← eSky Group (eSky.pl)

2026 eSky Group (Poland) — OxO criminal-forum claim; travel-customer PII alleged (May)

2026 Unknown records affected Share on X

Data compromised

Dates of birth, full names, addresses, emails, phone numbers per actor/OSINT summaries—authenticity and freshness disputed

Technical writeup

On 16 May 2026, threat-intelligence aggregators on X (e.g., DarkWebSonar) summarized a criminal-forum marketing claim by an actor branding itself OxO, alleging a data theft from Poland’s eSky online travel platform (eSky Group / eSky.pl). The advertised dataset was described as including dates of birth, full names, postal addresses, email addresses, and phone numbers—categories typical of flight-and-holiday booking profiles. BreachHistory indexes the OSINT claim while stressing that eSky had not issued a matching public forensic bulletin in indexed English/Polish trade press at catalog time, that no authoritative victim count accompanied the post, and that overlap with older travel-sector leaks or repackaged Polish retail dumps must be excluded before treating the file as a confirmed 2026 intrusion. Poland’s 2018 mis-sent identity-verification email to eSky.pl users (configuration error; company denied unauthorized access) is a separate historical incident and should not be conflated with this row.

Root cause

Alleged external exfiltration or reseller dump per OxO forum marketing; intrusion vector and corporate confirmation pending

References