CiberLATAMbywhalemate
Intelligence report

Mexico Cybersecurity Overview, August 2026

Ransomware, bank fraud, financial regulation, and service outages shaped August in Mexico, with 61 verified incidents.

Sep 1, 202616 min read
Mexico Cybersecurity Overview, August 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are automatically completed with verified dated facts within the period. Each one states its basis and counting criterion, so the figures reconcile across modules. They are the recurring month-to-month reading; the analysis that follows develops the cases without repeating this summary.

Indicator window: 62 dated facts in August 2026 · 2 from prior months (comparative frame, not monthly volume) · 1 without confirmed date (excluded from the indicators). Facts from prior months are used only as a comparative frame in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Verified Signal Monthly Dashboard August 2026 · Mexico Primary threat: Ransomware (22 of 61 events). Coverage: 62 dated events in August 2026 · 2 from prior months… VERIFIED EVENTS 61 period base: all counts measured from the bottom over this total RANSOMWARE / EXTORTION 22 2 encrypted assets confirmed · 3 exfiltration unencrypted (simple extortion) UNCLASSIFIED INCIDENTS 14 breaches or outages without declared threat type FRAUD / PHISHING 5 documented fraud campaigns documented REGULATION 8 standards, resolutions, or sanctions UNIQUE CVEs 2 CVE-2023-27997 / CVE-2026-68820
Verified Signal Monthly Dashboard — Base: 61 verified dated events in the period for Mexico.
MONTHLY FIXED MODULE Threat Axis Distribution August 2026 · Mexico Each event counts toward only one axis, so the total is exactly 61. "Unclassified incidents" is the remainder. Ransomware 22 Incidents 14 Regulation 8 Unclassified 7 Fraud 5 Vulnerabilities 5
Threat Axis Distribution — Each event is assigned to a single axis based on its classification; the total matches the 61 events in the period.
MONTHLY FIXED MODULE Sectoral Breakdown of Signals August 2026 · Mexico Base: 61 incidents in the period · total 77 because 14 incidents are classified in more than one sector. Public sector / OIV 37 Other / unidentified sector… 14 Telecom 7 Technology 6 Finance 5 Education 4 Energy 3 Retail / Consumer 1
Sectoral Breakdown of Signals — Heuristic sector classification by victim. One incident may affect more than one sector, so the total may exceed the base.
MONTHLY FIXED MODULE Critical infrastructure in Mexico August 2026 · Mexico 15 of the 61 events in the period touch critical infrastructure. One event may appear in more than one category. Public sector / government 37 Energy / utilities 1 Telecom / connectivity 6
Critical infrastructure in Mexico — Verified signal in public sector, finance, and essential services

Executive summary for the month in Mexico

August closed in Mexico with a month dominated by ransomware and extortion, a concentration of incidents across retail, local government, healthcare, and professional services, and a parallel wave of banking fraud, regulatory changes, and outages across public and private platforms. Of 61 verified events, the strongest signal was ransomware, with 22 cases, although the operational picture was broadened by 14 uncategorized incidents and several disruptions to digital services.

The most visible case was the San Luis Potosí City Council, where the narrative shifted from a hack with data theft to a later extortion attempt. Also significant was the appearance of Mexican victims on leak portals, with SEARS, Price Shoes, Cinépolis, Quaker State Mexico, Integraduanas, and Federis Abogados among the names most cited by technical and media sources. In several of those cases, the source does not specify whether encryption occurred, and in others the only evidence is a mention on a leak site.

At the same time, the financial sector was hit by phishing campaigns, caller ID spoofing, deepfakes, and social engineering fraud, while Banxico and the CNBV introduced regulatory changes on card payments, biometric verification, and risk controls. Added to that were exposed Fortinet credentials in public agencies, the temporary outage of gob.mx, and the UASLP incident, which affected university services, enrollment, and virtual classes.

The overall reading for Mexico in August is one of high risk, based on volume, sector diversity, and combined pressure on availability, confidentiality, and fraud. This was not just a series of isolated intrusions, but a sequence combining extortion, operational failures, leaks, regulatory updates, and the now visible use of AI by both attackers and authorities, as well as research teams.

Mexico, August 2026Selected timeline of verified eventsAug 1SIAC / PresidencyIDOR leakAug 5-6 UASLPcyberattackAug 15FortiBleedexposed credentialsAug 19 gob.mxtemporary outageAug 20-24SLP City HallextortionAug 24-25IQSEC 116victimsIncludes onlydated milestonesfrom the periodwith operationalweight orregulatoryclear.
Mexico, August 2026, timeline of the most notable events — Sequence of incidents and developments during the month with verified dates from the material.

