CoverageReportsCalendarReproducibilityContactVerlumia Intelligence ES EN FR
verlumia Support
Current edition: July 2026 · sealed See the edition archive →

Flagship report · Instituto Verlumia · Mexico

Verlumia Report
July 2026 Edition

The measured reading of the risk affecting citizens — computed from sealed official data, with the person at the center, not the company. Citizen Cyber-Risk Index (ICC).

75.8
High · /100 · citizen fraud Grade A · measured truth

In Mexico a citizen fraud case is reported every ~4 minutes — and July marks the highest reading of 2026.

First measured ICC figure for Mexico: computed from the official RNID/SESNSP series (139 months, 2015–2026) under the ICC/1.4 methodology, with auditable lineage and a hash per figure. Scope: one country. 2 of the ICC's 4 dimensions measured.

Executive summary

What this edition measures

The July 2026 findings for Mexico — measured first, context after, never at the same weight.

  • Citizen fraud is at its highest reading of 2026. The measured index stands at 75.8/100 ("High") in July, over 10,995 investigation case files reported (RNID/SESNSP), in the "High" band continuously since March. Grade A · measured truth.
  • Cyberbullying is persistent, not rising. 21.0% of internet users in 2024 (MOCIBA/INEGI), stable around 21% since 2021 (CI90 [20.5–21.5]). Grade B · survey.
  • We measure 2 of the ICC's 4 dimensions. Data exposure and Defense remain in incubation — declared, not estimated. The gaps are shown on purpose.
  • The nowcast is not the headline. The predictive annex (54.9) uses a proxy with weak predictive power; it is shown for transparency, never as the headline figure.
  • Third-party context is clearly separated. The threat landscape is included as reference (grade C), never as a Verlumia measurement — and without teal.
Panorama

The threat environment

Mexico does not measure in a vacuum: it operates in one of the most active threat environments in the region. This panorama is third-party context —not a Verlumia measurement— and is distinguished by design from our figures.

Context · reference · grade C · no teal

Threat landscape, from third-party sources. It helps situate the measured reading; it does not enter the index nor is it painted teal.

2ndmost-affected country in the region by ransomware (~237 thousand attempts in 12 months)Kaspersky 2025
~4 / seccyberattacks against Mexico on averageKaspersky 2025
1,000 M+credentials of people and organizations in LATAM found in breaches and stealer logs — direct fuel for fraud and impersonationCrowdStrike · LATAM 2025

Ransomware remains the most disruptive form of attack; also concerning is the use of AI by attackers —kits like WormGPT or FraudGPT cheapen campaigns— and the abuse of legitimate tools already present in the target environment to go unnoticed. Cybersecurity spending is growing, but investment does not keep pace with digitalization: measuring risk in a neutral, comparable way is, in itself, a defense.

The pillars

What we measure today

Citizen fraudA
75.8High

Official RNID/SESNSP count · 10,995 case files · Jul 2026 · monthly. In the "High" band continuously since March 2026. The registry does not split by channel: it includes digital fraud, it is not limited to it. It counts what is reported — there is under-reporting.

CyberbullyingB
21.0%stable

INEGI/MOCIBA survey · CI90 [20.5–21.5] · 2024 · annual. Persistent around 21% since 2021 — stability, not a rise. Base: internet users 12+, not total population.

The fraud series over time

Measured series end to end, 139 months (2015–2026). The headline is the official datum; the nowcast is shown as an annex, never as the headline.

Headline index (measured, grade A) Nowcast (annex, not headline)

Teal only in grade A (fraud). Cyberbullying is a survey estimate (grade B) and is measured separately; it is not composed with fraud into a single figure.

The gaps

What we don't measure yet

Data exposuregap

In incubation: no stable official source after the dissolution of INAI. Declared, not estimated.

Defensegap

In incubation: awaiting a source that meets the criterion. Declared, not estimated.

2 of the ICC's 4 dimensions are measured today. The gaps are shown on purpose: they are comparable country to country.

In incubation (measured, not yet comparable). A sealed baseline of direct cyber-harm exists —extortion by other means and identity impersonation, grade A, ACTA-037—, measured since 2026 but without a comparable series yet. It will be published once enough time has passed to support comparison, never before.
Citizen layer

The impact on people

Cyber-risk does not end at the company: it affects people's finances and dignity. Our cyberbullying measurement anchors this layer; the bank-complaint figures are attributed official context, not a Verlumia measurement.

