Mexico Financial Cyberattacks Surge 167% in 1Q26
By Duncan Randall | Journalist & Industry Analyst -
Tue, 07/07/2026 - 11:44
Cyberattack-related losses targeting Mexican financial institutions surged 167% year over year to MX$67.5 million in 1H26, driven by increasingly sophisticated multi-vector attacks affecting ATMs, operating systems, and electronic transfer channels. According to Banxico, the rising threat landscape requires more advanced detection and response systems to counter risks such as the Prometei Trojan and ransomware while maintaining uninterrupted retail banking operations. The increase in digital infrastructure vulnerabilities underscores a growing operational challenge for the financial sector, pushing institutions to accelerate cybersecurity investments to protect critical payment systems and domestic capital flows.
——
Cyberattacks targeting financial institutions and their core operating networks generated approximately MX$67.5 million (US$3.8 million) in losses in 1Q26, according to data disclosed by Mexico’s central bank (Banxico). The figure represents a 167% year-over-year increase compared with the same six-month period in 2025, when cyber incidents generated damages of MX$25.2 million (US$1.4 million).
Central bank records indicate that authorities detected three major security incidents between January and June, affecting three different operational areas: automated teller machines (ATMs), internal corporate systems, and bank transfer channels.
The first intrusion occurred in February, when a vulnerability within a commercial bank's ATM network resulted in infrastructure-related damages of MX$11.8 million (US$679,976).
The second attack, identified in March, generated losses of MX$55.7 million (US$3.2 million). Banxico reported that the specific type of malware used in the incident remains unidentified, although the attack involved the compromise of security mechanisms controlling interbank transfer operations.
The third cyber incident occurred in May and involved a Prometei-type Trojan malware infection, a threat capable of extracting sensitive information and modifying administrative access controls. Banxico identified the malware as a "Prometei" Trojan, which can infect connected devices within a network and modify its code to evade traditional security tools.
While the financial impact of the May incident remains under evaluation, Banxico emphasized that none of the three attacks resulted in direct losses for banking customers or compromised individual accounts. “Cyber risks continue to rank among the most relevant for the financial system globally,” the central bank stated in its latest Financial Stability Report released in June.
Following the escalation of geopolitical tensions after the Russia-Ukraine conflict, financial authorities established additional monitoring mechanisms to track potential cybersecurity threats affecting international payment systems. However, as global financial infrastructure did not become a major target of war-related cyberattacks and Mexico reported no related incidents, Banxico reduced its cybersecurity alert level from orange to yellow.
“The cybersecurity situation in Mexican banks requires constant attention and the implementation of efficient alert systems. These systems are necessary to address the continuous evolution of cyber threats,” said Raúl Mendivil, information technology specialist, National Polytechnic Institute.
Mendivil noted that while technological advances provide financial institutions and companies with new tools to strengthen security systems, they also create additional opportunities for attackers seeking unauthorized access. Cybercriminals frequently rely on social engineering techniques to manipulate employees into revealing passwords, credentials, or sensitive information.
Banxico data shows that since the beginning of the COVID-19 pandemic in 2020, malware-based attacks have gained greater relevance across Mexico’s financial sector. During this period, cybersecurity incidents have increased alongside the unauthorized sale of payment card information and corporate data encryption attacks, commonly known as ransomware.
Despite these challenges, Mexico ranked 27th among 105 economies with the lowest cybersecurity risk exposure between January 2021 and May 2023, according to the Cyberattack Risk Perception Index.
“Banxico will continue monitoring these indicators to identify changes in the cyber risk environment affecting the national financial sector in a timely manner and, if necessary, strengthen security measures to mitigate potential threats,” the institution concluded.
AI-Powered Vulnerability Detection Raises New Cybersecurity Concerns
The emergence of advanced artificial intelligence tools capable of identifying software vulnerabilities, such as Anthropic’s Mythos platform, is reshaping the cybersecurity landscape for organizations operating legacy infrastructure.
Although these technologies are primarily designed to improve defensive capabilities, concerns have increased over the possibility that automated vulnerability discovery tools could expose weaknesses in older financial systems before institutions are able to address them.
The International Monetary Fund (IMF) and the European Central Bank (ECB) have warned about the potential financial stability risks associated with AI-driven cyber threats, emphasizing the need for stronger governance frameworks, cybersecurity investment, and international cooperation.








