On November 19, 2025, Mexican insurance company AARCO appeared on the leak site of the Akira ransomware group. The attackers say they have exfiltrated 17 GB of internal files and plan to publish them soon. The data includes passports, driver licenses, Mexican IDs, personal phones, addresses, emails, fingerprints, plus client personal information, financial records, contracts, and other confidential corporate documents.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Aarco
Get alerted the next time Aarco files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Aarco’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details of the Breach
Public reporting indicates that AARCO, which sells auto, life, medical, home, and travel insurance to individuals and businesses in Mexico, was hit by a ransomware attack. The Akira group has listed the company on its public leak portal and stated it will release the 17 GB archive containing sensitive employee and customer records. No exact number of affected individuals has been confirmed, but the volume and variety of data suggest thousands of records are involved. The deadline for publication has not been publicly specified beyond the phrase “soon.”
Why This Matters for You and Your Family
If you or any member of your family holds an AARCO policy, your personal details may now sit in a ransomware data set. Passports, driver licenses, national IDs, home addresses, phone numbers, emails, and fingerprints are exactly the building blocks criminals need to open accounts in your name, file fraudulent claims, or sell your identity on underground markets. Even if you are not an AARCO customer, employees of the company face the same risk: their family addresses and contact information can be used to pressure them or to reach their spouses and children. Once this volume of data leaks, it rarely stays contained.
The Doxxing and Identity-Chain Risk
Stolen insurance files rarely travel alone. A single leaked email or phone number can be correlated with gaming accounts, social-media handles, and school records. This creates an identity chain that turns one breach into repeated harassment or targeted fraud. Credential leaks of this kind frequently cascade into account takeovers on gaming platforms, where children’s usernames and shared family passwords become entry points for further doxxing. The combination of official IDs and personal contact data makes it easier for attackers to map who lives where and who is related to whom.