A threat actor known as “Marx” claims to have access to millions of records allegedly linked to major companies, including Airbnb, Uber, PayPal, Booking.com, and Google, Cybernews reports.
However, an analysis of the data samples suggests the claims may be linked to a single compromised third-party SMS provider rather than separate breaches of each company.
In separate underground forum posts, Marx claims to be selling 20 million records from Airbnb, 9 million from Uber, 14 million from PayPal, 4 million from Booking.com and 7 million from Google. The claims have not been independently confirmed, and there is currently no evidence that the named companies themselves were directly breached.
Researchers who examined samples shared by the threat actor found similarities across the datasets, suggesting they may originate from the same source. The apparent source appears to be a third-party service that provides bulk SMS delivery and CRM-related functionality to businesses.
The samples examined by researchers primarily contained phone numbers and information about mobile carriers. Some of the alleged Uber data also included names appearing in SMS messages sent to people who had booked rides. The researchers noted that the number of claimed “records” does not necessarily represent the same number of affected individuals because a single SMS can be split into multiple database records.
The apparent exposure also appears to be geographically limited in the samples examined so far, with data linked mainly to India and Oman. Researchers said the message contents in the samples appeared heavily stripped and combined multiple SMS messages into individual database fields, making it difficult to determine the full scope of the alleged exposure.
Despite the limited information found in the samples, the potential security risks could be significant if the threat actor has access to the underlying SMS history. Researchers warned that the compromised data could potentially include authentication codes, tracking links and personally identifiable information contained in the original messages.
The alleged exposure could also increase the risk of phishing and impersonation attacks. A database containing phone numbers, mobile carriers and information about the services people use could allow criminals to create more convincing messages targeting specific users.
Marx’s activity reportedly began in early October, when the actor advertised around 11 million records allegedly linked to Mastercard transaction data. Researchers found that those samples also appeared to contain phone numbers and SMS messages, including notifications related to financial transactions.
The newer Airbnb, Uber, PayPal, Booking.com and Google claims appear to follow a similar pattern, raising the possibility that Marx is presenting different portions of data from the same compromised source as datasets belonging to different companies.
The threat actor has also claimed to have live access to the underlying system. If that claim is genuine, it could potentially allow the attacker to monitor communications and intercept time-sensitive information such as authentication codes. However, this claim has not been independently verified.
The profile used by Marx was reportedly created only a few weeks ago, and researchers said the actor’s posts have so far received limited attention from the wider cybercrime community.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
For now, the claims should be treated with caution. While the samples suggest that some form of third-party SMS data exposure may have occurred, there is not enough evidence to confirm the massive company-specific breach figures being advertised by the threat actor.



