Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > Hacker Claims Live Access to Transfast-Linked Portal With 11.8 Million SMS Records

Hacker Claims Live Access to Transfast-Linked Portal With 11.8 Million SMS Records

By: Jordan Vector — Cybersecurity Expert

Last updated: September 10, 2026

Human Written
Hacker Claims Live Access to Transfast-Linked Portal With 11.8 Million SMS Records
  • A forum actor claims to have live access to a Transfast messaging portal with more than 11.8 million SMS records.

  • The alleged data includes phone numbers and money-transfer messages, but no one has verified the claim.

  • The exposure could help criminals target remittance customers, but there is no evidence of a Mastercard payment-system breach.

A threat actor known as Marx is advertising access to what they claim is a live messaging database linked to Transfast, a cross-border payments company that Mastercard acquired in 2019.

The listing, which appeared on Sept. 7, 2026, claims access to 11,835,390 SMS messages recorded from January through early September. The alleged records include recipient phone numbers, transaction confirmations, and other money-transfer details.

The actor also offers a sample of 10,000 records and access to the portal used to view the messages. No independent source has confirmed that the data is real. Mastercard and Transfast have not publicly confirmed the alleged incident in the sources reviewed for this report.

The Figures in the Claim do not Match

The numbers in the listing need some clarification. The headline refers to about 1.8 million records. The dashboard shown by the actor reportedly displays 11,835,390 messages. Those figures may refer to different measurements. However, the available material does not explain the gap.

The actor claims that all 11.8 million messages show a delivered status. Also, the dashboard includes traffic charts, message types, account filters, and delivery statistics.

The actor describes the database as live rather than a historical dump. There’s a difference between the two. A static database would suggest previously stolen information. Live portal access could let an attacker search current messages and watch new activity.

The listing also claims that users can filter account profiles and transaction information. It gives no details about how the alleged access occurred.

Transfast does Use SMS for Money Transfers

The type of information in the claim fits some of Transfast’s documented services. Transfast’s terms say the company offers SMS notifications in some countries. These messages can tell recipients when a transaction has been collected or when funds are ready for collection.

The terms also say Transfast may send messages to the sender’s or receiver’s mobile number. Transfast says its wide platform handles all kinds of messaging for banks, financial institutions, and other clients. Mastercard pointed out these attributes as the reason for its acquisition of Transfast back in 2019.

As stated by Mastercard, Transfast provides the advantage of enabling P2P, B2P, and B2B transactions in more than 125 locations. This history makes the alleged SMS portal plausible. It does not prove that the actor has unauthorized access to it.

The Portal Also Supports One-Time Passwords

Another detail could matter if the claim proves true. The current Transfast Payer Web portal uses usernames and passwords. It also lets users get one-time passwords on their registered email or phone. Nonetheless, that doesn’t prove the attacker got around multi-factor authentication.

But it does show why researchers would need to establish exactly what the alleged account can access. If the account exposes only old delivery records, the main risks involve privacy and fraud. Also, if it exposes one-time codes or other login messages, the risk could become much more serious.

However, there is no evidence that OTP messages appear in the advertised dataset. Claims that the actor intercepted authentication codes should therefore remain unconfirmed.

The Data Could Help Target Remittance Scams

Even without passwords or payment card numbers, the alleged data could have value to criminals. A transaction message can connect a phone number with a recent money transfer. It may also show when someone sent or collected funds.

That information could help criminals create convincing follow-up scams. For example, a fraudster could contact a customer after a genuine transfer. They could pretend to be a bank, payment provider or transfer agent.

Knowing someone’s recent transaction history makes the message even more convincing. This threat may be especially great for those who regularly transfer funds internationally to relatives. However, this posting does not necessarily confirm the actual exploitation of the supposed information for fraud purposes.

No Evidence Shows a Mastercard Payment Breach

The difference between a messaging portal and a payment network is important. Mastercard acquired Transfast to expand its cross-border account-to-account payment services. Transfast connects banks and other financial institutions and supports several payment services.

The alleged access appears to involve a messaging system, not Mastercard’s card-processing network. There is no evidence in the material reviewed that the actor accessed Mastercard cardholder data, payment-card systems or Mastercard’s core transaction infrastructure.

Mastercard’s current materials also continue to identify Transfast-related operations within its Mastercard Transaction Services business. That means the claim should not be described as a Mastercard network breach unless new evidence supports that conclusion.

Key Questions Remain Unanswered

Several important questions still need answers. It is not clear who operates the alleged portal. It is also unclear how the actor obtained access or whether the account belongs to Transfast or a third-party messaging provider.

The advertised sample has not been independently validated. A screenshot of a logged-in dashboard can show that someone accessed a session. It cannot prove how they gained that access or whether the displayed information is genuine. The age and history of the forum account also provide little confidence on their own.

A similar unverified dark web listing involving DAMAC Properties, one of the UAE’s largest real estate developers, followed the same pattern. In July 2026, a threat actor claimed to have obtained 400,000 customer records from DAMAC Living, offering them for $10,000 in cryptocurrency.

Right now, all we have is an unverified claim. If the data turns out to be real, people who use cross-border money-transfer services could have their sensitive info leaked.

And if those messages include authentication details, things get much more serious. For now, though, unless Mastercard, Transfast, or a trusted security expert confirms the sample, we can’t call those 11.8 million messages a verified data breach.

Share this article

You might also like

Russian National Extradited to US Over Alleged Bank Account Takeover Fraud

Russian National Extradited to US Over Alleged Bank Account Takeover Fraud

A Russian man was extradited to the US for allegedly running a bank fraud scheme that stole millions of dollars.…

September 10, 2026
220 Million Passenger and Crew Records Exposed in Unsecured Database

220 Million Passenger and Crew Records Exposed in Vietnam-Linked Travel Database

Researchers found an unsecured database holding over 220 million passenger and crew records, including passport numbers and flight details. The…

September 9, 2026
Hacker Claims Root Access to Mexican Fuel Firm Mega Gas for $450

Hacker Claims Root Access to Mexican Fuel Retailer Mega Gasolineras With 1.9TB Data for $450

A threat actor is allegedly selling root-level access to the systems of Mexican fuel retailer Mega Gas on a cybercrime…

September 9, 2026

About the Author

Jordan Vector

Jordan Vector

Cybersecurity Expert

Jordan is a security researcher and advocate who focuses on making privacy practical. Whether he's explaining how to harden a browser or reporting on the latest surveillance disclosures, his goal is to equip readers with knowledge they can use immediately. Jordan believes that true security begins with understanding the digital landscape.

Comments (0)

No comments.