Cyber incidents

MX cybersecurity tracker

Known / reported cyber incidents against Mexican federal, state, municipal, private, and critical-infrastructure targets. Includes the recent Cajeme & Caborca municipal ransomware events in Sonora.

Incidents tracked
20
6 active / investigating
Top sector
Government
10 incidents
Top incident type
Data leak
6 incidents
Critical-infra hits
4
Pemex / Banxico / CFE / SPEI / Metro
MX state-as-operator
1
SEDENA Pegasus operations

Cyber-economy categories

Where the bulk of MX cyber damage actually happens — continuous campaigns and structural vulnerabilities, not one-off breaches.

Structural
  • Vishing / virtual kidnapping↑ Rising
    Vishing / virtual-kidnapping call centers
    ~70,000 successful extortions / year~2.4M call attempts / year (CNS)

    Primary delivery: smuggled phones in CDMX prisons (Reclusorio Norte, Reclusorio Oriente) and Tamaulipas / Nuevo León penitentiaries. 2024-25 sees heavy adoption of AI-cloned voice ('your relative crying for help') driven by stolen social-media voice samples + commercial deepfake tools. Average ransom: 5,000–80,000 MXN, paid via OXXO Spin, Bitso, or wire to mule accounts.

    Concentration:mx-cdmxTamaulipasNuevo LeónSources: CNS, CONDUSEF, Animal Político
  • Tax fraud (CFDI)↑ Rising
    Empresas-fantasma / fake CFDI invoice fraud
    ~$354B MXN / yr (~$20B USD) in fraudulent deductions12,000+ companies on SAT EFOS list

    Shell companies sold online to issue fake deductible CFDI invoices. Major cartel money-laundering vector — UIF investigations consistently link CFDI rings to Sinaloa, CJNG, and CDN financial cells. SAT publishes the EFOS (Empresas que Facturan Operaciones Simuladas) list publicly but enforcement lags.

    Concentration:mx-cdmxJaliscoNuevo Leónmx-mexSources: SAT, UIF, MCCI
  • Bank fraud↑ Rising
    Banking & card fraud (aggregate)
    $23B MXN / yr in reported losses+19% YoY 2023→2024

    Card cloning, online-banking fraud, SIM-swap take-overs, mule-account laundering. Tourist corridors (Cancún, Cabos, Puerto Vallarta) over-represented in skimmer reports. Real losses estimated 4-5× the reported figure due to under-reporting; CONDUSEF only sees disputes that go formal.

    Concentration:mx-cdmxmx-mexJaliscoNuevo LeónQuintana RooSources: CONDUSEF, Banxico, ABM
  • SIM-swap↑ Rising
    SIM-swap take-over fraud
    Hundreds of millions MXN / yr

    Spike after 2022 mobile-number portability changes loosened identity verification at carrier counters. Telcel, AT&T MX, and Movistar all named in CONDUSEF complaints. Bypasses SMS-based 2FA on banking, crypto exchanges, and social media.

    Concentration:mx-cdmxJaliscoNuevo LeónBaja CaliforniaSources: CONDUSEF, IFT
  • Card skimming→ Stable
    ATM / POS skimmer rings — tourist corridors
    Tens of millions USD/yr (industry estimate)100k+ tourist cards compromised / yr

    Cancún, Playa del Carmen, Cabo San Lucas, Puerto Vallarta. Operators were primarily Eastern European crews historically; now increasingly local cartel-aligned. Pump skimmers at PEMEX gas stations on Mex 200 / Mex 15 also a recurring theme.

    Concentration:Quintana Roomx-bcsJaliscoSources: Krebs on Security, Visa / Mastercard alerts
  • Crypto compound↑ Rising
    Pig-butchering crypto-compounds
    Estimated $1B+ USD/yr siphoned from US victims via MX-based ops

    Mexico is a destination for compounds operated by Asian-linked syndicates running 'sha zhu pan' (pig butchering) romance-investment scams against primarily US victims. Properties identified in Los Cabos, Riviera Maya, periphery of CDMX. Some operators reportedly trafficked in. Intersects with cartel real-estate fronts and protection rackets.

    Concentration:mx-bcsQuintana Roomx-mexSources: FBI IC3, Citizen Lab, Reuters
  • Regulatory vacuum↑ Rising
    Data-protection regulatory vacuum (post-INAI)
    Affects ~130M Mexican residents' PII

    Companion entry to the discrete INAI dissolution event. Private-sector breach disclosure / sanctioning vacuum lasting ≥ 6 months while transitional rules are drafted. International-investor attention via USMCA labor + privacy frameworks.

    Concentration:mx-cdmxSources: DOF, R3D, Article 19, Senado
  • CSAM hosting→ Stable
    CSAM hosting volume
    Top 5 global host (NCMEC reporting)

    Permissive hosting rules + weak enforcement put MX in NCMEC's top 5 globally for reported CSAM material. The FGR specialized cyber unit handles fewer than 100 prosecutions / yr against millions of NCMEC reports.

