Proofpoint Warns of Expanding Cyberattacks Targeting Mexico | #cybercrime | #infosec


Proofpoint researchers reveal that two prolific cybercrime groups are expanding their attacks against Mexican organizations and consumers through tax scams, fake invoices, and fraudulent business emails.

 

Mexico is a prominent target for financially motivated cybercrime as established threat actors expand their email campaigns using familiar business and government communications. New research from Proofpoint found that two prolific cybercriminal groups targeted Mexican organizations and consumers with large-scale campaigns designed to steal credentials, deliver malware and gain unauthorized access to devices.

Proofpoint researchers observed the activity throughout July and August 2026, identifying campaigns that relied on convincing lures involving companies, government entities, tax matters, invoices, and legal notifications. The tactics reflect an increasingly common challenge for organizations: malicious messages are designed to resemble routine business communications rather than obvious phishing attempts.

“Cybercriminals continue to adapt their tactics to appear increasingly legitimate, making malicious emails look like the routine business communications that employees receive every day,” says Luis Isselin, Country Manager, Proofpoint Mexico.

TA2725 Targets Mexico With 275,000 Malicious Emails

One of the most active groups identified by Proofpoint, TA2725, sent approximately 275,000 malicious emails targeting Mexico in a single campaign between July 19 and July 24, 2026. The group primarily used fraudulent business communications to persuade recipients to open malicious files or click on deceptive links. The messages included fake DocuSign notifications, CVs, tax invoices, court summonses, and consumer complaints.

TA2725 also expanded its activity into credential phishing, seeking usernames and passwords alongside its malware campaigns. Proofpoint says the group uses techniques designed to limit the delivery of its malicious payloads to intended countries. This approach can make campaigns more difficult to identify because the malicious content is not necessarily delivered indiscriminately across all recipients.

The combination of malware delivery and credential theft can create multiple opportunities for attackers after an initial interaction. Compromised credentials can provide access to corporate systems, while malware can enable information theft, remote access, and additional fraudulent activity.

TA4922 Expands Operations Into Mexico

Proofpoint also identified a significant change in the activity of another prolific threat actor, TA4922, which expanded its operations to target Mexico for the first time. TA4922 differs from groups that depend on a single malware family or narrowly defined objective. According to Proofpoint, the actor uses a broad range of malware, credential theft techniques and fraud schemes.

Its campaigns frequently use tax-related themes to make malicious messages appear legitimate. The group also increasingly relies on legitimate cloud platforms and file-sharing services to host malicious files, creating another layer of difficulty for users and security teams attempting to distinguish malicious activity from normal business operations.

The use of trusted cloud infrastructure is particularly relevant for organizations that rely heavily on cloud-based collaboration and document-sharing services. A message that directs an employee to a familiar type of platform can appear less suspicious than one containing an unfamiliar or clearly malicious domain.

“Organizations and individuals in Mexico should be especially cautious about unexpected emails related to invoices, taxes, legal notices, or requests to share documents, particularly when they are asked to download files or enter login credentials.,” says Isselin.

Email Security Becomes a Business Risk

The activity identified by Proofpoint illustrates how financially motivated cybercriminals are adapting their delivery methods to the environments in which employees already operate. Once malware is installed, attackers can potentially steal sensitive information, capture credentials, maintain remote access to compromised systems, commit financial fraud, or sell access to other criminal groups.

For Mexican organizations, the threat extends beyond the initial phishing message. A successful interaction can become an entry point for credential compromise, malware infection or further unauthorized activity across business systems.

Proofpoint recommends that organizations and users remain cautious with unsolicited emails involving invoices, taxes, legal notices, employment applications, and requests to share documents. “Recipients should verify senders before opening unexpected attachments or following links and should avoid entering corporate or personal credentials after accessing unsolicited email links,” says Isselin. 

Multifactor authentication can also reduce the impact of stolen passwords, while updated operating systems and security software can help limit malware infections.





Click Here For The Original Source.

——————————————————–

..........

.

.