Cyber & AI intelligence
Wasteland.
Briefs indexed2883
Issues29
Published Mondays07:30 CT
▣ Breach MEXICO-CALL-CENTER 2026-09-26

Mexican Call Centers: 12.9 Million Personal Records Offered for Sale on Telegram

"Mexico's Secretaría Anticorrupción y Buen Gobierno (Anti-Corruption and Good Government Ministry) is investigating a Telegram post that offers more than 12.9 million personal records. The seller says the data comes from…"

Mexico's Secretaría Anticorrupción y Buen Gobierno (Anti-Corruption and Good Government Ministry) is investigating a Telegram post that offers more than 12.9 million personal records. The seller says the data comes from several Mexican call centers. Every source here reports the 12.9 million figure, taken from the ministry's own statement. Some Spanish-language outlets round it to "casi 13 millones" (almost 13 million) (xeva, Tribuna). The ministry got hold of a 13,000-record sample from 13 separate databases. In that sample it found the trade names of 23 companies, including large Mexican and international banks and retailers. The records include names, contact details, dates of birth, RFC tax IDs, home addresses and banking data. The authorities have not yet confirmed that the full 12.9 million records are genuine, and they have not named a source for the leak. Readers should treat the headline count as the seller's claim until it is verified.

None of the eight sources available for this brief is a primary document. The most direct account is Dominio Público, which appears to reproduce the ministry's communiqué almost word for word. The other outlets mostly repeat that statement.

What Happened

The ministry says it found the listing through "monitoreo activo" (active monitoring). The Telegram post appeared on 22 September 2026, and in it a user offered databases "supuestamente atribuibles a diferentes call centers" (allegedly attributable to various call centers) (Dominio Público, El Financiero, xeva). The ministry announced its investigation on 24 September (Tribuna, xeva).

What investigators have done so far:

What is still unknown: xeva states plainly that the government has not established who leaked the data or where it came from. It has also not confirmed that the 12.9 million records are authentic. El Financiero notes the ministry did not say whether it will act against the seller or the Telegram group. Riviera Maya News reports that investigators are looking into whether organized crime is involved. No other source mentions this, so it should be read as unconfirmed.

A key point about the brand names: the ministry identified these companies' names inside the call-center databases. That is not a finding that any of those companies was breached. The likeliest explanation is that call centers held customer lists for these brands as outsourced vendors, for collections, telesales or customer service. None of the named companies had issued a public statement in the sources reviewed.

Related case: this is the second Telegram data listing the same ministry has flagged in less than a week. On 18 September, a post offered a 1.10 GB database said to contain more than 15 million Aeroméxico records. The ministry reviewed a 100,092-record sample and said on 20 September that the origin was not established and the data was only "presuntamente atribuible" (allegedly attributable) to the airline (UPI, CiberLATAM). Aeroméxico said some customer data was compromised in an international cyberattack in October 2025. It said no financial data, payment cards or passwords were exposed (CiberLATAM). The two cases are separate, and the sources do not link them.

What Was Taken

According to the ministry's description, as reproduced across the outlets, the records include:

Volume: more than 12.9 million records, as claimed by the seller and repeated by the ministry. The ministry has reviewed 13,000 of them, about 0.1%. The number of records does not equal the number of people affected. Call-center lists often contain the same person many times across different client campaigns.

Sensitivity: high. In Mexico, a person's RFC is built from their name and date of birth. With a phone number and address added, the data is enough to impersonate someone convincingly and to attempt account takeover. The phrase "datos bancarios" is the most worrying item, but no source says what it covers. It could be account numbers, card fragments, CLABE interbank account codes or credit-product details. Riviera Maya News says "sensitive banking data" was taken. The ministry's own wording is more cautious: the records "incluirían" (would include) banking data.

Why It Matters

The Attack Technique

The sources do not say how the data was obtained. No source names an intrusion method, a vulnerability or a threat actor, and the ministry says the source is still under investigation. The evidence so far points to a few plausible routes. These are analyst assessments, not confirmed findings:

  1. Insider sale. Call-center staff often have broad access to CRM (customer relationship management) systems and can export lists in bulk. Selling client lists is a known problem in the Mexican telemarketing industry.
  2. Compromised vendor systems. The data sat in 13 separate databases under different company names. That could mean several call centers were hit, or one aggregator (a firm that compiles lists from many sources) was compromised.
  3. Aggregated or resold lists. The listing may be old data from earlier leaks that has been repackaged. This would fit with the authorities not yet confirming the data is authentic.

The mix of RFC, date of birth and banking fields matches the kind of records used in debt collection and credit-product telesales.

What Organizations Should Do

  1. Check which vendors hold your customer data. List every call center, collections agency and telesales contractor that holds customer data. Confirm what fields each one receives, and remove RFC and banking data wherever the task does not need it.
  2. Enforce data-handling terms in contracts. Require vendors to control exports, log access, notify you of breaches within fixed deadlines, and delete data when a campaign ends. Audit them against those terms, not just their questionnaires.
  3. Seed lists with canary records. Put unique fake entries (a mailbox, a phone number or an RFC-style ID) into each vendor's dataset. If one turns up for sale, you know which vendor it came from.
  4. Monitor Telegram and dark-web markets for your brand name and your vendors' names. Ask for samples early, so you are not relying on a regulator to find the listing first.
  5. Tighten caller verification and fraud controls. Banks and retailers named in this listing should assume customers' names, RFCs and contact details are known to criminals. Stop using those details as proof of identity, and warn customers about calls from people posing as the bank.
  6. Prepare for regulator questions. Record your vendor-oversight evidence now. The ministry is using its LFPDPPP powers on its own initiative, and data controllers remain responsible for data their processors hold.

Sources: Mexico Probes Sale of 12.9 Million Personal Records From Call Cente... | Investigan venta de bases de datos de call centers: Vulneran 12.9 m... | México investiga presunta filtración de casi 13 millones de registr... | Mexico reviews possible Aeroméxico data leak — CiberLATAM | Mexico probes possible Aeromexico customer data breach - UPI.com | Mexico Data Leak: 12.9 Million Records Offered on Telegram | Buen Gobierno investiga presunta venta de más de 12.9 millones de r... | Anticorrupción investiga la venta ilegal de casi 13 millones de dat...