Mexico ransomware and cyber extortion policy

Mexico's New Cybersecurity Agency Bill Answers a Real Ransomware Crisis, But Repeats an Old Institutional Design Flaw

Mexico's Senate is weighing a National Cybersecurity Agency to fight a ransomware epidemic — but its takedown powers still lack judicial checks.

Mexico's Ransomware Crisis, By the Numbers People of Internet Research · Mexico 11th Global ransomware rank Mexico climbed from 16th (2024) to… 155 Ransomware victims recorded Documented Mexican ransomware vict… 5 Prior cybersecurity bills failed Cybersecurity law attempts that st… 60 days CISO naming deadline Window for federal agencies to nam… peopleofinternet.com
Mexico's Ransomware Crisis, By the Num… People of Internet Research · Mexico 11th Global ransomware rank 155 Ransomware victims recorded 5 Prior cybersecurity bi… 60 days CISO naming deadline peopleofinternet.com

Key Takeaways

A Real Crisis, Finally Getting a Real Answer

On August 27, 2026, Mexico's Senate received an initiative to enact a General Cybersecurity Law that would create a National Cybersecurity Agency (Agencia Nacional de Ciberseguridad, ANCS) and a National Cybersecurity System, with a normative council chaired by the Secretariat of Security and Citizen Protection and drawing on nine federal departments, according to the Senate's own communications office. It is the sixth attempt at comprehensive cybersecurity legislation since 2015, and the first with real bipartisan backing: it builds on a bill Senators Luis Donaldo Colosio Riojas (Movimiento Ciudadano) and Lucía Trasviña Waldenrath (Morena) first introduced on April 30, 2025.

The urgency is not manufactured. Mexico climbed from 16th to 11th place globally for ransomware victims between 2024 and 2025, and remains the second most-targeted country in Latin America after Brazil, according to IQSEC's 2026 threat report. Recorded Future's tracking counts 155 documented Mexican ransomware victims between November 2019 and September 2025, with government, manufacturing and IT the hardest-hit sectors — a toll that includes breaches of the Defense Secretariat (2022), the Infrastructure Ministry (2022), the National Water Commission (2023) and the Presidential Legal Counsel's Office (2024). Groups like LockBit, Qilin, CL0P and Kazu treat Mexican public institutions as soft targets, and the extortion that follows — public agencies and hospitals told to pay or watch citizen data leak — is not an abstraction. The steelman case for a dedicated agency is strong: Mexico is one of the only G20 economies without a peacetime civilian cybersecurity authority, and its incident response today is scattered across agencies with no single body that can compel disclosure, coordinate a national response, or set baseline standards for critical infrastructure operators.

What the Bill Actually Builds

The ANCS initiative rests on three pillars, per an analysis of the bill text by Mexican cybersecurity consultancy QMA: the agency itself, structured as a decentralized civilian body with its own legal personality and operational autonomy; a Critical Information Infrastructure Registry (RICI) that would classify systems by criticality tier; and a mandatory requirement, under bill articles 18 and 36(III), that regulated operators designate a formal cybersecurity officer with obligations scaled to that tier. Enforcement runs through an administrative — not criminal — sanctions regime: warnings, proportional fines, suspension, and disqualification for repeat offenders. That is a genuinely proportionate design choice; criminalizing security failures tends to push breach victims toward concealment rather than disclosure, which is precisely the wrong incentive for an agency that needs timely incident reporting to function.

The bill's drafters were also explicit that ANCS "operates strictly in the civilian sphere and does not encroach on military cybersecurity competencies" — language that reads as a direct response to why the last serious attempt collapsed. A 2023 cybersecurity bill from PVEM deputy López Casarín was withdrawn in March 2024 after digital-rights group R3D (Red en Defensa de los Derechos Digitales) warned it would let the new agency, alongside the National Guard and federal prosecutors, order the shutdown of IP addresses, domains and websites with no defined procedure or judicial safeguard. Learning from that failure and writing a civilian-only agency into the text is a real improvement.

The Unresolved Problem: Takedown Power Without a Judge

But the core objection R3D raised in 2023 has not gone away just because the military carve-out was added — it concerns any authority ordering a shutdown or compelling data handover without prior judicial authorization, regardless of which civilian body holds the pen. That concern looks considerably more urgent now than it did in 2023: a separate telecommunications and security reform package passed in July 2025 already lets the Armed Forces and National Guard conduct intelligence and surveillance activity without judicial restriction, requires carriers to retain user metadata for two years, mandates biometric SIM registration by May 2026, and dissolved the independent Federal Telecommunications Institute in favor of executive-controlled bodies, R3D documented in an August 27, 2025 analysis. Mexico's institutional trend line, in other words, has been toward fewer independent checks on state technical power, not more — and a new agency with authority over infrastructure classification and incident response sits directly downstream of that trend.

The fix is not to abandon ANCS. It is to write the safeguard directly into the statute the Senate is now debating: any order to disable a domain, IP address or service should require an independent judicial sign-off within a fixed window (say, 48 hours), mirroring how most OECD cybersecurity authorities structure emergency powers. Congress should also require ANCS to publish an annual transparency report on takedown orders and data requests — the kind of public accounting the dissolved IFT used to produce and that its executive-branch successor does not.

The Proportionate Path

Mexico does not have the luxury of waiting out another five failed attempts while ransomware groups treat its hospitals and water utilities as an open target. The Sheinbaum administration's parallel December 2025 National Cybersecurity Policy — which already gives federal agencies 60 days to name an institutional cybersecurity lead — shows the executive branch is moving with or without this law. A binding statute with real enforcement teeth is better than policy-by-decree. But proportionate regulation means proportionate power: an agency built to stop ransomware gangs from extorting Mexican institutions should not carry authority broad enough to silence a website with no judge in the loop. Congress can fix that with one clause. It should not let the good parts of this bill pass while leaving that gap for a future government to exploit.

Sources & Citations

  1. Excélsior: Habrá Agencia Nacional de Ciberseguridad
  2. DOF / ATDT — Política General de Ciberseguridad APF (Dec 17, 2025)
  3. R3D: La ampliación de la vigilancia estatal
  4. Mexico Business News: Mexico Rises to 11th Globally in Ransomware Attacks
  5. Recorded Future: Evaluating Mexico's New Cybersecurity Plan
  6. QMA: Ley de Ciberseguridad México 2026 — Colosio + CISO obligatorio
  7. Maya Comunicación: Ciberseguridad en México — la propuesta que busca crear una agencia nacional