VendorResearch

Mexico’s Cybersecurity Plan 2025-2030: Turning Ambition Into Defense


Mexico faces an increasingly complex cyber threat landscape, including ransomware, state-sponsored espionage, financial malware, data breaches, hacktivism, and cyber-enabled organized crime. Its 2025–2030 National Cybersecurity Plan seeks to address these challenges through stronger governance, new legislation, a national operations center, integrated incident-response teams, cyber exercises, AI-enabled defenses, and expanded regional cooperation. Insikt Group assesses ransomware as the leading threat while highlighting growing risks from foreign threat actors and credential theft. We recommend leveraging threat intelligence, applying international security frameworks, and fostering cyber education. Ultimately, Mexico’s progress will depend on turning an ambitious roadmap into durable institutions, effective regulation, and sustained international cooperation.

Mexico’s Cybersecurity Plan 2025-2030: Turning Ambition Into Defense

Mexico has no shortage of cyber threats. Ransomware attacks are rising, criminal groups are exploiting stolen credentials and financial malware, and state-linked threat actors increasingly view the country’s government agencies, universities, and critical infrastructure as attractive targets. Mexico’s new National Cybersecurity Plan (hereinafter referred to as “Plan”), introduced in December 2025, recognizes many of these risks. However, it remains uncertain as to whether the government can build the institutions needed to address them proactively.

Mexico is ranked as a “Tier 2” nation in the ITU’s 2024 Global Cybersecurity Index, placing it alongside Canada, Ecuador, and Uruguay in the upper ranks, trailing the United States (US) and Brazil, which have reached Tier 1 in the Americas. Despite that standing, Mexico is generally perceived by cyber experts as lagging behind international standards in institutional capacity-building, with international cooperation identified as an area requiring growth.

The question of whether the government can build the proper institutions has become more urgent in the aftermath of the FIFA World Cup 2026, which provided a high-profile stress test for Mexico’s digital defenses. With the tournament over and implementation of the government’s 2025-2030 cybersecurity plan beginning in earnest, Mexico faces a major opportunity to improve its cyber posture.

For this reason, the Plan represents a major opportunity for Mexican authorities to bring the country’s cyber readiness to the next level. Although there have been attempts to advance national cybersecurity policy, they have failed to gain traction. With this new Plan, President Claudia Sheinbaum’s administration has committed to full implementation over the course of her term, aided by her party’s majority control of Congress.

The Plan lays out a six-phase roadmap designed to gradually build Mexico’s cybersecurity capabilities through 2030, with later phases intended to deepen and institutionalize them.

  • The 2025 Foundation Phase established a general framework for governance, risk management, incident reporting, and coordination, as well as initial steps to deepen international cooperation, including Mexico’s formal membership in the Latin America and Caribbean Cyber Competence Centre (LAC4) and a cybersecurity Memorandum of Understanding (MOU) with Brazil.
  • The 2026 Expansion Phase, now underway, focuses on translating that framework into institutions through the passage of a new General Cybersecurity Law in Mexico, creation of a National Cybersecurity Operations Center, and integration of federal computer security incident response teams (CSIRTs).
  • The 2027 Consolidation Phase would establish a National Cyber Range for red team and blue team exercises.
  • The 2028 Maturation Phase would incorporate AI into cyber defense and develop a regional response center.
  • The 2029 Leadership Phase aims to position Mexico as a cybersecurity services exporter across Latin America and the Caribbean.
  • The 2030 Transformation Phase culminates in the establishment of a permanent Cybersecurity Observatory to track incidents, threats, and emerging technologies.

Threat Landscape

In a recent report, Insikt Group assessed Mexico’s threat landscape across six persistent categories:

Ransomware is identified as the dominant threat. From January 2020 through April 2026, Insikt Group documented 223 ransomware incidents involving 64 groups and over 100 victims in Mexico. The top ransomware groups were LockBit, Qilin, CL0P, Kazu, and ALPHV (BlackCat), with government, manufacturing, information technology (IT), and food and beverage as the sectors most heavily impacted.

op Five Ransomware Groups Impacting Mexico in 2025,' displaying the number of attacks over time from May 2020 to April 2026. The chart tracks activity for five ransomware groups: ALPHV (BlackCat), CL0P (FANCYCAT), Kazu, LockBit, and Qilin.

