Mexico City Criminalizes Phishing (Digital Fraud): Scope of the New Article 231 Bis and Considerations for Companies

The reform creates a specific criminal avenue against phishing and the spoofing of digital interfaces. Its significance for companies does not arise from a new administrative obligation, but from the need to prevent incidents, preserve evidence, and properly coordinate the legal and technical response.
Regulatory Context
On July 22nd, 2026, the Official Gazette of Mexico City published the Decree adding Article 231 Bis to the Criminal Code for the Federal District. The provision took effect on July 23rd, 2026.
The new offense punishes anyone who, through digital deception consisting of the creation or use of messages, web pages, domains, applications, or any other technological interface that simulates being legitimate, induces a person to disclose, capture, or provide personal, financial, or authentication data, for the purpose of obtaining an improper benefit for themselves or a third party, or of causing harm.
Penalty. Three to six years’ imprisonment and a fine of 200 to 600 Units of Measurement and Update (UMA). Based on the daily UMA value for 2026 ($117.31), the fine currently ranges from $23,462 to $70,386 pesos.
Aggravating circumstance. Penalties will increase by up to one half where the victim is a person with a disability or an elderly person, or where the offense affects a minor. At the upper end, the prison term could reach nine years.

Scope of the New Offense
The journalistic label “phishing” is useful, but the statutory text uses a broader concept: “digital deception.” The wording may cover fraudulent emails and messages, cloned pages, deceptive domains, spurious applications, and other interfaces that appear to belong to banks, retailers, platforms, authorities, or legitimate organizations.
Not every false message or security incident automatically constitutes the offense. To apply the article, the following must be established:
- The creation or use of a technological interface that simulates being legitimate.
- The inducement to disclose, capture, or provide personal, financial, or authentication data.
- The purpose of obtaining an improper benefit or causing harm.
Where, in addition to the capture of information, there are transfers of funds, identity theft, unlawful access to personal-data systems, or other harms, the possible concurrence of separate offenses and liabilities must be analyzed.
Territorial scope. As an offense under ordinary (local) jurisdiction, it applies to acts committed in Mexico City and, under the general rules of the local Criminal Code, to certain acts occurring in another state that produce effects in the capital.
Practical Impact
The new offense broadens the avenues for filing complaints against site cloning, credential capture, and the spoofing of digital channels. It is particularly relevant for financial institutions, technology platforms, e-commerce businesses, service companies, and, more generally, organizations that maintain customer-facing, user-facing, or employee-facing digital interfaces.
An organization may be involved as a victim of brand impersonation, as custodian of evidence, as controller of the compromised data, or as the point of contact with affected individuals and authorities.
Where the event involves personal data, a separate analysis must be conducted to determine whether a security breach also exists and which documentation, mitigation, notification, or data-subject response measures apply under the relevant data protection framework. The criminal complaint does not replace that analysis or the other legal or contractual obligations arising from the incident.
Recommended Action
Organizations should review and, where appropriate, update:
- Protocols to detect and take down domains, profiles, applications, or messages that impersonate their identity.
- The channels through which customers and staff can validate communications and report fraud.
- Mechanisms for filing complaints and coordinating with authorities.
- Clauses with customers and suppliers regarding the use of digital channels.
- Procedures to preserve digital evidence, including headers, URLs, domains, screenshots, logs, dates, devices, and communications.
The information security, privacy, legal, communications, and user-support functions should align their detection, escalation, and response processes with the new offense, paying particular attention to victims whose circumstances aggravate the penalty.

Closing Consideration
A coordinated review of these protocols makes it possible to identify gaps before a digital impersonation translates into financial, reputational, or regulatory harm. Ibarra Gallego’s Privacy and Data Protection team can support organizations in assessing their risk scenarios, updating controls, and defining response and documentation paths suited to their operations.
Sources
Official Gazette of Mexico City, No. 1908, July 22nd, 2026: https://data.consejeria.cdmx.gob.mx/portal_old/uploads/gacetas/ea479ed4b3e22bbbb3081b060f74550e.pdf
Criminal Code for the Federal District, Articles 7, 8, and 11: https://www.congresocdmx.gob.mx/media/documentos/9cd0cdef5d5adba1c8e25b34751cccfdcca80e2c.pdf
INEGI, 2026 UMA value: https://www.inegi.org.mx/temas/uma/
Recent News
Ximena Puente
- Allied Counsel