Mexico's World Cup Moment: A New Cyber Plan Meets Its First Big Test
The FIFA World Cup 2026 is stress-testing Mexico's seven-month-old National Cybersecurity Plan before the country even has a proper cybersecurity law.

Key points
- Mexico adopted its National Cybersecurity Plan in late 2024, roughly seven months before the FIFA World Cup 2026 kicked off, according to a June 25 analysis by threat intelligence firm Recorded Future.
- Latin American organisations suffered an average of nearly 3,150 cyberattacks per week in May 2025, a 13% rise year over year.
- An AI-assisted attack hit at least nine Mexican government agencies in 2025, stealing data but failing to reach operational-technology systems, the machinery running power grids and similar infrastructure.
- Mexico still has no single dedicated cybersecurity law, only overlapping regulations across different government bodies.
- Recorded Future rated Mexico's digital-security risk as "medium" before the tournament, but noted attacks have risen during the event.
Mexico is hosting three FIFA World Cup 2026 stadiums. That alone raises the country's profile. But the tournament is doing something else: forcing a stress test of a national cybersecurity plan that barely had time to leave the printer.
The plan, drafted by Mexico's Digital Transformation and Telecommunications Agency and adopted around seven months ago, sets targets for 2025. Those include building a National Cybersecurity Centre to track threats and completing a fuller national strategy by the end of the third quarter. Progress is real. So is the pressure.
"Cyber risk around the tournament is likely to be elevated, as the event creates a target-rich environment for ransomware groups" (ransomware is malicious software that locks an organisation's files until a payment is made), "hacktivists, fraud actors, credential thieves, and disinformation networks seeking financial gain or disruption," Recorded Future wrote in its June 25 report.
What does this mean for ordinary people attending or following the tournament?
Fans in Mexico City and Guadalajara should expect criminals to target booking systems, ticketing apps, and public Wi-Fi networks. Phishing messages, where criminals send fake emails or texts to trick people into handing over passwords or card details, spike reliably around major sporting events. We reported in June that fraud infrastructure was pre-staged months before kickoff, with phishing kits and lookalike domains built well ahead of the opening match. Any message about a ticket refund or an urgent account action tied to the World Cup deserves suspicion: go directly to the official site rather than clicking a link.
The Mexican government set up the "Kukulkán Plan" to coordinate security across host cities, covering information-sharing with the United States and Canada as well as FIFA. Risk exercises were run. Stadium perimeters were reinforced. The effort is genuine.
Yet gaps remain. NYU adjunct professor and Latin American telecoms expert José Felipe Otero notes the plan says little about protecting industrial and operational systems. It also does little to address third-party suppliers and the small businesses that make up most of Mexico's economy.
Legislation is another weak point. Mexican financial consultancy Nader Hayaux & Goebel found that several cybersecurity bills have been submitted to Congress, none of them enacted. The country still relies on a patchwork of laws spread across agencies.
Organisations across Latin America were hit with close to 3,150 cyberattacks per week in May 2025, up 13% from the year before, according to Recorded Future's June report, first covered by Dark Reading. Mexico is not the only target, but it's the one hosting the stadiums.
Mexico won't fix structural gaps before the final whistle. Watch whether a significant incident during the tournament forces the legislative conversation that years of proposals haven't.



