• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer

My TechDecisions

  • Best of Tech Decisions
  • Topics
    • Video
    • Audio
    • Mobility
    • Unified Communications
    • IT Infrastructure
    • Network Security
    • Physical Security
    • Facility
    • Compliance
  • RFP Resources
  • Resources
  • Podcasts
  • Project of the Week
  • About Us
    SEARCH
Network Security, News

After a Hack Costs Mexican Banks $20M, Banking Decision Makers Are Tightening Cybersecurity

Mexican banks are learning how to strengthen defenses against cyberattacks, and are ready to ward off future hacks.

April 1, 2019 Jessica Messier Leave a Comment

Mexican cybersecurity experts and bank customers are rethinking how to keep bank security airtight, especially after a 2018 cyberattack cost Mexican banks $20 million, Wired says.

The attack, which took place a little over a year ago, was possible due to “security holes in the targeted bank systems,” “sloppy and insecure network architecture within the Mexican financial system,” and “security oversights in in SPEI, Mexico’s domestic money transfer platform run by central bank Banco de México, also known as Banxico.” The attackers were thought to have been working for the North Korean state-sponsored group Lazarus, Wired says.

While it’s unclear how hackers specifically broke into the banks’ network, speculations suggest that attackers might have accessed internal servers from the public internet, conducted phishing attacks on employees, compromised employee credentials, and other methods. Wired also says that the SPEI app had “bugs and lacked validation checks,” which made it easy to breach and even “slip bogus transactions through.”

Wired says that attackers may have even gotten in because “the networks also weren’t well segmented, meaning intruders could use that initial access to penetrate deep into banks’ connections to SPEI and, eventually, SPEI’s transaction servers, or even its underlying code base.” This suggestion is especially problematic because attackers may have been able to access, track, and manipulate customers’ data.

Takeaways from decision makers:

While this particular breach cost Banxico millions and millions of dollars, it sparked a wakeup call for its cybersecurity personnel. Since the attack, Banxico has tightened it policies and controls around fund transfers, and established “minimum cybersecurity standards for Mexican banks that link their systems to SPEI,” Wired says.

Plus, Mexican banking institutions are talking to each other now, and sharing knowledge about these types of breaches to prevent future attacks. “The main problem on cybersecurity is that we don’t share knowledge and information or talk about attacks enough. People don’t want to make details about incidents public,” penetration tester and security advisor Josu Loza, who was an incident responder in the wake of these attacks, said at the recent RSA Security Conference.

However, Loza encourages decision makers in the banking space to share information with each other and invest in cyber defense and “network hygiene” to prevent the next slew of attacks, which are inevitable. “[T]he most important thing is the change of mind that makes business users want to pay for better security” he said.

If you enjoyed this article and want to receive more valuable industry content like this, click here to sign up for our digital newsletters!

Tagged With: Cyber Attacks, Cyber Security

Related Content:

  • Cloud, SASE, Aryaka How the Cloud is Redefining Media Production and…
  • Singlewire Software mass notification interview Singlewire Software on Mass Notification Solutions
  • URI catchbox 1 Catchbox Plus: The Mic Solution That Finally Gave…
  • Engaging virtual meeting with diverse participants discussing creative ideas in a bright office space during daylight hours Diversified Survey: Workplace AV Tech is Falling Short,…

Free downloadable guide you may like:

  • Download TechDecisions' Blueprint Series report on Security Awareness now!Blueprint Series: Why Your Security Awareness Program is Probably Falling Short

    Learn about the evolution of phishing attacks and best practices for security awareness programs to ensure your organization is properly prepared to defend against them in this report from TechDecisions' Blueprint Series.

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest Downloads

Practical Design Guide for Office Spaces
Practical Design Guide for Office Spaces

Recent Gartner research shows that workers prefer to return to the office for in-person meetings for relevant milestones, as well as for face-to-fa...

New Camera Can Transform Your Live Production Workflow
New Camera System Can Transform Your Live Production Workflow

Sony's HXC-FZ90 studio camera system combines flexibility and exceptional image quality with entry-level pricing.

Creating Great User Experience and Ultimate Flexibility with Clickshare

Working and collaborating in any office environment today should be meaningful, as workers today go to office for very specific reasons. When desig...

View All Downloads

Would you like your latest project featured on TechDecisions as Project of the Week?

Apply Today!

More from Our Sister Publications

Get the latest news about AV integrators and Security installers from our sister publications:

Commercial IntegratorSecurity Sales

AV-iQ

Footer

TechDecisions

  • Home
  • Welcome to TechDecisions
  • Contact Us
  • Comment Guidelines
  • RSS Feeds
  • Twitter
  • Facebook
  • Linkedin

Free Technology Guides

FREE Downloadable resources from TechDecisions provide timely insight into the issues that IT, A/V, and Security end-users, managers, and decision makers are facing in commercial, corporate, education, institutional, and other vertical markets

View all Guides
TD Project of the Week

Get your latest project featured on TechDecisions Project of the Week. Submit your work once and it will be eligible for all upcoming weeks.

Enter Today!
Emerald Logo
ABOUTCAREERSAUTHORIZED SERVICE PROVIDERSYour Privacy ChoicesTERMS OF USEPRIVACY POLICY

© 2025 Emerald X, LLC. All rights reserved.