Select your language

Technical failure or cyberattack? How vulnerable is Mexico to a collapse of its power grid?

Recent blackouts in Chile, Spain and Portugal reveal the fragility of power grids in the face of technical failures. Although they were not caused by cyberattacks, they illustrate the potential impact of one. Mexico, which is highly dependent on the CFE, faces similar risks without full preparation.

*By Víctor Ruiz

The blackouts in Chile, Spain and Portugal illustrate the potential consequences of a deliberate attack on critical infrastructure, such as power grids. While these events were the product of accidental failures rather than cyberattacks, their effects offer a snapshot of what could happen in the event of intentional aggression, with variations depending on the scale, target, and level of preparedness of the attack.

For context, in February 2025, Chile experienced a massive blackout that affected 98.5% of its population due to a failure in a 500 kV transmission line. This disruption paralyzed transportation, telecommunications, and essential services for more than eight hours. Although the recovery was relatively quick, the incident exposed the vulnerability of the country's protection systems.

- Publicidad -

Meanwhile, in April 2025, an oscillation in the power grid connecting Spain and Portugal — likely caused by an interconnector failure — left millions of people without power, impacting hospitals, airports, and transportation systems. The slow recovery evidenced the strong interdependence of European electricity grids.

In this sense, Mexico faces significant vulnerabilities both to accidental power failures, such as those that occurred in Chile and Spain, and to cyberattacks targeting its critical infrastructure, in particular the electricity grid operated by the Federal Electricity Commission (CFE). The country's heavy reliance on a single entity for electricity generation, transmission, and distribution concentrates both responsibility and risks.

Mexico's preparedness for a similar event is limited due to factors such as outdated infrastructure and lack of investment, as much of the CFE's transmission and distribution network requires urgent modernization. In addition, the lack of new transmission lines and natural gas storage capacities increases exposure to supply and demand disruptions, which could trigger a chain failure similar to the collapse observed in Chile after a single critical failure.

Similarly, electricity demand in Mexico has increased considerably, driven by phenomena such as nearshoring and recurrent heat waves; however, generation capacity has not grown at the same rate. In 2023, the National Energy Control Center (CENACE) declared several states of alert due to operating reserve margins of less than 6%, reflecting that the system operates close to its limit. In this context, an event such as the oscillation recorded in Spain could destabilise the National Interconnected System (SIN) if it were to coincide with a peak of high demand.

Another important point is that the CFE has shown the capacity to deal with regional blackouts, such as the one that occurred in March 2025 in the Yucatan Peninsula, where it managed to restore 47% of the service in a few hours after a failure in the gas supply. However, this event affected hundreds of thousands of users – and not millions – and required the implementation of rotating outages, which shows that managing a nationwide blackout would be considerably more complex. In the case of Chile, the rapid mobilization of military forces and the imposition of a curfew helped contain the disorder; in contrast, Mexico does not have a clear public protocol to face a similar scenario.

A key aspect is that, in Mexico, about 62% of electricity generation depends on fossil fuels, with the import of natural gas from the United States being especially critical. Events such as the one that occurred in January 2024 – when a wave of low temperatures in Texas caused a state of emergency in the SIN – show that external interruptions can seriously impact the country. A gas supply failure, such as the one recorded in Yucatan, could be repeated on a larger scale, with consequences similar to those observed in the blackouts in Chile or Spain.

In addition, the Mexican government's energy policy, focused on strengthening the CFE over private investment, has restricted the diversification of generation sources and reduced the resilience of the electricity system. Unlike Chile and Spain, where interconnection with other networks made it possible to mitigate the effects of blackouts, in Mexico the high dependence on a single entity could hinder and delay recovery in the event that a failure affects CFE's strategic nodes.

- Publicidad -

On the other hand, cyberattacks on critical infrastructure, such as the power grid, are a growing threat. Historical examples include the Stuxnet attack in Iran (2010), which damaged nuclear centrifuges, and the Industroyer malware in Ukraine (2016), which caused a blackout in Kiev.

