Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > Hacker Claims 1.94 Million Records Stolen from Chinese Booking Platform

Hacker Claims 1.94 Million Records Stolen from Chinese Booking Platform

By: Jordan Vector Cybersecurity Expert

Last updated: August 27, 2026

Human Written
Hacker Claims 1.94 Million Records Stolen from Chinese Booking Platform
  • A hacker claims to have leaked 1.94 million user records from a Chinese booking site.

  • The leaked data reportedly includes names, phone numbers, emails, and Chinese ID numbers.

  • Cybersecurity trackers have not confirmed the leak or named the platform yet.

A threat actor claims to have stolen a large database from a Chinese booking platform. The person posted it on an underground hacking forum. The database reportedly holds close to 1.94 million user records.

Threat intelligence accounts on X (formerly Twitter) like The Dark Web Informer first reported the claim. According to their report, an unnamed Chinese booking website may have suffered a serious breach. The name of the platform has not been shared publicly yet.

Details of the Alleged Data Leak

The hacker posted sample records to back up the claim. These samples allegedly show real user information. That includes full names and email addresses. Usernames and account IDs are also part of the leak. Phone numbers appear too, along with Chinese identification numbers.

The attacker offered the entire database as a free download. This makes the alleged data easy for other criminals to grab. A wide reach means more people could get hurt.

A separate alert from Brinztech named the hacker behind the post. The actor reportedly goes by “mosad.” Brinztech’s report said the database showed up on a forum called Spear.cx. This happened on August 26.

Brinztech also found copies of the data on public Telegram channels. That spreads the alleged leak even further. More platforms sharing the file means more people can access it, even without forum accounts.

Why this Alleged Leak Raises Concern

Chinese identification numbers make this case stand out. These numbers work like national ID cards. They tie directly to a person’s legal identity. Losing this kind of number carries more risk than losing a simple password.

When ID numbers mix with names and phone numbers, criminals gain a full profile. They could use it to pretend to be someone else. This is called impersonation, and it can lead to real financial harm.

Criminals could also use the data for targeted scams. They might send fake messages that look like they come from the real booking platform. Because the messages include real details, victims may trust them faster.

Email addresses and phone numbers open the door to phishing too. Attackers could send fake booking confirmations. They could also send fake refund alerts. Both tricks aim to steal even more personal data or money.

Booking platforms store a lot of customer details in one place. Names, trip plans, and payment habits all sit together. This makes such platforms valuable targets for hackers looking for large paydays.

A hacker known as “FlamingChina” claimed to have stolen over 10 petabytes of sensitive data from China’s National Supercomputing Center in Tianjin. The unverified dark web listing alleges access through a compromised VPN and six months of undetected data theft.

What Remains Unverified So Far

Right now, this stays an alleged leak, not a confirmed one. No official source has named the affected booking company. Dark Web Informer’s own report noted that the claims still need checking.

Nobody has confirmed that all 1.94 million records are real. Some data posted on hacking forums turns out to be old or reused. Other times, hackers exaggerate the numbers to boost their reputation.

There is also no proof yet that every record belongs to a different person. Some entries could repeat. Others might not connect to real accounts at all. Only the affected company or outside security experts can confirm the true scale.

Still, the pattern fits a growing trend. Hackers increasingly target travel and booking services. These platforms hold rich troves of personal data, which makes them frequent targets even when claims turn out to be partly false.

People who use Chinese booking platforms should stay alert regardless. Watch for strange emails about bookings you did not make. Avoid clicking links in messages that feel rushed or urgent.

Check any suspicious message directly through the official app or website. Do not use contact links inside the suspicious message itself. This simple habit blocks most phishing attempts before they start. Users should also watch bank and payment accounts closely. Report anything unusual right away. Fast action limits the damage if the leak turns out to be real.

For now, treat this as an unconfirmed claim backed by limited evidence. A hacker says they have the data. Two monitoring groups have spotted the listing online. But full proof of the source, scale, and accuracy still needs to come from independent investigators or the platform itself.

Share this article

About the Author

Jordan Vector

Jordan Vector

Cybersecurity Expert

Jordan is a security researcher and advocate who focuses on making privacy practical. Whether he's explaining how to harden a browser or reporting on the latest surveillance disclosures, his goal is to equip readers with knowledge they can use immediately. Jordan believes that true security begins with understanding the digital landscape.

Comments (0)

No comments.