2026 BePrime (MX) — ~12.6GB leak; admin accounts without MFA; client infrastructure exposure
Data compromised
Internal credentials, infrastructure and surveillance-management context, and client project artifacts per OSINT and specialist press—scope varies
Technical writeup
In mid-April 2026, DataBreaches.net, DigitalShield, and industry blogs described a large-scale compromise of BePrime, a Nuevo León, Mexico–based cybersecurity services firm, with public narratives citing roughly 12.6 GB of internal material and administrator accounts lacking multifactor authentication. Reported or alleged exposure included network and surveillance-console context (e.g., Meraki-style API material), plaintext credentials, and client-facing security workpapers in some writeups, alongside controversy over the firm’s response to journalists. Victim numbers were not standardized; treat as a services-sector supply-chain style incident with potential downstream client impact.
Root cause
Account takeover on high-privilege admin paths; absent MFA called out in reporting