National snapshot for the month in Mexico

Mexico showed a heterogeneous and persistent attack surface in August, with the federal government, local governments, education, retail, telecommunications and financial services among the most visible targets. Ransomware was the dominant threat, but its weight was not explained by encryption alone. Most of the published cases relied on extortion, exfiltration or simply appearing on leak sites, which increases reputational and legal pressure on victims.

Severity was uneven. There were confirmed disruptions, such as the outage of gob.mx and the incident at UASLP, as well as numerous cases where the available material does not allow confirmation of encryption, leakage or only a group claim. That mix points to a very active threat ecosystem, but also to a layer of media overexposure where not everything listed reflects the same level of compromise.

The country risk reading is high because the verified events were not concentrated in a single sector or a single vector. There was phishing, WhatsApp fraud, caller ID spoofing, deepfakes, credential exposure, critical vulnerabilities, extortion with stolen data and regulatory reforms that show sustained pressure on financial entities, public agencies and digital service operators.

At the regional level, Mexico continued to appear among the Latin American countries hit hardest by ransomware and digital fraud. Different sources place it behind Brazil in regional volume, and aggregated NTT DATA telemetry cited by Polls Politico MX places it as the second Latin American country with the most cyberattacks per minute during a measurement window that reported 459 attempts or blocks per minute. That figure is telemetry and should not be read as confirmed impact incidents.

Mexico: sectors with visible signalsThis is not a total of incidents by sector, but a reading of document densityGovernmentgob.mx, SLP, Tlaxcala, Nuevo LeónRetailSEARS, Price Shoes, CinépolisEducationUASLP, local campaignsFinancephishing, deepfakes, spoofingThe bar reflects document visibility in the corpus, not aggregated telemetry or absolute volume.
Mexico: sectors with visible signals in August 2026 — Qualitative comparison of the sectors that concentrated documented incidents and campaigns.

Period indicators in Mexico

Indicator August 2026 Previous month Change
Verified events in the period (basis for all indicators) 61 105 -44
Time window for the indicators 62 events dated August 2026 · 2 from prior months (comparison frame, not monthly volume) · 1 with no confirmed date (excluded from the indicators) Same criterion N/A
Unclassified incidents (breaches or outages) 14 12 +2
Cases with ransomware or extortion as the primary focus 22 55 -33
Confirmed asset encryption 2 N/D
Exfiltration without encryption (simple extortion) 3 N/D
Mentioned only on a leak site 1 N/D
Classification cannot be determined from the material 16 N/D
Documented fraud or phishing cases 5 7 -2
Documented regulatory moves 8 5 +3
Critical CVEs mentioned 2 19 -17
Sectors with at least one documented event 7 7 unchanged
Dominant threat of the month Ransomware (22 of 61 events) Ransomware (55 of 105 events) lower relative weight
Events with direct source confirmation 74% N/D N/D
Aggregated telemetry figures excluded from the volume 1 (aggregated attempts or blocks: not incidents with confirmed impact) N/A N/A

The period is based on 61 verified events. The time window includes 62 events dated August 2026, 2 from prior months used only as a comparison frame, and 1 event with no confirmed date excluded from the volume.

Relevant Incidents in Mexico

San Luis Potosí City Hall, hack and extortion after exfiltration

The month’s most sensitive incident involved San Luis Potosí City Hall, as it escalated from a data theft intrusion into a later wave of financial pressure. Sources agree that information was stolen, files were partially disclosed, and money was then demanded to prevent publication or speed up recovery. This was a clear case of exfiltration followed by extortion, although no system encryption was reported.

The technical and legal scope remained disputed for several days. The municipality said the material involved workers’ asset declarations and public data available on official platforms, but other reports cited names, CURP, phone numbers and addresses without redaction. Subsequent coverage reiterated that the actor tried to negotiate after the data theft, and ransomware.mx described the episode as exfiltration followed by extortion.

Autonomous University of San Luis Potosí, cyberattack with operational impact

UASLP went through an incident with confirmed operational impact, affecting Caja Virtual, registrations, virtual classes and administrative processes. The university disclosed the event in the first days of August, filed a complaint with the FGR and extended payment deadlines, while local media reported that the impact reached multiple internal areas. In this case, the material confirms service disruption, although it does not allow the initial vector to be identified precisely.

gob.mx, temporary outage of the federal digital presence

The August 19 disruption of gob.mx was publicly ambiguous, because ATDT attributed it to a connectivity cut and ruled out a cyberattack. Even so, the federal government’s main domain was offline for about two hours and affected key agency portals, including the Presidency of the Republic. The official response was brief and did not include a detailed technical report.