    Sources: NCMEC, INTERPOL

Incident list

Discrete known events — sorted by status (active / investigating / resolved) then date.

  • ActiveEnergyEspionage · Critical infra · Jun 01, 2024
    CFE — recurring intrusion attempts
    Target: CFE — Comisión Federal de Electricidad · Mexico City (corporate)

    Sustained intrusion attempts against CFE corporate and SCADA segments through 2024-2025. Attribution unclaimed; activity overlaps with patterns associated with state-sponsored APT campaigns reported by US allies.

  • ActiveRetail / SMBDigital extortion · Private · Apr 01, 2024
    CJNG digital-extortion campaign against Jalisco SMBs
    Target: Small/medium businesses in Jalisco · Attributed: CJNG cells · Guadalajara metro

    CJNG-affiliated operators using social media + leaked address data to dox business owners and demand piso payments via crypto wallets and OXXO Spin transfers. Reported pattern of doxing → physical visit if ignored.

  • ActiveDefenseData leak · Federal · Apr 15, 2023
    Continuing journalism mines the Guacamaya cache
    Target: SEDENA — derivative reporting from 2022 cache · Attributed: Guacamaya (original cache) · Aristegui / Latinus / Animal Político · Mexico City

    Major derivative stories surfaced from the original 6TB cache include: Encinas Pegasus targeting (Apr 2023), Cienfuegos US-MX coordination memos (Jun 2023), AMLO health files (Jan 2023), Ayotzinapa internal review notes (Sep 2023). The underlying breach is closed but each new round of reporting compounds the political damage.

  • ActiveOperatorMediaEspionage · Private · Jan 01, 2018
    SEDENA continues Pegasus operations against journalists / activists
    Target: Journalists, human-rights defenders, opposition officials · Attributed: SEDENA (NSO Group Pegasus) · Mexico City (operator)

    Citizen Lab, R3D and Article 19 documented SEDENA's continued procurement and deployment of NSO Group's Pegasus spyware after AMLO's 2018 commitment to halt federal use. Confirmed targets include Aristegui Noticias staff, deputy interior minister Alejandro Encinas (during the Ayotzinapa investigation), Centro Prodh attorneys, and US-MX-border journalists. Procurement contracts surfaced via the 2022 Guacamaya leak; subsequent infections detected as recently as 2024.

  • InvestigatingGovernmentRansomware · Municipal · Aug 22, 2024
    Cajeme (Ciudad Obregón) municipal ransomware
    Target: Ayuntamiento de Cajeme · Ciudad Obregón

    Cyberattack disrupted municipal payment portals, public-records lookup, and vehicle registration services for roughly two weeks. Mayor's office initially denied a ransom demand; subsequent disclosures suggested operational data was exfiltrated.

  • InvestigatingGovernmentEspionage · Federal · Oct 15, 2022
    SRE Foreign Ministry intrusion
    Target: SRE — Secretaría de Relaciones Exteriores · Mexico City

    Reported intrusion across multiple SRE servers, exposed in the wake of the Guacamaya leak. Scope includes consular data and bilateral diplomatic correspondence. Investigation ongoing; attribution unclaimed.

  • ResolvedGovernmentOther · Federal · Dec 20, 2024
    INAI dissolution — data-protection regulator absorbed by executive
    Target: INAI — Instituto Nacional de Transparencia · Mexico City

    Sheinbaum's 'austerity' constitutional reform formally dissolved the autonomous data-protection regulator (DOF Dec 2024) and absorbed its functions into the executive's anticorruption secretariat. LFPDPPP private-sector enforcement effectively paused; private breaches no longer have a primary regulator with sanctioning authority. R3D and Article 19 flag this as a structural cyber-risk multiplier.

  • ResolvedGovernmentRansomware · Municipal · Oct 04, 2024
    Caborca municipal services cyberattack
    Target: Ayuntamiento de Caborca · Caborca

    Municipal website and online services taken offline for approximately a week. Caborca is a notable target given its position in the Caborca Cartel war; intersection of cyber and physical extortion not ruled out.

  • ResolvedGovernmentDDoS · Federal · Apr 01, 2024
    INE election-period intrusion + DDoS waves
    Target: INE — Instituto Nacional Electoral · Mexico City

    Sustained intrusion attempts + DDoS during the June 2 2024 federal election cycle. INE confirmed nation-state-grade probes; PREP (preliminary results system) saw delayed availability windows attributed to traffic flooding. No confirmed breach of the voter-registration database; activity slowed but did not stop the count.

  • ResolvedGovernmentData leak · State · Mar 12, 2024
    Veracruz state government data leak
    Target: Gobierno del Estado de Veracruz · Xalapa

    State payroll, vendor contracts and citizen-service records exposed via a misconfigured admin portal. State-level cybersecurity unit took 9 days to confirm; opposition lawmakers requested federal audit.

