Mexico Hit With 324 Billion Attempted Cyberattacks: Fortinet Labs
Over 324 billion attempted cyberattacks hit Mexico during 2024, according to Fortinet Labs’ Global Threat Report 2025. The report highlights the intensive use of AI and automated tools by malicious actors.
"Our latest FortiGuard Labs report makes one thing clear: cybercriminals are accelerating their efforts, using AI and automation to operate at unprecedented levels of speed and scale," Derek Manky, Head of Security Strategy and Global VP of Threat Intelligence, FortiGuard Labs, writes in a press release.
The report shows a structural shift in the global threat landscape, marked by the growth of the cybercrime-as-a-service (CaaS) model on the dark web. This model facilitates mass access to exploit kits, credentials, remote access, and packaged malware. During 2024, underground forums added more than 40,000 new vulnerabilities to the National Vulnerability Database, an increase of 39% over the previous year.
The findings show an unprecedented increase in automated scanning of exposed digital infrastructure. FortiGuard Labs documented more than 1 billion scans per month globally targeting critical services such as SIP, RDP and IT/OT protocols such as ModbusTCP. These tactics allow attackers to quickly map attack surfaces and exploit emerging vulnerabilities more effectively.
AI is also being used to escalate phishing campaigns and circumvent conventional detection systems. Tools such as FraudGPT, BlackmailerV3, and ElevenLabs enable the creation of more realistic threats, making them harder to identify. These tools lack the ethical constraints that limit public AI models, increasing their effectiveness in social engineering campaigns.
The sectors most affected by targeted attacks in 2024 were manufacturing (17%), business services (11%), construction (9%), and retail (9%). The United States accounted for 61% of these attacks, followed by the United Kingdom (6%) and Canada (5%).
The cloud environment and the Internet of Things (IoT) also continue to be critical areas. In 70% of the incidents observed in the cloud, attackers gained access using credentials from unrecognized locations. This reflects the persistence of misconfigurations, excessive permissions, and poorly secured storage in these environments.
During 2024, over 100 billion compromised records were shared in underground forums, a year-on-year increase of 42%. The use of "blended lists" that integrate users, passwords and emails has facilitated large-scale automated credential theft attacks. Groups such as BestCombo, BloddyMery, and ValidMail stand out as prominent players in this trend.
To address this scenario, Fortinet integrated into the report the "CISO's Guide to Adversary Defense," which proposes a transition from traditional detection schemes to a continuous threat exposure management (CTEM) strategy. This includes automating responses, emulating adversarial behavior, prioritizing risks and using Breach and Attack Simulation (BAS) platforms to validate defenses against lateral movement and exploitation in real time.
The report highlights the need for proactive cyber defense based on advanced intelligence, continuous monitoring, zero trust architecture, and response automation to counter the exponential rise of AI-driven cyberthreats.






