LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Ualabee Data Breach (2025)

MEDIUM severityConfirmedHow we verify

Ualabee Data Breach (2025): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·May 6, 2025

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Ualabee Data Breach (2025)

Reported May 6, 2025. Approximately 472K people affected.

MEDIUM
Severity
472K
People affected
5
Data types exposed
May 6, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Ualabee disclosed a data breach on 6 May 2025 that exposed names, email addresses, phone numbers, dates of birth and profile photos of 472 000 users. If you have an account with the service, check the company’s notifications and consider changing passwords or enabling additional account protection.

Severity & verification
MEDIUM severityConfirmed
Contact / identity PII exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the Ualabee Data Breach (2025) breach?
472K accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In May 2025, the South American mobility services platform Ualabee experienced a data incident in which hundreds of thousands of user records were scraped from an interface on its platform. Public reporting dated 6 May 2025 states that the material included approximately 472,000 unique email addresses together with names, profile photos, dates of birth and phone numbers.

The scale of the exposure—nearly half a million people—means the event is of practical interest to anyone who has used the service. Exact technical details beyond the scraping of an interface remain limited in public accounts, so the known facts centre on the volume of records and the categories of personal data involved.

Breaking down the breach

According to the reported summary, the incident occurred in May 2025 when records were scraped from an interface belonging to Ualabee. The organisation is described as a South American mobility services platform. The scrape yielded hundreds of thousands of records, specifically 472,000 unique email addresses accompanied by names, profile photos, dates of birth and phone numbers.

No further public detail has been supplied on the precise date range of the scraping activity, the exact technical method used beyond access to an interface, or whether any additional systems were involved. Attribution to a particular threat actor is also absent from the available facts. The core confirmed elements are therefore the timing (May 2025, reported 6 May), the approximate number of people affected (472,000), the listed data types, and the description of the activity as scraping from a platform interface.

How a breach like this happens

Incidents involving the scraping of large volumes of personal data from a platform interface typically arise when an application programming interface, search function, or other publicly reachable endpoint returns user-related information without sufficient rate-limiting, authentication checks or data-minimisation controls. An automated process can then query the interface repeatedly, collect the returned fields, and assemble them into a structured dataset.

Such events do not always require an intrusion into internal servers; they can result from overly permissive design of a customer-facing or partner-facing interface. Once collected, the data may be stored, traded or published by whoever performed the scrape. Because no specific threat group is named in connection with this case, the description above remains general background on how scraping-type exposures commonly unfold rather than a reconstruction of this particular incident.

Who is Ualabee?

Ualabee operates as a mobility services platform serving users in South America. Organisations in this sector typically provide journey planning, public-transport information, ride or micro-mobility options, and related location-based services. To deliver those functions they ordinarily maintain user accounts that store contact details, profile information and, in many cases, travel-related preferences or history.

A breach affecting such a platform is consequential because the data held is directly linked to identifiable individuals who rely on the service for everyday movement. Exposure of contact and demographic fields can therefore reach a large, geographically concentrated user base and create lasting privacy and security considerations for those people as well as operational and reputational issues for the organisation itself.

The information in question

Public reporting names the following categories as exposed: dates of birth, email addresses, names, phone numbers and profile photos. The same accounts state that the scrape produced 472,000 unique email addresses together with the associated fields listed above. No additional data types are confirmed in the available facts.

Mobility platforms commonly hold further information such as account credentials, payment tokens or detailed trip histories; however, those categories are not reported as part of this incident and must be treated as unconfirmed. The only data types that can be stated as fact are those explicitly named: dates of birth, email addresses, names, phone numbers and profile photos.

Why it matters

For affected individuals the combination of name, email address, phone number, date of birth and a profile photo creates a ready-made identity package. That package can be used for targeted phishing, social-engineering attempts, SIM-swap efforts or the creation of convincing fake profiles. Even without financial data, the ability to link a real name and face to contact details and age increases the risk of harassment, account-takeover attempts on other services, and long-term privacy erosion.

For Ualabee the incident raises questions of user trust, potential regulatory scrutiny under applicable data-protection regimes, and the need to review how interfaces expose personal information. Because the records were obtained by scraping rather than by a confirmed internal compromise, the organisation still faces the practical task of notifying users, monitoring for misuse of the data, and hardening the relevant interfaces against similar bulk collection in future.

What to do if you're exposed

If you have used Ualabee and believe your details may be among the 472,000 records, the following practical steps are advisable:

Public detail on this incident remains limited to the facts summarised above. Continuing to follow official statements from Ualabee and applying the basic hygiene steps listed will reduce residual risk while further information, if any, becomes available.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyUalabee security record
74/100
DoxxScan™ · Moderate doxx risk
B 80Good record

1 reported incident on record.

See Ualabee’s full breach history →

More recent breaches

Pass'Sport Data Breach (2025)December 17, 2025APOIA.se Data Breach (2025)December 16, 2025SoundCloud Data Breach (2025)December 15, 2025Under Armour Data Breach (2025)November 17, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Ualabee Data Breach (2025) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram