The state prosecutor’s office in Guanajuato is facing a credibility test after an international hacker collective, Tekir APT, claimed it stole and encrypted 250 gigabytes of internal data, including case files and IDs. The office publicly downplayed the incident, describing the situation as routine “preventive” security checks. Meanwhile, employees reported sluggish systems, long waits, and a return to taking complaints on paper beginning late last week.
By Wednesday, November 12, the claim of a breach—and the denial—had hardened into parallel narratives. Local media reported that security researchers flagged Tekir APT’s post asserting a 250-GB exfiltration; the prosecutor’s office rejected that account even as internal operations faltered, according to staffers.
ComputerWeekly summarized the alert trail traced to Hackmanac, a threat-monitoring account on X, noting Tekir APT’s claim and a possible ransomware angle—an attack that locks systems and pressures victims with a deadline to pay a ransom. The outlet reports Hackmanac’s post, which names the prosecutor’s systems among affected subdomains.
Guanajuato prosecutor hack
What the public can verify right now is limited—and that’s fueling confusion. Reporters documented service disruptions at the agency, with wait times stretching to an hour and staff reverting to manual intake as terminals failed to load forms. The agency attributed the slowdown to security maintenance and updates; it did not confirm any encryption or theft. (AM; El Sol de León) Periódico AM+1
The core claim from Tekir APT is specific: 250 GB allegedly taken from the prosecutor’s network, with threats to publish if demands are not met by a stated deadline. Several local and national outlets echoed those details after the Hackmanac alert circulated on Tuesday. Periódico Correo reported the group’s attribution on November 11 and lawmakers’ calls on November 12 for a formal explanation and stronger digital security protocols.
Officials said they were “reviewing preventive controls” to ensure systems run properly. There was no acknowledgement of a breach or ransom demand. That message was consistent across multiple statements carried by local outlets.
What’s still in dispute—and why it matters
Two things can be true at once: a government can be experiencing a system outage while also insisting there’s no breach. But a widening gap between lived reality in service windows and public messaging erodes trust at a sensitive moment. If Tekir APT’s claim holds, the risks extend beyond inconvenience: case integrity, witness privacy, and chain-of-custody records could be exposed. If the claim is exaggerated—or false—residents still deserve a transparent, technical explanation for days of degraded service.
Independent signals continue to point to a real disruption. Multiple outlets documented the timeline: issues began Friday; by Tuesday, the cyber claim surfaced; by Wednesday, lawmakers were asking questions, and specialists floated competing theories, including the possibility of an insider-enabled intrusion—an unproven but plausible vector when privileged access is abused.
For residents, the practical advice is simple: monitor any email or phone number used in past complaints; be wary of unsolicited calls citing case numbers; and, if you filed a report this week, ask for a paper receipt and later verify that it has been entered into the digital system once restored. For the agency, the best practice now would be a brief technical bulletin: when the outage started, which systems were isolated, whether evidence chains were affected, and whether they engaged external incident response teams. Clear answers would quiet rumors faster than any denial.
Background research aggregates the same 250-GB figure and notes the ransom threat tied to a November timeframe, again citing Hackmanac’s alert. As of press time, no forensic report has been published, and the prosecutor’s office has not released indicators of compromise for other agencies to watch.
Until the office provides a fuller technical account—or Tekir APT proves control of stolen files—the story remains a standoff between a public denial and a detailed claim, with citizens caught in the middle trying to file complaints. What happens next will turn on evidence: logs, independent forensics, and whether the promised data leak materializes.