In Mexico, CFE and Pemex have been recurring targets, with around 4,000 cyberattacks reported to CFE in 2019 and one ransomware attack on Pemex that same year.

Are we vulnerable to cyberattacks?

Let's take into account that, although the CFE has invested in digitization processes to optimize its operating costs, this modernization has also increased its exposure to cyberattacks. Considering that 44.5% of global cyberattacks are directed at the energy sector, the CFE represents an attractive target as it is a critical infrastructure. The growing interconnection between Information Technology (IT) and Operational Technology (OT) – such as the SCADA systems that control the power grid – opens up potential access points for threats such as Industroyer, malware capable of manipulating electrical substations and causing blackouts.

Likewise, a 2024 report by the Superior Audit of the Federation (ASF) revealed that both the CFE and CENACE have deficiencies in their cybersecurity systems. In particular, in CENACE's EMS/SCADA system, the incident detection function achieved only 56% compliance, reflecting a limited ability to identify attacks in a timely manner. For its part, the CFE has not implemented adequate penetration tests or applied critical security updates, a situation similar to the one faced by Pemex in 2019, when vulnerable servers were not patched in time, facilitating an attack.

In 2019, the CFE also reported nearly 4,000 cyberattacks in a five-month period, of which approximately 40% originated in Mexico, followed by incidents from Ukraine, Singapore, and the United States. Among the most frequent attacks are techniques such as phishing, ransomware and cross-site scripting, focused on data theft or system control. The ASF warned that around 300 cyberattacks are registered per minute in Mexico, with the energy sector being one of the main targets.

- Publicidad -

Unlike countries such as the United States, which has NERC-CIP standards, or the European Union, with the NIS2 directive, Mexico does not have specific regulations to protect cybersecurity in the energy sector. The ASF has pointed out that the solutions currently implemented are not appropriate to the national context and that the shortage of cybersecurity specialists aggravates this vulnerability. In addition, it is estimated that 20% of cyberattacks have an internal origin, often due to human error, such as the opening of malicious emails. The extensive presence of subcontractors in the Mexican energy sector, who have access to critical systems, represents another security breach, as evidenced in international incidents where attackers take advantage of third parties to infiltrate key infrastructure.

What is the potential impact of a cyberattack?

A successful cyberattack on the CFE's power grid could lead to massive blackouts, similar to the attack in Ukraine in 2016, where malware like Industroyer shut down substations, leaving millions without electricity. According to a study by the University of Cambridge (2015), an attack on an electricity grid could generate losses of up to 1 trillion dollars, which is a plausible scenario for Mexico due to its high dependence on the CFE. In addition, the interruption of essential services such as hospitals, water and telecommunications would cause a collapse, as in Chile and Spain, although recovery could be slower if the attack affects SCADA systems or physical equipment (such as transformers, which take months to replace). This would also generate social and economic chaos, given that the centralization of the CFE means that an attack has repercussions at the national level. An incident similar to the one in 2019 with Pemex, where a ransomware attack paralyzed its operations, could halt key sectors of the Mexican economy, such as mining or nearshoring. In addition, it would compromise national security, as SILIKN's research unit considers energy cybersecurity as a critical issue for the country's security. A politically motivated attack, similar to those perpetrated by Russian or Chinese groups, could further destabilize the country, especially if combined with other attacks on sectors such as finance or health.

Conclusion

Mexico is not prepared to face a massive blackout similar to those that occurred in Chile or Spain, so it is essential to invest in the modernization of the electricity grid, including the upgrade of transmission lines and the storage of natural gas. In addition, it is necessary to diversify the sources of energy generation, promoting a greater participation of renewable energies and the private sector, in order to reduce dependence on the CFE. It is also essential to implement a national cybersecurity strategy specific to the energy sector, which includes clear rules, penetration testing, and continuous training. To improve resilience, collaboration with the private sector and international organizations must be strengthened, adopting best practices such as NERC-CIP or NIS2. Finally, it is crucial to develop well-defined contingency plans to handle mass blackouts, including protocols that protect essential services and facilitate coordination between the different institutions involved in the response.

