CiberLATAMbywhalemate
Intelligence reportAug 1, 202618 min read

Mexico: cybersecurity landscape, July 2026

Ransomware dominated July in Mexico, with 105 verified incidents, 55 extortion cases, and 19 critical CVEs mentioned.

Mexico: cybersecurity landscape, July 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are completed automatically with verified dated facts within the period. Each one states its source basis and counting criterion, so the figures reconcile across modules. They are the recurring month-to-month reading; the analysis that follows develops the cases without repeating this summary.

Indicator window: 108 dated facts in July 2026 · 1 from prior months (comparative frame, not monthly volume) · 2 after the period (excluded). Facts from prior months are used only as a comparative frame in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Verified Signal Monthly Dashboard July 2026 · Mexico Top threat: Ransomware (55 of 105 events). Coverage: 108 dated events in July 2026 · 1 previous months an… VERIFIED EVENTS 105 period base: total count measured from below on this total RANSOMWARE / EXTORTION 55 4 encrypted assets confirmed · 2 mention-only in leak site · 49 unclassified UNCLASSIFIED INCIDENTS 12 breaches or outages without declared threat type FRAUD / PHISHING 7 documented fraud campaigns REGULATION 5 standards, resolutions, or penalties UNIQUE CVEs 19 CVE-2026-0257 / CVE-2026-16723
Verified Signal Monthly Dashboard — Base: 105 verified dated events in the period for Mexico.
MONTHLY FIXED MODULE Threat Axis Distribution July 2026 · Mexico Each event is counted on just one axis, so the total is exactly 105. "Unclassified incidents" is the remainder. Ransomware 55 Vulnerabilities 16 Incidents 12 Unclassified 10 Fraud 7 Regulation 5
Threat Axis Distribution — Each event is assigned to a single axis based on its classification; the total matches the 105 events in the period.
FIXED MONTHLY MODULE Sectoral Distribution of Signals July 2026 · Mexico Base: 105 incidents in the period · total 126 because 19 incidents are classified in more than one sector. Public sector / OIV 50 Other / no sector ident… 37 Technology 21 Health 7 Telecom 6 Finance 2 Energy 2 Education 1
Sectoral Distribution of Signals — Heuristic classification by victim sector. One incident may affect more than one sector, so the total may exceed the base.
MONTHLY FIXED MODULE Critical Infrastructure in Mexico July 2026 · Mexico 21 of 105 events in the period involved critical infrastructure. One event may appear in more than one category. Public sector / government 50 Telecom / connectivity 3
Critical Infrastructure in Mexico — Verified signal in public sector, finance, and essential services

Monthly Executive Summary for Mexico

July 2026 left Mexico facing a cybersecurity agenda dominated by extortion and two parallel storylines. On one side, ransomware activity kept setting the pace, with cases published against private organizations, local government agencies, and a set of victims claimed on leak sites. On the other, massive data exposure incidents emerged in the public sector involving the Government of Sinaloa and the Presidency, both with sensitive material and an ongoing public debate over the true scope of the leaks.

The verified monthly base was high, with 105 confirmed events within the period and 12 incidents not classified as breaches or outages. The leading threat was ransomware, with 55 events, far above the previous month. Within that universe, only four cases resulted in confirmed asset encryption, two were limited to leak-site mentions, and in 49 it was not possible to determine the exact technical impact from the available material. That distinction matters, because the volume of claims does not automatically translate into the same number of intrusions with verified encryption.

The risk surface also expanded through regulatory action. There were five documented regulatory moves, focused on banking biometrics, phishing sanctions in Mexico City, and additional initiatives on AI and personal data. At the same time, 19 critical CVEs were mentioned, a figure far higher than the previous month, with several vulnerabilities actively exploited in Microsoft, Adobe, Linux, Palo Alto Networks, and other exposed environments.

The operational reading for Mexico is high risk. Not only because of the number of verified events and the intensity of the extortion component, but also because of the coexistence of public incidents, regulatory pressure on banking and data protection, and a technical layer where abuse of exposed services, configuration flaws, and active exploitation of critical vulnerabilities continued to appear as recurring access paths.

