A threat actor calling themselves Marx is advertising a massive dataset for sale, including millions of records allegedly stolen from some of the world’s biggest companies.
In separate posts, Marx claims to be selling 20 million records from Airbnb, 9 million from Uber, 14 million from PayPal, 4 million from Booking.com, and 7 million from Google. The attacker boasts of live access to a trove of data.
Cybernews contacted the allegedly affected companies but has received no comment.
The Source of the Data
Researchers at Cybernews investigated the data samples posted alongside the claims and found that the datasets appear to originate from a single source, rather than representing separate breaches for each company.
The data likely comes from a third-party provider — an SMS service used by businesses to communicate with customers. The service appears to offer business CRM functionality or bulk SMS delivery that can be integrated with customer relationship management systems.

“Leaks like this can vary greatly in severity based on how each company chooses to handle SMS message contents,” researchers explained. The main risk is that gathering a list of phone numbers associated with users of specific services, and their mobile carriers, increases the risk of phishing and impersonation attacks.
What Data Is Affected?
Researchers did not find extensive personal information in the samples they examined. The samples contain phone numbers and information about the mobile carriers being used. In the alleged Uber dataset, the exposed SMS messages also contain the names of people who booked rides.
“The number of records correlates to the number of SMS messages,” the researchers said. Longer messages can be split across multiple database records, meaning a claim involving millions of “records” does not necessarily translate into millions of individual customers.
Based on the samples, the apparent impact is geographically limited to India and Oman. Researchers noted that the message contents seem heavily stripped and contain content from numerous different SMS messages bundled into a single field. However, they warned: “We should assume that the threat actor has access to a full history of raw message contents, meaning every SMS message in full, including authentication codes, tracking links, and personally identifiable information.”
Who Is Marx?
Marx’s earliest known forum activity dates back to the beginning of October, when the actor advertised 11 million records allegedly connected to Mastercard transaction data. That dataset contained phone numbers and SMS messages, with the messages appearing to consist largely of notifications about completed transfers.
The current listings follow the same pattern, suggesting the source may be the same. Marx claims to have live access to the source and appears to be presenting different portions of it as datasets belonging to different corporate victims.
“What makes these claims more alarming is that the threat actor claims that they are maintaining live access to the compromised systems, allowing them to monitor sensitive communications in real time,” researchers said. “Allowing them to intercept time-sensitive secrets such as authentication codes at the same time, or before these messages reach the intended recipients.”
Researchers noted the threat actor’s profile was created three weeks ago and their posts so far do not seem to get any traction from the cybercrime community.
The Bottom Line
A hacker calling themselves Marx claims to be selling 54 million records from Airbnb, Uber, PayPal, Booking.com, and Google. Cybernews researchers say the data likely comes from a single third-party SMS provider rather than separate breaches. The samples contain phone numbers, mobile carriers, and some Uber rider names, with links to India and Oman. If genuine, the data could aid phishing and impersonation attacks.
My Opinion
This is a breach of a company that those giants trusted to send text messages. Every major company outsources something: Customer support, Cloud storage, SMS delivery, etc. They do it to save money and move faster. But every time they hand data to a third party, they are handing over a piece of their customers’ trust. When that third party gets breached, the brand name on the email is the one that hired the vendor.
The data allegedly for sale is not particularly sensitive by itself. Phone numbers. Mobile carriers. Some names. But that is not the point. The point is that if Marx really does have live access, the attackers can intercept authentication codes before they reach you.
Cybernews notes that Marx is a new profile with little traction. The claims may be exaggerated. But the warning is real. Companies need to stop treating third-party vendors as invisible.





