Aeroméxico is investigating a possible leak of customer information after the federal Ministry of Anti-Corruption and Good Governance (SABG) identified an online user offering to sell a trove of over 15 million passenger records.
However, Aeroméxico said Sunday that it hadn’t identified any compromise of its customers’ financial information.
🚨Detectan posible exposición de datos personales vinculada a Aeroméxico
La Secretaría Anticorrupción y Buen Gobierno identificó indicios de una posible filtración de datos personales en un sistema que podría estar relacionado con Aeroméxico.
El hallazgo surgió tras detectar,… pic.twitter.com/iSFbFpKhkx
— Azucena Uresti (@azucenau) September 20, 2026
In a statement, Aeroméxico said that “based on the information available,” it hadn’t identified any “exposure” of its customers’ “financial information,” including details of cards used to purchase flights.
The airline also said it hadn’t detected any compromise of customers’ Aeroméxico account passwords, including those used to access the Aeroméxico rewards program.
“Furthermore, this situation has not created any impact on our operations,” Aeroméxico said.
The airline released its statement after SABG said it had detected that a user of the social media and instant messaging platform Telegram was attempting to sell a 1.1 gigabyte database “supposedly attributable” to Aeroméxico and containing more than 15 million passenger records.
“Within the framework of active forensic monitoring of possible security incidents, the Ministry of Anti-Corruption and Good Governance identified signs of a possible exposure of personal data in a system that could be related to Aeroméxico,” the SABG said in a statement.
The ministry said that its monitoring allowed it to locate a Sept. 18 post on Telegram in which “a user offers a database supposedly attributable to Aeroméxico with more than 15 million records,” including — allegedly — the full names of customers of the airline, their e-mail addresses, their telephone numbers and their dates of birth.
The SABG said that it “obtained a sample of 100,092 records” and subsequently identified the names of various people, including those of public servants and public figures.
The ministry said it would “analyze the data obtained” and begin an investigation aimed at determining “the alleged responsibility for the compromised databases.”
Aeroméxico said it would cooperate with federal authorities and report on any relevant developments in a timely manner.
The airline also said it had begun its own “exhaustive investigation” in order to “verify the authenticity and veracity” of the information being offered to “third parties,” determine “its origin” and “establish the reach of any possible impact.”
While the airline said it hadn’t identified any compromise of its customers’ financial information, it advised its customers to stay alert to “unusual e-mails, messages or calls that seek personal or financial information.”
Aeroméxico didn’t say that its systems or databases had been targeted in a cyberattack.
However, hackers have previously targeted both companies and federal and state governments in Mexico. Among the victims of previous cyberattacks are the Ministry of National Defense and state oil company Pemex.
Mexico News Daily