CiberLATAMbywhalemate
Intelligence reportJul 8, 202618 min read

Situación Nacional de Ciberseguridad - Junio 2026 - México

June ended with 41 incidents, 17 ransomware or extortion cases, and regulatory signals in Mexico, with pressure on finance

Situación Nacional de Ciberseguridad - Junio 2026 - MéxicowhalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are completed automatically with verified facts and sources from the period. They are the recurring reading month after month; the later analysis develops the cases without repeating this summary.

SECURITY TRIBUNE / WHALEMATE Verified Signal Monthly Dashboard June 2026 · Mexico DOCUMENTED INCIDENTS 41 incidents, breaches, or leaks with sources RANSOMWARE/EXTORTION 17 documented cases in the period CVE MENTIONS 7 CVE-2026-20127 / CVE-2026-20182 FRAUD/PHISHING 4 documented cases in the period REGULATORY MOVES 1 rules, penalties, or proposals DOMINANT THREAT Incidents 41 documented events
Verified Signal Monthly Dashboard — Fixed-period summary for Mexico.
MONTHLY FIXED MODULE Distribution by threat axis June 2026 · Mexico Incidents 41 Ransomware 17 Vulnerabilities 9 Fraud 4 Regulation 1
Distribution by threat axis — Heuristic classification of verified incidents by threat type.
MONTHLY FIXED MODULE Sectoral distribution of signal June 2026 · Mexico Public sector / OES 20 Finance 17 Telecom 12 Technology 11 Retail / consumer 8 Health 1
Sectoral distribution of signal — Heuristic classification of verified facts by affected or mentioned sector.
FIXED MONTHLY MODULE Critical infrastructure in Mexico Verified signal in public sector, finance, and essential services Public sector / government 19 Explicit critical infrastructure 1 Telecom / connectivity 3 Classified incidents 11
Critical infrastructure in Mexico — Verified signal in public sector, finance, and essential services

Executive monthly summary for Mexico

June 2026 sent a clear signal in Mexico, the month was dominated by documented incidents, with 41 verified events, and by sustained ransomware and extortion pressure, which accounted for 17 cases. The picture is not one of an isolated event, but of a broad attack surface, with visible impact across finance, telecom, manufacturing, the public sector, and technology providers.

The financial sector was the clearest area for measuring damage. Banxico reported eight cyber incidents at institutions in the financial system through May 2026, double the total for all of 2025, and also identified ransomware families such as LockBit and Qilin in specific events. The technical readout of those cases shows a mixed pattern, with attacks that affected transfers, electronic channels, and, in some cases, the extraction of information hosted by third parties.

The month also showed a second layer of exposure, involving personal data and credentials. There were leaks tied to the cellular line registry, databases allegedly linked to education agencies, state environments, and fraudulent domains used in campaigns connected to the 2026 World Cup. In parallel, Nissan Americas confirmed a breach stemming from exploitation of Oracle PeopleSoft that reached operations in Mexico, exposing employee and former employee data.

On the active exploitation front, alerts centered on Cisco Catalyst SD-WAN, PostgreSQL Sidecar, FortiSandbox, and Microsoft Defender. Smartekh documented active campaigns against government entities in Mexico and described exploitation or recent abuse evidence in several high-risk CVEs. The overall picture is one of high tactical pressure, with adversaries combining ransomware, data leaks, supply chain abuse, and rapid use of newly disclosed vulnerabilities.

Mexico Country Intelligence for the Month

Mexico’s risk reading for June 2026 is high. Volume is heavy and severity is too, because this is not just a matter of more events, but of events with real capacity to disrupt financial services, extract sensitive information, apply extortion pressure, and force regulatory or technical responses in critical sectors. The combination of 41 documented incidents, 17 ransomware or extortion cases, 4 fraud or phishing cases, and 7 critical CVEs mentioned points to a month of sustained exposure.