July 2026 milestones in MexicoLeón fallsportal and proceduresSIDAC exposedIDOR and downloadsBanking biometricsand e.firmaSinaloa in focusmultiple portalsCDMX classifiesphishingMilestonesselected basedon verifiedincidents fromthe period, notaggregatedtelemetry.

Mexico: July 2026 milestones — Brief timeline of the month’s most visible incidents in Mexico.

Mexico National Monthly Overview

July brought an unfavorable mix for defense teams, with more ransomware reporting, more regulatory discussion, and greater public-sector data exposure. The dominant trend was clear, ransomware returned as the main focus with 55 of 105 verified incidents. The previous month, that same threat accounted for 15 of 56 incidents, so the increase was not marginal but structural in the available coverage.

The technical pattern was not uniform either. In several incidents claimed by groups or specialized monitors, the source did not specify whether there was encryption, only a leak, or just publication on a leak site. That means the total case count should be read with analytical caution. Some incidents did involve confirmed encryption, but others were publicly evidenced only by a claim or by data exposure. In response terms, that can require both forensic containment and legal and communications management, even when there is no public proof of prolonged unavailability.

The quality of the month’s sources was mixed. There were serious technical bulletins, press notes with useful operational detail, and ransomware monitoring reports that added context, but also coverage based on unconfirmed attributions or partial descriptions. For that reason, the most responsible snapshot for Mexico in July is one of an ecosystem under strong extortion pressure, weak configurations being exploited, and sensitive data being exposed, rather than a single coordinated campaign.

At the regional level, Mexico continued to appear among the Latin American countries drawing the most activity and attention from threat groups and security firms. Reports citing Kaspersky and other vendors placed the country among the most affected in the region in terms of attempts or claims, but those telemetry figures should be read as context, not as incidents. For the month under review, the verifiable point was the materialization of specific cases, not aggregate ecosystem telemetry.

Sectors with signal in MexicoPublic sectorBusiness servicesManufacturingTechnologyHealth care7 sectorsdocumentedNarrative view, not an exclusive sector total. One incident may affect more than one sector.

Mexico, signal distribution by sector — Sectors with at least one documented incident in the period.

Mexico period indicators

Indicator July 2026 Previous month Change
Verified facts in the period, basis for all indicators 105 56 +49
Indicator time window 108 facts dated July 2026, 1 from prior months, 2 after the period excluded Same N/A
Unclassified incidents, breaches, or outages 12 15 -3
Cases with ransomware or extortion as the primary focus 55 15 +40
Confirmed asset encryption 4 not provided N/A
Leak site mention only 2 not provided N/A
Classification not determinable from available material 49 not provided N/A
Documented fraud or phishing cases 7 2 +5
Documented regulatory moves 5 4 +1
Critical CVEs mentioned 19 4 +15
Sectors with at least one documented event 7 7 unchanged
Dominant threat of the month Ransomware (55 of 105 facts) Ransomware (15 of 56 facts) no shift in focus
Facts with direct source confirmation 59% not provided N/A
Aggregate telemetry figures excluded from the volume 3 (combined attempts or blocks, not incidents with confirmed impact) not provided N/A

Relevant Incidents in Mexico

León government and municipal service outages

The cyberattack against the Government of León was one of the month’s most visible events in local public sector reporting. Local media coverage indicated that the official website went offline and that the Citizen Services System was the main target. Reports also said the IT team was taken offline as a precaution to contain the damage, followed by security testing before services were restored.

The case left two operational takeaways. The first is service continuity, because the official website and the transparency portal stayed offline or had restricted access for several days. The second is uncertainty over exfiltration, since some reports mentioned possible data theft, but the city government itself said it had no conclusive public evidence that information had been taken. It is a clear example of why downtime should not be confused with a confirmed breach.

Sinaloa government, exposed portals and a dispute over the true scope

Sinaloa was at the center of one of the month’s most sensitive episodes. Proceso, El Sol de Sinaloa, Debate and Infobae all reported that multiple systems were affected and that the amount of exposed data may have been very large, with references to taxpayer rolls, payroll records, medical files, port logs, and databases of teachers and administrative staff. The strongest material points to about one million records across different datasets, although the exact scope still lacks definitive public technical validation.

