news.mlab.sh
Back to the feed
threat-intel

Bitbybit Studio : 25 millions de lignes revendiquées

High
Summary

A shadowy publication claims to have exposed 25 million records linked to Bitbybit Studio, an AI platform used for conversational commerce. The data includes personal information, message histories, orders, and technical logs. The claim is based on a purported zero-day vulnerability in a third-party system. While the volume and types of data are detailed, the authenticity and origin of the data remain unverified, presenting potential risks for malicious actors seeking to exploit the information for phishing campaigns and fraud.

A clandestine publication, operating under the title ‘bitbybit-25’, is alleging the exposure of 25 million records associated with Bitbybit Studio, a platform designed to transform conversations on platforms like WhatsApp and Instagram into commercial interactions, customer support, and payment processing. The publication claims that a vendor pirate obtained a database linked to Bitbybit Studio.

According to the publication’s account, the data was extracted in August 2026 due to a zero-day vulnerability affecting a system belonging to a third-party provider. The volume announced is 25,015,318 lines, equivalent to approximately 14GB. However, it’s important to note that these lines may not represent 25 million distinct individuals; multiple tables (such as ‘purchase’, ‘error’, ‘newsletter’, etc.) can pertain to a single user, conversation, or operation.

The published list provides a more detailed view of the alleged structure. The largest file, ‘MessageHistory’, contains 7,033,783 lines, while ‘ChatLists’ holds 2,910,554, and ‘MessageNew’ reaches 1,897,471 entries. Several datasets are announced around the one-million-line limit, including group messages, connection logs, contacts, associated buttons, and webhook data.

The content claimed goes beyond a simple list of identities. The filenames suggest a mix of personal data, conversational exchanges, technical metadata, operational information, and commercial traces. The author explicitly cites email addresses, full names, phone numbers, physical addresses, and logs of conversations with artificial intelligence.

An example is offered via an external file-sharing service. The publication is initially asking for a starting price of $1,000 (approximately $850 USD), presented as negotiable, and payment must be made in cryptocurrency – a classic malicious tactic.

The core element remains the assertion of a zero-day exploitation in a third-party system. A zero-day vulnerability is a previously unknown or unpatched weakness when it is exploited. In this case, no technical references, vulnerability identifiers, or vendor names are provided in the text transmitted.

Therefore, it’s crucial to distinguish between three levels: the publication exists in the provided elements, its author claims a compromise and details a set of files, and the technical origin of this extraction rests solely on their declarations. The announced volume and data categories remain claims until independent validation has established their authenticity.

However, some figures exhibit internal consistency within the overall presentation. The tables cover the expected functions of a conversational commerce platform: messages, contacts, tickets, campaigns, automations, orders, integrations, analyses, and advertising events. The 25,015,318 lines correspond to the total indicated by the author after adding up the different files cited.

This structure increases the potential interest for malicious actors. Personal contact information could be used to personalize phishing attempts. Conversation histories would provide additional context to mimic an existing business relationship. Technical logs could also reveal information about the internal workings of a platform or its integrations. These risks remain hypothetical until the actual content of the archive is confirmed.

Read the full article at ZATAZ