicator window: 108 dated facts in July 2026 · 1 from prior months (comparative frame, not monthly volume) · 2 after the period (excluded). Facts from prior months are used only as a comparative frame in the analysis, never as volume for this period.
Monthly Executive Summary for Mexico
July 2026 left Mexico facing a cybersecurity agenda dominated by extortion and two parallel storylines. On one side, ransomware activity kept setting the pace, with cases published against private organizations, local government agencies, and a set of victims claimed on leak sites. On the other, massive data exposure incidents emerged in the public sector involving the Government of Sinaloa and the Presidency, both with sensitive material and an ongoing public debate over the true scope of the leaks.
The verified monthly base was high, with 105 confirmed events within the period and 12 incidents not classified as breaches or outages. The leading threat was ransomware, with 55 events, far above the previous month. Within that universe, only four cases resulted in confirmed asset encryption, two were limited to leak-site mentions, and in 49 it was not possible to determine the exact technical impact from the available material. That distinction matters, because the volume of claims does not automatically translate into the same number of intrusions with verified encryption.
The risk surface also expanded through regulatory action. There were five documented regulatory moves, focused on banking biometrics, phishing sanctions in Mexico City, and additional initiatives on AI and personal data. At the same time, 19 critical CVEs were mentioned, a figure far higher than the previous month, with several vulnerabilities actively exploited in Microsoft, Adobe, Linux, Palo Alto Networks, and other exposed environments.
The operational reading for Mexico is high risk. Not only because of the number of verified events and the intensity of the extortion component, but also because of the coexistence of public incidents, regulatory pressure on banking and data protection, and a technical layer where abuse of exposed services, configuration flaws, and active exploitation of critical vulnerabilities continued to appear as recurring access paths.
Mexico National Monthly Overview
July brought an unfavorable mix for defense teams, with more ransomware reporting, more regulatory discussion, and greater public-sector data exposure. The dominant trend was clear, ransomware returned as the main focus with 55 of 105 verified incidents. The previous month, that same threat accounted for 15 of 56 incidents, so the increase was not marginal but structural in the available coverage.
The technical pattern was not uniform either. In several incidents claimed by groups or specialized monitors, the source did not specify whether there was encryption, only a leak, or just publication on a leak site. That means the total case count should be read with analytical caution. Some incidents did involve confirmed encryption, but others were publicly evidenced only by a claim or by data exposure. In response terms, that can require both forensic containment and legal and communications management, even when there is no public proof of prolonged unavailability.
The quality of the month’s sources was mixed. There were serious technical bulletins, press notes with useful operational detail, and ransomware monitoring reports that added context, but also coverage based on unconfirmed attributions or partial descriptions. For that reason, the most responsible snapshot for Mexico in July is one of an ecosystem under strong extortion pressure, weak configurations being exploited, and sensitive data being exposed, rather than a single coordinated campaign.
At the regional level, Mexico continued to appear among the Latin American countries drawing the most activity and attention from threat groups and security firms. Reports citing Kaspersky and other vendors placed the country among the most affected in the region in terms of attempts or claims, but those telemetry figures should be read as context, not as incidents. For the month under review, the verifiable point was the materialization of specific cases, not aggregate ecosystem telemetry.
Mexico period indicators
| Indicator | July 2026 | Previous month | Change |
|---|---|---|---|
| Verified facts in the period, basis for all indicators | 105 | 56 | +49 |
| Indicator time window | 108 facts dated July 2026, 1 from prior months, 2 after the period excluded | Same | N/A |
| Unclassified incidents, breaches, or outages | 12 | 15 | -3 |
| Cases with ransomware or extortion as the primary focus | 55 | 15 | +40 |
| Confirmed asset encryption | 4 | not provided | N/A |
| Leak site mention only | 2 | not provided | N/A |
| Classification not determinable from available material | 49 | not provided | N/A |
| Documented fraud or phishing cases | 7 | 2 | +5 |
| Documented regulatory moves | 5 | 4 | +1 |
| Critical CVEs mentioned | 19 | 4 | +15 |
| Sectors with at least one documented event | 7 | 7 | unchanged |
| Dominant threat of the month | Ransomware (55 of 105 facts) | Ransomware (15 of 56 facts) | no shift in focus |
| Facts with direct source confirmation | 59% | not provided | N/A |
| Aggregate telemetry figures excluded from the volume | 3 (combined attempts or blocks, not incidents with confirmed impact) | not provided | N/A |
Relevant Incidents in Mexico
León government and municipal service outages
The cyberattack against the Government of León was one of the month’s most visible events in local public sector reporting. Local media coverage indicated that the official website went offline and that the Citizen Services System was the main target. Reports also said the IT team was taken offline as a precaution to contain the damage, followed by security testing before services were restored.