The dominant trend was operational incidents, not rumors or abstract campaigns. There was evidence of compromise in banks, an industrial paper company, telecommunications, public agencies, and vendor environments. That suggests adversaries are still finding weak points both at the technology edge and inside systems that depend on third parties. The fact that 82 percent of the events have direct source confirmation reinforces the strength of the signal, although the available material also includes some uncertain references that require separating verified facts from claims that are not fully corroborated.

Mexico also faced an incomplete regulatory debate. Infobae reported that the country still lacks a fully implemented General Cybersecurity Law and a National CSIRT with robust capabilities, while the Executive Branch advanced a General Cybersecurity Policy for the Federal Public Administration. Added to that was the CRT requirement to link mobile phone lines to the CURP before June 30, a measure that affects digital identity and authentication processes in mass-market services.

In the regional context, the Mexican case ranks among the most active in Latin America for volume of pressure and for recurring ransomware. The country appears in journalistic and technical reports as one of the most targeted environments in the region, with a mix of opportunistic attacks, prepared campaigns, and exploitation of vulnerabilities in widely used components.

Mexico period indicators

Indicator Value
Documented incidents 41
Documented ransomware or extortion cases 17
Documented fraud or phishing cases 4
Documented regulatory moves 1
Critical CVEs mentioned 7
Sectors with at least one documented event 6
Dominant threat of the month Incidents (41 events)
Events with direct source confirmation 82%

Relevant Incidents in Mexico

Banxico and the Mexican Financial System

Banxico updated its technical report on cyber incidents in Mexico’s financial system in 2026, providing a concrete reference point for tracking how the problem has evolved. As of June 10, the central bank had documented eight incidents at financial institutions between January and May. Half of those cases involved two named ransomware strains, LockBit and Qilin, while the rest pointed to breaches affecting transfer services, electronic channels, or third-party applications.

The value of the report is not just the tally. It is also in the breakdown. The first event, in January, affected electronic transfers at a bank and was contained without losses. The second, in February, compromised channels and interbank payments and led to a loss of about 91.7 million pesos for the institution. In March and April, incidents appeared at a SOCAP and a Sofipo, confirming that pressure was not limited to traditional banking. In May, Banxico added a case at an IFPE and another bank with data exfiltrated from third parties, without affecting financial operations.

The technical reading is that the critical surface shifted between ransomware, third parties, and transaction services. There was no single dominant vector. There was a sequence of opportunities exploited by different actors or malware families, and that diversity makes response harder because it requires continuity controls, vendor monitoring, and channel integrity oversight. At the same time, public debate hardened around risks to transfers, payments, and digital services.

Mobile Phone Data Leak and Pressure on the CURP Registry

June also brought signs of mass exposure in the mobile telecom ecosystem. Infobae México reported that a leak attributed to hackers exposed data from 45,804 mobile users in Mexico, including names, phone numbers, and RFC. Coverage placed most of the case in Chiapas. Moncloa, meanwhile, reported about 45,000 records from the mobile subscriber registry, with Movistar affected and a connection to PANAUT.

The regulatory backdrop was immediate. The CRT reiterated that mobile lines had to be linked to a CURP by June 30, or they would be blocked. DPL News said that as of June 12, 59.167 million lines were linked out of 144 million total, leaving about 85 million still unregistered. In that climate, the leak gained operational relevance because a subscriber database intersects with authentication, account recovery, and commercial processes.

The episode was not isolated. At the same time, audiovisual and journalistic material circulated about a broader alleged leak of records tied to the same ecosystem, although some of that information was presented cautiously or as a theory about intermediaries. For the purposes of this report, the verifiable point is the confirmed exposure of tens of thousands of users and the fragility of the line registration scheme.

Copamex and DragonForce’s Public Threat

On June 3, DragonForce claimed to have attacked Copamex, described as a leading paper manufacturer in Mexico. The group threatened to publish sensitive data if its demands were not met. The source places the case in the industrial sector, specifically paper and manufacturing.

There is no independent confirmation in the available material of operational impact, but there is a public statement from the gang and an explicit threat to leak data. That format matters because it shows the pressure playbook, first the claim of compromise, then the warning of publication, then possible negotiation. In risk terms, Copamex falls into the same set of June cases where extortion and publicization of the attack are central parts of the harm.

