Mexico City Criminalizes Phishing: Up to Nine Years in Prison for Data Theft
Mexico City, July 23 – In a landmark move to combat the escalating threat of digital fraud, Mexico City has officially criminalized phishing, introducing specific penalties for those who steal personal and financial data through deceptive digital means. The reform, which incorporates Article 231 Bis into the Penal Code for the Federal District, was promulgated by the Head of Government and published in the Official Gazette of Mexico City, taking effect the day after its publication.
This legislative change addresses a long-standing legal loophole that previously forced authorities to prosecute phishing under more general fraud statutes, despite the distinct digital nature of these crimes. The new provision specifically targets individuals who, through digital deception, use messages, websites, domains, applications, or any other technological interface that simulates legitimacy to induce others to reveal personal data, financial information, or authentication credentials for illicit gain or to cause harm.
Penalties and Vulnerable Victims
The new law stipulates penalties ranging from three to six years in prison, in addition to fines of 200 to 600 Units of Measurement and Update (UMA). Significantly, if the victim is a person with a disability, an elderly individual, or a minor, the penalty can be increased by up to 50%, potentially leading to a maximum of nine years in prison. This aims to provide greater protection for the most vulnerable members of society against sophisticated digital attacks.
Phishing Evolves, and the Law Catches Up
Phishing, a form of digital fraud where criminals impersonate trusted entities like banks, companies, or government agencies through fake emails, text messages, phone calls, applications, or websites, has been a persistent problem in Mexico. The objective is to trick victims into sharing confidential information, which is then used to commit fraud or access their accounts.
The inclusion of Article 231 Bis acknowledges the unique characteristics of digital deception and covers various operational methods. The reform’s text extends beyond traditional email phishing to include cloned websites, fake applications, fraudulent domains, and any technological interface designed to impersonate a legitimate institution to obtain sensitive information. This broad definition also encompasses emerging modalities such as smishing (via SMS messages) and vishing (via phone calls), ensuring the law remains relevant as cyber-attacks continue to evolve.
Growing Digital Fraud in Mexico
This legislative update comes at a critical time, as digital fraud continues to rise in Mexico. Data cited by The Competitive Intelligence Unit (The CIU) indicates that approximately 13.5 million people in Mexico have fallen victim to phishing. Of these, 23.1% suffered financial losses, while others lost passwords or personal information that was subsequently used for further crimes.
Recent alerts from the Cyber Police of the Secretariat of Citizen Security have also highlighted phishing campaigns that use pop-up windows to simulate applications like WhatsApp, aiming to obtain users’ verification codes. Once an account is compromised, criminals can access conversations, contacts, and even use the compromised profile to further spread the fraud.
While specialists view this criminalization as a significant advancement in addressing technological crimes, they also point out ongoing challenges related to coordination among authorities and the effective enforcement of the norm against new and evolving forms of information theft.
Impact on Mexico City Residents
The new law is expected to provide a stronger legal framework for prosecuting cybercriminals and deterring future phishing attempts, thereby enhancing the security of digital transactions and personal data for Mexico City residents. Authorities emphasize the importance of public awareness and caution when engaging with digital communications and websites.
This move positions Mexico City at the forefront of legislative efforts to combat cybercrime in the region, offering a more robust defense against the sophisticated tactics employed by digital fraudsters.