-
A forum actor claims to have live access to a Transfast messaging portal with more than 11.8 million SMS records.
-
The alleged data includes phone numbers and money-transfer messages, but no one has verified the claim.
-
The exposure could help criminals target remittance customers, but there is no evidence of a Mastercard payment-system breach.
A threat actor known as Marx is advertising access to what they claim is a live messaging database linked to Transfast, a cross-border payments company that Mastercard acquired in 2019.
The listing, which appeared on Sept. 7, 2026, claims access to 11,835,390 SMS messages recorded from January through early September. The alleged records include recipient phone numbers, transaction confirmations, and other money-transfer details.
The actor also offers a sample of 10,000 records and access to the portal used to view the messages. No independent source has confirmed that the data is real. Mastercard and Transfast have not publicly confirmed the alleged incident in the sources reviewed for this report.
The Figures in the Claim do not Match
The numbers in the listing need some clarification. The headline refers to about 1.8 million records. The dashboard shown by the actor reportedly displays 11,835,390 messages. Those figures may refer to different measurements. However, the available material does not explain the gap.
The actor claims that all 11.8 million messages show a delivered status. Also, the dashboard includes traffic charts, message types, account filters, and delivery statistics.
The actor describes the database as live rather than a historical dump. There’s a difference between the two. A static database would suggest previously stolen information. Live portal access could let an attacker search current messages and watch new activity.
The listing also claims that users can filter account profiles and transaction information. It gives no details about how the alleged access occurred.
Transfast does Use SMS for Money Transfers
The type of information in the claim fits some of Transfast’s documented services. Transfast’s terms say the company offers SMS notifications in some countries. These messages can tell recipients when a transaction has been collected or when funds are ready for collection.
The terms also say Transfast may send messages to the sender’s or receiver’s mobile number. Transfast says its wide platform handles all kinds of messaging for banks, financial institutions, and other clients. Mastercard pointed out these attributes as the reason for its acquisition of Transfast back in 2019.
As stated by Mastercard, Transfast provides the advantage of enabling P2P, B2P, and B2B transactions in more than 125 locations. This history makes the alleged SMS portal plausible. It does not prove that the actor has unauthorized access to it.
The Portal Also Supports One-Time Passwords
Another detail could matter if the claim proves true. The current Transfast Payer Web portal uses usernames and passwords. It also lets users get one-time passwords on their registered email or phone. Nonetheless, that doesn’t prove the attacker got around multi-factor authentication.
But it does show why researchers would need to establish exactly what the alleged account can access. If the account exposes only old delivery records, the main risks involve privacy and fraud. Also, if it exposes one-time codes or other login messages, the risk could become much more serious.
However, there is no evidence that OTP messages appear in the advertised dataset. Claims that the actor intercepted authentication codes should therefore remain unconfirmed.
The Data Could Help Target Remittance Scams
Even without passwords or payment card numbers, the alleged data could have value to criminals. A transaction message can connect a phone number with a recent money transfer. It may also show when someone sent or collected funds.
That information could help criminals create convincing follow-up scams. For example, a fraudster could contact a customer after a genuine transfer. They could pretend to be a bank, payment provider or transfer agent.
Knowing someone’s recent transaction history makes the message even more convincing. This threat may be especially great for those who regularly transfer funds internationally to relatives. However, this posting does not necessarily confirm the actual exploitation of the supposed information for fraud purposes.
No Evidence Shows a Mastercard Payment Breach
The difference between a messaging portal and a payment network is important. Mastercard acquired Transfast to expand its cross-border account-to-account payment services. Transfast connects banks and other financial institutions and supports several payment services.
The alleged access appears to involve a messaging system, not Mastercard’s card-processing network. There is no evidence in the material reviewed that the actor accessed Mastercard cardholder data, payment-card systems or Mastercard’s core transaction infrastructure.
Mastercard’s current materials also continue to identify Transfast-related operations within its Mastercard Transaction Services business. That means the claim should not be described as a Mastercard network breach unless new evidence supports that conclusion.
Key Questions Remain Unanswered
Several important questions still need answers. It is not clear who operates the alleged portal. It is also unclear how the actor obtained access or whether the account belongs to Transfast or a third-party messaging provider.
The advertised sample has not been independently validated. A screenshot of a logged-in dashboard can show that someone accessed a session. It cannot prove how they gained that access or whether the displayed information is genuine. The age and history of the forum account also provide little confidence on their own.
A similar unverified dark web listing involving DAMAC Properties, one of the UAE’s largest real estate developers, followed the same pattern. In July 2026, a threat actor claimed to have obtained 400,000 customer records from DAMAC Living, offering them for $10,000 in cryptocurrency.
Right now, all we have is an unverified claim. If the data turns out to be real, people who use cross-border money-transfer services could have their sensitive info leaked.
And if those messages include authentication details, things get much more serious. For now, though, unless Mastercard, Transfast, or a trusted security expert confirms the sample, we can’t call those 11.8 million messages a verified data breach.