Employees at Mexico’s IMSS and SAT illegally disclosed personal data

07.10.2026

Two cases of misuse of personal data by employees of Mexican government agencies have come to light. The incidents involving the Mexican Social Security Institute (IMSS) and the Tax Administration Service (SAT) are described in the Second Activity Report of the Ministry of Anti-Corruption and Good Governance (SABG), which covers investigations and audits conducted in the public sector from September 2025 to June 2026.

At IMSS, an employee had legitimate access to the Modelo Preventivo de Enfermedades Crónicas (MPEC) system, which processed data on insured individuals. The employee copied the database and later published it online. The case materials were referred to the competent authorities to assess the employee’s possible administrative and criminal liability.

A similar situation occurred at SAT. A public servant also had legitimate access to personal data but used it for purposes unrelated to official duties. Information relating to one taxpayer was extracted, disclosed, and later used as a sample in an offer to sell data. A joint forensic investigation supported by Strategic Alliance Business Group identified the employee and confirmed their involvement in the incident, after which the internal control department filed a criminal complaint.

These two cases highlight a characteristic feature of insider threats. Employees do not necessarily need to bypass security controls or hack a system if they already have legitimate access to information. The risk emerges when that access is misused to copy, extract, or transfer data in violation of established security rules."

DLP systems help reduce the risk of such incidents by monitoring the activity of employees who work with sensitive information and detecting attempts to copy or transfer data through various channels. Next-Gen DLP Risk Monitor takes an even broader approach, extending its data loss prevention functionality with an advanced e-forensics toolset. This is crucial for exposing cases of corporate fraud just in time and investigation of violations. Security specialists can reconstruct the sequence of events, determine what information was affected, and collect evidence for ongoing investigation or reports for regulators.


ABOUT SEARCHINFORM

SearchInform is an information security and risk management product vendor as well as an MSS provider. The company's clients are more than 4000 companies in 20+ countries. Today, the team has products and services for comprehensive protection against insider threats at all levels of corporate information systems: FileAuditor (the DCAP class solution); DLP system with extended functionality; Risk Monitor (advanced platform for internal threat mitigation); SIEM system, Information Security outsourcing service.

Explore SearchInform’s full cybersecurity product portfolio, including DLP, DCAP, and insider risk management solutions.