Situación Nacional de Ciberseguridad - Junio 2026 - México
June ended with 41 incidents, 17 ransomware or extortion cases, and regulatory signals in Mexico, with pressure on finance
Key findings
- The month was dominated by documented incidents, with 41 events and a high risk reading due to volume and severity.
- The financial system showed the strongest signal, with eight incidents reported by Banxico and the presence of LockBit and Qilin.
- Ransomware and extortion remained the main threat, with 17 cases and several public claims of data leaks.
- Telecommunications came under pressure from the leak of user data and the requirement to register lines with CURP.
- There was active or limited exploitation of several critical CVEs in widely used software, with potential impact on government and companies.
- Mexico still lacked a fully consolidated cybersecurity legal framework, although it did advance a policy for the public administration.
- The combination of third parties, credentials, and transactional services continued to appear as the most repeated weak point.
Monthly reference modules
These modules are completed automatically with verified facts and sources from the period. They are the recurring reading month after month; the later analysis develops the cases without repeating this summary.
Executive monthly summary for Mexico
June 2026 sent a clear signal in Mexico, the month was dominated by documented incidents, with 41 verified events, and by sustained ransomware and extortion pressure, which accounted for 17 cases. The picture is not one of an isolated event, but of a broad attack surface, with visible impact across finance, telecom, manufacturing, the public sector, and technology providers.
The financial sector was the clearest area for measuring damage. Banxico reported eight cyber incidents at institutions in the financial system through May 2026, double the total for all of 2025, and also identified ransomware families such as LockBit and Qilin in specific events. The technical readout of those cases shows a mixed pattern, with attacks that affected transfers, electronic channels, and, in some cases, the extraction of information hosted by third parties.
The month also showed a second layer of exposure, involving personal data and credentials. There were leaks tied to the cellular line registry, databases allegedly linked to education agencies, state environments, and fraudulent domains used in campaigns connected to the 2026 World Cup. In parallel, Nissan Americas confirmed a breach stemming from exploitation of Oracle PeopleSoft that reached operations in Mexico, exposing employee and former employee data.
On the active exploitation front, alerts centered on Cisco Catalyst SD-WAN, PostgreSQL Sidecar, FortiSandbox, and Microsoft Defender. Smartekh documented active campaigns against government entities in Mexico and described exploitation or recent abuse evidence in several high-risk CVEs. The overall picture is one of high tactical pressure, with adversaries combining ransomware, data leaks, supply chain abuse, and rapid use of newly disclosed vulnerabilities.
Mexico Country Intelligence for the Month
Mexico’s risk reading for June 2026 is high. Volume is heavy and severity is too, because this is not just a matter of more events, but of events with real capacity to disrupt financial services, extract sensitive information, apply extortion pressure, and force regulatory or technical responses in critical sectors. The combination of 41 documented incidents, 17 ransomware or extortion cases, 4 fraud or phishing cases, and 7 critical CVEs mentioned points to a month of sustained exposure.
The dominant trend was operational incidents, not rumors or abstract campaigns. There was evidence of compromise in banks, an industrial paper company, telecommunications, public agencies, and vendor environments. That suggests adversaries are still finding weak points both at the technology edge and inside systems that depend on third parties. The fact that 82 percent of the events have direct source confirmation reinforces the strength of the signal, although the available material also includes some uncertain references that require separating verified facts from claims that are not fully corroborated.
Mexico also faced an incomplete regulatory debate. Infobae reported that the country still lacks a fully implemented General Cybersecurity Law and a National CSIRT with robust capabilities, while the Executive Branch advanced a General Cybersecurity Policy for the Federal Public Administration. Added to that was the CRT requirement to link mobile phone lines to the CURP before June 30, a measure that affects digital identity and authentication processes in mass-market services.
In the regional context, the Mexican case ranks among the most active in Latin America for volume of pressure and for recurring ransomware. The country appears in journalistic and technical reports as one of the most targeted environments in the region, with a mix of opportunistic attacks, prepared campaigns, and exploitation of vulnerabilities in widely used components.
