Ualabee Data Breach (2025): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Ualabee disclosed a data breach on 6 May 2025 that exposed names, email addresses, phone numbers, dates of birth and profile photos of 472 000 users. If you have an account with the service, check the company’s notifications and consider changing passwords or enabling additional account protection.
In May 2025, the South American mobility services platform Ualabee experienced a data incident in which hundreds of thousands of user records were scraped from an interface on its platform. Public reporting dated 6 May 2025 states that the material included approximately 472,000 unique email addresses together with names, profile photos, dates of birth and phone numbers.
The scale of the exposure—nearly half a million people—means the event is of practical interest to anyone who has used the service. Exact technical details beyond the scraping of an interface remain limited in public accounts, so the known facts centre on the volume of records and the categories of personal data involved.
Breaking down the breach
According to the reported summary, the incident occurred in May 2025 when records were scraped from an interface belonging to Ualabee. The organisation is described as a South American mobility services platform. The scrape yielded hundreds of thousands of records, specifically 472,000 unique email addresses accompanied by names, profile photos, dates of birth and phone numbers.
No further public detail has been supplied on the precise date range of the scraping activity, the exact technical method used beyond access to an interface, or whether any additional systems were involved. Attribution to a particular threat actor is also absent from the available facts. The core confirmed elements are therefore the timing (May 2025, reported 6 May), the approximate number of people affected (472,000), the listed data types, and the description of the activity as scraping from a platform interface.
How a breach like this happens
Incidents involving the scraping of large volumes of personal data from a platform interface typically arise when an application programming interface, search function, or other publicly reachable endpoint returns user-related information without sufficient rate-limiting, authentication checks or data-minimisation controls. An automated process can then query the interface repeatedly, collect the returned fields, and assemble them into a structured dataset.
Such events do not always require an intrusion into internal servers; they can result from overly permissive design of a customer-facing or partner-facing interface. Once collected, the data may be stored, traded or published by whoever performed the scrape. Because no specific threat group is named in connection with this case, the description above remains general background on how scraping-type exposures commonly unfold rather than a reconstruction of this particular incident.
Who is Ualabee?
Ualabee operates as a mobility services platform serving users in South America. Organisations in this sector typically provide journey planning, public-transport information, ride or micro-mobility options, and related location-based services. To deliver those functions they ordinarily maintain user accounts that store contact details, profile information and, in many cases, travel-related preferences or history.
A breach affecting such a platform is consequential because the data held is directly linked to identifiable individuals who rely on the service for everyday movement. Exposure of contact and demographic fields can therefore reach a large, geographically concentrated user base and create lasting privacy and security considerations for those people as well as operational and reputational issues for the organisation itself.
The information in question
Public reporting names the following categories as exposed: dates of birth, email addresses, names, phone numbers and profile photos. The same accounts state that the scrape produced 472,000 unique email addresses together with the associated fields listed above. No additional data types are confirmed in the available facts.
Mobility platforms commonly hold further information such as account credentials, payment tokens or detailed trip histories; however, those categories are not reported as part of this incident and must be treated as unconfirmed. The only data types that can be stated as fact are those explicitly named: dates of birth, email addresses, names, phone numbers and profile photos.
Why it matters
For affected individuals the combination of name, email address, phone number, date of birth and a profile photo creates a ready-made identity package. That package can be used for targeted phishing, social-engineering attempts, SIM-swap efforts or the creation of convincing fake profiles. Even without financial data, the ability to link a real name and face to contact details and age increases the risk of harassment, account-takeover attempts on other services, and long-term privacy erosion.
For Ualabee the incident raises questions of user trust, potential regulatory scrutiny under applicable data-protection regimes, and the need to review how interfaces expose personal information. Because the records were obtained by scraping rather than by a confirmed internal compromise, the organisation still faces the practical task of notifying users, monitoring for misuse of the data, and hardening the relevant interfaces against similar bulk collection in future.
What to do if you're exposed
If you have used Ualabee and believe your details may be among the 472,000 records, the following practical steps are advisable:
- Change passwords on any accounts that share the same email address or password as your Ualabee profile, and enable multi-factor authentication wherever available.
- Treat unsolicited messages that reference your name, phone number or date of birth with heightened caution; verify the sender through independent channels before clicking links or supplying further information.
- Monitor your email and phone for unusual account-recovery or verification requests that could indicate someone is attempting to take over other services.
- Consider placing a fraud alert with relevant credit or identity-protection services if you live in a jurisdiction that offers them, especially given the presence of date-of-birth data.
- Run a free exposure scan of your email address against known breach datasets to check whether the same address has appeared in other incidents.
Public detail on this incident remains limited to the facts summarised above. Continuing to follow official statements from Ualabee and applying the basic hygiene steps listed will reduce residual risk while further information, if any, becomes available.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Pass'Sport Data Breach (2025)APOIA.se Data Breach (2025)SoundCloud Data Breach (2025)Under Armour Data Breach (2025)Latest breaches
Read GalaxyWarden’s full analysis of the Ualabee Data Breach (2025) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.