Digital security in Mexico faces a new challenge: a presumed illegal service of telecommunications data extraction, offered by an actor identified as 'Eternal', is being investigated by independent media. The offer, circulating on dark web forums, promises access to call detail records (CDR), SMS, IMEI/IMSI numbers, and precise geolocation of mobile lines.
This type of practice, known as CDR Extraction, involves the unauthorized acquisition of telecommunications metadata. The CDR (Call Detail Record) is a record containing information about each call or message: source and destination numbers, time, and duration. Although it does not reveal content of conversations, it exposes behavioral patterns, contacts, and location, representing a serious risk to personal and corporate privacy.
What does the 'Eternal' actor offer?
According to gathered information, the service would include:
- Call history: dates, times, and dialed numbers.
- SMS records: metadata of text messages, including recipients and timestamps.
- IMEI/IMSI data: International Mobile Equipment Identity and Subscriber Identity, which identify the device and SIM card.
- Mobile line geolocation: possible real-time or historical tracking of device location.
This type of offering is not new, but the appearance of a clearly identified actor like 'Eternal' has put cybersecurity experts on alert. The main concern is possible complicity of insiders (employees) of telecom operators, who could access these databases from within.
A growing illegal market
CDR extraction has become a lucrative business for cybercriminals. This data is used for industrial espionage, blackmail, harassment, or even for targeted attacks on executives and political figures. In Mexico, the Federal Law on Protection of Personal Data establishes that telecommunications information is confidential and can only be delivered to competent authorities via court order.
Key fact: The unauthorized sale or delivery of telecommunications traffic data can constitute criminal offenses in Mexico, with penalties of up to 8 years in prison for those who illegally access computer systems or disclose personal data.
What does this mean for the average user?
Although it is not yet confirmed that 'Eternal's' service has been used, the mere announcement generates uncertainty. Users across all industries, especially financial, legal, and journalistic, could be compromised if an attacker obtains their metadata. Specialists recommend:
- Use messaging apps with end-to-end encryption (like WhatsApp or Signal).
- Be wary of suspicious calls or messages asking for personal information.
- Keep your phone's operating system updated and use two-factor authentication.
Reaction of authorities and operators
So far, there is no official statement from the Secretariat of Infrastructure, Communications, and Transportation (SICT) or major operators like Telmex, Telcel, or AT&T. Specialized media have contacted spokespersons, who have declined to comment “until verified information is available.” Meanwhile, the investigation continues, and it is expected that authorities will take action to protect citizens' privacy.
This news highlights the importance of vigilance in data protection and the need for companies to strengthen their internal controls to prevent leaks. Cybercrime is advancing, and prevention measures are more urgent than ever.