Mexico period indicators
| Indicator | Value |
|---|---|
| Documented incidents | 41 |
| Documented ransomware or extortion cases | 17 |
| Documented fraud or phishing cases | 4 |
| Documented regulatory moves | 1 |
| Critical CVEs mentioned | 7 |
| Sectors with at least one documented event | 6 |
| Dominant threat of the month | Incidents (41 events) |
| Events with direct source confirmation | 82% |
Relevant Incidents in Mexico
Banxico and the Mexican Financial System
Banxico updated its technical report on cyber incidents in Mexico’s financial system in 2026, providing a concrete reference point for tracking how the problem has evolved. As of June 10, the central bank had documented eight incidents at financial institutions between January and May. Half of those cases involved two named ransomware strains, LockBit and Qilin, while the rest pointed to breaches affecting transfer services, electronic channels, or third-party applications.
The value of the report is not just the tally. It is also in the breakdown. The first event, in January, affected electronic transfers at a bank and was contained without losses. The second, in February, compromised channels and interbank payments and led to a loss of about 91.7 million pesos for the institution. In March and April, incidents appeared at a SOCAP and a Sofipo, confirming that pressure was not limited to traditional banking. In May, Banxico added a case at an IFPE and another bank with data exfiltrated from third parties, without affecting financial operations.
The technical reading is that the critical surface shifted between ransomware, third parties, and transaction services. There was no single dominant vector. There was a sequence of opportunities exploited by different actors or malware families, and that diversity makes response harder because it requires continuity controls, vendor monitoring, and channel integrity oversight. At the same time, public debate hardened around risks to transfers, payments, and digital services.
Mobile Phone Data Leak and Pressure on the CURP Registry
June also brought signs of mass exposure in the mobile telecom ecosystem. Infobae México reported that a leak attributed to hackers exposed data from 45,804 mobile users in Mexico, including names, phone numbers, and RFC. Coverage placed most of the case in Chiapas. Moncloa, meanwhile, reported about 45,000 records from the mobile subscriber registry, with Movistar affected and a connection to PANAUT.
The regulatory backdrop was immediate. The CRT reiterated that mobile lines had to be linked to a CURP by June 30, or they would be blocked. DPL News said that as of June 12, 59.167 million lines were linked out of 144 million total, leaving about 85 million still unregistered. In that climate, the leak gained operational relevance because a subscriber database intersects with authentication, account recovery, and commercial processes.
The episode was not isolated. At the same time, audiovisual and journalistic material circulated about a broader alleged leak of records tied to the same ecosystem, although some of that information was presented cautiously or as a theory about intermediaries. For the purposes of this report, the verifiable point is the confirmed exposure of tens of thousands of users and the fragility of the line registration scheme.
Copamex and DragonForce’s Public Threat
On June 3, DragonForce claimed to have attacked Copamex, described as a leading paper manufacturer in Mexico. The group threatened to publish sensitive data if its demands were not met. The source places the case in the industrial sector, specifically paper and manufacturing.
There is no independent confirmation in the available material of operational impact, but there is a public statement from the gang and an explicit threat to leak data. That format matters because it shows the pressure playbook, first the claim of compromise, then the warning of publication, then possible negotiation. In risk terms, Copamex falls into the same set of June cases where extortion and publicization of the attack are central parts of the harm.
Ford de Mexico and Krybit’s Pressure
On June 28, Krybit claimed to have compromised Ford Motor Company, S.A. de C.V., meaning Ford de Mexico. DeXpose logged the claim and the threat to publish sensitive information if there was no negotiation. A later analysis, on June 30, said the company had not publicly confirmed any breach and that the alleged volume and nature of the data remained unverified independently.
That leaves two separate tracks. On one, the threat actor claims intrusion and uses it as leverage. On the other, there is not enough public confirmation to treat the case as a validated breach. Even so, the episode belongs to the broader set of 17 ransomware or extortion cases documented in the month, because the threat of leaking data is already part of the coercive pattern observed in Mexico.
