Hello techies, how are you all doing? Today I bring you some worrying news that affects millions of people in Mexico. The country has had some pretty tough months in terms of cybersecurity, and when I say tough, I mean that many of its most important institutions and organizations have been victims of a cascade of security breaches that have exposed sensitive information from their users. We’re talking about the data leak of the Mexican Social Security Institute, the security breach at the National Autonomous University of Mexico, the vulnerability in Telcel’s systems and signs of a leak in the Tax Administration Service. The list is extensive and truly worrying.
Between September 2025 and January 2026, Mexico has recorded at least a dozen serious cybersecurity incidents that have affected top-tier public bodies and private companies. The IMSS, the National Employment Service, the Secretary of Education of Chiapas, the Federal Electricity Commission and various state bodies have seen their systems compromised. The result has been the breach of sensitive data belonging to millions of Mexicans, including medical information, tax data, educational records and personal identification data. It’s the kind of information that, in the wrong hands, can cause enormous damage.
The case of the National Autonomous University of Mexico is especially striking because it shows that even the largest and most prestigious institutions are not prepared for this type of attack. A few weeks ago, the university confirmed that it suffered an unauthorized intrusion into five of its more than 100,000 computer systems during the holiday period. Although they initially assured that no personal information was extracted, journalistic investigations revealed that the hacker identified as ByteToBreach would have accessed the data of more than 380,000 students and academics, including enrollment numbers, institutional emails and encrypted passwords. But the most serious thing is that the attacker also had access to sensitive documents including reports of workplace harassment, alleged academic plagiarism and confidential communications from the rector’s office.
What makes this case even more worrying is that the security breach was not a sudden event. Internal documents reveal that the university detected a first unlawful access on March 13, 2025 and filed a complaint with the Attorney General’s Office, although the case did not progress. The definitive attack occurred between December 31 and January 1, coinciding with the fact that engineers and developers of the Technological Projects Coordination had gone months without being paid their fees due to audit processes. In other words, there were warning signs and internal problems that could have facilitated the attack. ByteToBreach, by the way, is not a stranger in the world of cybercrime. He has operated as a trader of stolen databases since at least June 2025 and has been linked to leaks affecting airlines, banks, government institutions and healthcare systems in several countries.
The Telcel case is equally serious because it happened right when the government was implementing the mandatory registration of mobile lines. Less than 24 hours after this measure came into effect, it was reported that the company’s official portal allowed anyone to consult the personal information of millions of customers without needing passwords or verification codes. Identity, CURP, RFC and email address were exposed simply by entering a phone number. Although Telcel initially issued an ambiguous statement saying the data was safe, hours later they acknowledged that there was a technical vulnerability that was corrected. The problem is that we don’t know how long that vulnerability was active or who may have accessed that data.
These security breaches pose a real and tangible risk to citizens. With data such as CURP, RFC, university enrollment numbers and email addresses circulating on the black market, the risks include identity theft, impersonation to carry out fraudulent procedures, targeted phishing campaigns and access to accounts on other platforms if passwords are reused. The leak of medical information from the IMSS, tax data from the SAT and educational records creates a complete profile of citizens that can be exploited in multiple ways. Users have no choice but to stay alert: don’t provide sensitive data via SMS, calls or emails without verifying the identity of the requester, change compromised passwords, monitor for possible fraudulent use and enable two-factor authentication whenever possible.
Best regards, Marta
Automatically published on 22/01/2026 at 12:05






