Mexico Data Leak Probe: 12.9 Million Records Offered for Sale on Telegram
MEXICO · DATA SECURITY
Key Facts
- —What happened Mexico’s anti-corruption ministry is investigating a Telegram offer of more than 12.9 million personal records.
- —What was exposed Names, birth dates, addresses, phone numbers, emails, tax IDs and bank details, which the seller ties to call centers.
- —Who is named A 13,000-record sample carried the names of 23 firms, including BBVA, Banorte, Santander and Amazon.
- —The catch A firm’s name in the sample does not prove it leaked anything; the source is not yet established.
- —What comes next The ministry is opening its own inquiry to find who is responsible for the exposed databases.
The Mexico data leak exposes the details fraudsters need to pose as your bank, in the second such alert in a week.

Mexico’s government is investigating an offer on the messaging app Telegram to sell more than 12.9 million records of personal data. The seller’s post attributes the possible Mexico data leak to several call centers, the ministry said.
The Secretaría Anticorrupción y Buen Gobierno (SABG), the anti-corruption and good-government ministry, announced the inquiry on Thursday 24 September. It found the Telegram post, dated 22 September, through active monitoring.
What the Mexico Data Leak Contains
The seller claims the databases hold more than 12.9 million records. They include full names, birth dates, home addresses, email addresses, landline and mobile numbers, and bank details.
They also include the RFC, Mexico’s tax ID number. The ministry obtained a sample of 13,000 records, drawn from 13 different databases.
The sample carried the trade names of 23 companies. Banks named include BBVA, Banorte, Santander, Banamex, HSBC, Scotiabank, Inbursa, Banregio, Afirme, Banco del Bajío, INVEX and IXE.
Retailers named include Liverpool, Sears, Suburbia, Sanborns, C&A, Soriana and Sam’s Club. Amazon, American Express, Banco Walmart and Credomatic also appear.
The ministry stresses these are signs of a possible leak. Its inquiry will establish where the databases came from and who, if anyone, is responsible.
It did not say how recent the records are, how the seller obtained them or what price was asked. Records are not the same as people, since one person can appear in several databases.
Even so, the scale is large. If every record were a different person, it would cover roughly one in ten Mexicans.
Why Call Center Data Is So Useful to Fraudsters
Outsourced call centers often serve several clients, which can put many customers’ data in one place. The sample came from 13 databases, not from one company.
The mix of data is what makes it dangerous. A caller who knows your name, birth date, address and bank details can sound very much like your bank.
Phone fraud and extortion calls are a long-running problem in Mexico. Leaked data makes those calls more convincing, and harder to spot.
Both of this week’s alerts started with sale offers posted on Telegram. The ministry found both through its own monitoring.
A Second Alert in a Week
On 20 September, the same ministry warned of a possible exposure of data linked to the airline Aeroméxico. A Telegram post dated 18 September offered a file of more than 15 million records.
The ministry took a sample of 100,092 records and found data on public servants and public figures among them. Aeroméxico said on 21 September the data likely came from an October 2025 breach at an outside provider’s customer-data platform.
The airline said no payment data, passwords or itineraries were exposed. In October 2025, security specialists had warned of threats by the hacking group ShinyHunters to publish Aeroméxico customer data.
Who Protects Your Data in Mexico Now
A December 2024 constitutional reform abolished INAI, the old transparency and data-protection institute, which ceased to exist in March 2025. Oversight of company-held data passed to the SABG, led by Raquel Buenrostro.
The ministry says it acts under articles 54 and 55 of the federal law on personal data held by private parties. Those rules let it open cases on its own initiative.
The law was published on 20 March 2025 and took effect the next day. Fines are set in UMA, a peso-based unit, and the heaviest ranges reach 320,000 UMA.
At 2026 values of MXN 117.31 (US$6.64) per UMA, that is about MXN 37.5 million (US$2.1 million). Fines can double for legally sensitive data, such as health or religion, which is not reported here.
No person or company had been named as responsible by 25 September. The ministry said any procedure would follow the law and protect the public interest.
What to Do If You Live in Mexico
Assume a caller who knows your details may still be a fraudster. Banks do not ask for your full card number, PIN, security codes or one-time passwords by phone.
If a call claims to be from your bank, hang up and call back on the number printed on your card. Check your statements for charges you do not recognise.
Turn on two-step verification for email and banking apps where you can. The National Guard runs a 088 line for confidential reports of cyber incidents.
If money leaves your account without your consent, report it to your bank at once. You can also file a complaint with Condusef, the federal financial consumer protection agency.
Foreign residents are just as exposed if they bank or shop with the firms named. The records include tax IDs and bank details, which many foreigners also hold.
What Comes Next
The SABG will analyse the sample and establish who is responsible for the exposed databases. None of the 23 firms had commented publicly by Friday morning.
The Aeroméxico file remains under review in parallel. Together, the two alerts involve nearly 28 million records offered for sale in one week.
Sources: El Universal, SABG statement, 24 September 2026; Infobae, inquiry and Aeroméxico alert, 24 September 2026; El Informador, possible leak, 24 September 2026.
Frequently Asked Questions
What data was offered in the Mexico leak?
Names, birth dates, addresses, emails, phone numbers, RFC tax IDs and bank details. The seller claimed more than 12.9 million records and tied them to call centers.
Which companies are involved?
A sample carried the names of 23 firms, including BBVA, Banorte, Santander, Banamex, HSBC, Amazon, Liverpool and Soriana. Their names appearing does not prove they leaked the data.
Who is investigating?
Mexico’s Secretaría Anticorrupción y Buen Gobierno, which now oversees personal data held by companies. It announced its inquiry on 24 September 2026.
How can I protect myself?
Treat unexpected calls from your bank with suspicion and call back on the official number. Never share security codes or one-time passwords by phone.
Connected Coverage
This article was produced by The Rio Times’ automated newsroom system. How we use AI · Report an error
Read More from The Rio Times