What happened
On September 20, 2026, Mexico's Secretaría Anticorrupción y Buen Gobierno (SABG) announced that its monitoring had found a Telegram post, dated September 18, offering a database attributed to Aeroméxico. The post claimed more than 15 million records in a 1.10 GB file, with names, emails, phone numbers and birth dates. SABG obtained a sample of 100,092 records that includes public servants and public figures. It said it would analyze the data and open an ex officio investigation under its authority to verify compliance with the Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP).
Aeroméxico said it had not identified exposure of financial data such as bank accounts or payment cards, or of passwords or itineraries. It also said it would investigate the data's authenticity and origin and cooperate with authorities, according to Mexico News Daily. On September 22 the airline reported preliminary findings: the material may correspond to an October 2025 incident at a third-party customer-management platform, as El CEO reported. Neither SABG nor the airline has publicly established whether this is a new breach or old data being resold.
The strongest case for the regulator's move
The case for SABG's speed is real. Leaked contact data fuels phishing and fraud the moment it circulates, and a sample containing public officials raises obvious security concerns. A regulator that waits for a victim complaint would learn about this only after the data had been sold. Proactive monitoring, followed by an ex officio probe, is exactly what a data protection authority is supposed to do. Notably, SABG also did not claim certainty: its own statement speaks of "indicios" of a possible exposure and of determining responsibility later.
Why the institutional design matters
The LFPDPPP was published in the Diario Oficial de la Federación on March 20, 2025, and repeals the 2010 law. It moved private-sector data protection oversight from the autonomous INAI to SABG, a direct executive-branch entity, with decisions challengeable through amparo.
This is the structural issue. A regulator that sits inside the executive, is also charged with anti-corruption, and is publicly describing a probe of a listed private company before the facts are settled creates two risks. The first is credibility: a data protection authority earns trust through predictable, evidence-led process, and independence from political incentives is part of that. The second is market impact. On the day Aeroméxico published its preliminary findings, its shares rose about 3.4% on the BMV, but the stock is still down roughly 28% for the year. That shows how sensitive a company's valuation can be to an unverified claim.
None of this proves SABG acted improperly. Its announcement was measured. The concern is about what a regime does when the next case is less carefully worded.
What the case does and does not show
It is easy to overread the facts. The database's provenance is unconfirmed. SABG itself stresses that having records does not establish they came from Aeroméxico's systems, a point Excélsior's account also notes. A claimed incident in October 2025 at a third-party platform, if confirmed, would shift the compliance question toward vendor management: whether a company that outsources customer data keeps adequate oversight of its processors. That is a legitimate question, and a more useful one than whether a Telegram seller's headline number is accurate.
It also matters that the exposed fields are identity and contact data, not payment data. Contact data is lower-severity than financial credentials but is precisely what drives targeted phishing. Proportionate regulation distinguishes those tiers rather than treating every leak as equivalent.
A pro-innovation reading
Mexico needs a credible privacy regime. Airlines, fintechs and platforms all hold personal data, and consumers deserve remedies when it leaks. A pro-innovation stance is not an anti-enforcement stance. Predictable enforcement is better for investment than either lax rules or sporadic, headline-driven action.
Three practices would make SABG's approach stronger.
- Verify before attributing. Announce monitoring findings as such, and name a company only after confirming authenticity or after the company has had a reasonable chance to respond.
- Publish process. Say what triggers an ex officio investigation, what timelines apply, and how findings will be released. Companies and the public can then judge whether the process is consistent.
- Focus on controls, not the headline count. The useful outcome is a finding on whether security measures and processor oversight were reasonable, not a tally of records.
The amparo route gives companies a judicial check on SABG decisions, which is a meaningful safeguard. It does not, however, undo reputational damage from an early announcement.
What to watch
The next signals are concrete. Does SABG publish a finding on whether the data matches the October 2025 incident? Does it examine the third-party platform's role? And does it explain, publicly, how it distinguishes a fresh breach from resold old data? Those answers will say more about the quality of Mexico's new regime than the first announcement did.
The 2025 reform consolidated authority in the executive. This case is an early, relatively low-stakes test of whether that authority will be exercised with the evidentiary discipline that an independent regulator would have been expected to show. The announcement was careful. The follow-through is what counts.