  • ResolvedGovernmentData leak · Municipal · Feb 09, 2024
    Aguascalientes city government breach
    Target: Municipio de Aguascalientes · Aguascalientes

    Citizen-service portal compromised; PII of property-tax filers exposed. Brief website defacement preceded the data leak.

  • ResolvedGovernmentRansomware · State · Nov 20, 2023
    Nuevo León state-government incident
    Target: Gobierno del Estado de Nuevo León · Monterrey

    Ransomware deployment against multiple state agencies. Public services partially restored within 5 days from offline backups; ransom demand and payment status not disclosed.

  • ResolvedTelecomData leak · Private · Jul 19, 2023
    Telcel / América Móvil customer-data leak
    Target: América Móvil — Telcel · Mexico City

    Database leak surfaced on a clearnet forum claiming ~36M Telcel customer records. Telcel disputed scope; researchers verified at least several million entries with full names + tax IDs (RFC) + addresses.

  • ResolvedDefenseOther · Federal · Mar 15, 2023
    SEDENA CCESI cyber-command stands up post-Guacamaya
    Target: CCESI — Centro de Comando, Control, Comunicaciones, Cómputo e Inteligencia · Mexico City (Campo Militar 1)

    Defensive restructuring rather than an incident: SEDENA migrated off the vulnerable Zimbra email stack, stood up the CCESI cyber-command center, and centralized incident response under a unified J6/J2 structure. No public details on subsequent OPSEC posture; outside researchers (R3D, Article 19) still rate cyber-exposure as high.

  • ResolvedDefenseData leak · Federal · Sep 19, 2022
    Guacamaya leaks 6TB of SEDENA emails
    Target: SEDENA — Secretaría de la Defensa Nacional · Attributed: Guacamaya (hacktivist collective) · Mexico City

    Largest cyber leak ever against the Mexican state. ~6 TB / ~4M internal SEDENA emails published, part of a multi-country LatAm campaign that also hit Chile's Joint Chiefs, Peru's army, Colombia's national police, and El Salvador. Vector: unpatched Zimbra mail server (CVE-2022-27925, public PoC at the time). Contents exposed surveillance of journalists, AMLO's medical records, internal cartel-cooperation deliberations, friction with DEA/FBI on shared operations, and sicario rosters from cartel sources. Continues to fuel named-source journalism three-plus years later.

  • ResolvedTransportRansomware · Critical infra · Aug 10, 2022
    CDMX Metro service disruption — suspected ransomware
    Target: STC Metro (CDMX subway) · Mexico City

    Multi-day disruption to fare-card and operational systems. CDMX government attributed to a 'cyber incident' without formally confirming ransomware; multiple researchers identified IOCs consistent with Lockbit affiliate activity.

  • ResolvedGovernmentRansomware · Federal · May 29, 2020
    Lotería Nacional / Pronósticos hit by Avaddon
    Target: Lotería Nacional / Pronósticos para la Asistencia Pública · Attributed: Avaddon · Mexico City

    Ransom demand unpaid; Avaddon published ~50 GB of internal contracts, financial records and employee data on its leak portal. Drawings and operations continued via backup systems.

  • ResolvedEnergyRansomware · Critical infra · Nov 10, 2019
    Pemex hit by DoppelPaymer ransomware
    Target: Pemex — Petróleos Mexicanos · Attributed: DoppelPaymer · Mexico City (HQ)

    DoppelPaymer demanded ~$5M USD; Pemex refused. Approximately 5% of corporate IT systems affected, no impact on production. Highlighted gaps in MX critical-infrastructure cyber posture.

  • ResolvedGovernmentData leak · Federal · May 10, 2019
    SAT (tax authority) intermittent breaches
    Target: SAT — Servicio de Administración Tributaria · Mexico City

    Multiple low-grade incidents across 2019-2024: forum-leaked taxpayer records, phishing campaigns spoofing SAT notifications. No mass dump confirmed; cumulative exposure is significant.

  • ResolvedFinanceFraud · Critical infra · Apr 26, 2018
    Banxico SPEI interbank fraud
    Target: SPEI (Banxico interbank system) — multiple member banks · Attributed: Unknown (likely organized crime / insiders) · Mexico City

    Approximately 300M MXN (~$15M USD) drained via fraudulent SPEI transfer instructions injected through compromised connections at several member banks. Banxico imposed mandatory backup-link operating mode for all participating institutions.

By target sector

  • Government10
  • Defense3
  • Energy2
  • Media1
  • Finance1
  • Transport1
  • Retail / SMB1
  • Telecom1

By target level

  • federal8
  • Critical infrastructure4
  • state2
  • municipal3
  • private3
Compiled from press releases, BleepingComputer / KrebsOnSecurity / Reuters / AP wire reporting, Guacamaya and Avaddon leak portals, and CISA advisories through 2025. Lat/lon approximate (HQ or service area, not forensic). Cross-references with the security & trade pillars: USMCA tracker for trade + diplomatic friction, Groups for cartel-cyber overlap (CJNG digital extortion).