The case left two operational takeaways. The first is service continuity, because the official website and the transparency portal stayed offline or had restricted access for several days. The second is uncertainty over exfiltration, since some reports mentioned possible data theft, but the city government itself said it had no conclusive public evidence that information had been taken. It is a clear example of why downtime should not be confused with a confirmed breach.
Sinaloa government, exposed portals and a dispute over the true scope
Sinaloa was at the center of one of the month’s most sensitive episodes. Proceso, El Sol de Sinaloa, Debate and Infobae all reported that multiple systems were affected and that the amount of exposed data may have been very large, with references to taxpayer rolls, payroll records, medical files, port logs, and databases of teachers and administrative staff. The strongest material points to about one million records across different datasets, although the exact scope still lacks definitive public technical validation.
The value of this case is not only in the volume, but in the mix of data. Fiscal, banking, labor, medical, and asset information can be combined for fraud, extortion, and identity theft. Several reports also said the information circulated in Telegram channels and cybercrime spaces, raising the secondary risk even as attribution and the technical origin remain under debate.
Integrated Citizen Services System at the Presidency
The SIDAC leak at the Presidency was another major incident. Maya Comunicación pointed to an IDOR vulnerability that allowed access to other users’ records by changing the folio in the URL, with at least 20 confirmed downloads and exposed access for about 24 hours. iWorld added that the material could compromise more than 400,000 records and sensitive complaints, with identification data and content related to homicide, drug trafficking, corruption, extortion, and abuse of authority.
The potential severity is high even though the file distribution was later removed. The type of information involved can be used for retaliation, extortion, or targeted social engineering. It also reinforces a recurring technical point this month, logic-based access errors can be just as dangerous as the exploitation of classic vulnerabilities.
Ransomware with BitLocker and printers in Mexico
One of the month’s most instructive cases was XEntry Team, as described by Securelist, TrendTIC, SC World, TMCnet Insight and other technical outlets. The group exploited a misconfigured MSSQL server and credentials exposed in public code, maintained persistence, deployed BitLocker, and used corporate printers to distribute ransom notes. In the Mexican case, the victim organization was not publicly identified, although the technique was well documented.
This incident matters because it combines extortion with a low level of malware customization. There was no traditional ransomware binary or a known RaaS operation. Instead, the attackers abused tools already present on the network and used an intrusion chain built on configuration flaws. That puts exposure hygiene back in focus, especially for MSSQL services, RDP, and internet-facing appliances.
Municipal and healthcare compromise in Culiacán
The Culiacán municipal health portal appeared in several references from the ransomware.mx monitor and in local coverage as a leak case that may have affected records of minors and patients. The available material does not allow a precise determination of whether there was encryption, pure exfiltration, or only a claim of responsibility, although it does confirm that the incident was considered relevant by monitors and the local press.
In practice, the risk here combines healthcare and minors’ data, two especially sensitive categories. Even without an official technical ruling, the mere circulation of the claim already requires a review of access controls, segmentation, and traceability in clinical repositories.
Promotora Zacapu, Qilin and the ransom claim
Qilin claimed to have attacked Promotora Zacapu, a real estate company, with a threat to publish sensitive information if the ransom was not paid. Ransomware.mx and Dexpose reflected that claim in July monitoring. This case fits the category of extortion with a leak site or public threat mention, because the material did not conclusively show operational impact or encryption.
Its analytical value lies in showing the sector breadth of the extortion campaign. The targets are not limited to public or financial environments. Mid-sized businesses are also exposed to blackmail and reputational pressure.
Contacto Garantido and the Qilin case with confirmed encryption
Unlike other claims this month, the Contacto Garantido case is reported with confirmed encryption in Hendry Adrian’s coverage. The report says Qilin encrypted files and disrupted operations at a Mexican professional services company. Here the source offers a much clearer classification than in other cases, there was verifiable operational impact.