Nissan Americas and the Cross-Border Impact of Oracle PeopleSoft
Nissan Americas reported a breach tied to exploitation of CVE-2026-35273 in Oracle PeopleSoft. The scope included operations in the United States, Canada, Mexico, and Brazil, with exposure of employee and former employee data, including names, banking details, financial and tax files, and national identifiers. Devel Group specified that the official notice was issued on June 25.
Although the intrusion is not limited to Mexico, it directly affects personnel and processes in the country. The case matters for two reasons. First, it involves widely deployed enterprise software. Second, it exposed data that can support fraud, impersonation, or later social engineering campaigns. Operationally, it is a high-value breach for actors who monetize identity and credentials.
Campaigns Against Government and Vulnerability Exploitation
Smartekh reported active campaigns against government entities in Mexico and pointed to active exploitation of CVE-2026-20262 in Cisco Catalyst SD-WAN Manager. Cisco’s advisory also included CVE-2026-20245 and described prior exploitation paths in other vulnerabilities in the same platform. The report also mentioned limited exploitation of CVE-2026-20253 in PostgreSQL Sidecar and proof-of-concept testing for CVE-2026-50656, RoguePlanet, in Microsoft Defender.
The significance here is not just the CVE list. It is the context in which they are being used. There is campaign activity, observed exploitation, and interest in systems that can serve as pivot points inside administrative networks. The detail carries weight because it points to government and to digital infrastructure used in environments with sensitive operational continuity.
Brief Timeline of High-Impact Events
| Date | Event | Sector | Type |
|---|---|---|---|
| June 3, 2026 | DragonForce claims attack on Copamex | Industrial, manufacturing | Ransomware/extortion |
| June 10, 2026 | Banxico updates eight financial incidents | Financial | Incidents and ransomware |
| June 11, 2026 | Cisco publishes Catalyst SD-WAN advisory | Technology, government | Critical vulnerability |
| June 18, 2026 | Radio Fórmula reports 237,000 ransomware attempts | General | Ransomware |
| June 22, 2026 | Mobile phone data leak | Telecommunications | Data breach |
| June 23, 2026 | Smartekh describes active campaigns against government | Government, technology | Active exploitation |
| June 28, 2026 | Krybit claims Ford de Mexico | Automotive | Ransomware/extortion |
| June 30, 2026 | Nissan Americas confirms breach via Oracle PeopleSoft | Automotive, HR | Data breach |
Threats and active campaigns in Mexico
Ransomware and extortion
The month was clearly dominated by ransomware and extortion, with 17 documented cases. The most visible pattern was groups announcing the intrusion, threatening to leak data, and setting negotiation deadlines. DragonForce and Krybit were the clearest examples in this period, both with victims in Mexico and both warning they would publish information if there was no deal.
Banxico adds another, more structural layer. In its financial incidents, LockBit and Qilin appear, two high-impact names in the region and in Mexico. LockBit also appears in cumulative analyses as the most active actor against Mexican entities so far this decade. That signal is significant because it connects the month’s immediate incidents with a longer-term trend.
| Group / actor | Victim or sector | Evidence this month | Documented impact |
|---|---|---|---|
| DragonForce | Copamex | Claim and leak threat | No public confirmation of damage |
| Krybit | Ford de México | Claim and publication threat | No independent verification of the leak |
| LockBit | Financial system | Identified by Banxico | Contained without losses in one case |
| Qilin | Financial system | Identified by Banxico | Loss of 91.7 million in one case |
Fraud and phishing
There were 4 documented fraud or phishing cases. The most visible block was tied to 2026 World Cup campaigns, where Cronup reported more than 4,300 fraudulent domains related to FIFA since August 2025 as part of Ghost Stadium. The domains cited in the material show a classic impersonation tactic, with names designed to capture credentials or mislead users.
