CiberLATAMbywhalemate
Intelligence report

Mexico Cybersecurity Report: September 2026

Ransomware led September in Mexico with 19 cases, 12 unclassified incidents, 8 regulatory moves, and 6 critical CVEs.

Oct 1, 202616 min read
Mexico Cybersecurity Report: September 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are completed automatically with verified dated facts within the period. Each one states its basis and counting criterion so the figures reconcile across modules. They are the recurring month-to-month reading, and the analysis that follows develops the cases without repeating this summary.

Indicator window: 62 dated facts in September 2026 · 1 without confirmed date (excluded from the indicators) · 1 after the period (excluded). Facts from previous months are used only as comparative context in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Monthly verified signal dashboard September 2026 · Mexico Main threat: Ransomware (19 of 61 events). Coverage: 62 dated events in September 2026 · 1 undated c… VERIFIED EVENTS 61 period baseline: all counts measured from below against this total RANSOMWARE / EXTORTION 19 1 mention on a leak site · 18 not determinable from the material UNCLASSIFIED INCIDENTS 12 breaches or outages with no declared threat type FRAUD / PHISHING 0 documented fraud campaigns REGULATION 8 rules, resolutions, or sanctions UNIQUE CVEs 6 CVE-2026-67276 / CVE-2026-81963
Monthly verified signal dashboard — Base: 61 verified dated events in the period for Mexico.
FIXED MONTHLY MODULE Threat Axis Distribution September 2026 · Mexico Each event is counted under only one axis, so the total is exactly 61. "Unclassified incidents" is the remainder. Ransomware 19 Unclassified 19 Incidents 12 Regulation 8 Vulnerabilities 3
Threat Axis Distribution — Each event is assigned to one axis based on its classification; the total reconciles to the 61 events in the period.
FIXED MONTHLY MODULE Sectoral Signal Distribution September 2026 · Mexico Base: 61 incidents in the period · total 77 because 15 incidents are classified in more than one sector. Public Sector / OIV 23 Other / no sector ident… 23 Telecom 9 Retail / Consumer 9 Finance 8 Technology 4 Energy 1
Sectoral Signal Distribution — Heuristic sector classification for the victim. One incident may affect more than one sector, so the total may exceed the base.
FIXED MONTHLY MODULE Critical infrastructure in Mexico September 2026 · Mexico 9 of 61 events during the period affect critical infrastructure. One event may appear in more than one category. Public sector / government 23 Telecom / connectivity 1
Critical infrastructure in Mexico — Verified activity in public sector, finance, and essential services

Executive monthly summary for Mexico

September closed in Mexico with ransomware as the dominant threat, 19 of 61 verified incidents, alongside 12 unclassified incidents, an unusual wave of 8 regulatory moves, and 6 critical CVEs mentioned. The month also showed a clear banking angle, with digital fraud and tighter regulation on authentication, identity, and mobile payments as the other major exposure area.

The most visible case was the investigation into a alleged Aeroméxico database offered on Telegram, which led to an official probe and a public dispute over the incident's true scope. The available documentation supports exposure of contact data and, in some materials, references to birth date and frequent flyer number, but does not show confirmed evidence of banking data or passwords. That caution does not lessen the event's weight, because the authority itself treated the case as a possible breach of data protection rules.

At the same time, the extortion front remained active, with claims against Mexican companies on the leak sites of several groups, including Qilin, Krybit, and Settra. In most cases, the material does not make it possible to determine whether there was encryption, exfiltration, or only the publication of the victim on a leak portal, so the right reading is that extortion pressure remained sustained, but with partial and uneven classification.

The other major line of the month was regulatory. Banxico, the CNBV, Congress, and other institutions pushed or applied changes affecting transfers, authentication, digital identity, biometric use, and platform liability. From an operational security standpoint, that creates a mixed picture, more formal obligations and more compliance friction, but also more room for error if teams do not adjust processes, access controls, and fraud monitoring.

National snapshot for Mexico this month

Mexico showed sustained, elevated cybersecurity pressure in September, not because of a single confirmed mass incident, but because of recurring ransomware, financial fraud, personal data exposure, new authentication rules, and 6 critical vulnerabilities mentioned in the material. The risk reading is high because several fronts were active at once, and because the most sensitive events affected air transport, financial services, the public sector, and essential services.