The episode mattered less for the stated cause than for the structural dependence it exposed. The widespread outage showed operational fragility in an architecture concentrated in a single domain, with screens that also exposed internal components such as WildFly and Nginx. In risk terms, it was a availability incident with systemic value, even if no intrusion was proven.

Telsur, Telcel, Telmex and continuity fragility in telecoms

August also brought several mass outages or intermittent failures in telecommunications, with Telmex and Telcel the most frequently mentioned names. Telcel had problems with top-ups, billing and the account linking portal, and the company acknowledged failures in some IP systems. Telmex, meanwhile, recorded several days of interruptions in internet and phone services.

These events are not tied to confirmed cyberattacks, but they do form part of the month’s operational continuity picture. The pattern matters because they coincided with the gob.mx outage and with reports of intermittent failures on other platforms, reinforcing the perception of broader degradation in digital infrastructure and connectivity.

Tlaxcala C5i, attempted computer vandalism

Tlaxcala reported an attempted breach of the C5i portal that was contained by the technical team without compromising the hosted information. The state government activated security protocols and restored the site. It is a case without a confirmed breach, but it is notable because it adds to the group of unclassified incidents and shows an early institutional response.

Nuevo León ICV, alleged leak under investigation

The case involving Nuevo León’s Vehicle Control Institute remained in a gray area throughout the month. Versions point to possible access to millions of records, including driver’s licenses and vehicle renewal data, but prosecutors said there was no formal complaint at the time of coverage and the institute said it was still assessing the veracity of the alleged attack. In evidentiary terms, it remains an incident under investigation.

Threats and active campaigns in Mexico

Ransomware and extortion in Mexico

Ransomware was the month’s most visible threat in Mexico, but its distribution was uneven across confirmed encryption, exfiltration without encryption, and simple listings on leak sites. Only two cases involved confirmed asset encryption in the material, three involved exfiltration without encryption, one was mentioned only on a leak portal, and sixteen remained without a conclusive classification. The rest of the incidents fall within the same extortion pressure, although with insufficient technical detail.

Among the clearest cases was the San Luis Potosí City Hall, which led to post-theft extortion, and Federis Abogados, listed by Booba Project with a claim that 61 GB had been stolen. SEARS, Price Shoes, Cinépolis, Quaker State Mexico, Integraduanas, and Centro Médico Especializado OSI also appeared, although in several of those cases the source only confirms the leak site posting or the actor’s claim.

Qilin remained the most recurrent actor in Mexican coverage. It was linked to victims in retail, logistics, energy, and manufacturing, and ransomware.mx described it as the most active group targeting Mexican organizations, with 23 victims recorded in Mexico and 14 published so far in 2026 through August 10. That source also says Qilin exfiltrates data before encrypting it, which helps explain the frequency of simple extortion in the reported cases.

The SEARS case, linked to SpaceBears, also drew significant attention in coverage. It appeared in several aggregators and technical outlets, with references to the alleged leak of customer data, including at least one password field, but without public confirmation from the company. Price Shoes was another case with strong technical documentation in ransomware.live and HookPhish, both with specific discovery and attack dates.

Fraud, phishing, and impersonation

The fraud and phishing front was highly active and also showed a jump in sophistication. Group-IB described a PhaaS operation, Balonx Sistema, that targets banking applications in Mexico through calls from attacker-controlled SIP infrastructure, real-time relay of OTP codes, and identity spoofing. At the same time, Condusef warned about fake messages, calls, verification codes, and WhatsApp campaigns designed to take over accounts or induce transfers.

The most visible strain involved deepfakes. The SSPC reported on networks using manipulated images and videos of officials to promote fake investments, with fund freezes and arrests, while Condusef and other outlets warned about bank impersonation through caller ID spoofing. The combination of deepfake, social engineering, and weak authentication is no longer theoretical in Mexico, and the month left several concrete examples.

APT, active exploitation, and technical intrusion activity

Although the monthly focus was on ransomware and fraud, there was relevant technical activity tied to active exploitation. CISA added CVE-2025-62593 to the KEV catalog for active exploitation against Ray, a framework used in AI environments. The reviewed material does not show a Mexican incident directly associated with it, but it does serve as an exposure signal for the local AI and cloud ecosystem, which already showed risks in the OpenAI and Hugging Face incident published during the period.

There was also activity in campaigns with a possible more traditional intrusion component, such as the exposure of Fortinet credentials linked to Mexican public agencies and the Grandoreiro case, which reappeared with a focus on Latin American users, with Mexico as an important country in detections. These are signals different from ransomware, but they converge on the same problem of credentials, initial access, and operational continuity.

