RansomHub claimed 313 GB stolen from Mexican government legal office

Organization
Government of Mexico (gob.mx)
Exploit
Ransomware
Industry
Government

On November 15, 2024, the RansomHub extortion group added the Mexican government's gob.mx domain to its dark web leak site and claimed it had taken 313 gigabytes of data. Reporting identified the affected body as the Consejeria Juridica del Ejecutivo Federal, the legal counsel's office of the federal executive branch, rather than the federal web portal as a whole.

The group said the stolen files covered contracts, insurance records, financial documents and confidential material. Samples posted with the listing showed government staff names, job titles, workplaces, phone extensions, email addresses, RFC tax reference numbers and headshots, along with scanned contracts dated 2023. Cyber Daily reported that one document was addressed to Mario Gavina Morales, the government's director of information technology and communications.

RansomHub gave the government ten days to pay an undisclosed ransom before publishing the files. The gob.mx site itself stayed online and there was no public indication that systems had been encrypted.

President Claudia Sheinbaum said the government was looking into the claim, telling reporters she had asked for a report on the alleged hack. Officials did not confirm the volume or content of what was taken, and no independent verification of the 313 GB figure was published. RansomHub had posted its first victim in February 2024, was the subject of a joint FBI and CISA advisory in August 2024 and was ranked among the most prolific ransomware operations of that year.

Sources