August 24, 2026
By esentry Team

SMS-XBomber Leak Exposes More Than Its Users

Threat Type: Database Exposure | Credential Exposure
Severity: High
Date Reported: 18 August 2026
Alleged Records: 2,014

Key Points

  • A threat actor identified as m00s3c claims to have accessed an exposed Firebase instance associated with SMS-XBomber.
  • The alleged database contains 2,014 records, including names, email addresses, phone numbers, account identifiers and plaintext passwords.
  • Records reportedly also contain phone numbers previously targeted through the SMS-XBomber service, potentially exposing individuals who never used the platform.
  • The exposure appears to have resulted from publicly accessible Firebase data, rather than exploitation of software vulnerability.

The Exposure

On 18th August 2026, a threat actor claimed to have uncovered a database belonging to SMS-XBomber, a service used to generate large volumes of SMS or verification messages against a selected phone number.

According to the threat actor, the Firebase instance contained 2,014 records linking SMS-XBomber accounts to personal information and activity. Alongside names, email addresses, phone numbers and account identifiers, the records allegedly contained plaintext passwords and fields tracking phone numbers targeted by individual accounts.  

That creates two distinct groups of potentially exposed individuals: the people who used the service and the people whose numbers were entered into it.

The latter may be the more significant finding. A person did not necessarily need an SMS-XBomber account to appear in the alleged dataset. If their number had been entered as a target, the database may have retained that information.

The exposure therefore provides a glimpse into both the operators of the activity and its intended recipients.

From Exposed Database to Credential Risk

The alleged presence of plain text passwords changes the risk considerably.

If the passwords are genuine, they would not need to be cracked before being used. Combined with the reportedly exposed usernames and email addresses, they could provide the basic ingredients for credential-stuffing or targeted account-takeover attempts, particularly where users have reused passwords elsewhere.

The database's activity records introduce another concern. The reported fields include numbers previously targeted by an account and the most recently targeted number. This effectively turns application data into a record of targeting activity.

For defenders monitoring the dark web, that distinction is useful. A conventional credential leak may tell an actor who a user is and how to authenticate them. This dataset allegedly adds another layer: who that user was targeting.

Attack Methodology

What Makes This Relevant

The incident is small in volume but interesting from an intelligence perspective.

The alleged dataset does not merely represent another collection of usernames and passwords. It potentially connects identity, credentials and targeting activity within a single source.

That combination can increase the usefulness of the data to subsequent threat actors. Compromised credentials can be tested against other services, while the associated target information could support further harassment or targeted activity.

It also highlights a recurring pattern in dark web discoveries: the initial access can be technically unsophisticated while the intelligence value of the resulting data is much higher.

The same actor reportedly claims to have identified other exposed databases, including an alleged 199,000-record Fit&Lean exposure, as well as a separate claim involving approximately 16,000 Silvi AI records through an IDOR vulnerability. This suggests the actor may be actively searching for poorly protected data sources rather than pursuing a single target.