Massive data leak: 54 million records linked to Airbnb, Uber, PayPal, Booking.com and Google compromised via SMS service provider
A new cybersecurity case is shaking the digital giants. According to information relayed by Cybernews researchers, a hacker operating under the pseudonym “Marx” would have put up for sale more than 54 million records linked to users of Airbnb, Uber, PayPal, Booking.com and Google. Analysis of the published samples suggests that these are not five separate hacks, but a single intrusion into a third-party service provider specializing in mass SMS sending.
This article will also interest you: Cybersecurity Alert: A Fake ChatGPT “Plus 5.6” Installed on the Official Site Traps Windows Users
A single source: the flaw in an SMS service provider
Cybernews researchers examined the data samples released by the hacker. Their conclusion is unambiguous: the files share a common origin, which rules out the hypothesis of five simultaneous attacks against the companies themselves. The most likely point of compromise is an SMS service provider used by these companies to communicate with their customers through customer relationship management (CRM) systems.
This type of service provider is integrated into platforms for sending order confirmations, delivery notifications or even single-use verification codes. A compromise at this level therefore potentially exposes all SMS communications passing through this service.
What data is actually exposed?
The samples analyzed by Cybernews mainly contain:
- Phone numbers
- The name of the associated mobile operator
- For the Uber dataset, the names of people who booked a ride
The messages themselves appear heavily truncated in the published excerpts. The researchers point out that the number of “records” is correlated with the number of SMS messages sent: a long message can be split into several lines in the database, which means that the same customer can appear several times. The real number of victims is therefore probably much lower than the 54 million announced.
Geographically, the numbers examined are predominantly Indian and Omani, but researchers warn that the exact scope of the leak remains impossible to determine due to data fragmentation.
A risk of interception of connection codes in real time
The most serious threat lies in the hacker's claim to have direct and permanent access to the compromised system. In this scenario, it could read SMS messages in real time and intercept one-time authentication codes even before they are received by the legitimate recipient.
The potential consequences are twofold:
- Ultra-targeted phishing (smishing): With a phone number and the name of the relevant service, a scammer can craft an extremely credible fraudulent text message, perfectly imitating official communications from Airbnb, PayPal or Booking.com.
- Account takeover: If the hacker actually intercepts the verification codes, they can bypass two-factor authentication and directly access victims' accounts.
The limits of SMS authentication
This case once again illustrates the intrinsic fragility of verification codes sent by SMS. Google also announced in February 2025 its intention to gradually abandon SMS codes for Gmail, in favor of more secure systems such as QR codes or access keys (passkeys). This decision follows years of exploitation of known vulnerabilities: SIM swapping, message interception and traffic pumping.
Other technology giants like Apple, Microsoft and Signal have already started a similar transition, and CISA (American cybersecurity agency) has been recommending moving away from SMS authentication since 2024.
How to protect yourself?
Faced with this type of threat, several best practices are essential:
- Favor authentication applications (Google Authenticator, Authy, Proton Authenticator, etc.) rather than SMS codes for double authentication.
- Never click on a link received by SMS from an unknown or unsolicited sender.
- Systematically verify the identity of the sender before communicating any personal information.
- Use unique, complex passwords for each service, ideally through a password manager.
- Enable login alerts on sensitive accounts (PayPal, Google, etc.) to detect suspicious activity.
A hacker with little credibility so far
Marx's profile, however, remains subject to caution. His account on the cybercriminal forum was created only three weeks ago, and his first announcements concerned data linked to Mastercard transactions. Other members of the forum currently give little credence to his offers. It is common on these platforms for sellers to inflate numbers and put famous brands on files of various origins to attract buyers.
The five companies concerned have not yet responded to requests from Cybernews. If the authenticity of the data were to be confirmed, it would be one of the most significant leaks in recent years, once again highlighting the vulnerability of the digital services supply chain.