Business Context and Reporting Period
This Form 6-K filing by Central North Airport Group (OMA) is dated November 6, 2024, covering the month of November. OMA operates 13 international airports across nine states in central and northern Mexico, serving major hubs like Monterrey and tourist destinations including Acapulco and Mazatlán. The company also manages hotel operations at Mexico City and Monterrey airports.
Key Financial Metrics
The filing text does not provide specific values for revenue, profit, cash flow, margins, debt, or liquidity. This report focuses exclusively on a material event rather than periodic financial results.
Material Changes and Events
The primary material change reported is an update regarding a cybersecurity incident previously disclosed on October 18, 2024. Key details include:
- Incident Nature: The event involved ransomware that encrypted certain files and systems, alongside the exfiltration of specific information.
- Impact on Operations: OMA states it has not suffered any material adverse effect on its operations, results, or financial position.
- Compromised Data: Information related to business customers, suppliers, and employees has been identified as compromised and purportedly released by attackers.
- Ransom Status: The company has not acceded to any payment demands from the attackers.
Management Commentary, Risks, and Outlook
Management is actively restoring systems using backups, notifying relevant authorities, and implementing mitigation measures. The company is investigating the extent of the data breach to inform affected parties as required. OMA is strengthening its security response protocols, policies, and detection capabilities. The filing includes standard forward-looking statement disclaimers, noting that actual results may differ due to risks discussed in the most recent Form 20-F.
Investor Verification Checklist
- Verify the scope of data exfiltration regarding customers, suppliers, and employees.
- Monitor for any future announcements regarding material financial impact or operational disruptions.
- Review the company's updated cybersecurity protocols and incident response timeline.
- Check for regulatory notifications or legal actions stemming from the data breach.