Skip to content
Back to Blog
high severity September 25, 2026 · 5 min read Unverified claim — what this is

Mexico investigating 12.9 million personal records offered on Telegram

If you are a customer of Mexico investigating, here’s what is being claimed, and what it would mean for you.

On 24 September 2026, Mexico’s SABG confirmed it found a Telegram post from 22 September offering more than 12.9 million personal records supposedly from call centers, including names, phones, emails, dates of birth, RFC numbers, addresses and banking details. Investigators have a sample of 13,000 records in which well-known banks and retailers were named. SABG has not confirmed that the full set is real or that any of those companies was breached.

— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Mexico investigating 12.9 million personal records offered on Telegram

On 24 September 2026, Mexico’s Secretaría Anticorrupción y Buen Gobierno (SABG) issued an official statement confirming it had found a Telegram post dated 22 September 2026. In that post, a user offered databases supposedly from various call centers, with more than 12.9 million records. SABG said those records would include full name, email address, phone and mobile numbers, date of birth, RFC (Mexico’s tax ID), home address and banking details, among other information.

Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

SABG obtained a sample of 13,000 records from 13 databases. Brand names that appeared in that sample were Amazon, American Express, Afirme, Banamex, Banco del Bajío, BBVA, Banorte, Banregio, HSBC, Inbursa, INVEX, Liverpool, Sam’s Club, Santander, Scotiabank, Sears, Suburbia, Banco Walmart, Credomatic, IXE, Sanborns, C&A and Soriana. The secretariat said it will analyse the sample and open investigations. It did not say the 12.9 million records are genuine, that they came from those companies, or that any company was breached. As of 25 September 2026, none of those companies had issued a public statement.

The brand names are not the part that matters

Coverage of this has led with Amazon, BBVA, Liverpool and “12.9 million.” That framing makes it sound as if your bank or your store was hacked, and as if that huge number is a counted fact. SABG did not say either of those things. Its statement is full of “possible,” “alleged” and “supposedly.” A Telegram user claimed to be selling call-center databases. Investigators copied a sample of 13,000 records, and those commercial names showed up. A logo in a seller’s sample is not a claimed breach of that company. The 12.9 million figure is the seller’s claim, not a total SABG has verified. Mexican outlets have been repeating the government comunicado, not independently checking the files.

Exposure Pack · one payment
The full list, and what to lock in ten minutes.
  • Every indexed leak tied to your address — all of them, named and dated
  • A deeper search of collected breach data — the kinds of your information it holds, where it finds you
  • What this kind of incident typically exposes
  • A ten-minute lock list written for this kind of organisation
One payment. Nothing renews, and no account is created. Emailed to you within a minute.

What that misses, if you are an ordinary customer, is the mix of fields. Full name, RFC, date of birth, home address, phone numbers and banking details are the same answers a call center already asks for before it will treat a caller as you. If even some of those rows are real, a stranger does not need to break into your bank. They can phone the same kind of help line and already know the questions that were supposed to keep them out. Whether the data sat at a household-name company or at a contractor you never chose is a later legal question. For you, the live risk is impersonation with a file that looks like a customer-service identity check.

You should also not expect a clean answer to the question that feels most urgent: whether you were in this. SABG has a sample, not a public list. There is no reliable way for you — or for any website — to check whether your details were in this specific offer. A “not found” result would not mean you were absent. Anyone who claims they can look you up in this incident is offering false comfort.

What to actually expect

  • You are unlikely to get a personal notice telling you that you were, or were not, included. SABG has not declared a claimed breach, and as of 25 September 2026 none of the 23 named companies had spoken publicly.
  • Headlines will keep repeating “12.9 million” and the same company list. That is the 24 September statement being copied, not new proof that the files are real or complete.
  • If some of the data is genuine, the near-term harm is not every account emptying at once. It is tailored phone calls and messages that already know your name, RFC, birthday, or a bank or store you use — including fake contacts that pretend to be about this investigation. The aim is to pass as you, or to talk you into handing over one more code.
  • SABG said it will study the 13,000-record sample and investigate alleged responsibility. That work will take time and may never produce a public, person-by-person result.

What you can and cannot fix

If your RFC, date of birth, full name or a home address of yours is in a file that was offered for sale, that copy cannot be pulled back. An RFC is not replaced. A date of birth does not change. An address you used remains a fact about you. The Telegram post existed; SABG already has a sample. Nobody can honestly promise to delete this.

  • Treat inbound calls and chats that already have your RFC, birthday, address or bank as hostile. Hang up. Call back on the number on your card, app or statement. That is the point of this alleged file: to make a stranger sound informed enough to pass as you.
  • Watch accounts you hold with any of the named banks and retailers for new credit, a changed phone or email on file, or transfers you did not make. Say something if it looks wrong — not because those firms have confirmed a breach, but because in Mexico a name plus RFC plus date of birth is often enough to start paperwork in someone else’s hands.
  • Change what can still be changed: passwords, and how you approve logins. Phone numbers were among the fields in the offer, which makes codes sent by text a weaker lock. Prefer the bank’s own app to approve access where that exists.
  • Shrink the public listings that can be bolted onto a leaked row. A bare record with your name, RFC and address becomes much more useful when it is joined to people-search pages that add relatives, extra phones, employers and previous addresses. Those listings, unlike the leaked file, can actually be taken down. That is the lever that still exists.

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove — and removing them is what we do.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample580 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

What to do now

Steps that match what this notice says was exposed

Every step below is free and you do it yourself, and none of it depends on Mexico investigating.

  1. Tell your bank before you do anything else. Account and routing details are the fastest-moving of the fields in this notice. Call the number on the back of your card rather than any number in an email, and ask them to watch the account and reissue the card.

One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.

Check your exposure
Mexico investigating is one listing. Your email is probably in others.
We can’t confirm any single incident against the sources we search, so we won’t pretend to. What we can show you is your own exposure — your email against 13.1B+ leaked records and the sites that publish your address. About 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity High includes account details that can be misused directly
Disclosed September 25, 2026
Last reviewed September 25, 2026
Affected Unconfirmed
Data exposed Full namesEmail addressesPhone numbersDates of birthRFC numbersHome addressesBanking details
Unverified claim — what this report is
This page documents a public listing on a ransomware/extortion group’s leak site, tracked via public threat-intelligence sources. A listing is the attacker’s claim. GalaxyWarden aggregates and reports such claims; we have not independently verified that a breach occurred, what data (if any) was taken, or the accuracy of anything the group asserts, and the named organisation has not necessarily confirmed the incident. Sections above describe what the listing shows and the group’s documented history — not verified findings about the named organisation. If you represent this organisation and believe anything here is inaccurate, tell us and we’ll review it promptly.
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email