-
An actor claims to have more than 11 million records from ixigo for sale, but the sample reveals OTP and verification SMS logs.
-
This listing is just one of several similar ads from this actor, all featuring the same SMS-aggregator log template.
-
Experts think the logs come from third-party SMS-gateway logs by brand and do not indicate a confirmed compromise, although the phone numbers may support smishing if true.
A threat actor on an underground forum claims to be selling data tied to ixigo. The platform belongs to Le Travenues Technology Ltd. It handles flight, train, bus, and hotel bookings across India.
The listing carries the title ‘database ixigo +11M.’ It also displays the ixigo logo. However, nobody has independently verified the claim yet. The post surfaced on a dark web monitoring feed tracked by Daily Dark Web.
What the Listing Actually Shows
The seller posted sample rows alongside the listing. Those rows contain SMS logs from a sender named ‘OIXIGO.’ The messages hold verification and account-activation codes sent to mobile numbers. The visible rows point to numbers in Qatar and France. Each record includes carrier information, delivery progress, and a timestamp, all of which were recorded on January 19, this year.
The listing claims a scope of more than 11 million records. That figure comes from the ‘+11M’ in the title. However, this indicated number does not stand as proof that the seller does have such volume of data, as sellers are known to inflate numbers to lure customers.
Security analysts reviewed the posted sample closely. Their finding matters for anyone worried about the claim. What is available in the logs is information on OTP and SMS delivery details.
The online records contain phone numbers of recipients, names of carriers, plus code texts. However, they disclosed no information about the identity of clients, reservations, passwords, and passport credentials. That is why, the above-mentioned categories do not correspond to the specific claim.
This is a fundamental distinction between severe violations and simple leaks. A full travel platform breach would entail much more exposure. Instead, the posted sample reflects something substantially less significant. The travel history, payment details, and identity data are simply absent.
One Actor Behind a Wave of Similar Listings
The ixigo listing is not a standalone event. It belongs to a burst of near-identical posts from the same actor. Each one follows a ‘Database <brand>’ naming pattern.
Earlier the same day, the actor posted listings for eGovBahrain, Medgulf, Borders, and Housing[.]com. The batch also included HSBC, BankBeirut, Binance, and Noon. Other names in the wave include Dubai Smart Travel, Morafiq, and La Marquise Diamonds.
At the same time, the actor added brands like Me Courier, Halamama, and others. Experts wonder how a person can list so many companies in such a short period.
Similar large-scale claims involving multiple major companies have also surfaced in the alleged Stealer Log leak claims from Apple, Google, and dozens of global firms. It is unusual for an actor to breach many unrelated companies in one go. The pace implies a shared source of the hack rather than numerous hacks.
Shared Sample Points to SMS-Gateway Logs
Analysts found significant information from the samples. Each of the samples utilizes the same SMS-aggregator log schema. The columns were identical across all the brands.
This sample includes a router or gateway column. In addition, it has a recipient number, country, carrier code, delivery status, and message. Such a uniform structure hardly exists in different breaches frequently.
As a result, experts prefer another explanation. The data was probably from the logs of a third-party SMS gateway. Someone divided these logs by sender brand and made each part a ‘database.’ This theory is more consistent with the facts than a series of breaches that are not related. It also explains how the same sender can publish so many brands within a day.
The Inclusion of Phone Numbers Still Matters
The leak of even a small number of phone numbers may result in very serious risks. If the information turns out to be true, these phone numbers still have a link to ixigo accounts in the digital space. It is possible for attackers to use them for smishing schemes.
They could also create OTP-related phishing attacks. A target, eagerly waiting for the confirmation of his/her travel details, may easily fall victim and provide his/her code. This is what makes travel brands a good target for social engineering attacks. When a message coincides with the booking, users can easily let down their guard in security matters.
Additionally, codes can also be helpful. Attackers may analyze the codes from earlier OTP logs and figure out the message structure a particular platform uses. With such knowledge, they can create convincing ones for their targets.
However, as a matter of fact, that is a mere claim by the threat actor. It means that there’s no proof regarding the compromise of the ixigo systems. The public should view the information with caution until independent confirmation appears.