Hacker Puts 54 Million Airbnb, Uber, PayPal, Booking.com, and Google Records Up for Sale

06.10.2026 5 minutes Author: Newsman

A threat actor using the alias Marx has put around 54 million records up for sale, claiming they are linked to users of Airbnb, Uber, PayPal, Booking.com, and Google. An analysis of the published samples suggests the data may not have come from separate attacks on each company, but rather from the compromise of a third-party service used for bulk SMS messaging.

In separate posts, Marx is offering 20 million records linked to Airbnb, 9 million to Uber, 14 million to PayPal, 4 million to Booking.com, and another 7 million to Google. The scale is striking, but such claims should be treated with caution. On cybercrime forums, sellers of stolen databases often use the names of well-known companies and impressive figures to attract attention to their offers, even when the information was not obtained directly from those companies’ systems.

Airbnb, Uber, PayPal, Booking.com, and Google have not yet publicly commented on the potential breach. If the authenticity of the data is confirmed, it could be used for targeted phishing, impersonation of company representatives, and, in some cases, account takeovers.

Приклад даних.

The Data May Have Been Stolen From a Third-Party SMS Provider

An analysis of the samples Marx published alongside his listings showed that the datasets appear to share a common source. This suggests that the incident may not involve five separate breaches of major companies, but rather a single compromised system. The likely source is believed to be a third-party SMS provider that the companies may have used to communicate with their customers.

Judging by the structure of the data, the service appears to provide businesses with bulk SMS messaging capabilities that can be integrated with CRM systems and used for automated customer communications.

“The severity of such breaches can vary significantly depending on how each company handles the content of SMS messages.”

Приклад даних.

The main risk is that even a list of phone numbers associated with users of a particular service, combined with information about their mobile carriers, can already be useful for phishing attacks and impersonating company representatives.

“Depending on the service, the risks may include account takeovers and access to more sensitive information, including names and addresses.”

What Data May Have Been Exposed

The published samples did not contain large amounts of detailed personal information. They include phone numbers and mobile carrier information. In the dataset Marx links to Uber, some SMS messages also contained the names of people who had booked rides.

“The number of records correlates with the number of SMS messages.”

This means that the claimed tens of millions of records do not necessarily correspond to the same number of affected users. Longer SMS messages can be split into several separate database records, so, for example, 20 million Airbnb records do not automatically mean 20 million individual customers.

Приклад даних.

Based on the available samples, the geographic scope of the potential compromise also appears to be limited to India and Oman. The message content in the fragments published by the threat actor has been heavily altered. In addition, parts of multiple different SMS messages may be combined into a single field, making it difficult to assess the full extent of the breach from the available data.

“At the same time, it should be assumed that the threat actor has access to the complete history of the original message content, meaning all SMS messages in full, including authentication codes, tracking links, and personal data.”

If Marx truly gained access to the full contents of the SMS messages, the consequences could be far more serious than a simple leak of phone numbers. Such messages may contain one-time login codes, links used to confirm transactions, order details, and other sensitive information.

What Is Known About Hacker Marx

The earliest known signs of Marx’s activity on cybercrime forums date back to early October this year. One of his first posts advertised the sale of 11 million records that he claimed were linked to Mastercard transactions. Samples from that dataset also contained phone numbers and SMS messages, many of which appeared to be notifications about completed money transfers.

The current Airbnb, Uber, PayPal, Booking.com, and Google datasets follow a similar structure. This further suggests that all of the data may have come from the same source. Marx claims to have direct access to that source, separating information associated with different companies and selling it as individual datasets.

“What makes these claims even more concerning is that the threat actor says he maintains persistent access to the compromised systems, allowing him to monitor sensitive communications in real time.”

Приклад даних.

If such access truly exists, the threat actor could potentially view sensitive messages immediately after they are sent.

“This would allow the interception of time-sensitive information, including authentication codes, as the messages are being delivered or even before the recipient sees them.”

At the same time, there is currently no confirmation that Marx actually maintains persistent access to the compromised system. His profile on the cybercrime forum was created around three weeks ago, and his listings have so far attracted little noticeable interest from other members of the cybercriminal community.

What This Means

The available data does not currently confirm separate breaches of Airbnb, Uber, PayPal, Booking.com, or Google. A more likely scenario is the compromise of a third-party SMS provider through which messages from multiple companies were processed.

The exact scale of the breach and Marx’s claimed real-time access to the system still require confirmation. However, even the phone numbers, carrier information, and SMS fragments already disclosed could be used for more convincing phishing attacks and account takeover attempts.

Subscribe
Notify of
0 Коментарі
Oldest
Newest Most Voted
Found an error?
If you find an error, take a screenshot and send it to the bot.
↑