Mexico, September 2026Verifiable milestones from the month, ordered by dateSep 1CFE blackoutsoutheastSep 10 Lawcybersecurity inprogressSep 15MFA andbanking malwareSep 20Aeromexico onTelegramSep 24RegulationdigitalSep 27 CitrixexploitedNotes: onlyconfirmed factsor attributedwith cautionwithin theperiod.
Mexico, September 2026, cybersecurity milestones — Brief chronology of the month’s most visible events, from critical infrastructure and ransomware to regulation and data exposure.

The month’s pattern was not a single dominant campaign, but a steady stream of attacks and claims across different verticals. In ransomware, SCILabs’ regional reference places Mexico among the Latin American countries hit hardest, with around 52 Mexican entities or companies affected in the first half of 2026 and close to 17.93% of regional cases. That helps explain why several September reports focused on operational resilience, not just prevention.

At the regional level, the country continued to appear as Latin America’s second-largest ransomware focal point and as a significant target for malicious email campaigns, credential theft, and pressure on critical infrastructure. The assessment does not require inflating telemetry or counting attempts as incidents, it is enough to note that, across 61 verified events during the period, exposure was spread across extortion, regulation, vulnerabilities, and breach or disruption events with strong media and operational impact.

Mexico period indicators

Indicator Value Previous month comparison
Verified facts in the period (base for all indicators) 61 61, no change
Time window for the indicators 62 facts dated September 2026 · 1 without confirmed date (excluded from the indicators) · 1 after the period (excluded) Same
Unclassified incidents (breaches or outages) 12 14, -2
Cases with ransomware or extortion as the primary focus 19 22, -3
Ransomware breakdown by impact type, leak site mention only 1 Not reported the previous month
Ransomware breakdown by impact type, classification not determinable from the material 18 Not reported the previous month
Documented fraud or phishing cases 0 5, -5
Documented regulatory moves 8 8, no change
Critical CVEs mentioned 6 2, +4
Sectors with at least one documented fact 6 7, -1
Main threat of the month Ransomware (19 of 61 facts) Ransomware (22 of 61 facts)
Facts with direct source confirmation 66% Not reported
Aggregated telemetry figures excluded from volume 1 (aggregate attempts or blocks, not incidents with confirmed impact) Not comparable

The indicator table leaves two important nuances. First, the month was not the noisiest in absolute terms for unclassified incidents or ransomware compared with the previous month, but it did concentrate more regulatory pressure and more technical exposure from actively exploited CVEs. Second, the lack of fraud or phishing in this count does not mean there was no fraud in Mexico. It means that, in September's material, no case classified that way appeared within the period cut.

Relevant Incidents in Mexico

Aeroméxico and the alleged database offered on Telegram

The investigation into Aeroméxico was the month’s most visible personal data incident, and it remained somewhere between partial confirmation and forensic caution. The authority detected a database allegedly linked to the airline, analyzed it, and opened an ex officio investigation, while the company said it found no exposure of financial information, payment cards, or passwords.

The materials agree that the sample analyzed included names, email addresses, phone numbers, and, in some cases, dates of birth. Frequent flyer numbers and signup dates are also mentioned in some coverage. The key point is that the available evidence does not allow the origin to be established with certainty, does not prove the database came directly from Aeroméxico, and cannot fully rule out a prior leak tied to a 2025 incident.

Malicious email campaign against Mexico attributed to TA2725 and TA4922

Proofpoint, as cited by several outlets, described large-scale email campaigns against Mexico during July and August 2026, with about 275,000 malicious messages in a single phase of the operation. The main objective was to steal credentials, install malware, and gain unauthorized access, using business, government, and everyday administrative lures.

The significance of the episode lies not in a confirmed single impact, but in its scale and the type of lure used. The sources reviewed describe an operation aimed at initial access capture, not ransomware, and highlight the presence of TA2725 and TA4922’s expansion into Mexico.

INCAN and the restoration of radiotherapy after a cybersecurity incident

The National Cancer Institute said its radiotherapy services had been restored and were operating normally as of September 11, after a cybersecurity incident temporarily affected its systems. The available reporting does not specify the technical family or the vector used.

Even with that limitation, the case matters because there was an operational impact and because this is a highly sensitive healthcare institution. The material does not include public attribution to a ransomware family or a complete description of the impact, so it should be classified as a confirmed incident that has not been fully typed.