Top Five Industries Impacted by Ransomware Groups in Mexico in 2025,' showing the number of attacks across five key industries from May 2020 to April 2026. The industries tracked are Food and Beverage, Government, Government - Non-US, Information Technology, and Manufacturing, with colored lines plotting the volume of attacks against each sector over time.

Figure 1: Top five ransomware groups and top five industries impacted by ransomware groups in Mexico, 2025 (Source: Insikt Group)

State-sponsored activity is a significant concern. Mexico is considered an attractive target for foreign cyber operations due to its deep integration into US supply chains, a nearshoring-linked manufacturing base, and underdeveloped cyber governance. Chinese state-sponsored group TAG-141 (FamousSparrow) deployed SparrowDoor malware against Mexico’s Universidad Nacional Autónoma in early 2025, and Asia-linked TGR-STA-1030 was observed targeting at least 70 government and critical infrastructure organizations. North Korea-sponsored remote IT-worker schemes have also affected Mexican entities.

Financial malware and fraud remain pervasive, particularly with the rise of AI deepfakes. Mexico ranks among the top five countries globally for infostealer victims, and approximately 780,000 payment cards were exposed on the dark web in 2025 alone. Prominent malware families active in Mexico include DanaBot, LummaC2, and banking trojans such as Mispadu, Grandoreiro, and Casabaneiro (Mekotio). In 2024, Fenix botnet targeted Mexican taxpayers by impersonating official government portals such as the Tax Administration Service (SAT).

Data breaches are widespread and often recycled on criminal forums. Insikt Group found nearly 500 references to posts on dark web special-access forums in which Mexico was identified as a cyberattack target between January 2020 and April 2026, across 26 industries and 308 unique usernames. DarkForums was the most commonly used platform for threat actors targeting Mexican entities.

Hacktivism carries both political and financial motivations. The hacktivist group “Chronus Team” emerged in late 2025, targeting institutions across Mexico and Latin America and claiming responsibility for data leaks affecting education, insurance, law enforcement, healthcare, and government sectors. In March 2026, it merged with “Mexican Mafia Team” to form “Chronus Mafia,” expanding its operational scope.

Organized crime and money laundering increasingly overlap with cyber. Mexican drug trafficking organizations (DTOs) leverage Chinese money laundering networks (CMLNs) and cryptocurrency to obfuscate illicit proceeds. These DTOs have been documented using cybercrime-as-a-service to surveil and intimidate informants cooperating with law enforcement.

Recommendations

Insikt Group recommends that organizations operating in Mexico take four key steps: leverage threat intelligence platforms to track threat actor activity, exposed credentials, and dark web chatter; adopt international frameworks such as the NIST Cybersecurity Framework (CSF) or ISO/IEC 27001 in anticipation of incoming regulatory mandates; conduct scenario-planning and cybersecurity wargaming exercises covering ransomware, espionage, and hacktivism; and invest in educating both employees and the general public on cyber hygiene, phishing recognition, and incident reporting.

Mexico’s near-term cyber trajectory will depend heavily on the passage and implementation of the proposed Federal Cybersecurity Law, which is expected to be introduced in 2026 by the ruling MORENA party. Even if passed, full implementation will likely unfold gradually over several years as agencies build out institutional frameworks. Looking further ahead, cybersecurity is expected to grow as a central pillar of the US-Mexico bilateral relationship, given deepening security cooperation and the countries’ working group on cyber issues, established in 2022.

About Insikt Group®

Recorded Future’s Insikt Group, the company’s threat research division, comprises analysts and security researchers with deep government, law enforcement, military, and intelligence agency experience. Its mission is to produce intelligence that reduces risk for customers, enables tangible outcomes, and prevents business disruption.



Source link