That makes the episode a useful counterpoint. Not everything that appears on leak sites is the same. Some posts are only claims, while others do describe real disruption. For defense and response prioritization, that difference is central.
Threats and active campaigns in Mexico
Ransomware and extortion with confirmed encryption
In July, at least four incidents with confirmed asset encryption appeared in the material reviewed. Among them, the Contacto Garantido case is the clearest. The section also includes other incidents where ransomware was described in more or less technical detail, although in several cases the material did not allow confirmation of the damage scale or the scope of the disruption.
The recurring pattern is abuse of exposed services, leaked credentials, misconfigurations, and access through the public-facing attack surface. The material does not show a clear predominance of CVE exploitation for ransomware against Mexico during the month, but rather hardening failures and poor perimeter management.
| Case | Impact type according to the material | Sector | Comment |
|---|---|---|---|
| Contacto Garantido | Confirmed asset encryption | Professional services | Qilin, with operational disruption described by the source |
| Promotora Zacapu | Unable to determine classification from the material | Real estate | Qilin threatened to publish data if payment was not made |
| Culiacán health portal | Unable to determine classification from the material | Public health | The source mentions a leak and a leak site, but does not clarify encryption |
| León, municipal services | Unable to determine classification from the material | Public sector | Disruption incident and formal complaint, with no conclusive public technical attribution |
Ransomware and extortion, leak site mention only
Two cases remained in the leak site mention only category. They matter for monitoring, but they should not be confused with confirmed intrusion or proven encryption. The distinction is relevant because extortion groups often use leak sites as a pressure tool even when public evidence of compromise is incomplete.
In the July report, that situation appears especially in claims from groups such as Qilin and Krybit, where the strongest data point is the publication or reference on the actor’s portal. Without internal telemetry or a forensic finding, the material does not support a stronger conclusion.
Fraud and phishing in Mexico
Phishing gained both regulatory and operational weight. Mexico City classified phishing as an independent crime, and at the same time several reports described its mass use in banking scams. The press material explained the most common mechanism, messages by SMS, WhatsApp, or email that imitate a financial institution to push the victim away from the official app and steal credentials, PINs, or other access data.
The technical side and the legal side aligned in the same month. That does not mean the problem has been solved, but it does show that the institutional ecosystem better recognizes the specific harm caused by these scams. There was also coverage of impersonation of 11 financial institutions reported by CONDUSEF during June, a useful context point, although it is not counted as a July incident.
| Fraud indicator | Monthly figure | Highlighted source |
|---|---|---|
| Documented fraud or phishing cases | 7 | CDMX, CONDUSEF, banking press |
| New criminal classification in CDMX | 3 to 6 years in prison, fines of 200 to 600 UMA | Gaceta Oficial, Infobae, UnoTV |
| Impersonation of financial institutions reported by CONDUSEF, June 2026 | 11 institutions | Debate |
APT, AI-assisted intrusion, and opportunistic hacktivism
Although ransomware dominated the month, a separate technical line emerged tied to the use of AI in intrusions against Mexican government organizations and a water utility in Monterrey. Dragos and Gambit Security, cited by Cryptonomist, described the use of Claude and GPT to speed up reconnaissance, tool development, and exploitation, with automated password spraying attempts against an industrial gateway. There is no public evidence that the OT environment was breached, but the case showed a new form of offensive assistance.
In parallel, Proceso attributed a series of attacks against Sinaloa portals to Hackers$ Crew, and ransomware.mx reported several entries associated with the collective or with linked aliases. In the available material, the attribution remains more declarative than forensic, but the visibility of those names across multiple sources suggests sustained pressure on public portals and exposed databases.
