top of page

MEXICAN AUTHORITIES DISCOVERED A CLANDESTINE TAP ON THE TUXPAN-AZCAPOTZALCO PIPELINE, AND A US GOVERNMENT CYBERSECURITY STUDY IDENTIFIED RESOURCE GAPS LIMITING STATE AND LOCAL CYBER THREAT PROTECTION

10 minutes ago
3 min read

September 10-16, 2026 | Issue 37 - NORTHCOM Team 

Troy Scott Jr., Vanessa Neubauer, Maya Kerr Coste, Dominic Perfetti, Noah Clarke, Matthew George, Laura Ospina, Sarah Granados, Aristide Devevey, Sharon Preci 

Olivia Turnbull, Embedded Editor; Clémence Van Damme, Senior Editor


Underground Pipeline Infrastructure[1]


DateSeptember 10, 2026

LocationAxapusco, Mexico State, Mexico

Parties involvedMexico; physical security of Mexico’s state-owned petroleum company Petróleos Mexicanos (Pemex); Pemex’s infrastructure; pipeline infrastructure; authorities; criminal group Jalisco New Generation Cartel (CJNG); criminal groups; criminal organizations; cartels; personnel; informal roadside sellers 

The eventMexican authorities discovered a clandestine tap connected to the Tuxpan-Azcapotzalco pipeline.[2]

Analysis & Implications

  • The breach of a protective barrier along the pipeline will likely expose Pemex’s insufficient physical infrastructure defense protocols, likely straining the corporation’s security capacity to detect and deter future clandestine taps. Weak monitoring of fuel pressure systems and vulnerable concrete walls will likely reduce Pemex’s ability to identify pressure anomalies promptly, likely extending the period during which covert connections can remain undetected. This will likely prompt criminal groups, including CJNG, to pursue extraction opportunities using adaptive methods, including compressors to circumvent pressure-monitoring triggers, likely undermining the integrity of current physical barriers and monitoring systems. Criminal organizations’ ability to bypass current security measures will likely expand critical vulnerabilities for future exploitation of pipeline infrastructure, likely straining Pemex’s limited capacity to adequately address damages caused by illicit fuel theft.

  • Disruption of the clandestine tap on the pipeline will likely have a limited impact on the broader profitability of illicit hydrocarbon extraction, likely sustaining criminal incentives to target Pemex infrastructure. Cartels’ adapting illegal hydrocarbon extraction framework will likely continue despite the loss of this pipeline tap, with replaceable access points and sustained profits likely allowing established resale and distribution networks, such as cartel-linked gas stations and informal roadside sellers, to persist and produce durable revenue streams. Continued profit from illicit fuel sales will likely facilitate the efforts of criminal groups involved in organized fuel theft to retain personnel, transportation, storage, and logistical capabilities, likely enabling them to establish new access points after disrupting individual taps.  New tap locations will likely allow illicit extraction to persist across the pipeline system, likely limiting the lasting security gains achieved by site-specific physical protections. 


DateSeptember 10, 2026

LocationUSA 

Parties involvedUSA; military; state and local authorities; federal cybersecurity agency Cybersecurity and Infrastructure Security Agency (CISA); state IT leadership association National Association of State Chief Information Officers (NASCIO); government IT services General Dynamics Information Technology (GDIT); other security agencies; cybersecurity personnel; emergency services; affected communities; public; social media and news platforms; Iran; Iran-linked actors

The eventNASCIO and GDIT identified major funding, staffing, and training gaps limiting state and local governments’ ability to protect critical infrastructure from cyber threats.[3]

Analysis & Implications

  • The funding and staffing gaps affecting infrastructure protection will likely persist as continued US military operations in Iran place competing demands on federal resources, likely delaying cybersecurity improvement across critical sectors. Contested funding for federal departments, including the Department of Defense, will likely constrain additional funding for CISA and other security agencies, likely limiting necessary access to cybersecurity personnel, training, and technical assistance. Persistent gaps in security support will likely leave internet-exposed water and electricity systems vulnerable to Iranian cyber operations, likely enabling Iran-linked actors to disrupt facilities with minimal capabilities. Continued exploitation of these weaknesses will very likely strain utilities’ and emergency services’ response capacity, likely increasing the risk of temporary water and electricity disruptions for affected communities.  

  • Resource gaps in state and local infrastructure protection will likely enable Iran-linked actors to portray localized cyberattacks as evidence of broader insecurity, likely heightening public fear over the reliability of essential services. Limited staffing and training will likely reduce smaller facilities’ ability to contain incidents and communicate recovery promptly, likely prolonging public uncertainty following otherwise limited disruptions. Iran-linked actors will likely exploit this uncertainty by publicizing attacks through social media and news platforms, likely exaggerating their operational impact and presenting isolated vulnerabilities as systemic failures. Heightened perceptions of infrastructure insecurity will likely erode public trust in state and local authorities, likely pressuring governments to redirect limited resources from long-term cybersecurity improvements towards immediate public reassurance.

[2] Clandestine tap connected to the Tuxpan-Azcapotzalco pipeline found in Axapusco, State of Mexico, Infobae, September 2026, https://www.infobae.com/mexico/2026/09/10/hallan-toma-clandestina-conectada-al-poliducto-tuxpan-azcapotzalco-en-axapusco-edomex/ (Translated by Google)

[3] State authorities warn they lack resources to address cyber threat to critical sectors, CyberSecurity Dive, September 2026, https://www.cybersecuritydive.com/news/state-infrastructure-resources-cyberthreats/830178/ 

 
 
  • Linkedin
  • Instagram
  • Twitter
  • Facebook

Interested in joining us? Learn more

 

© The Counterterrorism Group (CTG) - 2026 - This website and all of its contents are copyrighted by The Counterterrorism Group, Inc. 2026. Any use, reproduction or duplication of the contents of this website without the express written permission of The Counterterrorism Group (CTG) is strictly prohibited.

bottom of page