MyBusybee Allegedly Exposed 60GB of SMS Data
A threat actor using the alias “valrsafety” has claimed responsibility for a data breach involving MyBusybee, Inc., a Philippine technology company that provides SMS and messaging services to businesses and organizations.
The claim was published on September 2, 2026, at approximately 4:14 AM, with the threat actor alleging that around 60GB of data had been obtained.
According to the threat actor's post, the allegedly compromised data contains information connected to approximately 160 million users and around 2,500 companies using the platform. The claim includes data from organizations across sectors such as gaming, cryptocurrency, finance, business, and government.
MyBusybee's own website describes its services as including SMS marketing, notifications, two-way messaging, delivery reports, and automated messages such as OTPs, transaction notifications, and other time-sensitive messages. The company also states that its messaging services cover more than 168 million Philippine mobile devices.
Based on the screenshots and description published by the threat actor, the alleged dataset contains several types of information, including:
• SMS messages sent through the platform
• Mobile numbers associated with SMS recipients
• Company and account information
• Usernames and account roles
• Account registration dates
• Account expiration dates
• Account status
• Platform credit or balance information
• Other account activity and operational records
The screenshots show structured records from different MyBusybee accounts, including accounts associated with businesses and government-related organizations.
The screenshots published by the threat actor contain records associated with several organizations and accounts. Examples visible in the samples include Pacific Digital, ItnioTech, MyBusybee, and government-related accounts.
Their appearance in the alleged MyBusybee records does not necessarily mean that these organizations were independently breached. The information may have been stored or processed through the MyBusybee platform.
The reported exposure of SMS message contents is the most significant aspect of the claim. MyBusybee provides services for OTPs, transaction notifications, account activity alerts and other automated messages.
If the threat actor's claims are confirmed, access to historical SMS records could potentially expose sensitive communications between organizations and their customers, including messages related to account verification and transactions.
Other contents