Millions of Airbnb, Uber, and Google records are for sale, hackers claim
The attackers boast of live access to a trove of data.

Image by Cybernews
- A hacker called Marx claims to sell 54 million records tied to Airbnb, Uber, PayPal, Booking.com, and Google.
- Cybernews researchers say samples appear to come from one third-party SMS provider, not separate company breaches.
- Samples show phone numbers, mobile carriers, and some Uber rider names, with apparent links to India and Oman.
- If genuine, the data could aid phishing, impersonation, and possibly account takeover attacks.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
A threat actor calling themselves Marx is advertising a spectacular dataset for sale, including millions of records allegedly stolen from some of the world’s biggest companies.
In separate posts, Marx claims to be selling 20 million records from Airbnb, 9 million from Uber, 14 million from PayPal, 4 million from Booking.com, and 7 million from Google.
With such numbers at stake, the hacker's claims may sound too good to be true. It is quite common on underground forums to claim large brands and tout impressive numbers to market their stolen datasets, which may not even be taken from named companies.
We’ve contacted the allegedly affected companies, but so far, no comment has been received. However, if proven to be legitimate, such exposed data could result in increased risks of phishing attacks and, in some cases, account takeovers.
Breach at a third-party SMS provider
Our researchers investigated the data samples posted alongside the claims and found that the datasets appear to originate from a single source, rather than representing separate breaches for each company.
From what our team gathers, a third-party provider – an SMS service used by businesses to communicate with customers – may have been breached.
The service appears to offer business CRM functionality or, more specifically, bulk SMS delivery that can be integrated with customer relationship management systems.
“Leaks like this can vary greatly in severity based on how each company chooses to handle SMS message contents,” our researchers explained.
According to them, the main risk is that gathering a list of phone numbers associated with users of specific services and products, and their mobile carriers, increases the risk of phishing and impersonation attacks.
“Depending on the service, the dangers may extend to account takeovers, access to more personally identifiable information such as names and addresses,” they added.
What data is allegedly affected?
Our researchers did not find extensive personal information in the samples they examined.Samples contain phone numbers and information about the mobile carriers being used. In the alleged Uber dataset, the exposed SMS messages also contain the names of people who booked rides.
"The number of records correlates to the number of SMS messages," the researchers said.
Longer messages can be split across multiple database records, meaning that a claim involving millions of "records" does not necessarily translate into millions of individual customers.
Based on the samples, the apparent impact is also geographically limited to India and Oman. “In the samples shared by the threat actor, the message contents seem to be heavily stripped, and contain contents from numerous different SMS messages bundled into a single field,” said our research team, noting that such a structure restricts the ability to estimate the full scope of breached data.
“However, we should assume that the threat actor has access to a full history of raw message contents, meaning every SMS message in full, including authentication codes, tracking links, and personally identifiable information.”
Who is the attacker, Marx?
Marx's earliest known forum activity dates back to the beginning of this October, when the actor advertised 11 million records allegedly connected to Mastercard transaction data.
According to our researchers, the dataset contained phone numbers and SMS messages, with the messages appearing to consist largely of notifications about completed transfers.
The current listings of Airbnb, Uber, PayPal, Booking.com, and Google datasets appear to follow the same pattern, suggesting that the source may be the same.
Marx claims to have live access to the source and appears to be presenting different portions of it as datasets belonging to different corporate victims.
“What makes these claims more alarming is that the threat actor claims that they are maintaining live access to the compromised systems, allowing them to monitor sensitive communications in real time,” our researchers said.
“Allowing them to intercept time-sensitive secrets such as authentication codes at the same time, or before these messages reach the intended recipients,” they added.
Our researchers note that the threat actor’s profile was created 3 weeks ago. So far, their posts don't seem to get any traction or interest from the cybercrime community.