From Information Sharing to Intelligence Production: GASA Mexico in Forbes
Blog ·

The United States authorized private companies to take part in cyber operations against the criminal networks that run fraud from abroad. The memorandum signed by Donald Trump on 12 August 2026 brings them in under the direction and control of the federal government, and names financial fraud among the threats it seeks to counter.
The United States authorized private companies to take part in cyber operations against the criminal networks that run fraud from abroad. The memorandum signed by Donald Trump on 12 August 2026 brings them in under the direction and control of the federal government, and names financial fraud among the threats it seeks to counter.
Sissi de la Peña, Director of the GASA Mexico Chapter , examined that decision in Forbes México under the title "De compartir información a construir inteligencia: el siguiente paso contra el fraude".
The memorandum belongs to a broader trajectory. The United States had been working from a strategy centred on defending its own systems, formalised in the executive order of June 2025. The executive order of March 2026 gave the Departments of Justice, Homeland Security, State and Defense 120 days to deliver a plan identifying the organisations behind scam centres. That deadline expired in early July, and the August instrument operates as its implementation mechanism. Mexico-linked operations already form part of that agenda: the U.S. Treasury has sanctioned the timeshare scam network operating out of Puerto Vallarta on six occasions, with more than 90 individuals and companies designated.
Even so, the memorandum carries three clear limits. It names no Mexican organisation as a target. It does not by itself authorise operations against systems located in the country. And it does not clarify how sovereignty questions will be resolved when an operation crosses borders. Those gaps open a space for definition in which Mexico needs to arrive at the conversation with a position of its own, built on convergence between the cybersecurity and anti-fraud agendas.
That position starts with measuring what happens at home. According to GASA's State of Scams in Mexico 2025 report, scam losses in the country exceeded 139 billion pesos during 2025. Seventy-six percent of respondents trust their own ability to recognise a scam, and those who say they always identify one lost more money on average than everyone else. For years prevention was built around the last link in the chain, teaching people not to open a link or to distrust a call. That work remains necessary and reaches its limits against structures that automate contact with millions of people and change mechanisms within hours.
The evidence about a single criminal operation sits in separate places. A bank sees a suspicious transfer. A telecom operator records a calling pattern. A platform detects accounts created under similar patterns. An authority receives matching complaints. Each actor holds one piece of the same case.
Knowing that an account received a suspicious transfer is information. Discovering that the account is connected to twenty others created under similar patterns, and that the associated phone numbers appear in complaints filed with other entities, is intelligence.
Producing it requires common standards, clear rules on what can be shared and with whom, and a definition of which institution holds the mandate to turn those signals into actionable intelligence. The Mexico Chapter's second roundtable identified that the fraud, cybersecurity and anti-money laundering functions work with the same data without connecting it. The cybersecurity law now under discussion in Congress is the available instrument for enabling that exchange under clear rules.
Our thanks to Forbes México for the space for this conversation.
Suscríbete al boletín de GASA para recibir actualizaciones periódicas sobre prevención de estafas, investigaciones y mejores prácticas.