CiberLATAMbywhalemate

Mexico reviews possible Aeroméxico data leak

Mexico’s anti-corruption office opened a review of a reported Aeroméxico data exposure. The airline said it had previously suffered a cyberattack.

Whalemate Labs · AI-assisted researchPublished:2 min read

Mexico’s Anti-Corruption and Good Government Ministry began reviewing a sample of 100,092 personal data records that were allegedly linked to Aeroméxico and offered on Telegram. Aeroméxico said some customer data was compromised in an international cyberattack in October 2025, but said it did not find exposure of financial data, payment cards or passwords.

Mexico’s Anti-Corruption and Good Government Ministry has begun reviewing a sample of 100,092 personal data records that were allegedly linked to Aeroméxico and offered on Telegram. The case is still under review, and authorities have not yet definitively confirmed either the source of the possible incident or the final number of people affected.

What did authorities detect?

The ministry identified signs of a possible exposure of personal data after forensic incident monitoring, according to Radio Fórmula, based on a Telegram post circulated on Sept. 18, 2026. That post reportedly offered a 1.10 GB database with more than 15 million records allegedly linked to Aeroméxico.

Infobae México said the sample under review includes 100,092 records, while Aristegui Noticias described the file as a 1.10 GB database with more than 15 million records. In both cases, the information is presented as allegedly associated with the airline, not as a conclusion confirmed by authorities.

What did Aeroméxico say?

Aeroméxico acknowledged that some customer data was compromised in an international cyberattack in October 2025, and said it did not identify exposure of financial information, payment card data or customer account passwords. The airline later said, preliminarily, that the exposed data was limited to full names, dates of birth, email addresses and phone numbers.

Coverage from El Mañana added that flight itineraries were not exposed and that the unauthorized access likely took place through a customer information management platform run by an external provider, adding technical context about the possible point of compromise. Aristegui Noticias also said the company’s preliminary forensic findings could correspond to data stolen in that same international campaign in October 2025.

What happens next in the investigation?

For now, the case remains under review, and Mexican authorities have not definitively confirmed the source of the possible incident or the full scope of the exposure. The combination of preliminary findings, Telegram posts and Aeroméxico’s partial acknowledgment keeps the file open while investigators try to determine which data were actually affected and how many people may be impacted.

Sources

View all