Ford de Mexico and Krybit’s Pressure

On June 28, Krybit claimed to have compromised Ford Motor Company, S.A. de C.V., meaning Ford de Mexico. DeXpose logged the claim and the threat to publish sensitive information if there was no negotiation. A later analysis, on June 30, said the company had not publicly confirmed any breach and that the alleged volume and nature of the data remained unverified independently.

That leaves two separate tracks. On one, the threat actor claims intrusion and uses it as leverage. On the other, there is not enough public confirmation to treat the case as a validated breach. Even so, the episode belongs to the broader set of 17 ransomware or extortion cases documented in the month, because the threat of leaking data is already part of the coercive pattern observed in Mexico.

Nissan Americas and the Cross-Border Impact of Oracle PeopleSoft

Nissan Americas reported a breach tied to exploitation of CVE-2026-35273 in Oracle PeopleSoft. The scope included operations in the United States, Canada, Mexico, and Brazil, with exposure of employee and former employee data, including names, banking details, financial and tax files, and national identifiers. Devel Group specified that the official notice was issued on June 25.

Although the intrusion is not limited to Mexico, it directly affects personnel and processes in the country. The case matters for two reasons. First, it involves widely deployed enterprise software. Second, it exposed data that can support fraud, impersonation, or later social engineering campaigns. Operationally, it is a high-value breach for actors who monetize identity and credentials.

Campaigns Against Government and Vulnerability Exploitation

Smartekh reported active campaigns against government entities in Mexico and pointed to active exploitation of CVE-2026-20262 in Cisco Catalyst SD-WAN Manager. Cisco’s advisory also included CVE-2026-20245 and described prior exploitation paths in other vulnerabilities in the same platform. The report also mentioned limited exploitation of CVE-2026-20253 in PostgreSQL Sidecar and proof-of-concept testing for CVE-2026-50656, RoguePlanet, in Microsoft Defender.

The significance here is not just the CVE list. It is the context in which they are being used. There is campaign activity, observed exploitation, and interest in systems that can serve as pivot points inside administrative networks. The detail carries weight because it points to government and to digital infrastructure used in environments with sensitive operational continuity.

Brief Timeline of High-Impact Events

Date Event Sector Type
June 3, 2026 DragonForce claims attack on Copamex Industrial, manufacturing Ransomware/extortion
June 10, 2026 Banxico updates eight financial incidents Financial Incidents and ransomware
June 11, 2026 Cisco publishes Catalyst SD-WAN advisory Technology, government Critical vulnerability
June 18, 2026 Radio Fórmula reports 237,000 ransomware attempts General Ransomware
June 22, 2026 Mobile phone data leak Telecommunications Data breach
June 23, 2026 Smartekh describes active campaigns against government Government, technology Active exploitation
June 28, 2026 Krybit claims Ford de Mexico Automotive Ransomware/extortion
June 30, 2026 Nissan Americas confirms breach via Oracle PeopleSoft Automotive, HR Data breach

Threats and active campaigns in Mexico

Ransomware and extortion

The month was clearly dominated by ransomware and extortion, with 17 documented cases. The most visible pattern was groups announcing the intrusion, threatening to leak data, and setting negotiation deadlines. DragonForce and Krybit were the clearest examples in this period, both with victims in Mexico and both warning they would publish information if there was no deal.

Banxico adds another, more structural layer. In its financial incidents, LockBit and Qilin appear, two high-impact names in the region and in Mexico. LockBit also appears in cumulative analyses as the most active actor against Mexican entities so far this decade. That signal is significant because it connects the month’s immediate incidents with a longer-term trend.