The value of this case is not only in the volume, but in the mix of data. Fiscal, banking, labor, medical, and asset information can be combined for fraud, extortion, and identity theft. Several reports also said the information circulated in Telegram channels and cybercrime spaces, raising the secondary risk even as attribution and the technical origin remain under debate.

Integrated Citizen Services System at the Presidency

The SIDAC leak at the Presidency was another major incident. Maya Comunicación pointed to an IDOR vulnerability that allowed access to other users’ records by changing the folio in the URL, with at least 20 confirmed downloads and exposed access for about 24 hours. iWorld added that the material could compromise more than 400,000 records and sensitive complaints, with identification data and content related to homicide, drug trafficking, corruption, extortion, and abuse of authority.

The potential severity is high even though the file distribution was later removed. The type of information involved can be used for retaliation, extortion, or targeted social engineering. It also reinforces a recurring technical point this month, logic-based access errors can be just as dangerous as the exploitation of classic vulnerabilities.

Ransomware with BitLocker and printers in Mexico

One of the month’s most instructive cases was XEntry Team, as described by Securelist, TrendTIC, SC World, TMCnet Insight and other technical outlets. The group exploited a misconfigured MSSQL server and credentials exposed in public code, maintained persistence, deployed BitLocker, and used corporate printers to distribute ransom notes. In the Mexican case, the victim organization was not publicly identified, although the technique was well documented.

This incident matters because it combines extortion with a low level of malware customization. There was no traditional ransomware binary or a known RaaS operation. Instead, the attackers abused tools already present on the network and used an intrusion chain built on configuration flaws. That puts exposure hygiene back in focus, especially for MSSQL services, RDP, and internet-facing appliances.

Municipal and healthcare compromise in Culiacán

The Culiacán municipal health portal appeared in several references from the ransomware.mx monitor and in local coverage as a leak case that may have affected records of minors and patients. The available material does not allow a precise determination of whether there was encryption, pure exfiltration, or only a claim of responsibility, although it does confirm that the incident was considered relevant by monitors and the local press.

In practice, the risk here combines healthcare and minors’ data, two especially sensitive categories. Even without an official technical ruling, the mere circulation of the claim already requires a review of access controls, segmentation, and traceability in clinical repositories.

Promotora Zacapu, Qilin and the ransom claim

Qilin claimed to have attacked Promotora Zacapu, a real estate company, with a threat to publish sensitive information if the ransom was not paid. Ransomware.mx and Dexpose reflected that claim in July monitoring. This case fits the category of extortion with a leak site or public threat mention, because the material did not conclusively show operational impact or encryption.

Its analytical value lies in showing the sector breadth of the extortion campaign. The targets are not limited to public or financial environments. Mid-sized businesses are also exposed to blackmail and reputational pressure.

Contacto Garantido and the Qilin case with confirmed encryption

Unlike other claims this month, the Contacto Garantido case is reported with confirmed encryption in Hendry Adrian’s coverage. The report says Qilin encrypted files and disrupted operations at a Mexican professional services company. Here the source offers a much clearer classification than in other cases, there was verifiable operational impact.

That makes the episode a useful counterpoint. Not everything that appears on leak sites is the same. Some posts are only claims, while others do describe real disruption. For defense and response prioritization, that difference is central.

Threats and active campaigns in Mexico

Ransomware and extortion with confirmed encryption

In July, at least four incidents with confirmed asset encryption appeared in the material reviewed. Among them, the Contacto Garantido case is the clearest. The section also includes other incidents where ransomware was described in more or less technical detail, although in several cases the material did not allow confirmation of the damage scale or the scope of the disruption.

The recurring pattern is abuse of exposed services, leaked credentials, misconfigurations, and access through the public-facing attack surface. The material does not show a clear predominance of CVE exploitation for ransomware against Mexico during the month, but rather hardening failures and poor perimeter management.

Case Impact type according to the material Sector Comment
Contacto Garantido Confirmed asset encryption Professional services Qilin, with operational disruption described by the source
Promotora Zacapu Unable to determine classification from the material Real estate Qilin threatened to publish data if payment was not made
Culiacán health portal Unable to determine classification from the material Public health The source mentions a leak and a leak site, but does not clarify encryption
León, municipal services Unable to determine classification from the material Public sector Disruption incident and formal complaint, with no conclusive public technical attribution

Ransomware and extortion, leak site mention only

Two cases remained in the leak site mention only category. They matter for monitoring, but they should not be confused with confirmed intrusion or proven encryption. The distinction is relevant because extortion groups often use leak sites as a pressure tool even when public evidence of compromise is incomplete.

