Unverified claim — July 14, 2026: Threat-intelligence reporting flagged a Telegram post advertising approximately 8 million records allegedly tied to the Government of Mexico City (CDMX). Ciudad de México had not issued a matching public breach confirmation at indexing time. Treat the row count as actor marketing until a regulator or city agency validates it.
What was advertised
According to CyberX, the Telegram listing cites personal information, residential addresses, identification numbers, birth certificate details, CURP, electoral and geographic records, and additional citizen-related fields.
Separately, DailyDarkWeb documented early July 2026 underground posts claiming access to CDMX Secretariat of Administration and Finance (SAF) systems. That thread may or may not be the same seller as the ~8M advertisement.
Mexico's 2026 breach background
CDMX does not exist in a vacuum. January 2026 saw the Chronus Group hacktivist wave against federal agencies; July brought World Cup tourism and a new national cybersecurity plan fighting for attention. Local government SAF systems hold payroll, vendor, and taxpayer-adjacent rows that fraud crews prize for impersonating municipal offices.
When a city of nine million people hears "millions of records," the useful question is not "is the number real?" but "what phishing template does this enable tomorrow?"
What to do if you live or pay taxes in CDMX
- Do not download forum dumps—they may contain malware and re-victimize people whose data is already exposed elsewhere.
- Skeptical of SMS or WhatsApp citing real RFC or CURP fragments or municipal fine amounts; go to cdmx.gob.mx or official apps directly.
- Enable bank transaction alerts if tax-refund or CLABE-change scams spike after forum posts.
Canonical record
Government of Mexico City 2026 forum claim on BreachHistory — unverified.
Sources: CyberX, DailyDarkWeb, CDMX official site.