SMS-XBomber Database Leak Allegedly Exposes Users and SMS Targets

An alleged SMS-XBomber database leak exposes 2,014 records containing plaintext passwords, account details and phone numbers reportedly targeted through the tool.
Screenshot of a forum post claiming the SMS-XBomber database was obtained from an exposed Firebase instance, with 2,014 records and plaintext passwords.
A threat actor claims an exposed Firebase instance belonging to SMS-XBomber contained 2,014 records, including account details, plaintext passwords and phone numbers allegedly targeted through the SMS flooding tool.

A database allegedly belonging to the SMS-XBomber project has been leaked, potentially exposing not only users of the SMS flooding tool but also phone numbers they allegedly targeted.

A threat actor published the claim on 18 Aug. 2026, saying an exposed Firebase instance allowed them to retrieve 2,014 records associated with the project. The actor claims the database contains names, email addresses, phone numbers, plaintext passwords, account identifiers and records of phone numbers targeted through the tool.

The leak is unusual because the exposed data allegedly provides visibility into both sides of SMS bombing activity. According to the database structure described by the threat actor, records include a user’s phone number alongside fields tracking every number attacked and the most recently targeted number.

Plaintext passwords raise a second exposure risk

The threat actor claims passwords associated with SMS-XBomber accounts were stored in plaintext rather than as cryptographic hashes.

If authentic, that creates an additional credential-theft risk for users who reused the same passwords on email accounts, social networks or other services. The alleged dataset also includes email addresses and usernames, potentially giving attackers enough information to attempt credential stuffing or targeted account takeover attempts.

BreachNews is not publishing the leaked records, phone numbers, passwords or other personally identifiable information contained in the samples.

Targeted phone numbers reportedly logged by the tool

The purported database contains fields described as tracking all phone numbers previously targeted by an account and the last number targeted. That means people who never registered for SMS-XBomber could potentially appear in the leak simply because their numbers were entered into the tool.

SMS bombing typically involves triggering large volumes of SMS or verification messages toward a phone number, potentially flooding the recipient with unwanted notifications and making legitimate messages harder to identify.

The threat actor did not disclose evidence establishing how long the Firebase database had allegedly been exposed or how many of the 2,014 records represent unique individuals.

Another alleged Firebase exposure surfaces

The actor claims the database was discovered while scanning for exposed Firebase deployments, pointing to a possible configuration issue rather than exploitation of a software vulnerability. BreachNews has previously reported similar incidents involving publicly accessible Firebase data, including a Fit&Lean exposure that allegedly affected 199,000 user fitness profiles.

The same threat actor was also behind a separate recent claim involving Silvi AI, where approximately 16,000 user records were allegedly exposed through an IDOR flaw.

BreachNews has not independently verified the complete SMS-XBomber dataset or established whether the records were obtained from an active production database. The samples supplied with the claim appear structured consistently with the described fields, but that alone does not establish the provenance or completeness of the leaked data.

No public statement addressing the alleged exposure had been identified from the SMS-XBomber project maintainers at time of publication.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site