Data breach
Aero Mexico (Partial)
- Records
- 20,570,299
- Breach date
- 10 October 2025Estimated
- Added
- 3 October 2025
What was exposed
4 types of data · 1 more reported · 1 puts you at serious risk
- Email addresses1
- Names1
- Passport numbers1
- Phone numbers1
- Dates of birthReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
Aeroméxico customer data has surfaced in a large extortion campaign tied to attacks on Salesforce customer databases. The listing covers roughly 20.6 million records associated with the airline, with an estimated attack date of October 10, 2025. The group behind the campaign, which calls itself Scattered LAPSUS$ Hunters, published a data leak site on October 3, 2025 naming 39 companies whose Salesforce instances it claims to have compromised, including Aeroméxico, Toyota, FedEx, Qantas and others. No individual or group is recorded as claiming this specific listing in the index.
The airline itself did not publicly confirm the incident at the time. That changed nearly a year later, after a database allegedly containing Aeroméxico customer records appeared for sale on Telegram.
Breach Timeline
October 3, 2025: The group Scattered LAPSUS$ Hunters launched a data leak site on the dark web listing 39 companies, including Aeroméxico, and gave them until October 10, 2025 to begin ransom negotiations, according to Help Net Security.
September 18, 2026: A Telegram post offered a 1.10-gigabyte database allegedly belonging to Aeroméxico with more than 15 million records, according to Mexico's Ministry of Anticorruption and Good Government, as reported by El Fondo.
September 20, 2026: The ministry announced an investigation after identifying signs of personal data exposure.
September 21, 2026: Aeroméxico confirmed that customer personal data was compromised in an October 2025 cyberattack, per the airline's statement reported by Proceso.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses, phone numbers, passport numbers, and names. Our investigation team estimates the indexed dataset contains about 20.6 million rows, though it has not determined exact counts for each data type.
In its September 2026 statement, Aeroméxico said its preliminary forensic analysis found the exposed information included customer names and telephone numbers, and in some cases birth dates and email addresses. The airline said it has not identified exposure of financial data such as bank accounts or payment cards, nor passwords or flight itinerary details. The Telegram post identified by Mexican authorities reportedly offered records containing full names, emails, landline and mobile phone numbers, birth dates, and registration dates.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Passport numbers and full contact details are valuable to criminals. They can be used for targeted phishing, since a message that includes your real name, email, and phone number is far more convincing than generic spam. Scammers may impersonate the airline, a travel agency, or a government office, referencing your booking or travel history to extract payment details or additional personal information.
Passport numbers alone are generally not enough to open accounts or commit identity fraud by themselves, but combined with names and birth dates they can support more sophisticated schemes, including fraudulent travel-related communications. Because Aeroméxico says no passwords or financial data were exposed, direct account takeover or payment fraud appears less likely, though customers should still treat any unexpected contact claiming to come from the airline with suspicion.
What Is Aeroméxico Doing in Response?
The airline said it activated response protocols and mitigation measures after learning of the incident and stated it has taken measures to address it. Aeroméxico acknowledged that while the unauthorized access occurred on a customer information platform run by an external provider, it remains responsible for protecting customer data, and said it is working with that provider to reinforce containment actions. It has advised customers to stay alert to suspicious messages, calls, or emails requesting personal details. Mexico's Ministry of Anticorruption and Good Government has opened an investigation and announced an official inspection into the airline's data protection compliance.
What Should You Do If You Were Affected?
Be cautious with unsolicited calls, texts, or emails that reference Aeroméxico, your bookings, or your personal details. Verify directly through official airline channels before responding.
Never share payment card numbers, passwords, or passport scans in response to an unexpected message.
If you receive a phishing attempt referencing your real name or phone number, report it to the relevant platform and to Aeroméxico.
Monitor your accounts for unusual activity, and consider reviewing your passport issuance authority's guidance if you believe your passport number was compromised.
