Aeromexico has confirmed that a data breach affecting more than 15 million customer records did not expose bank accounts, payment cards, passwords or flight itineraries.
The airline said an internal investigation determined the unauthorized access occurred in October 2025 through a customer management platform operated by an external provider.
The compromised data includes names, email addresses, phone numbers, and in some cases, dates of birth and registration dates.
Aeromexico said the incident did not affect its operations or services, but advised customers to be wary of phishing attempts and suspicious communications.
Independent reports said the breach came to light on September 18, when Mexico’s Ministry of Anti-Corruption and Good Governance detected a file containing the records being offered for sale on Telegram.