In the July report, that situation appears especially in claims from groups such as Qilin and Krybit, where the strongest data point is the publication or reference on the actor’s portal. Without internal telemetry or a forensic finding, the material does not support a stronger conclusion.

Fraud and phishing in Mexico

Phishing gained both regulatory and operational weight. Mexico City classified phishing as an independent crime, and at the same time several reports described its mass use in banking scams. The press material explained the most common mechanism, messages by SMS, WhatsApp, or email that imitate a financial institution to push the victim away from the official app and steal credentials, PINs, or other access data.

The technical side and the legal side aligned in the same month. That does not mean the problem has been solved, but it does show that the institutional ecosystem better recognizes the specific harm caused by these scams. There was also coverage of impersonation of 11 financial institutions reported by CONDUSEF during June, a useful context point, although it is not counted as a July incident.

Fraud indicator Monthly figure Highlighted source
Documented fraud or phishing cases 7 CDMX, CONDUSEF, banking press
New criminal classification in CDMX 3 to 6 years in prison, fines of 200 to 600 UMA Gaceta Oficial, Infobae, UnoTV
Impersonation of financial institutions reported by CONDUSEF, June 2026 11 institutions Debate

APT, AI-assisted intrusion, and opportunistic hacktivism

Although ransomware dominated the month, a separate technical line emerged tied to the use of AI in intrusions against Mexican government organizations and a water utility in Monterrey. Dragos and Gambit Security, cited by Cryptonomist, described the use of Claude and GPT to speed up reconnaissance, tool development, and exploitation, with automated password spraying attempts against an industrial gateway. There is no public evidence that the OT environment was breached, but the case showed a new form of offensive assistance.

In parallel, Proceso attributed a series of attacks against Sinaloa portals to Hackers$ Crew, and ransomware.mx reported several entries associated with the collective or with linked aliases. In the available material, the attribution remains more declarative than forensic, but the visibility of those names across multiple sources suggests sustained pressure on public portals and exposed databases.

Critical vulnerabilities with impact in Mexico

CVE Software Exploitation Source
CVE-2026-35273 Oracle PeopleSoft PeopleTools Exploited between May 27 and June 9, 2026, with a Nissan breach that reached employees in Mexico Telefónica Tech
CVE-2026-48282 Adobe ColdFusion Active path traversal exploitation with potential for RCE Ransomware.mx
CVE-2026-56164 Microsoft SharePoint Server Exploited in the wild, under active use CSIRT Telconet, Check Point Research
CVE-2026-56155 Active Directory Federation Services Exploited in the wild, under active use CSIRT Telconet, Check Point Research
CVE-2026-50522 Microsoft SharePoint Active exploitation confirmed iurlek
CVE-2026-63030 WordPress Active exploitation, known together with wp2shell iurlek
CVE-2026-60137 WordPress Active exploitation, known together with wp2shell iurlek
CVE-2026-6875 ServiceNow artificial intelligence platform Active exploitation confirmed iurlek
CVE-2026-40138 BeyondTrust Remote Support and Privileged Remote Access Critical preauthentication vulnerability Ransomware.mx
CVE-2026-53359 Linux KVM x86 kernel Use-after-free in shadow paging Ransomware.mx
CVE-2026-31694 Linux FUSE Privilege escalation to root Cronup
CVE-2026-16812 Arista VeloCloud Active exploitation, CVSS 10.0 Código Vigía
CVE-2026-20251 Splunk Secure Gateway RCE with low-privilege authenticated users Telefónica Tech
CVE-2026-58443 Gitea Critical vulnerability reported Devel Group
CVE-2026-0257 Palo Alto Networks firewalls Authentication bypass used as initial access vector for Qilin Devel Group
CVE-2026-59269 Not specified in the material File published by INCIBE-CERT INCIBE-CERT
CVE-2026-59686 to CVE-2026-59690 Kemp LoadMaster, ECS Connection Manager, Connection Manager for ObjectScale Five severe vulnerabilities published by Progress Devel Group
CVE-2026-16723 FastJson Active zero-day exploitation Devel Group
CVE-2026-35273 and CVE-2026-20251 should not be read as exclusive Mexican incidents, but as vulnerabilities relevant to entities with regional exposure and supply chains present in Mexico

Regulation and compliance in Mexico

July was one of the busiest months for regulation. Mexico City made phishing an independent crime, with penalties of three to six years in prison and fines of 200 to 600 UMA, with harsher sanctions when the victim is a minor, an older adult, or a person with a disability. It signals a tougher criminal approach to digital fraud, and it could have practical effects on complaints and on how online scams are argued in court.

