ISO 27001 Certificate
SOC 1 Type I Certificate
SOC 2 Type II Certificate
PCI DSS
HIPAA
RGPD
Internal validation & live display
Multiple badges & continuous verification
Faster underwriting decisions
ISOSOC2 Type 1SOC2 Type 2PCI DSSHIPAAGDPR

Bienvenido al perfil oficial de Banorte. El Banco Fuerte de México.

Banorte A.I CyberSecurity Scoring

Banorte

Company Details

Linkedin ID:

banorte

Employees number:

4,924

Number of followers:

36,818

NAICS:

52211

Industry Type:

Banking

Homepage:

http://www.banorte.com.mx

IP Addresses:

0

Company ID:

BAN_6048335

Scan Status:

In-progress

AI scoreBanorte Risk Score (AI oriented)

Between 750 and 799

https://images.rankiteo.com/companyimages/banorte.jpeg
Banorte Banking
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
globalscoreBanorte Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/banorte.jpeg
Banorte Banking
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

Banorte Company CyberSecurity News & History

Past Incidents
1
Attack Types
1
EntityTypeSeverityImpactSeenBlog DetailsIncident DetailsView
BanorteData Leak8546/2014
Rankiteo Explanation :
Attack with significant impact with customers data leaks

Description: In August 2022, a hacking forum publicly dumped millions of records from Mexican bank "Banorte". The dumped data included 2.1M unique email addresses, physical addresses, names, phone numbers, RFC (tax) numbers, genders and bank balances. Though the data is "outdated" and dates back 8 years to 2014, still it contains sensitive information that can be misused in multiple ways.

Banorte
Data Leak
Severity: 85
Impact: 4
Seen: 6/2014
Blog:
Rankiteo Explanation
Attack with significant impact with customers data leaks

Description: In August 2022, a hacking forum publicly dumped millions of records from Mexican bank "Banorte". The dumped data included 2.1M unique email addresses, physical addresses, names, phone numbers, RFC (tax) numbers, genders and bank balances. Though the data is "outdated" and dates back 8 years to 2014, still it contains sensitive information that can be misused in multiple ways.

Ailogo

Banorte Company Scoring based on AI Models

Cyber Incidents Likelihood 3 - 6 - 9 months

🔒
Incident Predictions locked
Access Monitoring Plan

A.I Risk Score Likelihood 3 - 6 - 9 months

🔒
A.I. Risk Score Predictions locked
Access Monitoring Plan
statics

Underwriter Stats for Banorte

Incidents vs Banking Industry Average (This Year)

No incidents recorded for Banorte in 2025.

Incidents vs All-Companies Average (This Year)

No incidents recorded for Banorte in 2025.

Incident Types Banorte vs Banking Industry Avg (This Year)

No incidents recorded for Banorte in 2025.

Incident History — Banorte (X = Date, Y = Severity)

Banorte cyber incidents detection timeline including parent company and subsidiaries

Banorte Company Subsidiaries

SubsidiaryImage

Bienvenido al perfil oficial de Banorte. El Banco Fuerte de México.

Loading...
similarCompanies

Banorte Similar Companies

MCB Bank Limited

Welcome to the Official LinkedIn page of MCB Bank Limited. Established in 1947, MCB Bank Limited is one of the largest Banks in Pakistan with a total customer base exceeding 7 million. We have products and services to suit the every need of customers. To learn more about MCB Bank, please visit our w

Comerica Bank

Comerica Incorporated (NYSE: CMA) is a financial services company headquartered in Dallas, Texas, strategically aligned by the Business Bank, the Retail Bank, and Wealth Management. The Business Bank provides companies of all sizes with an array of credit and non-credit financial products and servic

NatWest Group

Our ambition is simple: to succeed with our customers. Because when they succeed, so do we. Whether it’s buying a home, investing for tomorrow, growing a business, or helping our customers to build a more sustainable future, we can succeed with customers by understanding their world and what matte

ING is a pioneer in digital banking and on the forefront as one of the most innovative banks in the world. As ING, we have a clear purpose that represents our conviction of people’s potential. We don’t judge, coach, or tell people how to live their lives. However big or small, modest or grand, we em

Punjab National Bank

“Fired by the spirit of nationalism and founded on the idea that Indians should have a national bank of their own, which would further the economic interest of the country, Punjab National Bank Ltd was the result of the efforts of far-sighted visionaries and patriots, among whom were persons like La