The World Cup also served as a cross-cutting lure. Onesec warned about fake sites and insecure Wi-Fi networks used to infect devices and steal corporate credentials. The risk does not stop with fans, because the end goal is to use access obtained through sports-themed bait to compromise Mexican organizations. It is an example of how a fraud campaign can become a way into enterprise networks.
APT, hacktivism, and opportunistic campaigns
There is no solid attribution to a classic APT in the available material, but there are opportunistic campaigns and actions with a hacktivist or public-pressure component. The Copamex case combines extortion with a threat of exposure. The report on Guanajuato, although uncertain, illustrates the use of criminal narrative to locate police officers. And the activity against government described by Smartekh suggests continued interest in agencies with exposed technology.
Pressure on Mexico in June did not depend on a single malware family or a single motive. There was extortion, credential theft, software exploitation, data leakage, and, in some cases, publicizing the intrusion as part of the harm. That makes campaign-level classification more useful than counting isolated events.
Critical vulnerabilities with impact in Mexico
| CVE | Software | Exploitation | Source |
|---|---|---|---|
| CVE-2026-20262 | Cisco Catalyst SD-WAN Manager | Active exploitation confirmed by Cisco | Cisco, Smartekh |
| CVE-2026-20245 | Cisco Catalyst SD-WAN | Privilege escalation, required netadmin | Cisco |
| CVE-2026-20253 | PostgreSQL Sidecar | Limited exploitation observed | Splunk, Smartekh |
| CVE-2026-50656 | Microsoft Defender | Public PoC, escalation to SYSTEM | Smartekh |
| CVE-2026-35273 | Oracle PeopleSoft | Exploitation in the Nissan Americas breach | Cyber Defense Magazine, Devel Group |
| CVE-2026-20182 | Cisco Catalyst SD-WAN | Prior path to obtain credentials | Cisco |
| CVE-2026-20127 | Cisco Catalyst SD-WAN | Prior path to obtain credentials | Cisco |
These seven CVEs matter for two reasons. First, several already show active or limited observed exploitation. Second, the impact in Mexico is not theoretical, it is reflected in campaigns, third-party breaches and mitigation advisories affecting government networks and companies with a regional footprint.
Regulation and compliance in Mexico
June brought a clear regulatory shift, but the broader framework remains incomplete. The executive branch published the General Cybersecurity Policy for the Federal Public Administration as the guiding instrument following the launch of the National Cybersecurity Plan. At the same time, the available material stresses that the plan is still in an early phase and that advanced monitoring, response, and national coordination capabilities are not expected until 2027 or 2028.
Infobae also reported that Mexico still does not have a fully developed General Cybersecurity Law before Congress, one that would set clear obligations, oversight, and penalties for failing to meet minimum standards. That legal gap exists alongside a hard operational reality, where the state and regulated sectors have to respond to incidents before the legal structure is fully in place.
In telecommunications, the CRT added pressure with a mandatory registry for mobile lines linked to CURP. The measure had a strong compliance impact because, as of June 12, a large share of lines remained unregistered. At the same time, discussion of SOCAPs and 24/7 monitoring appeared in commercial and compliance material, although no additional verifiable regulatory event was included in the source list. For this report, the only regulatory move counted as such is the CRT requirement to register lines.
Most affected sectors in Mexico
The financial sector was hit hardest, both in volume and in the quality of the signal. Banxico documented eight incidents through May, with events affecting banks, a SOCAP, a Sofipo and an IFPE. That points to broad pressure on institutions with different operating models, but the same risk of disruption to transfers and digital channels. The loss of 91.7 million in a February case marks a threshold that cannot be dismissed as statistical noise.
Telecommunications was the second focus, not because of the total number of confirmed incidents, but because of data exposure and the regulatory weight of line registration. Leaks involving mobile phone users, the reference to Movistar and the requirement to link service to CURP put this sector at the center of the digital identity debate. Mobile lines are also a critical piece for two-factor authentication, account recovery and transaction validation.