Critical vulnerabilities with impact in Mexico
| CVE | Software | Exploitation | Source |
|---|---|---|---|
| CVE-2026-35273 | Oracle PeopleSoft PeopleTools | Exploited between May 27 and June 9, 2026, with a Nissan breach that reached employees in Mexico | Telefónica Tech |
| CVE-2026-48282 | Adobe ColdFusion | Active path traversal exploitation with potential for RCE | Ransomware.mx |
| CVE-2026-56164 | Microsoft SharePoint Server | Exploited in the wild, under active use | CSIRT Telconet, Check Point Research |
| CVE-2026-56155 | Active Directory Federation Services | Exploited in the wild, under active use | CSIRT Telconet, Check Point Research |
| CVE-2026-50522 | Microsoft SharePoint | Active exploitation confirmed | iurlek |
| CVE-2026-63030 | WordPress | Active exploitation, known together with wp2shell | iurlek |
| CVE-2026-60137 | WordPress | Active exploitation, known together with wp2shell | iurlek |
| CVE-2026-6875 | ServiceNow artificial intelligence platform | Active exploitation confirmed | iurlek |
| CVE-2026-40138 | BeyondTrust Remote Support and Privileged Remote Access | Critical preauthentication vulnerability | Ransomware.mx |
| CVE-2026-53359 | Linux KVM x86 kernel | Use-after-free in shadow paging | Ransomware.mx |
| CVE-2026-31694 | Linux FUSE | Privilege escalation to root | Cronup |
| CVE-2026-16812 | Arista VeloCloud | Active exploitation, CVSS 10.0 | Código Vigía |
| CVE-2026-20251 | Splunk Secure Gateway | RCE with low-privilege authenticated users | Telefónica Tech |
| CVE-2026-58443 | Gitea | Critical vulnerability reported | Devel Group |
| CVE-2026-0257 | Palo Alto Networks firewalls | Authentication bypass used as initial access vector for Qilin | Devel Group |
| CVE-2026-59269 | Not specified in the material | File published by INCIBE-CERT | INCIBE-CERT |
| CVE-2026-59686 to CVE-2026-59690 | Kemp LoadMaster, ECS Connection Manager, Connection Manager for ObjectScale | Five severe vulnerabilities published by Progress | Devel Group |
| CVE-2026-16723 | FastJson | Active zero-day exploitation | Devel Group |
| CVE-2026-35273 and CVE-2026-20251 should not be read as exclusive Mexican incidents, but as vulnerabilities relevant to entities with regional exposure and supply chains present in Mexico |
Regulation and compliance in Mexico
July was one of the busiest months for regulation. Mexico City made phishing an independent crime, with penalties of three to six years in prison and fines of 200 to 600 UMA, with harsher sanctions when the victim is a minor, an older adult, or a person with a disability. It signals a tougher criminal approach to digital fraud, and it could have practical effects on complaints and on how online scams are argued in court.
There were also advances and debates around digital identity and personal data. The Secretariat of Anti-Corruption and Good Governance announced a fine against the Mexican Football Federation for the handling of personal data through Fan ID, and it later emerged that the agency had set its first public criteria on data protection based on that case. At the same time, discussions continued on multi-biometric banking, liveness checks, facial recognition verification, and the use of official databases to validate identity in higher-risk transactions.
Banks came under greater regulatory scrutiny. Coverage focused on the CNBV, the ABM, and the move to e.firma in employer filings with the IMSS, along with the replacement of the NPIE certificate. There was also discussion of stricter documentation and cyber risk requirements under frameworks such as Basel IV. By July, the message was clear, cyber risk management was no longer just a technical issue, it had become an explicit part of operational compliance.
On AI, Mexico continued with a fragmented framework. There were federal debates, sector-specific initiatives, a repeal in San Luis Potosí, and multiple views on the absence of a general law. What can be verified for the month is that the country kept regulating in pieces, while political pressure grew for a more comprehensive rule.
| Regulatory front | Verifiable July event | Practical impact |
|---|---|---|
| Mexico City, phishing | Independent criminal offense | Strengthens criminal prosecution of digital fraud |
| Fan ID | MXN 42,849,095 fine | Sets a precedent in data protection |
| IMSS, e.firma | NPIE eliminated and transition to SAT certificate | Increases reliance on federal credentials |
| CNBV, biometrics | Tightened requirements for high-value transactions | Raises KYC controls and identity verification |
| AI | National debate and sector-specific rules | General-law gaps persist |
Most affected sectors in Mexico
The public sector was the most visible in terms of reputational and operational impact, though not necessarily in absolute volume. León, Sinaloa and the Presidency drew public attention, with a mix of disruptions, information exposure and debate over attribution. When a leak includes registries, payroll records, medical files or citizen complaints, the potential damage goes beyond the affected system and reaches administrative processes, public trust and personal safety.
The financial sector was also prominent, but through a mix of fraud, biometrics, identity theft and regulation. Not everything was an intrusion. Several reports during the month showed pressure to tighten KYC, validate identity with biometrics and strengthen data handling. The fraud side remains critical, even if the incident category is not always formally recorded as a breach.