Cyberbullying reached 21.0% of internet users in 2024 —about 18.9 million people (MOCIBA)— and fraud victimization is, according to ENVIPE, the most frequent crime in the country.

Context · reference · grade C · no teal
2.48 Mcomplaints of possible bank fraud (1st half 2025, +5.2% year over year)CONDUSEF
$10,714 Mamount claimed for fraud (pesos); banks refunded roughly a quarterCONDUSEF
+77%rise in identity-theft fraud in Mexico (2024 vs 2023) — the flip side of stolen credentialsCONDUSEF
How to read it

The reading key

Grade A · measured truth (teal)

Official count of facts. The only grade painted teal.

Grade B · survey

Sample estimate with its stated confidence interval. No teal.

Grade C · reference

Third-party indices and context (the whole panorama and the bank complaints). No teal. A country's institutional capacity is not the same as measured citizen protection.

Regulatory context

The framework took a leap

  • General Cybersecurity Policy for the Federal Public Administration (Dec 2025). Published in the DOF and in force; it unifies mandatory criteria for the Federal Public Administration.
  • National Cybersecurity Plan 2025–2030 (Dec 2025). The country's first specialized framework; it contemplates a National Strategy and a future General Law.
  • Cybersecurity Law bill, in the Senate. It would create a National Agency and an incident-reporting regime; publication expected toward the second half of 2026.

Incident reporting will stop being voluntary and accountability will become enforceable. Demand accelerates for a credible measure of risk — a neutral yardstick that neither the regulator nor a vendor can offer without conflict.

The case record

The lineage of every figure

Every measured figure in this report is generated from sealed data —not typed— and carries its lineage, so it is reproducible. The full case record per figure lives in its sub-index:

PillarSourceVersionGradeSealed edition · lineage
Fraud RNID · SESNSP ICC/1.4 A Jul 2026 · serie_retroactiva_fraude.csv 4651ab20… · methodology.yaml 27b0e9d3… · anchor 90ad6270… · commit ca52e1f · ACTA-023/024/022 · see full case record →
Cyberbullying INEGI · MOCIBA ICC/1.4 · mociba 0.2.0 B · CI90 2021-2024 · serie_acoso_2021-2024.csv 8DF2B91A… · connector 57e8c11b… · ACTA-030/027/029 · see full case record →
Annex, not headline (principle 5). The fraud nowcast for Jul 2026 (54.9, "Elevated") uses a proxy of weak predictive power (0.39 correlation with the official count, ACTA-021). It is shown for transparency; it is never the headline.

Check it yourself. Every figure in this report has its downloadable reproduction package: the sealed output, the exact methodology of that version, the official (open) input and the hashes to verify byte for byte. The 75.8 headline can be reproduced with a calculator from the SESNSP datum.

Measure to protect, not to surveil. This index doesn't only measure whether an organization is secure; it measures whether it protects the people who depend on it. That's why it never incorporates personal data.

Scope and governance

What this reading is — and is not

The headline of each report is the strongest measured figure of that country —here, fraud—, not a fixed pillar; and it is never compared numerically with another country without its own record. Comparability rests on identical criteria, not on direct numerical comparisons across countries. A regional report would be a separate, later publication.

About this edition. July 2026 edition · Mexico · sealed and immutable. The ICC-fraud figure is real, computed under the public ICC/1.4 methodology with auditable lineage, and approved by Jorge A. Ramírez Vargas as signatory. Any third party with the same inputs and methodology reproduces the figure. No valuation, no ARR, no "leader." Scope: one country. Governed by the five guiding principles + an ethos of non-fabrication and auditability.

Sources

SESNSP · RNID (crime incidence, common-jurisdiction (fuero común) 2015–2026, fraud series — the ICC anchor) · INEGI · MOCIBA 2024 · ENVIPE 2025 · CONDUSEF (complaints; identity theft 2024). Third-party context (grade C): Kaspersky 2025 · CrowdStrike (LATAM Threat Landscape 2025). Framework: DOF (General Cybersecurity Policy for the FPA, Dec 2025) · National Cybersecurity Plan 2025–2030. Context figures are third-party and do not constitute a Verlumia measurement.