Government and public administration appeared in both concrete incidents and active campaigns. Mentions of leaks involving IMSS, SAT, UNAM, the Ministry of Health, Civil Protection and state platforms, while reported as part of a broader review and with uncertain attribution, reinforce the sense of constant pressure on public-sector environments. Smartekh also described activity against government entities during the month.
Industry and manufacturing were exposed as well, with Copamex as the most visible case. Automotive entered the picture through Nissan Americas and Ford de México. Education and services tied to data registration were also affected by references to databases allegedly linked to USICAMM and material on admissions processes, although some of those references did not meet the threshold for independent confirmation and therefore cannot be treated as hard facts. In total, six sectors had at least one documented event, and the sector spread confirms the risk was not limited to a single vertical.
| Sector | Documented event | Signal level |
|---|---|---|
| Financial | Eight incidents reported by Banxico | High |
| Telecommunications | Leak of 45,000 records and CURP requirement | High |
| Government | Active campaigns and leak mentions | High |
| Industry, manufacturing | Claimed attack on Copamex | Medium |
| Automotive | Nissan breach and claim against Ford de México | High |
| Education | Mentions of USICAMM and related processes | Medium |
Trends and signals to watch in Mexico
There is no month-over-month baseline, because this is the first archived period with this indicator format for Mexico. For that reason, it would be wrong to invent an intermonthly trend. A broader direction can still be read within the month itself.
The first signal to watch is ransomware’s continued role as the main form of pressure. This is not just about encryption, but about extortion with possible data leaks, amplified by actors who publish victim lists and negotiation deadlines. The second signal is the convergence between credential fraud and high-profile public events, such as the 2026 World Cup. Fake domains and lure sites will remain useful for harvesting logins that are later sold or reused.
The third signal is exposure in enterprise software and remote administration infrastructure. Cisco, Splunk, Microsoft and Oracle appear in the material as components with real or potential impact in Mexico. When a critical vulnerability combines with active campaigns and abuse in government or corporate environments, response time shrinks. The fourth signal is third-party dependence, visible in the financial system and in data leak cases.
Security guidance for Mexico teams
- Prioritize access containment and segmentation in transfer services, especially in financial institutions and core banking providers.
- Review third-party exposure and delegated applications, with an inventory of dependencies that could affect electronic channels, payments, or authentication.
- Urgently patch the components named this month, with focus on Cisco Catalyst SD-WAN, Oracle PeopleSoft, PostgreSQL Sidecar, Microsoft Defender and FortiSandbox where applicable.
- Strengthen monitoring for stolen credentials, password reuse, and phishing campaigns tied to World Cup 2026 or known brands.
- Validate response plans for extortion threats involving data leaks, because reputational and operational damage was already part of the month.
- In telecom and mass services, review signup, registration and identity verification flows, because subscriber exposure affects fraud and impersonation.
- In government and the public sector, harden administrative access controls and log oversight on platforms exposed to active exploitation.
Material limitations
This report was built exclusively from the material provided, with no internet access. The factual body includes sources with different levels of confirmation, and in several cases the material itself flags uncertainty or claims that were not independently verified. When a story did not offer direct confirmation, it was treated as contextual signal rather than hard fact.
There is also no comparable baseline for the previous month in this format, so no month-over-month change was included. The sector analysis and risk readout are based on the documented facts from June 2026 and their editorial consolidation, without extrapolating figures beyond the supplied corpus.
The domains, CVEs, amounts, and groups mentioned correspond only to what the listed sources allowed to verify. No additional IoCs or external investigative elements not contained in the base material were added.
