Phone Numbers and Passenger Names

Airbnb, Uber, PayPal: Hacker Offers Millions of Data Records

Paypal
Facebook
X
LinkedIn
Reddit
WhatsApp
Source: mundissima/Shutterstock.com

A hacker is allegedly offering data from Airbnb, Uber, and PayPal. According to Cybernews, it originates from an SMS service provider.

An attacker going by the name Marx is allegedly offering data records from major companies for sale on cybercrime forums. In separate posts, he cites 20 million data records from Airbnb, 9 million from Uber, 14 million from PayPal, 4 million from Booking.com, and 7 million from Google, totaling 54 million. The companies mentioned have not yet commented to Cybernews.

Ad

Common Source Instead of Individual Attacks

The research team at Cybernews examined the samples included with the offers. According to their findings, the data appears to originate from a single source rather than separate attacks on the individual companies. A third-party provider used by companies to send SMS messages to their customers was likely compromised. The service apparently offers bulk SMS messaging that can be integrated with CRM systems. Which provider is involved remains unknown.

Phone Numbers and Passenger Names

The researchers did not find extensive personal data in the samples. They contain phone numbers and details about the respective mobile network provider. In the alleged Uber data, the SMS messages also include the names of individuals who booked rides. The samples pertain to users in India and Oman.

According to the researchers, the number of data records corresponds to the number of SMS messages. Longer messages may be split across multiple entries. Millions of data records therefore do not necessarily mean millions of affected customers. Because the message contents in the samples are heavily truncated and multiple SMS messages are combined in a single field, the exact scope cannot be precisely estimated.

Ad

“However, we should assume that the attacker has access to the complete history of unedited message content—meaning each SMS in full, including authentication codes, tracking links, and personal data.”

Cybernews Researchers

Allegedly Ongoing Access

Marx claims to still have access to the source. According to the researchers, this would allow him to read messages in real time, including time-sensitive data such as authentication codes before they reach the recipients. This ongoing access has not been verified.

The forum profile for Marx was created about three weeks ago. In early October, he had already offered 11 million data records allegedly connected to Mastercard transactions. These also contained phone numbers and SMS messages, predominantly notifications about completed transfers. So far, the offers have met with little interest in the cybercrime community.

If the data is genuine, Cybernews notes that the risk of phishing and scam attempts increases for those affected, with attackers posing as well-known services. Depending on the service, account takeovers may also be possible.

(Editorial Team)

Ad

Weitere Artikel