Back to Blog
Incident Analysis

2.3 Terabytes: Mexico's Citizen Records and the Systems Nobody Owned

Plaza Cyber Security TeamJanuary 30, 20266 min read
Rows of wooden card-catalogue drawers holding filed personal records
Rows of wooden card-catalogue drawers holding filed personal records

On 30 January 2026, a group calling itself Chronus published around 2.3 terabytes of data drawn from at least 25 Mexican public institutions. The material covered an estimated 36.5 million people — close to 28% of the country's population.

It landed three weeks after Mexico published its National Cybersecurity Plan 2025–2030.

What was in it

The institutions named included IMSS-Bienestar, the public healthcare system; SAT, the federal tax authority; the Instituto Nacional de Perinatología; the Morena political party; state health departments and prosecutors' offices in Chihuahua, Tabasco and Tamaulipas; the municipality of Benito Juárez, which contains Cancún; and a private university clinic in Yucatán.

The single largest set came from IMSS-Bienestar: roughly 1.8 TB holding records on 3.15 million people, reportedly including validations drawn directly from RENAPO, the national population registry.

Across the whole release the data types were about as sensitive as a national dataset gets — CURP and RFC identifiers, social security numbers, medical records, voter registration credentials, internal government documents, and biometric material including photographs and fingerprints. Mexico's Anti-Corruption Secretariat opened investigations. No victim notification process was announced.

The government's answer, and why it does not settle anything

The federal digital transformation agency, ATDT, responded the same day. Its position was that this was "not a violation of the authorities' infrastructure" — the data, it said, came from obsolete platforms operated by private-sector third parties rather than from live government systems.

Take that at face value for a moment, because it may well be accurate. It is still not the defence it appears to be.

A decommissioned system that is still reachable, still holds current citizen records, and still accepts working credentials has not been decommissioned. It has been forgotten. The distinction matters to an administrator reading an asset register and matters not at all to the 36 million people whose fingerprints are now in circulation. "Obsolete" describes the software's support status. It says nothing about whether the data inside it is current, and in this case the data plainly was.

The second half of the answer — that the platforms belonged to third parties — is the same shape of argument. Where a vendor holds citizen records on the state's behalf, the state's obligation does not transfer with the hosting. Nor does the harm.

The AI story, and why we are not leading with it

Almost every English-language account of Mexico's 2026 breaches foregrounds something else: a claim that a single operator used AI agents to break into the government.

On 25 February 2026, the Israeli security firm Gambit Security published a report alleging that one unidentified attacker had compromised nine Mexican government organisations between late December 2025 and mid-February 2026, using Anthropic's Claude Code and OpenAI's GPT-4.1, and exfiltrating roughly 195 million taxpayer records from SAT along with data from the Mexico City civil registry, the INE electoral institute, the state governments of Jalisco, Michoacán, Tamaulipas and Estado de México, and Monterrey's municipal water utility. It was covered by well over a hundred outlets.

It has not been corroborated by any Mexican authority, and several have rejected it outright.

  • ATDT issued its denial on 30 January — twenty-six days before Gambit published — stating that no publication of sensitive data attributable to a government intrusion had been identified.
  • SAT said it had reviewed its access logs and found no illegitimate access or anomalous behaviour.
  • INE said there were no corroborated security incidents allowing it to validate the narrative of mass data exfiltration, and that it had not identified the breaches described.
  • The state government of Jalisco also publicly denied that a breach had occurred.

Two further points are worth recording. Gambit announced the report on the same day it announced a $61 million funding round. And an independent researcher has since published evidence that a Mexican federal API was exposing in the region of 186 million citizen records on the open internet, retrievable by anyone who sent a request — no intrusion, no exploit chain, no AI agent required.

We are not in a position to adjudicate this, and we are not trying to. Gambit's report is detailed and may be substantially correct; agencies have incentives to deny, and an absence of evidence in access logs is weaker than it sounds when logging is incomplete. But a reader deserves to know that the most-repeated version of this story rests on a single vendor's unverified account, that the named victims deny it, and that a far more mundane explanation for the same data being in circulation is on the table. Of the many outlets that carried Gambit's claims, very few carried the denials.

Four things worth taking from this

Decommissioning is a security task with an owner and a completion date. Most organisations can name the systems they switched off. Far fewer can prove the data left with them. If a platform is retired, confirm the records were exported or destroyed, the credentials revoked, and the host actually shut down — then take it off the network and off the asset register in that order.

Your third parties' obsolete systems are your exposure. The contract may move the hosting. It does not move the obligation, and it certainly does not move the consequences. Ask suppliers directly what happens to your data when a platform of theirs reaches end of life, and get the answer in writing.

Know what your public interfaces return. An API that answers questions nobody authorised it to answer is a breach that produces no alerts, because nothing abnormal happens. Inventory what is internet-facing, and test what it gives up to an unauthenticated request.

Read breach claims the way you would read any other vendor marketing. Threat research published by a company selling a product is often excellent and often the only account available. It is still a source with an interest. Check whether the named victims have responded, whether anyone independent has reproduced the findings, and whether the described threat happens to match what the publisher sells. That habit costs nothing and would have changed how most of the world read this story.

Sources

#data breach#government#legacy systems#third-party risk#incident analysis