aiq.com.mx Listed by lockbit3 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The aiq.com.mx Listed by lockbit3 Ransomware Group (reported October 30, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
When an airport operator appears on a ransomware group's leak site, the practical concern is straightforward: internal files may no longer be under the organisation's sole control. For staff, contractors, partners and anyone whose details sit inside those systems, that raises the possibility of exposed business records, contact information or operational documents circulating beyond their intended audience. Public detail on this incident remains limited, yet the listing itself is enough to warrant careful attention from people connected to the facility.
On 30 October 2023, the ransomware group known as lockbit3 listed aiq.com.mx, identified as Aeropuerto Internacional de Querétaro, claiming that internal files had been exfiltrated. The number of people affected is unknown, and the precise contents of the material have not been independently confirmed in the available record.
Breaking down the breach
According to the reported information, aiq.com.mx was listed by lockbit3 on 30 October 2023. The group asserted that internal files were taken in a ransomware attack and characterised the material as business information belonging to Aeropuerto Internacional de Querétaro. No public figure has been given for the volume of data, the number of individuals involved, or the exact date the intrusion began. The method of initial access has not been disclosed. What is stated is simply that the organisation appeared on the group's leak site with a claim of exfiltrated internal files. Whether the data was subsequently published, sold or withheld after negotiation is not detailed in the available facts.
Who is lockbit3?
Lockbit3 is the name associated with a prolific ransomware operation that has functioned as a ransomware-as-a-service offering. In this model, core developers supply the malware and leak-site infrastructure to affiliates who carry out intrusions. The group is widely documented for using double-extortion tactics: encrypting systems while also copying data, then threatening to release the stolen material if a ransom is not paid. Listings on its leak site serve as public pressure. Lockbit3 and its predecessors have claimed responsibility for attacks across many sectors and countries over several years. In this case, the appearance of aiq.com.mx constitutes a claim by the group; it does not by itself constitute independent verification of every detail the actors may have asserted.
Who is aiq.com.mx?
aiq.com.mx is the online presence of Aeropuerto Internacional de Querétaro, the international airport serving the Querétaro region of Mexico. Airport operators manage complex day-to-day functions that typically include airline and ground-handler relationships, facility maintenance, security coordination, procurement, human resources and regulatory compliance. Organisations of this type routinely hold contracts, internal correspondence, employee records, vendor details and operational documentation. A breach affecting such an entity is consequential because airports sit at the intersection of commercial aviation, local economic activity and public infrastructure. Disruption or exposure of internal information can affect not only the operator but also the wider network of companies and individuals who interact with the airport.
The information in question
The available facts state that internal files were exfiltrated in a ransomware attack and describe the material as business information. No further breakdown of data types—such as specific categories of personal data, financial records or passenger-related files—has been provided. Exact contents therefore remain unconfirmed. Organisations that run airports commonly maintain employee and contractor information, commercial agreements, operational schedules, security-related procedures and correspondence with government or airline partners. Any of these could theoretically fall under “internal files,” yet it would be inaccurate to treat particular categories as established fact when they have not been named. The scale of the exfiltration is likewise undisclosed.
The real-world impact
For individuals whose information may have been inside the taken files, the concrete risks include unwanted contact, targeted phishing that references genuine internal details, or the misuse of business identifiers in fraud attempts. Employees and contractors can face heightened exposure if personnel or payroll-related documents were among the material. Vendors and partner organisations may find commercial terms or contact lists circulating, which can complicate negotiations or invite social-engineering attempts. For the airport operator itself, the incident raises operational, reputational and regulatory considerations: restoring confidence among airlines and passengers, reviewing access controls, and determining whether any legal notification duties apply under Mexican data-protection rules. Because the number of people affected is unknown and the precise data types are unconfirmed, the full scope of harm cannot yet be measured. The prudent stance is to treat the claim seriously while recognising the limits of what has been publicly established.
Were you affected?
If you work at, contract with, or regularly do business with Aeropuerto Internacional de Querétaro, consider practical steps. Monitor financial and email accounts for unexpected activity. Treat unsolicited messages that reference airport business or personal details with caution. Change passwords on work-related and personal accounts that may have been used in shared systems, and enable multi-factor authentication where it is available. Keep records of any suspicious contact. You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets. Public detail on this incident is limited; staying alert to official statements from the organisation remains the most reliable way to learn whether further notification is forthcoming.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
castores.com.mx Listed by lockbit3 Ransomware Groupestes-express.com Listed by lockbit3 Ransomware Groupitsservicios.com.mx Listed by lockbit3 Ransomware Groupgroupe-idea.com Listed by lockbit3 Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the aiq.com.mx Listed by lockbit3 Ransomware Group →
Publicly posted by lockbit — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.