Tlajomulco, lingering doubts over possible data loss

Four months after the March attack on the data processing centers of the Tlajomulco municipal government, public doubts remained about the loss or compromise of sensitive databases, including property records, beneficiary rolls, and spending receipts. The Jalisco Congress called for a more detailed assessment and a backup and recovery plan.

The value of the event in September is institutional rather than technical. It shows that some incidents do not end when the initial disruption stops, but when it becomes clear what data left the environment, which systems were compromised, and what recovery measures were documented.

Hidalgo C5i, an alleged access dispute and denial

Coverage of Hidalgo’s C5i showed a gap between what an investigator published and the official version from the state Public Security Ministry. The authority denied that its intelligence systems had been breached and said there was no official confirmation of compromise of the 911 dispatch desk or manipulation of emergency services.

During the same period, ads circulated on clandestine forums claiming to offer access to the dispatch system. Those ads were not independently verified, so the case should be read as a sign of criminal interest in public infrastructure, not as a confirmed intrusion.

Threats and Active Campaigns in Mexico

Ransomware and extortion: sustained pressure, partial classification

Mexico accounted for 19 cases with ransomware or extortion as the primary focus within the 61 incidents in the period, but only part of that total could be classified precisely. In one case, the material refers only to the victim’s appearance on a leak site, while in 18 cases the source does not allow us to determine whether there was encryption, exfiltration, or simply a public extortion claim.

That distinction matters. The month’s signal is not just whether there was more or less ransomware, but that sources index group activity unevenly. For operational reading, the 19 cases should be treated as active extortion pressure, without assuming the same technical method in all of them.

Qilin and Grupo Juste

Qilin was one of the most repeated names in the Mexican material for the month. Different tracking platforms recorded Grupo Juste as a victim, but the available material did not allow an independent confirmation of the real scope or the compromised data.

The source describes a claim on a leak site and not necessarily a ransom event validated by the organization. That places the episode in the category of a mention or incomplete classification, not confirmed operational impact.

KRYBIT, Tender and other claims in Mexico

KRYBIT appeared linked to several Mexican entries, including Tender, Grupo Juste and other cases listed on monitoring platforms. In some records, the incident appears as a claim or victim posting, but the material does not independently confirm either the intrusion or the exfiltration.

At the tactical level, what is clear is the persistence of extortion pressure on Mexican service, retail and manufacturing companies. The challenge for analysis is that many sources of this type describe the leak site, not the underlying technical incident.

Fraud and phishing: no single case, but plenty of operational signal

There were no fraud or phishing cases documented as closed incidents within the period, but campaigns, alerts and sector responses were abundant. The most visible front was digital banking, where Condusef and ABM stressed mobile malware, impersonation of institutions, code theft and the use of fake apps.

This is not a risk gap. It was a month in which fraud showed up mainly as a campaign pattern and as accumulated statistics, not as a single standalone event. The right reading is in the set of warnings, claims and operational recommendations.

APT, intrusion with AI tools and activity against critical infrastructure

The campaign attributed to CL-CRI-1131 stands out as the clearest case of sophisticated intrusion outside the financial axis. Unit 42 and sources that cite its analysis describe an operation against a transportation organization, federal ministries and municipal water utilities in Mexico and Ecuador, using living-off-the-land, batch scripts and tooling hosted on attacker infrastructure.

The material also mentions the use of AI to generate code and explore networks in the case of the Monterrey water provider, although by mid-September no service disruption had been confirmed as attributable to that activity. The relevant technical detail is that the attempt to pivot toward OT was blocked.

Critical vulnerabilities affecting Mexico

CVE Software Exploitation Source
CVE-2026-88771 Citrix NetScaler ADC and NetScaler Gateway Active exploitation confirmed on unpatched systems Syswork México, 2026-09-27
CVE-2026-88772 Citrix NetScaler ADC and NetScaler Gateway Active exploitation confirmed on unpatched systems Syswork México, 2026-09-27
CVE-2026-85880 Windows Advanced Local Procedure Call, ALPC Actively exploited zero-day, privilege escalation Syswork México, 2026-09-21
CVE-2026-81963 Windows Update Stack Actively exploited zero-day, privilege escalation Syswork México, 2026-09-21
CVE-2026-67276 MikroTik RouterOS Active exploitation using the MikroTrick technique Heraldo de Puebla, 2026-09-10
CVE-2026-86060 MikroTik RouterOS Active exploitation using the MikroTrick technique Heraldo de Puebla, 2026-09-10

Technically, September brought a mix of flaws in edge appliances, Windows systems and routers widely used in small networks. The common thread was the need for urgent patching, but with a catch, several of these vulnerabilities were already being exploited at the time of coverage, so the real response window was short.