There were also advances and debates around digital identity and personal data. The Secretariat of Anti-Corruption and Good Governance announced a fine against the Mexican Football Federation for the handling of personal data through Fan ID, and it later emerged that the agency had set its first public criteria on data protection based on that case. At the same time, discussions continued on multi-biometric banking, liveness checks, facial recognition verification, and the use of official databases to validate identity in higher-risk transactions.

Banks came under greater regulatory scrutiny. Coverage focused on the CNBV, the ABM, and the move to e.firma in employer filings with the IMSS, along with the replacement of the NPIE certificate. There was also discussion of stricter documentation and cyber risk requirements under frameworks such as Basel IV. By July, the message was clear, cyber risk management was no longer just a technical issue, it had become an explicit part of operational compliance.

On AI, Mexico continued with a fragmented framework. There were federal debates, sector-specific initiatives, a repeal in San Luis Potosí, and multiple views on the absence of a general law. What can be verified for the month is that the country kept regulating in pieces, while political pressure grew for a more comprehensive rule.

Regulatory front Verifiable July event Practical impact
Mexico City, phishing Independent criminal offense Strengthens criminal prosecution of digital fraud
Fan ID MXN 42,849,095 fine Sets a precedent in data protection
IMSS, e.firma NPIE eliminated and transition to SAT certificate Increases reliance on federal credentials
CNBV, biometrics Tightened requirements for high-value transactions Raises KYC controls and identity verification
AI National debate and sector-specific rules General-law gaps persist

Most affected sectors in Mexico

The public sector was the most visible in terms of reputational and operational impact, though not necessarily in absolute volume. León, Sinaloa and the Presidency drew public attention, with a mix of disruptions, information exposure and debate over attribution. When a leak includes registries, payroll records, medical files or citizen complaints, the potential damage goes beyond the affected system and reaches administrative processes, public trust and personal safety.

The financial sector was also prominent, but through a mix of fraud, biometrics, identity theft and regulation. Not everything was an intrusion. Several reports during the month showed pressure to tighten KYC, validate identity with biometrics and strengthen data handling. The fraud side remains critical, even if the incident category is not always formally recorded as a breach.

Manufacturing, business services and information technology kept appearing among the sectors with the most ransomware signals in open monitors. That matches the pattern from the previous month, although in July the publicity pressure and publication volume were higher. Health also reappeared, both in confirmed cases and in early warning material, and that means healthcare incidents should not be treated as isolated.

The sector reading, then, is not of a single front but of three layers. Government and public services for leaks and outages, finance for fraud and compliance, and industry and services for extortion and infrastructure exposure. The seven sectors with documented incidents show cross-cutting coverage, not a problem confined to one vertical.

The month-over-month comparison shows a sharp acceleration across nearly every front that matters. Verified incidents rose from 56 to 105. Ransomware or extortion cases climbed from 15 to 55. Documented fraud and phishing increased from 2 to 7. Critical CVEs mentioned jumped from 4 to 19. Only the number of sectors with documented incidents stayed flat at 7.

That points to a denser risk agenda, not necessarily a more orderly one. Last month already showed signs of extortion, but in July the publications multiplied and more cases included technical detail. At the same time, regulatory pressure increased on banking, biometrics, and digital fraud. For security and compliance teams, the overlap between incident, regulation, and reputation became tighter.

There are three signals worth following closely. The first is whether public ransomware cases continue shifting from simple listings on leak sites to confirmed encryption or leaks with demonstrable impact. The second is whether public portals and citizen service systems keep exposing logic flaws, such as the SIDAC IDOR, beyond classic infrastructure issues. The third is whether active exploitation of critical CVEs turns into local incidents, especially in collaboration software, identity systems, remote gateways, and exposed platforms.