PT Bank Rakyat Indonesia (Persero) Tbk

Bank Rakyat Indonesia (BRI) adalah salah satu bank milik pemerintah yang terbesar di Indonesia. BRI didirikan di Purwokerto, Jawa Tengah oleh Raden Bei Aria Wirjaatmadja pada 16 Desember 1895. Lebih dari 128 tahun memberi pelayanan terbaik bagi seluruh lapisan masyarakat, BRI turut andil dalam upa

At BBVA we are leading the transformation of banking worldwide, united in pursuing our goal of bringing the age of opportunity to everyone. Firmly focused on the future, our on-going digital transformation is already producing disruptive innovations that power our vision of banking. Every one of o

China CITIC Bank

Overview Thinking on the corporate banking of small and medium sized commercial banks • Ranked the 99th among 2008 Global Top 500 Financial Brands • Chen Xiaoxian, the Bank’s President, was granted “Top 10 Financial Figures” Award in the fourth consecutive year • Selection activity about the ranki

Attijariwafa bank

With our universal banking model, our pan-African scope, the complementarity of our businesses and our solid expertise, we are a leading player in the Moroccan and African financial sector. For over a century, we’ve been able to adapt by diversifying our business lines, renewing our offers and rev

newsone

Banorte CyberSecurity News

October 16, 2025 07:00 AM
Researchers find much Mexican satellite data is unencrypted and easily hacked

Using inexpensive equipment installed on a rooftop in San Diego, computer scientists from two universities in the United States were able to...

March 03, 2025 08:00 AM
Data Breach at Mexico’s National Institute of Anthropology

A cybersecurity incident has struck Mexico's National Institute of Anthropology and History (INAH), with a threat actor known as ByteRev0luti0n claiming...

April 11, 2023 07:00 AM
Sonda Confirms Ransomware Attack; Dismisses Reports of Huge Loss

Nearshore IT integrator Sonda confirmed that it suffered a ransomware attack, but added that the cyber incident only affected 2% of its...

August 16, 2022 07:00 AM
When Efforts to Contain a Data Breach Backfire

Earlier this month, the administrator of the cybercrime forum Breached received a cease-and-desist letter from a cybersecurity firm.

May 29, 2018 07:00 AM
Mexico Foiled a $110 Million Bank Heist, Then Kept It a Secret

On a Tuesday morning in early January, the computer system at Mexico's state-owned trade bank went haywire. Some of Bancomext's workers couldn't get their PCs...

April 30, 2018 07:00 AM
Mexico Tells Banks to Take Steps to Guard Against Suspected Hack

Mexico's monetary authority asked about a dozen banks to take emergency measures to shore up the country's electronic payment network after...

April 27, 2018 07:00 AM
Mexican Banks Targeted in Cyber Attack

Cyber attackers attempted to penetrate Mexico's electronic payment systems Friday, forcing three banks to enact contingency plans,...

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

Banorte CyberSecurity History Information

Official Website of Banorte

The official website of Banorte is http://www.banorte.com.mx.

Banorte’s AI-Generated Cybersecurity Score

According to Rankiteo, Banorte’s AI-generated cybersecurity score is 795, reflecting their Fair security posture.

How many security badges does Banorte’ have ?

According to Rankiteo, Banorte currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.

Does Banorte have SOC 2 Type 1 certification ?

According to Rankiteo, Banorte is not certified under SOC 2 Type 1.

Does Banorte have SOC 2 Type 2 certification ?

According to Rankiteo, Banorte does not hold a SOC 2 Type 2 certification.

Does Banorte comply with GDPR ?

According to Rankiteo, Banorte is not listed as GDPR compliant.

Does Banorte have PCI DSS certification ?

According to Rankiteo, Banorte does not currently maintain PCI DSS compliance.

Does Banorte comply with HIPAA ?

According to Rankiteo, Banorte is not compliant with HIPAA regulations.

Does Banorte have ISO 27001 certification ?

According to Rankiteo,Banorte is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.

Industry Classification of Banorte

Banorte operates primarily in the Banking industry.

Number of Employees at Banorte

Banorte employs approximately 4,924 people worldwide.

Subsidiaries Owned by Banorte

Banorte presently has no subsidiaries across any sectors.

Banorte’s LinkedIn Followers

Banorte’s official LinkedIn profile has approximately 36,818 followers.

NAICS Classification of Banorte

Banorte is classified under the NAICS code 52211, which corresponds to Commercial Banking.

Banorte’s Presence on Crunchbase

No, Banorte does not have a profile on Crunchbase.