Sources
- ¿Avanza realmente la ciberseguridad en México? Seis meses después del anuncio la protección a la ciudadanía sigue en el papelInfobae
- México recibe 237 mil ataques ransomware y prende alertas sobre ciberseguridadRadio Fórmula
- Banxico reporta aumento de ciberataques contra instituciones financieras en México durante 2026 y advierte riesgos para transferencias, pagos y servicios digitalesEl Imparcial
- Ciberseguridad en México 2026 es un desafío para la regiónReseller
- Incidentes cibernéticos ocurridos en 2026 en el sistema financiero nacionalBanco de México
- Se reportaron ocho incidentes cibernéticos en lo que va del 2026El Economista
- Se duplican incidentes cibernéticos en instituciones financieras en 2026, según BanxicoImagen Radio
- Ocho ataques en cinco meses: el sistema financiero mexicano bajo asedio digitalCiberconciencia Digital
- México: triple marco de cumplimiento digital con Veeam24xsiempre
- Copa Del Mundo 2026: El Desafío En Ciberseguridad Ya ComenzóCronup
- Evaluating Mexico's New Cybersecurity PlanRecorded Future
- DragonForce Targets Mexican Paper Giant CopamexDeXpose
- Radar CTI | México en la mira: campañas activas contra gobierno ...Smartekh
- Copilot y LiteLLM: 2 vulnerabilidades críticas en junio 2026Ecosistema Startup
- Feed De Noticias De Ciberseguridad [03/06/2026]CronUp
- Patch Tuesday de junio de 2026 - SplashtopSplashtop
- Krybit Ransomware Targets Ford de Mexico - DeXposeDeXpose
- Krybit Ransomware Lists Ford de México as a VictimBreached.company
- Victim: ford.mx - Ransomware.liveRansomware.live
- Nissan Americas Hit in Global Oracle PeopleSoft Data BreachCyber Defense Magazine
- Oracle PeopleSoft Zero-Day (CVE-2026-35273) Exploitation and ...Rescana
- Critical Oracle PeopleSoft Vulnerability Actively Exploited in ShinyHunters CampaignArctic Wolf
- Oracle PeopleSoft Critical Vulnerability (CVE-2026-35273)Trend Micro
- Sistema financiero mexicano, blanco de ataques cibernéticosEl Financiero
- Sin prórroga de la CRT: quedan seis días para registrar el celular con la CURPLa Jornada Maya
- México | Aún sin vincular a una CURP, 85 millones de celularesDPL News
- ¿Cómo registrar tu línea celular en 2026? Esto es lo que debes hacerRecord
- Presunto hacker acusa plan para ubicar policías de GuanajuatoEl Sol de León (OEM)
- Soy Docente: ¿OTRA VEZ HACKEAN A LA USICAMM (2026)?Soy Docente (YouTube)
- Mundial 2026: Alertan por ola de 55 millones de ciberataques y lavado de dinero en MéxicoEl Cronista
- Filtración de datos de telefonía en México: 45.000 usuarios afectadosMoncloa
- Days before mandatory registration, user data leaked in MexicoYouTube
- Ciberataques, fraudes y robo de identidad, los riesgos que enfrentan los aficionados en el Mundial 2026Reporte Índigo
- Hackers exhiben fragilidad del registro de celulares: se filtran datos de 45 mil usuarios de telefoníaInfobae México
- Ransomware en México incrementa nivel de riesgo del mercadoReseller
- Nissan Confirma Compromiso Masivo de Empleados Tras Explotacion de 0-day en Oracle PeopleSoft CVE-2026-35273Devel Group
- Remediate Catalyst SD-WAN Security Advisory (Junio de ...)Cisco
- El grupo de ransomware más activo del mundo llegó a ...El Heraldo de Puebla
- se reportaron ocho incidentes cibernéticos en lo que va del 2026Yahoo Noticias
- Feed De Noticias De Ciberseguridad [01/06/2026] - CronUpCronUp Ciberseguridad
- Qilin: La Amenaza que Puede Paralizar tu Empresa en 2026Care Telecom
- Microsoft corrige 200 vulnerabilidades en el Patch Tuesday de junio 2026Infosertecla
- Radar Tecnológico Junio 2026 | SAP, IA y AgTechHéctor Pincheira
- Portaltic.-Google corrige más de 100 vulnerabilidades en Android, una de ellas de día cero y bajo explotación activaNotimerica / Portaltic
- June 2026: Biggest Cyber Attacks, Data Breaches, Ransomware ...CM-Alliance
