Ransomware victim disclosure
← All victimsSociedad Hipotecaria Federal
listed as gob.mx · Claimed by Lockbit5 · listed 5 months ago
Status timeline
- ListedJan 21, 2026
- Data leakeddate unknown
At a glance
- Group
- Lockbit5
- Status
- Data leaked
- Country
- Mexico
- Sector
- Public Sector
- Listed on leak site
- Jan 21, 2026
About the victim
AI dossier — public-source company profileSociedad Hipotecaria Federal (SHF) is a Mexican government development bank headquartered in Mexico City, founded in 2001. It operates under the public sector to promote the development of mortgage markets and housing finance in Mexico. As a federal entity, it provides guarantees, financing, and financial instruments to support affordable housing access for Mexican citizens.
- Industry
- Government Development Banking & Mortgage Finance
- Address
- Mexico City, Mexico
- Founded
- 2001
Attack summary
Severity: critical — The victim is a Mexican federal government development bank handling mortgage and housing finance data. Data published status confirms exfiltration of what is likely regulated financial and PII data at scale from a government institution, meeting the critical threshold.LockBit 5 claims to have attacked Sociedad Hipotecaria Federal and has published data (disclosed status: data_published), indicating exfiltration of internal data from this Mexican federal government financial institution.
Data the group says was taken
AI dossier — extracted from the leak post- Government financial records
- Mortgage and housing finance data
- Internal documents
- Employee or customer PII
What the group claims
Founded in 2001 and headquartered in Mexico City, Mexico, Sociedad Hipotecaria Federal is a governme...
Sources
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