Critical vulnerabilities mentionedMexico, September 2026CVE-2026-88771CVE-2026-88772CVE-2026-85880CVE-2026-81963CVE-2026-67276CVE-2026-86060Citrix NetScaler, active exploitationCitrix NetScaler, active exploitationWindows ALPC, zero-dayWindows Update Stack, zero-dayMikroTik RouterOS, MikroTrickMikroTik RouterOS, MikroTrick
Critical CVEs mentioned in Mexico — Comparative map of the six critical vulnerabilities mentioned in this month’s material.

Citrix, Microsoft and MikroTik appearing in the same month points to different attack surfaces. This was not only about ransomware or fraud. Part of Mexico's risk in September came from exposed infrastructure and edge devices that, if left unpatched, can open the door to intrusion, lateral movement and persistence.

Regulation and compliance in Mexico

September was a dense month for regulation. Banxico and the CNBV moved rules on transfers, authentication, and user experience. Congress pushed forward bills on digital identity, AI, data protection, and cybersecurity, while the data protection authority kept acting on exposure cases and sanctions.

The news is not just the volume of initiatives, but the convergence of topics. Digital identity, biometrics, payment security, critical infrastructure, and platform liability started to appear in the same political and regulatory package.

Banxico, the CNBV, and the reshaping of payments and authentication

Banxico published Circular 9/2026 with a compliance deadline of December 14, 2026, for adjustments to mobile apps and transfer rules. At the same time, the material shows consultations and changes on SMS authentication, interchange fees, and user experience standardization.

For compliance teams, the signal is twofold. There is more regulatory detail on how digital channels must operate, but also more risk of rolling out partial or rushed changes. The impact is not abstract, it affects onboarding, authentication, user support, and anti-fraud monitoring.

Digital identity, biometrics, and data protection

Deputy Karina Margarita del Río Zenteno promoted an initiative to elevate to constitutional status the right to a secure, interoperable, and free digital identity. At the same time, other proposals targeted a General Law on Digital Identity and Citizenship, and the harmonization of rules on data protection, cybersecurity, and electronic signatures.

In the financial sector, regulation already incorporates fingerprint and facial biometrics as part of customer identification. That makes biometric data governance more important, because the regulatory surface is no longer limited to credentials and passwords.

Cybersecurity as an evolving legislative framework

The Senate received a bill to enact a Cybersecurity Law that proposes a National Cybersecurity Agency, a CSIRT, and a national system. The bill is still under review, so it should not be treated as current law, but it does signal the policy agenda.

In parallel, Congress advanced other regulatory pieces on AI, digital content, and platform liability. The result is a month in which Mexican regulation moved quickly, although it still has not closed a unified framework.

Most affected sectors in Mexico

The financial sector was again the most exposed by volume of signals, though not always by the same type of incident. Alerts on fraud, guidance from Condusef and ABM, complaint reports, authentication changes, and references to biometrics all converged in the same month. This was not a single attack, but a persistent risk surface.

Services, government, transportation, and healthcare also stood out, mainly because of ransomware incidents, breaches, or outages, and intrusions that cut across multiple verticals. In the public sector, the material again points to a classic problem, the late confirmation of scope, which makes it harder to distinguish between exposure, compromise, and a criminal claim.

Industry and manufacturing remain under pressure, especially in ransomware contexts and in activity linked to Russian-speaking actors. The BlackCat case and the reference to more than a dozen affected Mexican industrial and manufacturing companies reinforce that reading, although not every mention carries the same evidentiary weight.

In utilities and essential services, the main signal came from water and energy infrastructure. The Monterrey case and the operation targeting municipal water, along with events in the southeast power sector and reports on Hidalgo’s C5i, show that interest in critical services does not fade even when the final confirmation of operational damage is uneven.

The main trend this month was a drop in the number of unclassified incidents and ransomware cases compared with the previous month, but with a tradeoff, the number of critical CVEs mentioned rose and regulatory volume held steady. That points to less noise on some fronts and more technical pressure on others, not a structural improvement in risk.

