Caja Popular Mexicana
| Primary URL | Location | Industry | www[.]cajapopularmexicana[.]com[.]mx |
Country
Mexico
|
Financial Services
|
|---|
Profile
Caja Popular Mexicana is a Mexican financial cooperative headquartered in Mexico that provides savings and loan services to its member base under a cooperative ownership model where members are both customers and owners. The institution serves over three million members, giving it a notable presence in the Mexican financial landscape and indicating a substantial scale of operations. As a cooperative, its governance structure is member‑driven, with decision‑making processes designed to reflect the interests of those who hold accounts and utilize its services. The organization maintains a network of physical branches that support in‑person transactions alongside digital platforms that support online services. Its core offerings include savings accounts and loan products aimed at meeting the financial needs of individuals and small enterprises within its membership. The cooperative operates under the supervision of Mexican financial regulators, which oversee compliance with banking standards, consumer protection rules, and prudential requirements applicable to deposit‑taking institutions.
On October 6, 2023, Caja Popular Mexicana was targeted by a ransomware attack carried out by the BlackCat group, which encrypted critical data and disrupted both branch operations and online services for its more than three million members. The attack was characterized as a data‑seizure for ransom rather than an attempt to steal money, and no direct monetary losses to customers were reported as a result of the incident. During the ensuing recovery period, service interruptions persisted for credit products and new account access, while core banking functions were gradually restored through coordinated efforts. Regulatory authorities collaborated with the cooperative on containment measures, forensic analysis, and the implementation of remedial actions to address the breach. Cybersecurity experts who examined the event suggested that the severity of the disruption pointed to potential shortcomings in the institution’s security maturity, indicating areas where defensive controls could be strengthened. Although the total financial impact on the organization has not been disclosed, the episode has prompted ongoing engagement between the cooperative, regulators, and security specialists to enhance resilience against future cyber threats.
