Ransomware victim disclosure
← All victimsSociedad Hipotecaria Federal
listed as gob.mx · Claimed by LockBit · listed 5 months ago
Status timeline
- ListedJan 21, 2026
- Data leakeddate unknown
At a glance
- Group
- LockBit
- Status
- Data leaked
- Country
- Mexico
- Sector
- Public Sector
- Listed on leak site
- Jan 21, 2026
About the victim
AI dossier — public-source company profileSociedad Hipotecaria Federal (SHF) is a Mexican government development bank founded in 2001 and headquartered in Mexico City. It operates under the public sector to promote mortgage credit and housing finance, supporting the development of the primary and secondary mortgage markets in Mexico. As a federal entity, it serves as a key financial institution for housing policy.
- Industry
- Government Mortgage & Housing Finance
- Address
- Mexico City, Mexico
- Founded
- 2001
Attack summary
Severity: critical — The victim is a federal government mortgage bank handling regulated financial and housing data at national scale; data_published status confirms exfiltration and public release of potentially sensitive PII and financial records from a critical public-sector financial institution.LockBit claims to have compromised Sociedad Hipotecaria Federal and has published data associated with the attack, with the disclosure status marked as data_published, indicating exfiltration and release of data.
Data the group says was taken
AI dossier — extracted from the leak post- Government mortgage records
- Financial institution data
- Internal documents
- Potentially sensitive citizen/borrower PII
What the group claims
Founded in 2001 and headquartered in Mexico City, Mexico, Sociedad Hipotecaria Federal is a governme...
Sources
- Victim sitegob.mx
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

