HIGH SEVERITYTravel: Air

Aero Mexico Data Breach

Aeromexico Airline Breach (Salesforce, 2025): 20.6 Million Customer Records Including Passport Numbers Exposed

Mexican airline operating domestic and international passenger services.

Verified by ObscureIQ Intelligence

7.5Severity
20.6MRecords
4Fields
2025Year

ObscureIQ Breach Intelligence Scores
11.6
Breach Risk Index
29
Data Value
40
Market Recency
206
days
Since Breach

Risk Interpretation

High risk of travel fraud, phishing, loyalty abuse, and booking impersonation. Flight data can also reveal travel patterns and periods of likely absence from home.

🎯 Impact & Downstream Threats

The institutional impact on Aeroméxico has unfolded against an unusually crowded backdrop of similarly affected enterprises, including Toyota, FedEx, Disney, Marriott, Stellantis, Qantas, and dozens of others. That shared exposure spreads regulatory and journalistic attention across the cohort but does not reduce the airline's individual obligations under Mexican data-protection law. Aeroméxico faces likely customer notification, potential class-action exposure in jurisdictions where affected pa

Primary downstream threats:
  • SIM swap attacks where phone numbers are present
  • Targeted phishing campaigns using exposed email addresses

🔓 Threat Vectors

Phishing, credential stuffing & account takeover
Name-based social engineering
International identity fraud & border exploitation
SIM swapping, vishing & SMS phishing

📋 Breach Intelligence

EntityAero Mexico (Aeromexico)
OrganizationPrivate Company • Mexico / Global
Breach Date2025-10-10
DBC Added2025-10-03
Added Date2025-10-03
Records~20.6M (20,570,299 records)
Attack VectorUnknown
Threat ActorScattered Lapsus$ Hunters (Scattered Spider + LAPSUS$ + ShinyHunters)
Data SubjectsCustomer: Direct
Breach PathwaySupply_Chain:Platform
Supply ChainSalesforce
SourceDataBreach.com / ObscureIQ
SensitivityStandard
Breach ID64.0
StatusConfirmed

📝 Executive Summary

Aeroméxico, the flag carrier airline of Mexico, was named on October 3, 2025 as one of approximately 39 victims of a coordinated data-theft campaign targeting Salesforce customer instances. The threat collective behind the campaign calls itself Scattered Lapsus$ Hunters and combines members of three established cybercrime groups: Scattered Spider, Lapsus$, and ShinyHunters.\n\nThe attackers did not exploit a vulnerability in Salesforce itself. They used social engineering, including voice phishing of employees and OAuth-token abuse via compromised third-party applications connected to Salesforce, to authorize malicious connected apps and export customer relationship management data through the platform's API. The Aeroméxico subset of the campaign reportedly exposed approximately 20.6 million customer records, with public reporting from threat-actor sources mentioning figures as high as 30 million. The fields included names, email addresses, phone numbers, and passport numbers held in the airline's Salesforce environment.\n\nFor affected passengers, the practical risk is unusually high because of the inclusion of passport numbers. Combined with name and contact data, passport details support international identity-verification bypass, fraudulent visa or travel-document applications, and credible impersonation in border or immigration contexts. Affected travelers should treat their passport details as compromised, monitor for unusual travel-related contact, and remain alert to phishing referencing past Aeroméxico bookings, Club Premier loyalty status, or customer service tickets. Anyone receiving extortion-style messages referencing the breach should report them to law enforcement and not engage with payment demands, since Salesforce and most named victims have publicly refused to negotiate.

🏢 About Aero Mexico

Aeroméxico is the flag carrier airline of Mexico, headquartered in Mexico City and operating both domestic Mexican routes and international service across the Americas, Europe, and Asia. The airline is part of the SkyTeam alliance and runs the Club Premier loyalty program. As one of Mexico's largest airlines, it processes a high volume of passenger booking, identity, payment, and loyalty data through customer relationship management and reservation systems, including a Salesforce-based CRM environment used to manage customer engagement.

Company | Passenger air transportation | Commercial airline operations | Mexico / Global
Private CompanyMexico / Globalaeromexico.com

🗂 Why They Hold Your Data

Commercial airlines collect passenger identity, contact details, booking records, payment-adjacent information, itinerary data, and loyalty or support records across air-travel operations.

📰 Recent Developments

Aeroméxico is one of dozens of organizations exposed in a wave of attacks against Salesforce customer instances by a threat collective calling itself Scattered Lapsus$ Hunters, which combines members of Scattered Spider, Lapsus$, and ShinyHunters. The group launched a public extortion portal on October 3, 2025 listing the airline alongside roughly 39 victims and set an October 10 ransom deadline. Salesforce publicly stated it would not pay extortion demands. Law enforcement, including the FBI and France's BL2C, took the public-facing portal offline. Aeroméxico has not issued detailed customer-facing statements about the incident as of early 2026.

🔍 Data Points Exposed

4 verified field types:
Email
Phone Number
Passport
Name

Exposure Categories

CredentialsPASSPORT

Canonical Fields

email_address, full_name, passport_number, phone_number

🌐 Dark Web Verification

Confirmed
  • Dataset containing ~20.6M records identified in breach intelligence sources
  • Data indexed and searchable across breach notification platforms
  • Source: aeromexico-salesforce-2025

🛡 Recommended Actions

⚠️ Do not assume this is low sensitivity.

1Freeze Your Credit
Place a credit freeze with Equifax, Experian, and TransUnion.
2Expect Targeted Phishing
Watch for emails referencing this breach. Verify through official channels.
3Enable MFA Everywhere
Enable multi-factor authentication on all accounts.
4Monitor Accounts
Watch for unauthorized activity on financial and personal accounts.
5Check Your Exposure
ObscureIQ clients: this breach is indexed in your profile.

Protect Yourself

Check If You’re Affected

Enter your email to check if your data appears in this breach.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed.

High-Risk? Get an Exposure Audit

Full-spectrum exposure audits for executives and public figures.

Request Consultation

ObscureIQ Advisory

We combine proprietary dark web access with commercial and restricted breach intelligence to verify exposure and assess real-world risk.

If you are:
  • A public-facing individual
  • A high-profile executive
  • A customer of Aero Mexico
  • Or concerned about credential reuse
Services
AuditsWipesThreat MonitoringTraining

Classification Tags

TravelEmailPhone

Powered by the ObscureIQ Breach Intelligence Database

© 2026 ObscureIQ · All Rights Reserved · Data Licensing

Latest from ObscureIQ

Credit

What Is Credit Monitoring? And Do I Want It? (Answer: Not Really)

July 14, 2025
Every time there’s a major data breach, companies scramble to offer “free” credit monitoring. It sounds like a responsible move.…
breach economycredit freezecredit scoreequifaxexperian
Credible Threats

Lock Down Browsers. Wipe Employee Footprints. Win Breach Wars.

September 2, 2025
Lock Down Browsers. Wipe Employee Footprints. Win Breach Wars. Over 80% of security incidents now start in the browser. Chrome.…
brave browserbreachesbrowser exploitbrowserschrome
Analysis

Sextortion Spam

May 10, 2025
Sextortion scams aren’t new, but they remain one of the most effective forms of cyber-enabled fraud. These scams don’t rely…
bitcoindeadlinefeargoogle maps apiransom