Banorte’s Presence on LinkedIn

Yes, Banorte maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/banorte.

Cybersecurity Incidents Involving Banorte

As of December 15, 2025, Rankiteo reports that Banorte has experienced 1 cybersecurity incidents.

Number of Peer and Competitor Companies

Banorte has an estimated 7,039 peer or competitor companies worldwide.

What types of cybersecurity incidents have occurred at Banorte ?

Incident Types: The types of cybersecurity incidents that have occurred include Data Leak.

Incident Details

Can you provide details on each incident ?

Incident : Data Breach

Title: Banorte Data Breach

Description: In August 2022, a hacking forum publicly dumped millions of records from Mexican bank 'Banorte'. The dumped data included 2.1M unique email addresses, physical addresses, names, phone numbers, RFC (tax) numbers, genders, and bank balances. Though the data is 'outdated' and dates back 8 years to 2014, it still contains sensitive information that can be misused in multiple ways.

Date Detected: 2022-08-01

Date Publicly Disclosed: 2022-08-01

Type: Data Breach

What are the most common types of attacks the company has faced ?

Common Attack Types: The most common types of attacks the company has faced is Data Leak.

Impact of the Incidents

What was the impact of each incident ?

Incident : Data Breach BAN162871222

Data Compromised: Email addresses, Physical addresses, Names, Phone numbers, Rfc (tax) numbers, Genders, Bank balances

What types of data are most commonly compromised in incidents ?

Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Email Addresses, Physical Addresses, Names, Phone Numbers, Rfc (Tax) Numbers, Genders, Bank Balances and .

Which entities were affected by each incident ?

Incident : Data Breach BAN162871222

Entity Name: Banorte

Entity Type: Bank

Industry: Finance

Location: Mexico

Customers Affected: 2.1M

Data Breach Information

What type of data was compromised in each breach ?

Incident : Data Breach BAN162871222

Type of Data Compromised: Email addresses, Physical addresses, Names, Phone numbers, Rfc (tax) numbers, Genders, Bank balances

Number of Records Exposed: 2.1M

Sensitivity of Data: High

Additional Questions

Incident Details

What was the most recent incident detected ?

Most Recent Incident Detected: The most recent incident detected was on 2022-08-01.

What was the most recent incident publicly disclosed ?

Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2022-08-01.

Impact of the Incidents

What was the most significant data compromised in an incident ?

Most Significant Data Compromised: The most significant data compromised in an incident were email addresses, physical addresses, names, phone numbers, RFC (tax) numbers, genders, bank balances and .

Data Breach Information

What was the most sensitive data compromised in a breach ?

Most Sensitive Data Compromised: The most sensitive data compromised in a breach were bank balances, names, physical addresses, phone numbers, email addresses, RFC (tax) numbers and genders.

What was the number of records exposed in the most significant breach ?

Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 2.1.

cve

Latest Global CVEs (Not Company-Specific)

Description

NXLog Agent before 6.11 can load a file specified by the OPENSSL_CONF environment variable.

Risk Information
cvss3
Base: 8.1
Severity: HIGH
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Description

uriparser through 0.9.9 allows unbounded recursion and stack consumption, as demonstrated by ParseMustBeSegmentNzNc with large input containing many commas.

Risk Information
cvss3
Base: 2.9
Severity: HIGH
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Description

A vulnerability was detected in Mayan EDMS up to 4.10.1. The affected element is an unknown function of the file /authentication/. The manipulation results in cross site scripting. The attack may be performed from remote. The exploit is now public and may be used. Upgrading to version 4.10.2 is sufficient to fix this issue. You should upgrade the affected component. The vendor confirms that this is "[f]ixed in version 4.10.2". Furthermore, that "[b]ackports for older versions in process and will be out as soon as their respective CI pipelines complete."

Risk Information
cvss2
Base: 5.0
Severity: LOW
AV:N/AC:L/Au:N/C:N/I:P/A:N
cvss3
Base: 4.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
cvss4
Base: 5.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

MJML through 4.18.0 allows mj-include directory traversal to test file existence and (in the type="css" case) read files. NOTE: this issue exists because of an incomplete fix for CVE-2020-12827.

Risk Information
cvss3
Base: 4.5
Severity: HIGH
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:L
Description

A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vulnerability allows authorized users to leak arbitrary information from unprotected endpoints in the control plane’s host network (including link-local or loopback services).

Risk Information
cvss3
Base: 5.8
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=banorte' -H 'apikey: YOUR_API_KEY_HERE'

What Do We Measure ?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge