Mexico's Secretaría Anticorrupción y Buen Gobierno (Anti-Corruption and Good Government Ministry) is investigating a Telegram post that offers more than 12.9 million personal records. The seller says the data comes from several Mexican call centers. Every source here reports the 12.9 million figure, taken from the ministry's own statement. Some Spanish-language outlets round it to "casi 13 millones" (almost 13 million) (xeva, Tribuna). The ministry got hold of a 13,000-record sample from 13 separate databases. In that sample it found the trade names of 23 companies, including large Mexican and international banks and retailers. The records include names, contact details, dates of birth, RFC tax IDs, home addresses and banking data. The authorities have not yet confirmed that the full 12.9 million records are genuine, and they have not named a source for the leak. Readers should treat the headline count as the seller's claim until it is verified.
None of the eight sources available for this brief is a primary document. The most direct account is Dominio Público, which appears to reproduce the ministry's communiqué almost word for word. The other outlets mostly repeat that statement.
What Happened
The ministry says it found the listing through "monitoreo activo" (active monitoring). The Telegram post appeared on 22 September 2026, and in it a user offered databases "supuestamente atribuibles a diferentes call centers" (allegedly attributable to various call centers) (Dominio Público, El Financiero, xeva). The ministry announced its investigation on 24 September (Tribuna, xeva).
What investigators have done so far:
- They obtained a sample of 13,000 records from 13 databases held in the names of different legal entities ("personas morales").
- They found 23 brand names in the sample: Amazon, American Express, Afirme, Banamex, Banco del Bajío, BBVA, Banorte, Banregio, HSBC, Inbursa, INVEX, Liverpool, Sam's Club, Santander, Scotiabank, Sears, Suburbia, Banco Walmart, Credomatic, Ixe, Sanborns, C&A and Soriana (Dominio Público, El Financiero, Tribuna). Riviera Maya News lists only nine of these, but it does not contradict the fuller list.
- They opened ex officio proceedings. The ministry is acting on its own initiative ("de oficio") under Articles 39(I), 54 and 55 of the Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP), Mexico's private-sector data protection law (Dominio Público).
What is still unknown: xeva states plainly that the government has not established who leaked the data or where it came from. It has also not confirmed that the 12.9 million records are authentic. El Financiero notes the ministry did not say whether it will act against the seller or the Telegram group. Riviera Maya News reports that investigators are looking into whether organized crime is involved. No other source mentions this, so it should be read as unconfirmed.
A key point about the brand names: the ministry identified these companies' names inside the call-center databases. That is not a finding that any of those companies was breached. The likeliest explanation is that call centers held customer lists for these brands as outsourced vendors, for collections, telesales or customer service. None of the named companies had issued a public statement in the sources reviewed.
Related case: this is the second Telegram data listing the same ministry has flagged in less than a week. On 18 September, a post offered a 1.10 GB database said to contain more than 15 million Aeroméxico records. The ministry reviewed a 100,092-record sample and said on 20 September that the origin was not established and the data was only "presuntamente atribuible" (allegedly attributable) to the airline (UPI, CiberLATAM). Aeroméxico said some customer data was compromised in an international cyberattack in October 2025. It said no financial data, payment cards or passwords were exposed (CiberLATAM). The two cases are separate, and the sources do not link them.
What Was Taken
According to the ministry's description, as reproduced across the outlets, the records include:
- Full names
- Email addresses, landline numbers and mobile numbers
- Dates of birth
- RFC (Registro Federal de Contribuyentes), Mexico's taxpayer ID
- Home addresses
- Banking data (the ministry did not describe it further)
- Other personal data ("entre otros")
Volume: more than 12.9 million records, as claimed by the seller and repeated by the ministry. The ministry has reviewed 13,000 of them, about 0.1%. The number of records does not equal the number of people affected. Call-center lists often contain the same person many times across different client campaigns.
Sensitivity: high. In Mexico, a person's RFC is built from their name and date of birth. With a phone number and address added, the data is enough to impersonate someone convincingly and to attempt account takeover. The phrase "datos bancarios" is the most worrying item, but no source says what it covers. It could be account numbers, card fragments, CLABE interbank account codes or credit-product details. Riviera Maya News says "sensitive banking data" was taken. The ministry's own wording is more cautious: the records "incluirían" (would include) banking data.
Why It Matters
- Vendors are the weak point. The 23 brands did not need to be breached themselves. Data they passed to outsourced call centers may have leaked from those contractors. Security programs that end at the company's own network do not cover this.
- This is ready-made material for fraud. Collections and telesales lists sort people by the bank or retailer they deal with. That lets criminals pose convincingly as BBVA, Banamex or Santander, and impersonation of bank call centers is already common in Mexico.
- Telegram is now the main marketplace. Two large listings in Mexico in one week were both posted on Telegram, and the regulator found both by monitoring the platform itself.
- Enforcement is taking shape. The anti-corruption ministry now carries out LFPDPPP enforcement, which the INAI used to handle. It is using its ex officio powers visibly. Companies whose data sits with vendors should expect regulators to ask them about oversight of those vendors.
The Attack Technique
The sources do not say how the data was obtained. No source names an intrusion method, a vulnerability or a threat actor, and the ministry says the source is still under investigation. The evidence so far points to a few plausible routes. These are analyst assessments, not confirmed findings:
- Insider sale. Call-center staff often have broad access to CRM (customer relationship management) systems and can export lists in bulk. Selling client lists is a known problem in the Mexican telemarketing industry.
- Compromised vendor systems. The data sat in 13 separate databases under different company names. That could mean several call centers were hit, or one aggregator (a firm that compiles lists from many sources) was compromised.
- Aggregated or resold lists. The listing may be old data from earlier leaks that has been repackaged. This would fit with the authorities not yet confirming the data is authentic.
The mix of RFC, date of birth and banking fields matches the kind of records used in debt collection and credit-product telesales.
What Organizations Should Do
- Check which vendors hold your customer data. List every call center, collections agency and telesales contractor that holds customer data. Confirm what fields each one receives, and remove RFC and banking data wherever the task does not need it.
- Enforce data-handling terms in contracts. Require vendors to control exports, log access, notify you of breaches within fixed deadlines, and delete data when a campaign ends. Audit them against those terms, not just their questionnaires.
- Seed lists with canary records. Put unique fake entries (a mailbox, a phone number or an RFC-style ID) into each vendor's dataset. If one turns up for sale, you know which vendor it came from.
- Monitor Telegram and dark-web markets for your brand name and your vendors' names. Ask for samples early, so you are not relying on a regulator to find the listing first.
- Tighten caller verification and fraud controls. Banks and retailers named in this listing should assume customers' names, RFCs and contact details are known to criminals. Stop using those details as proof of identity, and warn customers about calls from people posing as the bank.
- Prepare for regulator questions. Record your vendor-oversight evidence now. The ministry is using its LFPDPPP powers on its own initiative, and data controllers remain responsible for data their processors hold.
Sources: Mexico Probes Sale of 12.9 Million Personal Records From Call Cente... | Investigan venta de bases de datos de call centers: Vulneran 12.9 m... | México investiga presunta filtración de casi 13 millones de registr... | Mexico reviews possible Aeroméxico data leak — CiberLATAM | Mexico probes possible Aeromexico customer data breach - UPI.com | Mexico Data Leak: 12.9 Million Records Offered on Telegram | Buen Gobierno investiga presunta venta de más de 12.9 millones de r... | Anticorrupción investiga la venta ilegal de casi 13 millones de dat...