Víctor Ruiz, founder of SILIKN, certified cybersecurity instructor (CSCT),™ (ISC)² Certified in Cybersecurity℠ (CC), EC-Council Ethical Hacking Essentials (EHE) Certified, EC-Council Certified Cybersecurity Technician (CCT), Ethical Hacking Certified Associate (EHCA), Cisco Ethical Hacker & Cisco Cybersecurity Analyst, and leader of the Querétaro chapter of the OWASP Foundation.

 

Andrea Ochoa Restrepo
Andrea Ochoa RestrepoEmail: [email protected]
Editora
Comunicadora Social- Periodista. MSC en Economía Aplicada con énfasis en Políticas Públicas. Diplomada en Emergencia Climática. Con más de 12 años en medios.

No comments

• If you're already registered, please log in first. Your email will not be published.

Leave your comment

In reply to Some User
The Challenge of Global Instability: Towards a Comprehensive Security and Defense Response

The Challenge of Global Instability: Towards a Comprehensive Security and Defense Response

The growing convergence between physical and digital threats is forcing organizations to rethink their security strategies. Faced with this scenario, there is a need for comprehensive approaches...

AI applied to medical security

AI applied to medical security

The Directorate of the Medical Emergency System (SEM), attached to the Ministry of Health of El Salvador, strengthened its technological infrastructure with the modernization of its video...

Eight Red Dot Awards Highlight Innovation in Technology Design

Eight Red Dot Awards Highlight Innovation in Technology Design

International. The technology company Ajax Systems announced that it has won eight awards in the Red Dot Design Award, one of the most prestigious global awards in the field of industrial design....

Villa María del Triunfo reinforces its security with intelligent video surveillance

Villa María del Triunfo reinforces its security with intelligent video surveillance

Peru. The district of Villa María del Triunfo has launched an intelligent video surveillance system that already shows results in terms of citizen security and that will be expanded in a second...

Milestone Systems grows 10% by 2025 and reinforces its commitment to artificial intelligence and intelligent video

Milestone Systems grows 10% by 2025 and reinforces its commitment to artificial intelligence and intelligent video

Denmark. The company reported net income of $340 million in 2025, representing a 10% growth from the previous year. The company spent about a third of this revenue on innovation, with an emphasis on...

Micro Key Solutions Reinforces Latin America Strategy with New Key Appointments

Micro Key Solutions Reinforces Latin America Strategy with New Key Appointments

United States. In response to the growth in demand for monitoring and management software solutions in the security industry, Micro Key Solutions announced the expansion of its operations in Latin...

Grupo Multisistemas strengthens its presence in Mexico with a new office in Morelia

Grupo Multisistemas strengthens its presence in Mexico with a new office in Morelia

Mexico. Grupo Multisistemas de Seguridad Industrial (GMSI) advances in its national growth strategy with the inauguration of new offices in Morelia, Michoacán, with the aim of expanding its coverage...

Case study: Security system modernization with artificial intelligence and centralized monitoring

Case study: Security system modernization with artificial intelligence and centralized monitoring

Mexico City. The Superior Audit Office of the Federation (ASF) implemented an ambitious technological renovation project in its five headquarters located in Mexico City, with the aim of...

Automated key and equipment management strengthens security in mining operations

Automated key and equipment management strengthens security in mining operations

International. Access and equipment management in the mining industry is evolving towards increasingly automated models, in response to operational complexity and occupational safety demands.

Security becomes a technological platform

Security becomes a technological platform

Mexico. Security is moving from a set of standalone systems to an integrated technology platform that combines artificial intelligence, video analytics, sensors, access control, and data platforms....

Suscribase Gratis
Remember Me
SUBSCRIBE TO OUR ENGLISH NEWSLETTER
DO YOU NEED A SERVICE OR PRODUCT QUOTE?
LATEST INTERVIEWS
SITE SPONSORS










LATEST NEWSLETTER
Latest Newsletter