
The RansomHub ransomware gang has claimed responsibility for a significant cyberattack on the Mexican government, alleging the theft of 313 gigabytes of sensitive data. The group publicized its claims on November 15 by listing the official government domain, gob.mx, on its leak site.
RansomHub described the compromised platform as central to governmental innovation, efficiency, and public participation. The group also shared a sample of the allegedly stolen data, which reportedly includes contracts, insurance documents, financial records, and other confidential files.
The ransomware group appears to have specifically targeted the Legal Counsel of the Federal Executive Branch (CJEF). The leaked data samples disclosed personal information such as names, emails, roles, tax registration numbers (RFC), and headshots of CJEF staff members. Additionally, scanned contracts from 2023 were included, one of which was addressed to Mario Gavina Morales, the Mexican government’s Director of Information Technology and Communications.
RansomHub has demanded a ransom payment within 10 days, threatening to release the stolen data if the demand is unmet. The Mexican government has not issued a public statement addressing the incident. Despite the group’s claims, the affected website, gob.mx, continues to function normally.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543