Critical vulnerabilities affecting Mexico

CVE Software Exploitation Source
CVE-2023-27997 FortiGate Critical vulnerability tied to FortiBleed, with credential exposure in Mexican public agencies; the material does not document confirmed local exploitation during the month Infobae México, ITECS
CVE-2025-62593 Ray-Project Ray Active exploitation confirmed by CISA, classified as RCE via browser and DNS rebinding; no confirmed local incident is documented in Mexico CISA, The Hacker News, NVD / NIST

In the material reviewed, only two critical CVEs appeared with journalistic or technical relevance. That does not mean there were no other critical vulnerabilities in the region, only that this document set did not include any additional cases dated August 2026 with verifiable local impact in Mexico.

Regulation and Compliance in Mexico

Mexico’s regulatory agenda moved faster than the federal cybersecurity law. In August, changes in transparency, data protection, financial supervision, and anti-money laundering rules took shape, but no federal cybersecurity law was published in the Diario Oficial de la Federación. That gap was one of the month’s clearest features.

Banxico and the CNBV opened public consultations on new rules for payment rails, with changes to interchange fees and interoperability requirements. At the same time, the CNBV stepped up its risk-based approach to currency exchange houses and money transmitters. In banking, the MTU timetable also kept pushing the debate over transfer limits and enhanced verification.

Data protection was also being reshaped. The federal government said it would strengthen the transparency digital platform after the INAI was dissolved, while the Secretaría Anticorrupción y Buen Gobierno took on new oversight and sanctioning powers under the LFPDPPP of 2025. In the State of Mexico, new transparency and data protection laws also formalized the end of the Infoem and the transition to Transparencia Mexiquense.

In Mexico City, the Pacto Digital added initiatives on children’s digital rights, privacy, data protection, and digital security. The city congress also criminalized phishing and opened debates on digital violence and deepfakes. Together, these moves point to regulation advancing in layers, with a strong local and sector-specific component.

Sectors most affected in Mexico

The most exposed sector was government, at the federal, state and municipal levels. There were outages at gob.mx, exposure in Presidencia’s SIAC/SIDAC, incidents at Nuevo León’s ICV, an attempted attack at Tlaxcala’s C5i, and the case involving the San Luis Potosí City Council. The pattern is clear, even if the event types varied: availability, data leakage, extortion and institutional disruption.

Retail and e-commerce also had a heavy month. SEARS, Price Shoes and Cinépolis appeared in leak portals or in technical ransomware reports, with Qilin and SpaceBears as the most visible actors. The exposure was not uniform, but it was enough to support a reading of growing pressure on mass-market brands with large customer bases and complex operational dependencies.

Education remained an important target. UASLP was at the center because of the impact on virtual classes, virtual cash operations and enrollment, and the public-sector ecosystem in the state also showed signs in Tlaxcala and in other academic or administrative portal cases. IQSEC’s material also reinforces that manufacturing, business services, health care and commerce are among the most exposed sectors, and that a single incident can affect more than one sector.

Finance, payments and telecoms completed the picture. There was bank fraud, caller ID spoofing, biometrics, MTU, a public consultation on interchange fees, and failures at Telcel and Telmex. In Mexico, the month showed that risk is no longer measured only by intrusion incidents, but by the combination of access, identity, continuity, compliance and user trust.

The comparison with the previous month shows a shift in composition rather than a drop in risk. Verified incidents fell from 105 to 61, but the relative weight of ransomware dropped from 55 to 22 while regulatory moves increased from 5 to 8. That points not to easing conditions, but to a plateau in activity with broader thematic dispersion and more compliance items.

Unclassified incidents rose from 12 to 14, which should be read as a sign of documentary ambiguity rather than an improvement in the environment. Fraud or phishing cases fell from 7 to 5, but the quality of the reported campaigns worsened in sophistication, with deepfakes, caller ID spoofing and PhaaS. In other words, less apparent volume, but greater deception capacity.

The drop in critical CVEs mentioned, from 19 to 2, also needs context. The decline does not mean fewer critical vulnerabilities in circulation, but fewer dated mentions in the material analyzed for this month. The focus shifted from lists of flaws to credential misuse, extortion and availability failures, which fits a more selective exploitation scenario.

The public sector and the financial sector remained the most sensitive, but retail and logistics gained visibility. If that trend continues, September should show more pressure on chains with customer data, payment systems and hybrid platforms. It will also be worth watching whether the San Luis Potosí and gob.mx cases lead to stricter technical reviews or new regulatory adjustments.

