What happened
On September 18, 2026, a Telegram user offered a database of more than 15 million records, about 1.10 GB, attributed to Aeroméxico. According to El Financiero's account of the Secretaría Anticorrupción y Buen Gobierno (SABG) statement, the fields include full names, emails, phone numbers, dates of birth and account creation dates. The SABG obtained a sample of 100,092 records that included public servants and public figures. It said it had found signs of a possible personal-data exposure, which could lead to an investigation under articles 54 and 55 of the LFPDPPP, the private-sector data protection law. Aeroméxico said it had identified no exposure of financial information, payment card data or account passwords.
The authenticity, origin and scope of the data are unconfirmed. Everything below is analysis of the regulatory response, not a finding that Aeroméxico was breached or at fault.
The case for a forceful response
The strongest argument for aggressive enforcement is that a leak of names, phone numbers and birth dates is not harmless just because no card numbers are involved. That combination is what phishing and social-engineering fraud need, and the sample reportedly includes public officials, who are prime targets. Individuals cannot inspect an airline's security practices or negotiate over them. A regulator that investigates quickly, before the company's account hardens, is doing what a data protection authority is for.
The investigation is also legitimate on procedural grounds. Under the 2025 law, published in the Diario Oficial on March 20, 2025 and in force the next day, the authority that took over INAI's data functions is the SABG. The SABG said on March 21, 2025 that data protection duties fall directly to the ministry and that companies as well as government agencies must meet high standards. Opening a verification on public reports of a leak is squarely within that mandate.
The problem: what the big fine rewarded
The way SABG has used its powers so far is less reassuring. Its major LFPDPPP sanction, announced July 12, 2026, was MXN 42,849,095 against the Mexican football federation over its Fan ID system. The SABG found that the federation's privacy notice did not tell fans that their biometric photographs are sensitive data, and that consent was collected through a website checkbox rather than a signature or other authentication mechanism. It also cited breaches of the principles of responsibility and lawfulness.
The biometric angle is a legitimate concern, and the fine is open to challenge in court. But the findings, as the SABG describes them, concern notice wording and consent mechanics. They do not describe any harm to fans, any breach, or any failure of technical safeguards. If the regulator's largest penalty goes to a formality while its investigation of a 15-million-record leak is still at the stage of a Telegram post, companies will rationally spend their compliance budgets on drafting notices and collecting signatures. Encryption, access controls, logging and vendor audits, which prevent leaks, will get less.
Proportionate regulation would weight penalties toward outcomes: failures of security safeguards, late or missing notification to affected people, and negligent vendor management. Paperwork defects should draw corrective orders first and fines for repeated or deliberate failures.
Independence and transparency
The second unresolved issue is structural. INAI was an autonomous body that was dissolved, and, as law firm analysis of the 2025 reform notes, its responsibilities moved to the Ministry of Anticorruption and Good Governance. A ministry that answers to the executive is now the regulator of private companies and also of government agencies, whose own data leaks it investigates. When the SABG looks into public-sector incidents, it is investigating its own branch of government.
This is not proof of bad faith. But it means credibility depends on process: published reasoning, a clear standard for what counts as a reportable exposure, and consistent treatment of public and private holders. Aeroméxico's case, involving a private firm and a high-profile sample, is the easy one. The harder test is whether identical scrutiny reaches a government agency with a comparable leak.
What good enforcement would look like here
- Verify first. Confirm whether the data is genuine, current and from Aeroméxico's systems, or a third party's, or a repackaged old scrape. Fines for a leak the company did not cause would punish the victim of a crime.
- Publish the standard. State what safeguards the SABG expects of a large data controller, so that the outcome is predictable for airlines, banks and start-ups alike.
- Penalise the failure, not the incident. Breaches happen to well-run firms. The question is whether reasonable safeguards and prompt notification were in place.
- Use the same yardstick for government. Apply equal standards to public institutions.
- Keep it appealable. Sanctions should stay open to judicial review, and the SABG should accept that.
Why it matters beyond one airline
Mexico has a large digital economy and a data law that now reaches processors as well as decision-makers. A regulator that concentrates on demonstrable security failures gives firms a reason to invest in real protection and gives consumers a remedy where it matters. One that concentrates on form pushes costs onto smaller companies least able to afford legal teams, without making leaks less likely. The Aeroméxico investigation is the first chance to show which of the two SABG intends to be.