The regional comparison also remains tense. This month’s sources insist that Mexico remains among the most attacked countries in Latin America, although that sits alongside the methodological reminder that many figures disclosed by vendors are telemetry or attempts, not confirmed incidents. The useful signal is not just the count, but the persistence of the same vectors: exposed services, phishing, identity abuse, and configuration flaws.

Indicador Julio 2026 Junio 2026 Lectura
Hechos verificados 105 56 Alza marcada
Ransomware o extorsión 55 15 Aceleración fuerte
Fraude o phishing 7 2 Crecimiento visible
Movimientos regulatorios 5 4 Actividad sostenida
CVEs críticos mencionados 19 4 Mayor presión técnica
Sectores con hechos 7 7 Sin variación

Security recommendations for teams in Mexico

First, focus on exposure management. Several incidents this month showed that initial access did not come from a sophisticated chain, but from misconfigured MSSQL, exposed credentials, unpatched edge services, and weak logical access. That calls for reviewing inventory, external exposure, and configuration posture before moving on to more advanced controls.

Second, harden identity and access controls. This month made clear that identity is the central vector, from banking phishing and impersonation to banking biometrics, e.signature, access to citizen systems, and leaks of sensitive data. Strong MFA, anomaly monitoring, privilege review, and validation of access flows should be a priority, especially in service portals and back offices with sensitive information.

Third, segment critical environments more effectively. Cases tied to healthcare, citizen services, and operational technology show that a breach in IT can escalate into OT, or that a leak in a portal can lead to amplified impact. Separating networks, limiting trust between domains, and reviewing print queues, repositories, and industrial gateways helps reduce the blast radius.

Fourth, prepare legal and reputational response. In July there were incidents where it was not clear whether encryption had been used, but there was public exposure, information funneling, and pressure from a leak site. When that happens, the security team needs to work with legal, privacy, and communications from the first hour. The difference between a leak and a takedown can be blurry for the public, not for the regulator.

Fifth, treat active CVE exploitation as an action list, not an appendix. With 19 critical vulnerabilities mentioned, several already exploited in the wild, patch timing cannot depend on the normal maintenance cycle. Products exposed to the internet, federated authentication, collaboration tools, and remote gateways need explicit priority.

Priority Action Reason
High Review MSSQL, RDP, VPN, and appliance exposure Repeated vectors in July intrusions
High Strengthen MFA and privilege controls Initial access through identity was recurring
High Validate offline backups and restore testing Minimizes the impact of encryption and extortion
Medium Audit citizen portals and repositories with sensitive data Reduces the risk of IDOR and mass leaks
Medium Align response with legal and privacy teams Many claims involve personal data
Medium Speed up patching of exploited CVEs The month showed cross-sector active exploitation

Material limitations

This report was built exclusively from the material provided for Mexico in July 2026. The time window covered by the indicators includes 108 dated events in July 2026, plus 1 earlier event used only as a comparative frame, and excludes 2 events after the period. No external information or internet sources were used.

An indicator at 0, or a lack of detail, does not mean the event did not exist in the region or the country. In particular, if a CVE or a category does not appear as monthly volume, that only means it was not recorded in the material analyzed under this window and these criteria. It should not be interpreted as a lack of vulnerabilities, attacks, or real-world exploitation.

The ransomware and extortion taxonomy also has methodological limits. In several cases, the material only mentions a victim on a leak site or an actor claim, without making it possible to determine whether there was encryption, exfiltration, or both. When the source did not make that clear, the classification was kept as not determinable.

Aggregate telemetry figures, attempts, blocks, and weekly vendor averages were left out of the count. Events without confirmed dates and any reference not within the available sources to cite were also excluded. Consumer social media, sponsored content, and promotional material were not used as evidence for trends, unless the open source provided a verifiable datum that could be independently attributed.

Comparative modules and monthly figures should be read as a snapshot of the period, not as a complete series of Mexican risk. Where a note provided regional or sector context, it was used for interpretation and not to invent additional incidents. If a source referred to attempts, blocks, or scans, it was treated as telemetry and not as an incident with confirmed impact.

Sources