SESNSP · RNID — headline. The national registry of fraud investigation case files.
CONDUSEF — contrast. Its complaints index (open CSV) is checked once a year against the trend.
Sources & Criteria
Every number in the index comes from an official source we name. And we do something unusual: we also publish the sources we evaluated and decided not to use, with the criterion that left them out.
Today three Mexican state institutions feed the index: the SESNSP, INEGI and CONDUSEF. No figure comes from anything else —not a market estimate, not artificial intelligence—. And unlike almost everyone, we also publish what we evaluated and did not use: that is the part that gives certainty to what we do publish.
Every figure you'll see has a clearly identified source. This is where each one comes from:
SESNSP · RNID — headline. The national registry of fraud investigation case files.
CONDUSEF — contrast. Its complaints index (open CSV) is checked once a year against the trend.
The fraud number is the official count of investigation case files that SESNSP publishes each month. It is a counted fact, not an estimate — that's why it's the only one painted teal.
INEGI · MOCIBA — headline. The Cyberbullying Module, the national survey with which INEGI measures how many people experienced cyberbullying. Comparable series 2021–2024.
The cyberbullying figure comes from MOCIBA, a survey. That's why it's an estimate with a stated margin, not a count — and it's not painted teal. Saying "survey" instead of "count" is part of the honesty.
No stable official source that meets the criterion, after the wind-down of INAI and the IFT.
These two dimensions still have no reliable source that can support measurement. We say so openly instead of forcibly filling them in: a declared gap is more honest than an invented number.
One more dimension, direct cyber-harm (remote crimes: extortion by other means and identity impersonation), is already measured from its 2026 baseline (grade A, RNID) but is not yet published: the category is new in the official registry and has no comparable series. It will be published as ICC/2.0 once enough time has passed to support a meaningful comparison. To measure is not to publish.
Being a government source is necessary, but not enough: to feed a figure, a source must also be reproducible and comparable. It enters only if it meets all five inclusion criteria; it is set aside —and the reason documented— if it meets any exclusion criterion.
The same official institution may enter the index with one product and stay out with another. The deciding factor is never the institution's name or prestige, but a concrete question about the file it publishes.
It publishes two different things. Its complaints index comes in an open, processable file: it can be sealed with its digital fingerprint and recomputed anytime — that's why it enters, as an annual fraud contrast. Its quarterly cyber-fraud bulletin comes as a PDF only: there is no series to anchor or recompute — that's why that product does not enter the data, even though it comes from exactly the same body. What separated one from the other was not CONDUSEF; it was whether that specific file can be audited.
The source that can be reproduced enters, not the one with the better letterhead.
INEGI has run its cyberbullying survey several times. The 2021 to 2024 editions ask about the same population and with the same time window: they are comparable to each other, so they form the series we publish. Those of 2015 to 2017 were experimental exercises with a different base; mixing them would break the year-over-year comparison. It's not that they are "bad" — it's that they don't line up. That's why the same survey enters with some editions and not others.
A figure is only worth something if it can be compared with last year's.
INAI recorded personal-data breaches — precisely the Exposure dimension we lack today. But the body was dissolved in 2025: there is no longer anyone producing that data continuously. Here a product is not set aside for its format; the entire source is lost. That's why Exposure remains a declared gap —open, in plain sight— until another institution takes up that measurement. It is the only case in which a whole body is set aside.
We measure series, not stray snapshots; without continuity there is no series.
Three bodies, three different questions — can it be reproduced? can it be compared over time? will it keep existing? None is answered by looking at the institution's logo. That is, exactly, the criterion in action.
The real registry, sealed in v1.0 of the criterion (ACTA-031). The same institution may feed the index with one product and be set aside on another: what is evaluated is the specific file, not the institution's name.
.xls) + unverified universe.Every figure and decision at Verlumia is governed by five guiding principles. This register puts the third principle into practice: auditability runs end to end, from source selection to the figure — shown as method, "this we use, this we don't, and why," never as a superlative. The same criterion applies in every country that replicates the index. Want the explained version? Read "Which sources we use and which we discard" (grade C · outreach).