Manufacturing, business services and information technology kept appearing among the sectors with the most ransomware signals in open monitors. That matches the pattern from the previous month, although in July the publicity pressure and publication volume were higher. Health also reappeared, both in confirmed cases and in early warning material, and that means healthcare incidents should not be treated as isolated.
The sector reading, then, is not of a single front but of three layers. Government and public services for leaks and outages, finance for fraud and compliance, and industry and services for extortion and infrastructure exposure. The seven sectors with documented incidents show cross-cutting coverage, not a problem confined to one vertical.
Trends and signals to watch in Mexico
The month-over-month comparison shows a sharp acceleration across nearly every front that matters. Verified incidents rose from 56 to 105. Ransomware or extortion cases climbed from 15 to 55. Documented fraud and phishing increased from 2 to 7. Critical CVEs mentioned jumped from 4 to 19. Only the number of sectors with documented incidents stayed flat at 7.
That points to a denser risk agenda, not necessarily a more orderly one. Last month already showed signs of extortion, but in July the publications multiplied and more cases included technical detail. At the same time, regulatory pressure increased on banking, biometrics, and digital fraud. For security and compliance teams, the overlap between incident, regulation, and reputation became tighter.
There are three signals worth following closely. The first is whether public ransomware cases continue shifting from simple listings on leak sites to confirmed encryption or leaks with demonstrable impact. The second is whether public portals and citizen service systems keep exposing logic flaws, such as the SIDAC IDOR, beyond classic infrastructure issues. The third is whether active exploitation of critical CVEs turns into local incidents, especially in collaboration software, identity systems, remote gateways, and exposed platforms.
The regional comparison also remains tense. This month’s sources insist that Mexico remains among the most attacked countries in Latin America, although that sits alongside the methodological reminder that many figures disclosed by vendors are telemetry or attempts, not confirmed incidents. The useful signal is not just the count, but the persistence of the same vectors: exposed services, phishing, identity abuse, and configuration flaws.
| Indicador | Julio 2026 | Junio 2026 | Lectura |
|---|---|---|---|
| Hechos verificados | 105 | 56 | Alza marcada |
| Ransomware o extorsión | 55 | 15 | Aceleración fuerte |
| Fraude o phishing | 7 | 2 | Crecimiento visible |
| Movimientos regulatorios | 5 | 4 | Actividad sostenida |
| CVEs críticos mencionados | 19 | 4 | Mayor presión técnica |
| Sectores con hechos | 7 | 7 | Sin variación |
Security recommendations for teams in Mexico
First, focus on exposure management. Several incidents this month showed that initial access did not come from a sophisticated chain, but from misconfigured MSSQL, exposed credentials, unpatched edge services, and weak logical access. That calls for reviewing inventory, external exposure, and configuration posture before moving on to more advanced controls.
Second, harden identity and access controls. This month made clear that identity is the central vector, from banking phishing and impersonation to banking biometrics, e.signature, access to citizen systems, and leaks of sensitive data. Strong MFA, anomaly monitoring, privilege review, and validation of access flows should be a priority, especially in service portals and back offices with sensitive information.
Third, segment critical environments more effectively. Cases tied to healthcare, citizen services, and operational technology show that a breach in IT can escalate into OT, or that a leak in a portal can lead to amplified impact. Separating networks, limiting trust between domains, and reviewing print queues, repositories, and industrial gateways helps reduce the blast radius.
Fourth, prepare legal and reputational response. In July there were incidents where it was not clear whether encryption had been used, but there was public exposure, information funneling, and pressure from a leak site. When that happens, the security team needs to work with legal, privacy, and communications from the first hour. The difference between a leak and a takedown can be blurry for the public, not for the regulator.