Recommendations for security teams in Mexico

First, review exposure to credentials and privileged access in public and private environments. This month’s material shows several credential-backed vectors, from Fortinet to banking campaigns and access to management platforms. Closing active sessions, rotating credentials, and strengthening MFA remain immediate measures, not generic advice.

Second, clearly separate ransomware response from extortion tied to data exfiltration. In August, there were cases of confirmed encryption, cases with no encryption, and cases where only a leak site mention appeared. That difference matters for containment, evidence preservation, legal notification, and reputational handling.

Third, harden identity verification processes in banking, fintech, and customer service. Caller ID spoofing, OTP relay, and deepfake campaigns are already operating in Mexico. Teams should limit trust in phone channels, forbid sensitive verification outside authenticated channels, and audit workflows that allow data changes or transfers without friction.

Fourth, strengthen operational continuity and test dependencies on centralized infrastructure. The outage at gob.mx showed that a single connectivity failure can cut off access to multiple federal portals. The same applies to telecom and university services. Contingency plans should include controlled degradation, alternate messaging, and recovery tests with external dependencies.

Fifth, monitor the regulatory surface and adjust compliance controls in time. Rules on payments, biometrics, PLD/FT, and data protection are changing quickly. Security, compliance, and legal teams need a shared table so technical implementation does not arrive late or conflict with the regulatory text.

Frequently Asked Questions

What risk mix dominated August in Mexico, ransomware, fraud, or regulation?

Ransomware and extortion dominated, with 22 events in that track, plus banking fraud campaigns and eight regulatory moves. The month also brought operational incidents, leaks, and rule changes in payments, biometrics, and personal data. See "Indicators for the period in Mexico" and "Regulation and compliance in Mexico".

Which cases had confirmed operational impact, and which were only attacker claims?

UASLP and the temporary outage of gob.mx had confirmed operational impact. By contrast, several ransomware cases, including SEARS, Price Shoes, Cinépolis, and Quaker State Mexico, appeared only as leak site posts or group claims, with no public confirmation from the victims of encryption or damage. See "Relevant incidents in Mexico" and "Active threats and campaigns in Mexico".

Which sectors are under the most visible pressure, and how do they relate to the month's incidents?

Government, retail, education, finance, health, logistics, and telecom all had documented events. The pressure was not uniform, but it was broad, with local and federal government affected by availability issues and leaks, and retail and payments exposed to ransomware and fraud. See "Most affected sectors in Mexico" and "Relevant incidents in Mexico".

Which critical CVEs appeared, and what do they mean for Mexico?

Only two critical CVEs were mentioned in the analyzed material, CVE-2023-27997 in FortiGate and CVE-2025-62593 in Ray. Neither was tied to a confirmed local intrusion in Mexico during August, but both reinforce risk for public, cloud, and AI environments. See "Critical vulnerabilities with impact in Mexico".

What should a Mexican security team prioritize after reading this report?

It should prioritize credentials, MFA, continuity, and identity validation. The month showed extortion campaigns, phishing, deepfakes, connectivity failures, and exposure of access in public agencies. The most urgent response is to reduce the access surface and test recovery of critical services with external dependencies. See "Recommendations for security teams in Mexico".

Does the NTT DATA telemetry figure count as confirmed incidents?

No. The figure cited by Polls Politico MX, 459 attacks per minute for Mexico in the measurement window covered by NTT DATA, is aggregated telemetry for attempts or blocks, not incidents with confirmed impact. It provides context, but it is not included in the month's total. See "Material limitations".

Material limitations

This report was built exclusively from the material provided for Mexico and August 2026. The 61 verified facts from the period form the basis of the indicators. The 2 facts from prior months were used only as comparative context, and the undated fact was excluded from the total. Nothing outside that corpus was included.

A zero indicator, especially for CVEs, does not mean there were no critical vulnerabilities or exploitation in the region. It means none were recorded in this month’s analyzed material with the required classification. This report did mention two critical CVEs, and the same principle applies to any axis that may appear empty in future editions.

The aggregated NTT DATA telemetry figure cited by Polls Politico MX, 459 attacks per minute for Mexico in the measured window, is not a count of incidents with confirmed impact. It refers to automated attempts or blocks and, by methodology, is not added to the monthly volume.

Publications without a confirmed date and any source not included on the authorized list were also left out of the calculation. Facebook, Instagram, TikTok, Threads, Reddit, and LinkedIn posts were not used. When a source was an aggregator, sponsored content, or secondary reporting, it was treated only as contextual support and not as the sole basis for establishing a trend.

Sources