Kaspersky's GReAT team reported widespread wireless security weaknesses across public Wi-Fi environments in Mexico City, Guadalajara, and Monterrey after a passive wardriving assessment conducted ahead of the 2026 FIFA World Cup. The researchers recorded 84,588 signals and 69,473 unique SSIDs, finding strong standardization in ISP deployments, heavy dependence on the 2.4 GHz band, and frequent use of default or revealing SSID naming conventions, including names derived from BSSID metadata that can expose infrastructure details.
While WPA2/WPA3 was the dominant protection scheme overall, the study found that open networks remained common and that nearly half of detected access points advertised WPS, including roughly half of otherwise secured WPA2/WPA3 networks. Kaspersky warned that encryption alone does not reflect real wireless security posture because default configurations, predictable naming, and WPS exposure can aid reconnaissance and enable evil twin hotspots, credential harvesting, and man-in-the-middle attacks in dense tourist areas expected to attract World Cup visitors.

Map this exposure pattern across your cloud, code, and identities.
2 events from the most recent confirmed update back to the earliest known activity.
On 2026-05-21, Kaspersky GReAT published a passive wardriving assessment of public Wi-Fi environments in Mexico City, Guadalajara, and Monterrey ahead of the 2026 FIFA World Cup. The report documented 84,588 signals and 69,473 unique SSIDs, highlighting risks from open networks, WPS exposure, default naming, and metadata leakage.
On 2021-05-13, Securelist published an analysis of Wi-Fi networks observed in Monterrey, Mexico, detailing SSID patterns, hardware prevalence, channel usage, and encryption practices. The report highlighted widespread WEP use and warned that provider-managed sequential naming or key patterns could expose many networks to compromise.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcesecurelist.com
Open sourcesecurelist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.