Fifth, treat active CVE exploitation as an action list, not an appendix. With 19 critical vulnerabilities mentioned, several already exploited in the wild, patch timing cannot depend on the normal maintenance cycle. Products exposed to the internet, federated authentication, collaboration tools, and remote gateways need explicit priority.
| Priority | Action | Reason |
|---|---|---|
| High | Review MSSQL, RDP, VPN, and appliance exposure | Repeated vectors in July intrusions |
| High | Strengthen MFA and privilege controls | Initial access through identity was recurring |
| High | Validate offline backups and restore testing | Minimizes the impact of encryption and extortion |
| Medium | Audit citizen portals and repositories with sensitive data | Reduces the risk of IDOR and mass leaks |
| Medium | Align response with legal and privacy teams | Many claims involve personal data |
| Medium | Speed up patching of exploited CVEs | The month showed cross-sector active exploitation |
Material limitations
This report was built exclusively from the material provided for Mexico in July 2026. The time window covered by the indicators includes 108 dated events in July 2026, plus 1 earlier event used only as a comparative frame, and excludes 2 events after the period. No external information or internet sources were used.
An indicator at 0, or a lack of detail, does not mean the event did not exist in the region or the country. In particular, if a CVE or a category does not appear as monthly volume, that only means it was not recorded in the material analyzed under this window and these criteria. It should not be interpreted as a lack of vulnerabilities, attacks, or real-world exploitation.
The ransomware and extortion taxonomy also has methodological limits. In several cases, the material only mentions a victim on a leak site or an actor claim, without making it possible to determine whether there was encryption, exfiltration, or both. When the source did not make that clear, the classification was kept as not determinable.
Aggregate telemetry figures, attempts, blocks, and weekly vendor averages were left out of the count. Events without confirmed dates and any reference not within the available sources to cite were also excluded. Consumer social media, sponsored content, and promotional material were not used as evidence for trends, unless the open source provided a verifiable datum that could be independently attributed.
Comparative modules and monthly figures should be read as a snapshot of the period, not as a complete series of Mexican risk. Where a note provided regional or sector context, it was used for interpretation and not to invent additional incidents. If a source referred to attempts, blocks, or scans, it was treated as telemetry and not as an incident with confirmed impact.
Sources
- Biometría facial en la banca mexicana: qué exige la nueva resolución de la CNBVFacephi Observatory
- El Gobierno de México abre un debate nacional para regular el uso de la IA y las redes sociales en menoresInfobae México
- Regulación de IA en México genera posturas encontradas en el CongresoRadioNet
- San Luis Potosí deroga ley que regulaba el uso de la IA y amenazaba la libertad de expresiónInfobae México
- Casos de ciberataques aumentan 38% en México, empresas registran escalada en diversos sectoresInfobae
- ¿Hay una iniciativa de ley para regular que menores usen redes sociales? Sheinbaum aclara campaña de concientizaciónInfobae México
- Las Noticias Más Importantes de IA HoyTrend Micro
- IA y ciberdelincuencia, peligro inminenteEl Financiero
- IA sí, responsabilidad no: el modelo nacionalExpansión Política
- DPL News Spotlight Política DigitalDPL News
- La IA dirigida a la tecnología operativa: perspectivas sobre amenazas emergentesCryptonomist
- AI Targeting Operational Technology: Emerging Threat InsightsThe Cryptonomist (versión en inglés)
- Sin contrapesos: ¿El gobierno ya no está obligado a justificar previamente el acceso a tus datos personales?Infobae México
- CONDUSEF alerta por suplantación de 11 instituciones financieras: cómo evitar caer en fraudes en 2026Debate
- Kaspersky Security Services Identifies Ransomware Actors Using BitLocker and Printers in Latin AmericaTMCnet Insight
- El nuevo gran riesgo del sistema financieroPortafolio
