Monitor de actividad
Ransomware en México
Seguimiento de la actividad de ransomware observada en organizaciones mexicanas. Grupos más activos, sectores afectados y víctimas recientes.
- Ciudad de México17
- Nuevo León7
- Jalisco5
- Chihuahua4
- Baja California3
- Michoacán2
- Sinaloa2
- Yucatán2
- Coahuila1
- México1
- Quintana Roo1
- San Luis Potosí1
- Sonora1
- Veracruz1
Sin estado determinado: 218
- Culiacán Municipal Health Portal Breached in Mexico, Minors' and Patients' Medical Records Leaked7 de julio de 2026
A threat actor using the alias derm0nix (Hackero$ Crew) claims to have breached the Portal de Salud de Culiacán, the official digital health system of the Culiacán municipal government in Mexico, and has leaked the data for free.
- Logistics Conglomerate Grupo ATC Data Offered for Sale After Ransom Refused2 de julio de 2026
A threat actor using the alias Straightonumberone is selling what they describe as data stolen from Grupo ATC, a Mexican logistics conglomerate (comprising TLE, TLEA, and PHES), for $1,000 after a ransom negotiation reportedly failed.
- Durango State Education Department Allegedly Breached, Exposing Records of Thousands of Primary School Children26 de junio de 2026
A threat actor using the alias D3spair157 (operating as “Sociedad Privada 157”) has posted what they describe as a data leak from the Secretaría de Educación del Estado de Durango (SEED), Mexico's Durango state education department, reportedly obtained using administrator credentials to its student-management portal.
- Taxpayer Database From Mexico's Coahuila State Government Allegedly Leaked25 de junio de 2026
Threat actors using the aliases M1sery157 and D3spair157 (operating as “Sociedad privada 157”) have posted what they describe as a database scraped from a Coahuila state government portal in Mexico.
- Ransomware Attack Update - July 11th, 202612 de julio de 2026
Ransomware Attack Update - July 11th, 2026
- Dutch Police Suspect Local Accomplices in Odido Breach Affecting 6.2 Million Customers10 de julio de 2026
Dutch police say they have uncovered strong indications that local criminals were involved in the cyberattack against telecommunications provider Odido, which exposed personal information belonging to millions of customers.
- French Baby-Products Marketplace Bebeboutik Allegedly Breached, Seller Portal Database of 500,000 Rows Leaked10 de julio de 2026
A threat actor using the alias ChimeraZ claims to be leaking a database from the seller portal of Bebeboutik (sales.bebeboutik.fr), a French private-sales marketplace for baby and children's products.
- French Business School PPA Breached, Nearly 294,000 Records of Students, Alumni, and Prospects Leaked10 de julio de 2026
A threat actor using the alias 84City has posted an SQL dump they attribute to PPA Business School, described as one of the largest private higher-education groups in France, offering preparatory programs and bachelor's degrees across art, design, digital, communication, and business.
- Former Ransomware Negotiator Sentenced for Helping BlackCat/ALPHV Extort U.S. Victims10 de julio de 2026
A former ransomware negotiator from Florida has been sentenced to federal prison for helping BlackCat/ALPHV ransomware actors extort U.S. victims while he was supposed to be helping victims respond to attacks.
- Federal Prisoner Charged With Stealing $290K in Forfeited Cryptocurrency9 de julio de 2026
A man already serving a federal prison sentence has been charged with allegedly stealing and laundering cryptocurrency that had been forfeited to the United States.
- GhostApproval Flaw Exposes Trust Boundary Weakness in Major AI Coding Assistants9 de julio de 2026
Security researchers at Wiz have disclosed GhostApproval, a vulnerability pattern affecting several major AI coding assistants and exposing a trust-boundary problem between developers, AI agents, and the local filesystem.
- Thepha District Public Health Office in Thailand Breached, Databases Dumped and Server Access Offered9 de julio de 2026
A threat actor using the alias Monkeydance claims to have breached the Thepha District Public Health Office, a local health authority in Thailand operating under the Ministry of Public Health.
- Norway Arrests 28 in Dark Web CSAM Crackdown Tied to Monero Payments9 de julio de 2026
Norway’s National Criminal Investigation Service, known as Kripos, says 28 men have been arrested across seven countries in an international dark web operation tied to Monero payments.
- French IT School ESGI Breached, Over 26,000 Student Enrollment Records Leaked8 de julio de 2026
A threat actor using the alias 84City has posted an SQL dump they attribute to ESGI (École Supérieure de Génie Informatique), a private French higher-education school specializing in IT and digital technology, based in Paris with campuses across France.
- AssuranceAmerica Data Breach Exposes Driver’s License Numbers of 6.99 Million People8 de julio de 2026
U.S. insurance provider AssuranceAmerica has confirmed a data breach affecting nearly 7 million people, exposing personal information and driver’s license numbers.
- Foxit PDF Reader RCE Flaw CVE-2024-30326 Highlights PDF Attack Surface8 de julio de 2026
A remote code execution vulnerability in Foxit PDF Reader, tracked as CVE-2024-30326, highlights the continued risk of malicious PDF files being used as an initial access vector.
- GitLost Shows How GitHub AI Agents Can Leak Private Repository Data7 de julio de 2026
Noma Labs has disclosed GitLost, a prompt injection vulnerability that showed how GitHub’s AI-powered Agentic Workflows could be tricked into leaking private repository data through a public GitHub issue.
- French Medical Platform Follow Data Offered for Sale, Over 2 Million Patient Records Exposed7 de julio de 2026
A threat actor using the alias Saturne is selling a database from Follow, a French Ségur-certified medical software and patient-record platform used by specialist doctors and surgeons.
- Payment Firm Nayax Allegedly Fully Breached, Actor Threatens 100TB Release With Over 1 Billion Card Records7 de julio de 2026
A threat actor using the alias TheSyndicate claims to have fully compromised Nayax, an Israeli global payments and fintech company (NASDAQ: NYAX, TASE: NYAX.TA), stating they have been inside its systems for almost a year.
- When the Password Check Fails, You're In: The Hidden Admin Backdoor in Tenda Router Firmware (CVE-2026-11405)7 de julio de 2026
CVE-2026-11405 is an undocumented authentication backdoor in multiple versions of Tenda router firmware.