Group / actor Victim or sector Evidence this month Documented impact
DragonForce Copamex Claim and leak threat No public confirmation of damage
Krybit Ford de México Claim and publication threat No independent verification of the leak
LockBit Financial system Identified by Banxico Contained without losses in one case
Qilin Financial system Identified by Banxico Loss of 91.7 million in one case

Fraud and phishing

There were 4 documented fraud or phishing cases. The most visible block was tied to 2026 World Cup campaigns, where Cronup reported more than 4,300 fraudulent domains related to FIFA since August 2025 as part of Ghost Stadium. The domains cited in the material show a classic impersonation tactic, with names designed to capture credentials or mislead users.

The World Cup also served as a cross-cutting lure. Onesec warned about fake sites and insecure Wi-Fi networks used to infect devices and steal corporate credentials. The risk does not stop with fans, because the end goal is to use access obtained through sports-themed bait to compromise Mexican organizations. It is an example of how a fraud campaign can become a way into enterprise networks.

APT, hacktivism, and opportunistic campaigns

There is no solid attribution to a classic APT in the available material, but there are opportunistic campaigns and actions with a hacktivist or public-pressure component. The Copamex case combines extortion with a threat of exposure. The report on Guanajuato, although uncertain, illustrates the use of criminal narrative to locate police officers. And the activity against government described by Smartekh suggests continued interest in agencies with exposed technology.

Pressure on Mexico in June did not depend on a single malware family or a single motive. There was extortion, credential theft, software exploitation, data leakage, and, in some cases, publicizing the intrusion as part of the harm. That makes campaign-level classification more useful than counting isolated events.

Concentración temática de señal verificada en MéxicoBarras con los indicadores del período para México en junio de 2026.Mexico, June 2026Indicators from the periodIncidents 41Ransomware 17Fraud 4Regulation 1CVE 74117417

Verified signal topic concentration in Mexico — Simple comparison of the main documented trends for the month.

Critical vulnerabilities with impact in Mexico

CVE Software Exploitation Source
CVE-2026-20262 Cisco Catalyst SD-WAN Manager Active exploitation confirmed by Cisco Cisco, Smartekh
CVE-2026-20245 Cisco Catalyst SD-WAN Privilege escalation, required netadmin Cisco
CVE-2026-20253 PostgreSQL Sidecar Limited exploitation observed Splunk, Smartekh
CVE-2026-50656 Microsoft Defender Public PoC, escalation to SYSTEM Smartekh
CVE-2026-35273 Oracle PeopleSoft Exploitation in the Nissan Americas breach Cyber Defense Magazine, Devel Group
CVE-2026-20182 Cisco Catalyst SD-WAN Prior path to obtain credentials Cisco
CVE-2026-20127 Cisco Catalyst SD-WAN Prior path to obtain credentials Cisco

These seven CVEs matter for two reasons. First, several already show active or limited observed exploitation. Second, the impact in Mexico is not theoretical, it is reflected in campaigns, third-party breaches and mitigation advisories affecting government networks and companies with a regional footprint.

Regulation and compliance in Mexico

June brought a clear regulatory shift, but the broader framework remains incomplete. The executive branch published the General Cybersecurity Policy for the Federal Public Administration as the guiding instrument following the launch of the National Cybersecurity Plan. At the same time, the available material stresses that the plan is still in an early phase and that advanced monitoring, response, and national coordination capabilities are not expected until 2027 or 2028.

Infobae also reported that Mexico still does not have a fully developed General Cybersecurity Law before Congress, one that would set clear obligations, oversight, and penalties for failing to meet minimum standards. That legal gap exists alongside a hard operational reality, where the state and regulated sectors have to respond to incidents before the legal structure is fully in place.

In telecommunications, the CRT added pressure with a mandatory registry for mobile lines linked to CURP. The measure had a strong compliance impact because, as of June 12, a large share of lines remained unregistered. At the same time, discussion of SOCAPs and 24/7 monitoring appeared in commercial and compliance material, although no additional verifiable regulatory event was included in the source list. For this report, the only regulatory move counted as such is the CRT requirement to register lines.

