Skip to content

11.8 Million Transfast Payment SMS Records Offered With Portal Access

Breach Report United States Payments Live Access Claimed

11.8 Million Transfast Payment SMS Records Offered With Portal Access

A forum actor posting as Marx is advertising access to what they describe as a live database of messaging records belonging to Transfast, a cross border payment network acquired by Mastercard in 2019 and now operating as part of its transaction services business. The material is not payment card data but the SMS delivery logs of a messaging portal used to send transactional notifications, containing recipients' phone numbers, transaction confirmations and money transfer details. The dashboard shown reports 11,835,390 messages, all recorded as delivered, between January and early September 2026. The actor offers a sample and links to the portal itself. The claim is unverified.

Messages11,835,390
PeriodJan to Sep 2026
AccessClient portal
ActorMarx

Post details

TargetTransfast
ParentMastercard
CountryUnited States
SectorCross border payments
ListingAccess and sample offered
Volume11.8M messages
Stated sourceMessaging portal
Observed

!What the post claims

  • 11,835,390 messages
  • All recorded as delivered
  • January to September 2026
  • Database described as live
  • Recipient phone numbers
  • Transaction confirmations
  • Money transfer details
  • Message direction types
  • Account profile filtering
  • Delivery status counts
  • Traffic volume charts
  • Client portal access shared
  • Sample of 10,000 records
  • Payment network named
  • Parent company named
  • Contact by messenger
  • No price stated
  • No mechanism described

Screenshots

Forum post advertising Transfast messaging records, observed 7 September 2026.

Mapped techniques

Mapped from the actor's own account. Claimed, not confirmed.

  • Initial access T1078 Valid accounts Inferred The proof is a signed in view of a messaging provider's customer portal with filters and reporting intact, which indicates account access rather than a database taken offline.
  • Collection T1213 Data from information repositories Stated Message logs covering eight months are queryable through the portal, and a sample has been extracted from them.
  • Credential access T1111 Multi factor authentication interception Inferred Conditional and unconfirmed. Transactional messaging channels commonly carry one time codes as well as confirmations, and if any appear here then live portal visibility becomes a credential problem rather than only a privacy one.

Potential impact

Message logs from a payment network tie a phone number to a confirmed transfer, which produces a list of people who recently moved money and roughly when, and that is the working brief for remittance fraud. The affected population sharpens it, since cross border transfer customers are frequently migrant workers sending money home, a group already targeted heavily and often reachable in a second language. The unresolved question is whether the same channel carries one time codes; if it does, then live visibility of delivered messages is an account takeover capability, not a historical disclosure, and the urgency changes completely.

iStatus Unverified

Framing matters here more than usual: what is shown is a messaging provider's portal serving the payment company, and nothing in the post indicates a compromise of Mastercard's own payment systems. The dashboard is internally coherent, with delivery counts matching the traffic chart across the stated period, but a screenshot demonstrates a session rather than access that persists, and no acquisition route is given. The account is days old with almost no standing. Dark Web Informer has not retrieved the sample, is not linking the portal or contact addresses, and neither company has publicly addressed the claim.

Dark Web Informer // Threat Intelligence

Latest