Mexico investigating 12.9 million personal records offered on Telegram
If you are a customer of Mexico investigating, here’s what is being claimed, and what it would mean for you.
On 24 September 2026, Mexico’s SABG confirmed it found a Telegram post from 22 September offering more than 12.9 million personal records supposedly from call centers, including names, phones, emails, dates of birth, RFC numbers, addresses and banking details. Investigators have a sample of 13,000 records in which well-known banks and retailers were named. SABG has not confirmed that the full set is real or that any of those companies was breached.
— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Editor’s note: The claims described below originate from a ransomware group’s leak-site posting and have not been independently verified by GalaxyWarden. A listing of this kind is an assertion made by the group during an extortion attempt. It is not evidence that a breach occurred, and we report it as a claim rather than as a finding.
Mexico investigating customer?
See what’s already exposed about you — free, 15sWe check your email against known public breach records and the sites that publish your address, then show you what to do about each one. We don’t hold this company’s data. No account, no card.
Here for work? Check a company domain’s exposure.
On 24 September 2026, Mexico’s Secretaría Anticorrupción y Buen Gobierno (SABG) issued an official statement confirming it had found a Telegram post dated 22 September 2026. In that post, a user offered databases supposedly from various call centers, with more than 12.9 million records. SABG said those records would include full name, email address, phone and mobile numbers, date of birth, RFC (Mexico’s tax ID), home address and banking details, among other information.
SABG obtained a sample of 13,000 records from 13 databases. Brand names that appeared in that sample were Amazon, American Express, Afirme, Banamex, Banco del Bajío, BBVA, Banorte, Banregio, HSBC, Inbursa, INVEX, Liverpool, Sam’s Club, Santander, Scotiabank, Sears, Suburbia, Banco Walmart, Credomatic, IXE, Sanborns, C&A and Soriana. The secretariat said it will analyse the sample and open investigations. It did not say the 12.9 million records are genuine, that they came from those companies, or that any company was breached. As of 25 September 2026, none of those companies had issued a public statement.
The brand names are not the part that matters
Coverage of this has led with Amazon, BBVA, Liverpool and “12.9 million.” That framing makes it sound as if your bank or your store was hacked, and as if that huge number is a counted fact. SABG did not say either of those things. Its statement is full of “possible,” “alleged” and “supposedly.” A Telegram user claimed to be selling call-center databases. Investigators copied a sample of 13,000 records, and those commercial names showed up. A logo in a seller’s sample is not a claimed breach of that company. The 12.9 million figure is the seller’s claim, not a total SABG has verified. Mexican outlets have been repeating the government comunicado, not independently checking the files.
- Every indexed leak tied to your address — all of them, named and dated
- A deeper search of collected breach data — the kinds of your information it holds, where it finds you
- What this kind of incident typically exposes
- A ten-minute lock list written for this kind of organisation
What that misses, if you are an ordinary customer, is the mix of fields. Full name, RFC, date of birth, home address, phone numbers and banking details are the same answers a call center already asks for before it will treat a caller as you. If even some of those rows are real, a stranger does not need to break into your bank. They can phone the same kind of help line and already know the questions that were supposed to keep them out. Whether the data sat at a household-name company or at a contractor you never chose is a later legal question. For you, the live risk is impersonation with a file that looks like a customer-service identity check.
Advertisement
Know the day any company files a breach.
Every SEC 8-K Item 1.05 and state breach notification — dated, sourced, and delivered by email + a JSON API the day it posts. Track any company, not just the ones in the news.
GalaxyWarden Signals and RecentBreaches share common ownership.
You should also not expect a clean answer to the question that feels most urgent: whether you were in this. SABG has a sample, not a public list. There is no reliable way for you — or for any website — to check whether your details were in this specific offer. A “not found” result would not mean you were absent. Anyone who claims they can look you up in this incident is offering false comfort.
What to actually expect
- You are unlikely to get a personal notice telling you that you were, or were not, included. SABG has not declared a claimed breach, and as of 25 September 2026 none of the 23 named companies had spoken publicly.
- Headlines will keep repeating “12.9 million” and the same company list. That is the 24 September statement being copied, not new proof that the files are real or complete.
- If some of the data is genuine, the near-term harm is not every account emptying at once. It is tailored phone calls and messages that already know your name, RFC, birthday, or a bank or store you use — including fake contacts that pretend to be about this investigation. The aim is to pass as you, or to talk you into handing over one more code.
- SABG said it will study the 13,000-record sample and investigate alleged responsibility. That work will take time and may never produce a public, person-by-person result.
What you can and cannot fix
If your RFC, date of birth, full name or a home address of yours is in a file that was offered for sale, that copy cannot be pulled back. An RFC is not replaced. A date of birth does not change. An address you used remains a fact about you. The Telegram post existed; SABG already has a sample. Nobody can honestly promise to delete this.
- Treat inbound calls and chats that already have your RFC, birthday, address or bank as hostile. Hang up. Call back on the number on your card, app or statement. That is the point of this alleged file: to make a stranger sound informed enough to pass as you.
- Watch accounts you hold with any of the named banks and retailers for new credit, a changed phone or email on file, or transfers you did not make. Say something if it looks wrong — not because those firms have confirmed a breach, but because in Mexico a name plus RFC plus date of birth is often enough to start paperwork in someone else’s hands.
- Change what can still be changed: passwords, and how you approve logins. Phone numbers were among the fields in the offer, which makes codes sent by text a weaker lock. Prefer the bank’s own app to approve access where that exists.
- Shrink the public listings that can be bolted onto a leaked row. A bare record with your name, RFC and address becomes much more useful when it is joined to people-search pages that add relatives, extra phones, employers and previous addresses. Those listings, unlike the leaked file, can actually be taken down. That is the lever that still exists.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on Mexico investigating.
- Tell your bank before you do anything else. Account and routing details are the fastest-moving of the fields in this notice. Call the number on the back of your card rather than any number in an email, and ask them to watch the account and reissue the card.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
For security and vendor-risk teams: get an alert the day a vendor you watch files a breach with a US regulator or the SEC — the filing itself, dated and sourced, plus an API. GalaxyWarden Signals →
A staff address in a leak usually means a third party was breached, not you — check your own domain’s exposure. Exposure Monitoring →
Report details & sourcing
Related breaches
Crunchbase Massive Personal Records Leak — January 2026
ShinyHunters exfiltrated approximately 2 million records from the business-intelligence platform Cru…
Anywhere Real Estate 17K Records — February 2026
Real-estate brokerage Anywhere Real Estate disclosed a breach exposing PII for approximately 17,000 …
ICE/DHS Agents Personal Data Leak — January 2026
A whistleblower posted personal data on approximately 4,500 ICE/DHS agents to a doxxing site in Janu…