A database of over 15 million records was put up for sale on Telegram after a cyberattack.
Aeroméxico confirmed on Monday, September 21, 2026, that customer personal data was compromised in an international cyberattack that took place in October 2025. Based on a preliminary forensic analysis, the carrier determined that the exposed information includes customer names and telephone numbers, and in some cases birth dates and email addresses.
The airline stated that the unauthorized access occurred in a customer information management platform run by an external provider. Aeroméxico added that it has not identified any exposure of financial data, such as bank accounts or payment cards, nor passwords or flight itinerary details. The carrier activated response protocols and mitigation measures upon learning of the incident, and advised customers to remain alert to suspicious messages, calls, or emails requesting personal details.
The confirmation follows an investigation opened by Mexico's Ministry of Anticorruption and Good Government. The ministry reported identifying signs of personal data exposure on September 20, 2026, after locating a Telegram post on September 18 offering a 1.10-gigabyte database allegedly belonging to the airline with more than 15 million records. The files reportedly include full names, emails, landline and mobile phone numbers, birth dates, and registration dates.
Authorities obtained a sample of 100,092 records matching those fields, which included names of public servants and public figures. The ministry announced an official inspection to verify compliance with articles 54 and 55 of the Federal Law on the Protection of Personal Data Held by Private Parties.
Newsletter
Markets in your inbox, weekly
Latin America-focused analysis, investment themes and the week in finance.
Keep reading