- Límites a la Inteligencia Artificial: la postura del PAN en San Luis PotosíEl Heraldo de México
- https://skyportsystems.net/ransomware-actors-exploit-bitlocker-and-corporate-printers-in-latin-americaSkyport Systems (blog técnico)
- Suman siete reportes de posibles ciberataques a sistemas públicos de Sinaloa en julioEl Sol de Sinaloa (OEM)
- Ataque atribuido a modelos de IA reabre debate sobre control tecnológicoGaceta Mexicana
- Phishing bancario: Así opera el fraude que pretende vaciar tu cuenta y cómo detectarlo a tiempo para evitarloEl Imparcial
- New ransomware group uses printers to deliver ransom notesSC World
- México regula la inteligencia artificial por sectores mientras aplaza la ley generalEl Economista
- Regulación la IA, discusión obligada para el Congreso: Kenia LópezVertigo Político
- Presunto hackeo al gobierno de Sinaloa habría expuesto cerca de un millón de registros con datos fiscales, bancarios y médicosInfobae México
- Sophos AI Security Report 2026ITware Latam
- Hackeo en Sinaloa: Habrían sido filtrados datos de 4,000 pacientes, cuentas bancarias y másDebate
- Hackeo en Sinaloa: Habrían sido filtrados datos de 4000 pacientes, cuentas bancarias y másDebate
- Expertos alertan sobre una creciente táctica de ransomware: hackers imprimen demandas de rescate durante ataques en América LatinaTrendTIC
- Errores de configuración que alimentan el ransomware: lecciones de Colombia y MéxicoCarmona.mx
- Nova extorsão com BitLocker: abuso de RDP, MSSQL e RMMSecurelist Brasil / Kaspersky
- Extorsión BitLocker: el esquema XEntry con impresorasHelpRansomware (republica Securelist)
- BitLocker Extortion: The XEntry Printer Ransom SchemeHelpRansomware (republica Securelist)
- Diputada mexicana promueve iniciativa para sancionar amenazas a través de medios digitalesInfobae (agencias)
- El IMSS lanza importante aviso sobre el trámite que ahora se debe hacer en líneaInfobae
- Resumen Semanal PLD: 11 al 17 de Julio de 2026PLD.mx
- PT propone incluir inteligencia artificial en los planes de estudio de México con reglas para proteger datos y orientar su uso en clases y evaluacionesEl Imparcial
- Nuevo intento por penalizar la IAEl Economista
- Prueba de Vida: Nuevo requisito obligatorio para la apertura de cuentas digitalesHelp-AI México
- El laberinto constitucional de la regulación de la IA en MéxicoEl Universal
- DragonForce Posts Eighteen Victims Across Eight Countries in 48 HoursDaily Security Review
- Nu recibe autorización final para operar como banco en México | avances 2026Mundi
- Entre la regulación de la IA y la ley mordaza, una agenda polémica divide a San LázaroEl Debate
- Biometría bancaria en México: quién queda afueraLadonware
- Bancos pedirán huella dactilar o reconocimiento facial para retiros y depósitos mayores a 140,000 pesos con una nueva regulación de la CNBV para reducir fraudes financieros en MéxicoEl Imparcial (citando Expansión)
- Nuevo requisito bancario en México 2026: ¿Por qué pedirán biométricos e INE para retirar o depositar efectivo?El Debate
- El reto de los bancos no es reconocer rostros, sino protegerlosMilenio
- Regulación de redes sociales y de IA: Estos son los temas primordiales para Morena en el CongresoEl Financiero
- El reto de los bancos no es reconocer rostros, sino protegerlosMilenio
- Regular la inteligencia artificial: un primer paso en propiedad industrial, muchos pendientes por delanteECIJA
- Qué es KYC en México: Guía para Bancos y FintechsFIMPE
- El fraude de identidad sintética con IA alcanza el 48.3% de los casos en América LatinaEl Economista
- León Investigates Alleged Attack on Citizen Services SystemSecurity Tribune
- Portal de Transparencia en León se queda sin acceso a archivos tras hackeoAM León
- Morena busca regular la Inteligencia Artificial; ¿qué contempla la ley?XEU Noticias
- Ciberataques en México: 83.3% de las organizaciones sufrió incidentesGrupo En Concreto
- ANPD apura vazamento de dados de 500 mil pacientesPoder360
- Organização social é investigada por vazamento de dados de pacientesAgência Brasil
- Condusef recibe 12 denuncias por fraude financiero cada minutoInformador
- El truco del correo falso: el silencioso método con el que los hackers están vulnerando a las víctimasInfobae
