Key Takeaways
- Mexican authorities are examining a database allegedly containing more than 15 million Aeromexico customer records.
- Aeromexico has found no evidence so far that payment-card data or passwords were exposed, and flights remain unaffected.
- Investigators are working to determine whether the data came from Aeromexico, a third party, or an earlier security incident.
Mexico’s Anti-Corruption and Good Government Ministry has opened an ex officio investigation into a database advertised on Telegram and allegedly linked to Aeromexico. The 1.10 GB file is said to contain more than 15 million customer records, potentially making the case one of the more significant aviation data exposures reported in the region.
According to UPI, the advertised information includes full names, email addresses, landline and mobile phone numbers, dates of birth and passenger registration dates. Those fields may not include direct financial credentials, but they could still support phishing, account impersonation and other forms of social engineering.
Authorities obtained a sample containing 100,092 records with the same fields described in the Telegram listing. The sample included information associated with public officials and public figures, although the ministry did not identify those people.
That finding was enough to trigger closer scrutiny. It was not, however, definitive proof that Aeromexico’s current systems were breached.
The ministry has described the information as “allegedly attributable” to Aeromexico because investigators have not established the database’s origin. The next phase will involve determining whether the information came directly from Aeromexico, from systems operated by a third party, or from data compromised in an earlier incident.
Aeromexico has launched its own investigation into the database’s authenticity and source. Aeromexico said it had found no evidence, as of Sept. 21, that financial information, payment-card numbers or customer account passwords had been exposed. Flight operations also continue normally.
That distinction matters. A compromise involving customer information does not automatically indicate interference with reservation, flight-planning or operational technology. Still, personal data can remain useful to criminals long after the immediate incident has passed.
Names, birth dates and contact details can give fraudulent messages a convincing level of detail. Criminals can use that information to pose as Aeromexico, reference a passenger relationship and request a password reset, payment or identity document, making the outreach appear highly legitimate.
The investigation is proceeding under Mexico’s Federal Law on Protection of Personal Data Held by Private Parties. Authorities will assess whether regulated personal information was exposed, how it was handled and whether violations occurred. Sanctions could follow if the evidence shows failures covered by the law, but no such determination has yet been announced.
The question of timing adds another layer to the investigation. Authorities are examining whether the Telegram listing reflects a fresh intrusion, a repackaged subset of previously stolen information, or a database assembled from multiple sources.
Mexico Business News reported that the government inquiry followed the discovery and forensic review of the Telegram sample.
Aviation has become an attractive target because carriers retain large volumes of identity, contact, travel and loyalty information across interconnected systems. Customer-service applications, contractors and cloud environments can widen the number of places where data is stored or accessed.
Recent cases reinforce the point. Qantas reported a 2025 breach affecting about 2.8 million customers, with names, email addresses and frequent-flyer numbers among the exposed information. A 2026 Packetlabs review of the Qantas incident highlighted the security implications of airline systems and third-party access. WestJet has also appeared among aviation-sector cybersecurity examples, showing that the pressure is not confined to one market.
For Aeromexico, attribution will shape nearly everything that follows: regulatory exposure, customer notification decisions, remediation work and the credibility of future security assurances. Until the source and age of the records are established, the Telegram database remains an allegation backed by a substantial sample, not a confirmed new breach. The operational impact may be limited today, but the identity risk could persist much longer.
⬇️