[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2ct66b9re6ij0":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":28,"seoTitle":15,"seoTitleEn":29,"seoDescription":15,"seoDescriptionEn":30,"logoUrl":31,"isVerified":4,"isSensitive":32,"isSpamList":32,"isMalware":32,"company":33},"68e3266eda11adda488253e3","ualabee","Ualabee Data Breach","ualabee.com","2025-05-06T00:00:00.000Z","2025-06-13T06:24:35.000Z","2026-07-03T14:51:06.409Z","2026-07-19T00:00:07.405Z","Third party breach","",[],472296,"known",null,"unknown","High",[23,24,25,26,27],"Dates of birth","Email addresses","Names","Phone numbers","Profile photos","\u003Cp>The Ualabee data breach is an incident associated with the South America-focused mobility and public transportation services platform Ualabee, which occurred in May 2025. The record covers 472,296 unique email addresses and contains fields that can directly identify the user, such as date of birth, name, phone number, and profile photo. Due to the context of the mobility service, the risk is not limited to contact information alone; it is also possible to target users with messages that appear to be related to their urban transportation and daily movement habits.\u003C\u002Fp>\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\u003Cp>In this record, when the email address, name, phone number, date of birth, and profile photo are considered together, the risk of phishing increases significantly. The profile photo and date of birth can help an attacker create messages that appear more personal and trustworthy to the user. The phone number, on the other hand, facilitates the use of SMS, messaging apps, and calling channels.\u003C\u002Fp>\u003Cp>When fields such as name, email, phone, or address come together, attackers can approach the user as if there were a genuine service relationship. This information alone is not proof of account takeover; however, it provides a strong starting point for fake support messages, delivery notifications, password reset attempts, and personalized fraud flows. Password or payment card data is not listed in the record; nonetheless, fields like date of birth and profile photo can be used in account recovery, fake authentication, and social engineering scenarios. Mobility-themed campaigns, route notifications, subscription updates, or app verification messages should be evaluated with particular care.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The date of the incident is May 6, 2025, and the number of affected email accounts is recorded as 472,296. Security logs indicate that the data was collected through an interface on the platform, and the exposed fields include date of birth, email, name, phone number, and profile photo. Since these fields are consistent with the existing record, the verified status is maintained.\u003C\u002Fp>\u003Cp>When explaining the scope, it should not be assumed that all fields will be present in every row. Some records may be missing a profile photo or phone information. In addition, this does not mean that payment systems or plaintext password data have been leaked. The actual risk to the user is that personal contact and profile information linked to the mobility account could be misused.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>Users at risk are those who have opened a Ualabee account, used mobility services, or shared phone or profile information. Since daily transportation applications can generate messages close to the user's routine, fake route, ticket, subscription, notification, or campaign messages may appear more convincing.\u003C\u002Fp>\u003Cp>Users with a birth date and profile picture should also be careful against the risk of creating fake accounts, guessing identity verification questions, or matching through social media. If the phone number is up to date, the risk is not limited to email; the user can also be targeted via SMS and calls.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Users in the matching area should check that they are using a unique password on their Ualabee account and should change it if they have used the same password on other accounts. Even if a password is not found in the record, the email address can be combined with other data sets. If the date of birth is used in account recovery questions, these questions should be updated.\u003C\u002Fp>\u003Cp>Instead of opening incoming links directly, the user should log in through the known web address or application of the relevant service. The fact that the caller knows the name, email, address, or past transaction information does not prove they are trustworthy. One-time verification codes, payment card information, or account passwords should not be shared in any support conversation.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>In the long term, a password manager, unique passwords, two-factor authentication on possible accounts, and the habit of removing unnecessary personal information from accounts reduce risk. Reusing the same email address on different platforms makes it easier to combine different breaches; therefore, using separate email or alias addresses for critical accounts can be considered.\u003C\u002Fp>\u003Cp>Since fields such as profile photo and date of birth do not change over time, the impact of this incident should not be seen as short-term. Users should reduce unnecessary publicly available profile information on social media and mobility accounts, and enable additional security layers for services where login is done with a phone number.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>LeakData check shows whether the queried email address is found in this record or not. A positive result does not necessarily mean that all data fields definitively belong to that user; however, it should be considered a sufficient warning for precautionary measures. A negative result only indicates that there is no match in this dataset and does not rule out the possibility of appearing in other breaches.\u003C\u002Fp>\u003Cp>If a positive result is obtained, the user should be especially careful with messages themed around mobility, transportation, campaigns, and application verification. If the email address is not visible, there is no match for this specific record; however, since the same phone or email may be involved in other violations, regular monitoring should be maintained.\u003C\u002Fp>","Ualabee Data Breach (472.3 Thousand Reported Records)","Ualabee Data Breach. 472.3 Thousand reported records were reported. Reported data: Dates of birth, Email addresses, Names. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fualabee_com.webp",false,{"name":34,"sector":35,"country":36,"website":9,"websiteArchiveUrl":15,"websiteStatus":15,"websiteCheckedAt":19},"Ualabee","Mobility \u002F Public Transport","Argentina"]