LIVE · cybersecurity feed
Live wire
mexicohigh

Evaluating Mexico’s New Cybersecurity Plan

Mexico has introduced a new National Cybersecurity Plan to combat threats such as organized crime, geopolitical risks, and AI advancements. This initiative addresses recent cyber incidents affecting government and institutional bodies, aiming to mitigate data theft, ransomware, and service disruptions. The plan acknowledges Mexico's vulnerability to various cyber threats, including ransomware and state-sponsored activities, and identifies the dark web as a platform for planning attacks.

zeroday.news · 38d ago

Mexico has introduced a new National Cybersecurity Plan designed to address the nation's most pressing cyber threats over the next six years. The plan, published in December 2025, aims to bolster Mexico's digital defenses against organized crime, geopolitical adversaries, and emerging artificial intelligence threats, a move prompted by a series of significant cyber incidents affecting federal, state, and local institutions. These attacks have underscored the urgent need for a more unified national strategy to combat data theft, ransomware, service disruptions, and damage to institutional reputations.

Analysis of cyber trends from 2020 to 2026 indicates that Mexico has historically been a primary target for ransomware, financial malware and fraud, and hacktivism. Data breaches, organized crime-related cyber activities, and state-sponsored cyber threats also represent substantial risks. The government, healthcare, and financial sectors have been particularly vulnerable, with ransomware consistently identified as the leading threat. Mexico's deep integration into U.S. supply chains, its role in nearshoring manufacturing, and its developing cyber governance frameworks make it an attractive target for state-sponsored cyber operations. Furthermore, Mexico ranks among the top five countries globally for documented victims of infostealer malware and stolen payment card data.

The National Cybersecurity Plan, officially the 2025–2030 National Cybersecurity Plan, was released by the Mexican Digital Transformation and Telecommunications Agency (ATDT). Its objective is to modernize Mexico's federal cyber policy to align with current threat landscapes and foster a more secure and resilient digital security ecosystem. While the plan itself does not introduce new laws or policies, it establishes benchmarks and indicators to guide progress. The ATDT aims for Mexico to become a regional leader in cybersecurity through this initiative.

Mexico's commitment to cybersecurity was reflected in its "Tier 2" ranking in the International Telecommunication Union's (ITU) 2024 Global Cybersecurity Index, placing it among leading Latin American nations. However, the ITU has identified international cooperation as an area for improvement, and cybersecurity experts generally view Mexico as lagging in institutional capacity-building compared to international standards. The ATDT asserts that the plan will elevate Mexico's standing in regional cybersecurity, contributing to the protection of its digital assets and population, and strengthening overall security across Latin America and the Caribbean.

The plan's rollout follows a period of significant cyber incidents, including a 2022 hacktivist leak of sensitive files from the Secretariat of National Defense (SEDENA), a ransomware attack on the Secretariat of Infrastructure, Communications, and Transportation (SICT) in the same year, a BlackByte ransomware attack against the National Water Commission (CONAGUA) in 2023, and a RansomHub attack affecting the Legal Counsel’s Office of the Presidency in 2024. Incidents at the state and local levels, such as the exposure of Mexico City government emails in 2024 and an intrusion involving Yucatán’s Va y Ven transit system in 2025, highlight the widespread vulnerability of public institutions to data theft, service disruptions, ransomware, and reputational harm due to a fragmented response capability.

The National Cybersecurity Plan outlines a phased approach to enhancing Mexico's cyber capabilities. The initial "Foundation Phase," which began with the plan's publication in December 2025, involved establishing a general cybersecurity framework covering responsibilities, governance, risk management, incident reporting, vulnerability management, training, and coordination. During this phase, Mexico also joined the Latin America and Caribbean Cyber Competence Centre (LAC4) and signed a cybersecurity Memorandum of Understanding with Brazil.

The "Expansion Phase," currently underway in 2026, includes the development of a new National Cybersecurity Strategy by the third quarter, the passage of a new General Cybersecurity Law, and the creation of a National Center for Cybersecurity Operations for continuous threat monitoring and early detection of cyberattacks. This phase also aims to integrate a broader network of public, private, academic, and international incident response teams, identify critical infrastructure, establish a federal vulnerability assessment program, launch a Federal Virtual Academy, create a National Cybersecurity Contact Network (RNCC-MX), sign additional bilateral agreements, develop a federal CERT/CSIRT Network, and establish a critical alert system for the federal government.

Future phases include the "Consolidation Phase" in 2027, focused on establishing a National Cyber Range for realistic training exercises involving various cyber threats. The "Maturation" phase in 2028 will integrate artificial intelligence for cyber defense and develop a regional Latin America response center. The "Leadership" phase in 2029 aims to position Mexico as a leading regional cybersecurity provider by exporting services.

Organizations operating in Mexico are advised to enhance their threat detection capabilities, prioritize threat visibility, and strengthen incident response planning. This includes leveraging cyber threat intelligence solutions, adopting international cyber standards, conducting scenario-planning exercises for various threats, and educating staff and the public on cyber safety and incident response. The upcoming 2026 FIFA World Cup, co-hosted by Mexico, is expected to be an initial test of the country's resilience and ability to maintain digital services amidst increased international attention and tourism.

mexicocybersecurity planransomwareorganized crimeai threats
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.

ai

7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran

Plus: The FBI eyes AI-powered tech to detect future crimes, Russia charges Telegram’s founder, xAI sues to stop a state’s “nudification” ban, and the Democrats learn a lesson about getting scammed.