The month-over-month comparison also shows that documented fraud and phishing fell from 5 to 0 in the September material. That should not be read as real relief in risk, because the month itself was full of warnings about bank fraud, fake apps and financial brand impersonation. What declined was the count of closed incidents in the sample, not the underlying exposure.

In ransomware, the drop from 22 to 19 primary-axis cases does not erase the continuity of the phenomenon. September shifted more toward damage classification, mentions on leak sites and distributed extortion pressure than toward major episodes with confirmed encryption.

The other signal to watch is the regulatory acceleration. The previous month already brought movement in payments and authentication, but September added digital identity, AI, legislative cybersecurity and data protection. For compliance teams, that means more touchpoints between legal, technology and risk functions.

Security recommendations for Mexico

  1. Review perimeter exposure and mobile channels immediately, especially in environments using Citrix NetScaler, Windows, and MikroTik devices. This month’s actively exploited vulnerabilities leave no room for long patch cycles.

  2. Prioritize detection of credential theft and account takeover in digital banking. This month’s material shows campaigns by email, SMS, and fake apps, plus mobile overlays and verification code capture.

  3. Tighten monitoring for data leakage and postings on leak sites, because part of the ransomware activity during the period appears only as a mention or an unconfirmed claim. It is worth separating encryption, exfiltration, and simple extortion pressure with discipline.

  4. Review governance around personal and biometric data. Between Aeroméxico, digital identity initiatives, and facial recognition and fingerprint capture rules, the regulatory focus is no longer limited to passwords, but also includes sensitive identity information.

  5. Validate response plans with the business and with vendors. The Aeroméxico case again showed that third parties and external platforms can sit at the center of an incident, even if technical attribution remains open.

  6. Prepare an updated compliance map for Banxico, CNBV, and Congress. Obligations on transfers, user experience, identity, and data protection accumulated in September and should not be treated as isolated pieces.

Frequently Asked Questions

What changed in Mexico between the banking fraud and September ransomware?

In September, banking fraud stopped appearing as a closed incident in the sample, but it continued to dominate the operational conversation through alerts from Condusef, ABM and Banxico. Ransomware remained the leading threat by volume, with 19 of 61 incidents, and it was also supported by leak sites and incomplete classification.

Aeroméxico became the focus of an investigation after a base was offered on Telegram, while Congress and the federal administration pushed initiatives on digital identity, data protection and cybersecurity. The three lines converge on the same point, more sensitive personal data and greater regulatory pressure on how it is handled.

What do the Citrix, Windows and MikroTik CVEs indicate together?

Together they show three different attack surfaces, edge appliances, operating systems and widely used routers, with active exploitation in the same month. That makes patching and segmentation a priority, because the risk was not concentrated in one vendor or one type of infrastructure.

How does the malicious email campaign connect to Mexican digital banking?

Proofpoint's campaign sought credentials and initial access through everyday lures, while digital banking showed alerts tied to mobile malware, clones of institutions and code theft. They are different fronts, but they meet in the same chain, social engineering, access capture and later fraud.

Which sectors should pay the most attention after September?

Financial services, government, industry and utilities are the most exposed based on what the sample showed. Finance for fraud and regulation, government for unclassified incidents and extortion pressure, and critical infrastructure for multivertical campaigns and exploited vulnerabilities in exposed systems.

Material limitations

This report covers only facts dated September 2026 within the provided material. One fact without a confirmed date was excluded from the indicators, and one fact after the period was also excluded from the count. When numbers appear in prose, they refer to the base of 61 verified facts from the period.

A zero indicator, especially in the documented fraud or phishing cases, means those items did not appear in the material reviewed for this cut, not that they did not occur in Mexico or the region. The same applies to the nuance on CVEs: the 6 critical vulnerabilities mentioned do not exhaust the full universe of exploited flaws, only what was observed in the month's sources.

The indicator window included 62 facts dated September 2026, plus 1 without a confirmed date that was excluded and 1 after the period that was excluded. Facts from earlier months were used only for comparison when the material allowed it, never as part of the month's volume.

The base excluded attempts, blocks, or aggregated scans that the material treated as telemetry, because they do not amount to incidents with confirmed impact. Sponsored content, commercial releases, and notes without enough support to turn them into a trend were also left out.

Sources