Most affected sectors in Mexico

The financial sector was hit hardest, both in volume and in the quality of the signal. Banxico documented eight incidents through May, with events affecting banks, a SOCAP, a Sofipo and an IFPE. That points to broad pressure on institutions with different operating models, but the same risk of disruption to transfers and digital channels. The loss of 91.7 million in a February case marks a threshold that cannot be dismissed as statistical noise.

Telecommunications was the second focus, not because of the total number of confirmed incidents, but because of data exposure and the regulatory weight of line registration. Leaks involving mobile phone users, the reference to Movistar and the requirement to link service to CURP put this sector at the center of the digital identity debate. Mobile lines are also a critical piece for two-factor authentication, account recovery and transaction validation.

Government and public administration appeared in both concrete incidents and active campaigns. Mentions of leaks involving IMSS, SAT, UNAM, the Ministry of Health, Civil Protection and state platforms, while reported as part of a broader review and with uncertain attribution, reinforce the sense of constant pressure on public-sector environments. Smartekh also described activity against government entities during the month.

Industry and manufacturing were exposed as well, with Copamex as the most visible case. Automotive entered the picture through Nissan Americas and Ford de México. Education and services tied to data registration were also affected by references to databases allegedly linked to USICAMM and material on admissions processes, although some of those references did not meet the threshold for independent confirmation and therefore cannot be treated as hard facts. In total, six sectors had at least one documented event, and the sector spread confirms the risk was not limited to a single vertical.

Sector Documented event Signal level
Financial Eight incidents reported by Banxico High
Telecommunications Leak of 45,000 records and CURP requirement High
Government Active campaigns and leak mentions High
Industry, manufacturing Claimed attack on Copamex Medium
Automotive Nissan breach and claim against Ford de México High
Education Mentions of USICAMM and related processes Medium

There is no month-over-month baseline, because this is the first archived period with this indicator format for Mexico. For that reason, it would be wrong to invent an intermonthly trend. A broader direction can still be read within the month itself.

The first signal to watch is ransomware’s continued role as the main form of pressure. This is not just about encryption, but about extortion with possible data leaks, amplified by actors who publish victim lists and negotiation deadlines. The second signal is the convergence between credential fraud and high-profile public events, such as the 2026 World Cup. Fake domains and lure sites will remain useful for harvesting logins that are later sold or reused.

The third signal is exposure in enterprise software and remote administration infrastructure. Cisco, Splunk, Microsoft and Oracle appear in the material as components with real or potential impact in Mexico. When a critical vulnerability combines with active campaigns and abuse in government or corporate environments, response time shrinks. The fourth signal is third-party dependence, visible in the financial system and in data leak cases.

Security guidance for Mexico teams

  1. Prioritize access containment and segmentation in transfer services, especially in financial institutions and core banking providers.
  2. Review third-party exposure and delegated applications, with an inventory of dependencies that could affect electronic channels, payments, or authentication.
  3. Urgently patch the components named this month, with focus on Cisco Catalyst SD-WAN, Oracle PeopleSoft, PostgreSQL Sidecar, Microsoft Defender and FortiSandbox where applicable.
  4. Strengthen monitoring for stolen credentials, password reuse, and phishing campaigns tied to World Cup 2026 or known brands.
  5. Validate response plans for extortion threats involving data leaks, because reputational and operational damage was already part of the month.
  6. In telecom and mass services, review signup, registration and identity verification flows, because subscriber exposure affects fraud and impersonation.
  7. In government and the public sector, harden administrative access controls and log oversight on platforms exposed to active exploitation.

Material limitations

This report was built exclusively from the material provided, with no internet access. The factual body includes sources with different levels of confirmation, and in several cases the material itself flags uncertainty or claims that were not independently verified. When a story did not offer direct confirmation, it was treated as contextual signal rather than hard fact.

There is also no comparable baseline for the previous month in this format, so no month-over-month change was included. The sector analysis and risk readout are based on the documented facts from June 2026 and their editorial consolidation, without extrapolating figures beyond the supplied corpus.

The domains, CVEs, amounts, and groups mentioned correspond only to what the listed sources allowed to verify. No additional IoCs or external investigative elements not contained in the base material were added.

Sources