Roomer Travel Account Data on More Than 200,000 Users Shared on a Forum
A forum actor posting as slvsh3r has published what they describe as the client database of Roomer Travel, a marketplace and mobile app for buying and reselling non refundable hotel reservations. The post claims more than 200,000 records and the sample shows account identifiers, first and last names, usernames, email addresses, verification flags, currency preferences and referral codes. Fields for phone number, postal address, credit balance and payout configuration are present in the schema but empty in every visible row, and no password field appears at all. The files are unlocked for a nominal forum fee. The claim is unverified.
▣Post details
!What the post claims
- More than 200,000 records
- Account identifiers
- First and last names
- Usernames
- Email addresses
- Account verified flags
- Currency preference
- Referral codes
- Credit balance fields
- Payout configuration fields
- Stripe enabled flag
- PayPal account field
- Address fields present but empty
- Phone fields present but empty
- Profile photo field
- No password field in sample
- Automated or test accounts visible
- Sequential identifiers
◱Screenshot
☷Mapped techniques
The post describes no intrusion method. Both entries are inferred from the artefacts, not stated.
- Collection T1213 Data from information repositories Inferred Records appear as nested objects with sequential identifiers and empty optional branches, which reads as a serialised export from an application rather than a scrape of profile pages.
- Exfiltration T1567 Exfiltration over web service Inferred Distribution runs through forum hosting behind a points wall. The route out of the environment is not described.
⚠Potential impact
This is a thin set by the standards of what it advertises. Strip out the empty branches and what remains is a name, a username and an email address per account, with no passwords, no addresses, no phone numbers and no payment identifiers populated anywhere in the sample. As a privacy matter that is limited. Where it has value is context: everyone in this file is a user of a marketplace for reselling hotel bookings that cannot be refunded, which means a good proportion of them have either lost money on a trip or are trying to recover some of it. That is an unusually receptive audience for refund and rebooking fraud, and a message referencing a real account, a real username and the correct platform will clear the first bar of suspicion for many of them. Two things deserve checking against the full file rather than the sample. Whether the payout fields are populated anywhere, since a PayPal address tied to a named seller is a materially different exposure, and whether address and phone are filled for the subset who completed transactions, which is where a partial export would show its seams.
iStatus Unverified
The sample carries one detail that argues for authenticity: several records contain machine generated gibberish in the name fields, the sort of automated or test account that accumulates in any real production table and that someone fabricating a file would have no reason to invent. Identifiers also run sequentially in a narrow band well above the claimed record count, which is consistent with a slice of a larger table rather than a complete export, and sits awkwardly with the headline figure. Set against that, no intrusion method, date or access route is given, the volume cannot be checked from what is shown, and the near total absence of populated optional fields means the set may be far less complete than the count suggests. The account is established, with a purchased forum rank. Dark Web Informer has not retrieved the file and is not linking it, nor the archive credentials. Roomer Travel has not publicly addressed the claim.
Dark Web Informer // Threat Intelligence