Menu
Browse
Date:

Dec 2022

Location:

Mexico

Summary

A cyberattack targeted the Instituto de Información Estadística y Geográfica del Estado de Jalisco and the state Congress, compromising servers and disrupting operations. The institute's website became inaccessible due to the breach, while the legislative body experienced a ransomware infection named "Play" that encrypted data across 14 servers, affecting parliamentary records, procedural documents, and accounting systems. Operational continuity was maintained through temporary tools, though the full scope of data loss—whether deletion or theft—remained undetermined. Authorities noted potential links to cybercriminal groups active in other regions, including Argentina. The incident highlighted systemic vulnerabilities, with the institute reporting over 29 billion cyberattacks against its systems in a seven-month period prior.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On December 5, 2022, the Instituto de Información Estadística y Geografía (IIEG) of Jalisco publicly disclosed a cyberattack that disabled its website, forcing it into prolonged maintenance. The attack was first detected on the evening of December 5, though preliminary evidence suggested the compromise may have originated earlier. The IIEG stated it had identified potential suspects through social media account analysis but could not establish communication with the perpetrators or determine their motives. This incident disrupted public access to statistical and geographic information managed by the institute, creating administrative burdens and diverting taxpayer resources toward incident resolution. The IIEG emphasized that its systems had been heavily targeted historically, enduring over 29.284 billion cyberattacks between May and November 2021 alone according to the General Directorate of Information Technologies.

Cyber Incident Image

Separately, the Jalisco State Congress reported a ransomware attack during the weekend of December 2-4, 2022, affecting 14 of its 17 legislative servers. Legislative officials confirmed the intrusion began with a breach of their computing systems, rendering stored data inaccessible. The "Play" ransomware variant encrypted parliamentary records including session minutes, procedural documents, legislative gazettes, legal demands, and accounting files. Systems personnel detected the encryption malware but could not ascertain whether data was exfiltrated or permanently destroyed. Temporary workarounds enabled legislative operations to continue while forensic investigations proceeded. Congress leadership filed a formal complaint with the State Prosecutor’s Office and noted connections to cybercriminal activity targeting government entities in Córdoba, Argentina. No ransom demands or recovery timelines were disclosed publicly during the initial response phase.

Sources
Sources available to members
1 source