- Las quejas por fraude bancario escalan un 31.5% ante la Condusef en 2026, pero las instituciones financieras rechazan reembolsar el 75.7% de los montos reclamados tras los robos de dinero mediante engaños digitalesEl Imparcial
- Ataques cibernéticos en León: Municipio ha contenido 1.6 millones, afirma Ale GutiérrezEl Sol de León (OEM)
- La CNBV exige a bancos mexicanos verificar a sus clientes ...Cointelegraph en Español
- Ciberataque deja sin servicio la página del Gobierno de León; hackers roban datos de ciudadanosLa Silla Rota
- Facial Biometrics in Mexican Banking: What the New CNBV Resolution Requires and How to Be Compliant by NovemberFacephi Observatory
- CNBV endurece reglas de biometría y ciberseguridad en la bancaImagen Radio
- Filtran datos de 400 mil denunciantes tras fallo de seguridad en PresidenciaMaya Comunicación
- Security articles – infraestructura de phishing modular contra instituciones financieras mexicanasMinistang.com
- Todo sobre la regulación para retailers en MéxicoPirani Risk
- Ciberataque a gobiernos de Sinaloa expone datos de casi un millón de personasProceso
- Panorama de ransomware en México | Monitor de incidentesRansomware.mx
- [Intel MX] 2026-07-03 Ciberataque a servicios de León y logística en ventaRansomware.mx
- 273 victims for Mexico - Ransomware.live mapRansomware.live
- Reportan hackeo en la Presidencia de México que habría comprometido 400 mil denunciasDiario de Yucatán
- Alertan por ola de ciberataques en México; sufren fraudes 8 de cada 10 empresasPeriódico AM
- Ransomware: krybit claims duflosa.com (MX) — Not FoundMatproof
- Ransom! Contacto Garantido (JUL-2026)hendryadrian.com
- Ya no hackean tu empresa: la inteligencia artificial lo hace por ellos, sola, en segundosEl Heraldo de Puebla
- Filtran bases de datos del Gobierno de Sinaloa y Ayuntamiento de CuliacánRevista Espejo
- Filtran información del Sistema Integral de Atención Ciudadana de la Presidencia de la RepúblicaiWorld
- Cumple 24 horas caída la página de León por hackeo; congela trámites y pago de multasPeriódico AM
- Ataques de ransomware aumentaron 20% en primera mitad de 2026Fast Company México
- 277 victims for MexicoRansomware.live
- Intel MX, boletín de inteligencia de amenazasRansomware.mx
- Victim: shelby.com.mxransomware.live
- Una pelea campal, datos biométricos y una presunta extorsión: los antecedentes de la millonaria multa a la Federación Mexicana de FútbolEl País
- Mexico: Record USD 2.14 Million Fine for Biometric Data ProcessingBaker McKenzie
- Primeros criterios públicos de la SABG en materia de protección de datos personales tras la resolución del caso Fan IDRitch
- Phishing ya es delito en la CDMX: hasta 6 años de cárcel y 70000 pesos de multaInfobae México
- FMF impugnará multa de 43 millones de pesos por el Fan ID tras sancion por proteccion de datos personales asegura que hubo irregularidades en el procesoEl Imparcial
- Aprueban en comisión tipificar la suplantación de identidad digitalEl Heraldo de México
- Presentan paquete de reformas para fortalecer la protección digital en BCEl Mexicano
- Qilin Ransomware Targets Promotora ZacapuDexpose
- Boletín Semanal de Ciberseguridad, 3 julio - Telefónica TechTelefónica Tech
- [Intel MX] 2026-07-07 Servicios de negocio en la mira y cuatro CVE que no admiten demoraRansomware MX
- Microsoft corrige vulnerabilidades críticas en el Patch Tuesday de julio de 2026CSIRT Telconet
- 20th July – Threat Intelligence ReportCheck Point Research
- Resumen diario de ciberseguridad – 2026-07-22iurlek
- Phishing es delito en CDMX: penas de cárcel y multasUnoTV
- Mexico Financial Cyberattacks Surge 167% in 1Q26Mexico Business News
- Ataques cibernéticos se incrementan 5.0% durante MundialLa Razón
- HACKEAN PRESIDENCIA DE SHEINBAUM: Exponen datos de TODOS los denunciantesMLDA
- Falla 10 de 10 en Arista VeloCloud ya está bajo ataqueCódigo Vigía
- 6 mil millones de ataques en un mes. ¿Qué nos dice eso ...Nova Sistemas
- Panorama de Ciberseguridad: Semana del 06 al 10 de julio de 2026Cronup
- Vulnerabilidades CVE — MexicoDevMexicoDev
- Malware TimbreStealer ataca empresas mexicanas: alerta WatchGuardNotiMX
- [Intel MX] 2026-07-13 Un día sin víctimas en MéxicoRansomware.mx
- Día: 28 julio, 2026Devel Group
- El «Patch Tuesday» de julio de 2026 corrige 622 ...Malwarebytes
- Vulnerabilidades | INCIBE-CERTINCIBE-CERT
- Día: 21 julio, 2026Devel Group
