AI News Feed
Market watch
Cybersecurity

Burger King Russia Data Breach via Mindbox Leaks 3.2 Million Records

Burger King Russia breach leaks 3.2M emails and personal data; payment data unaffected, with phishing risks.

Have I Been Pwned? said the exposed data includes names, genders, dates of birth, phone numbers and approximate geolocations, and spans 2018 to August 2024. It added that Burger King Russia acknowledged the incident and advised that payment or passport details were not included.

The breach was first disclosed in October 2024. Burger King told TASS, Russia's national news agency, that unidentified hackers attacked Mindbox. Mindbox helps businesses gather and use customer information for personalized, omnichannel marketing campaigns, including email and SMS campaigns, push notifications, loyalty programs and chatbots. The company says more than 1,100 businesses use its platform, including L'Oréal, Panasonic, KFC, JBL and United Colors of Benetton.

At the time, Burger King said payment information was not compromised. "Among the victims of the attack may also be the data of customers of the Burger King restaurant chain," the company said. "Burger King confirms that among the personal data, the accuracy of which is being clarified, there is no information about payment details: open information about transactions is not transmitted or stored by third parties."

The exact method of the attack has not been disclosed. It is not known whether Mindbox contained a zero-day vulnerability or whether an employee's login credentials or session tokens were exposed. Third-party supply-chain attacks of this kind are common and can affect multiple companies using the same tools, though Mindbox has not reported additional victims.

In its 2024 results announcement, Mindbox said the attack was its "first serious information security incident" and that it was quickly detected and contained "thanks to threat detection tools." After the breach, Mindbox said it found and eliminated points where employees without access rights to sensitive data could indirectly obtain them, suggesting an identity-based attack rather than a zero-day exploit. The company changed development processes to find such points before they enter the product, reformed its internal role system to make permissions stricter and more granular, limited project access scenarios, introduced a mechanism for confirming access by another employee and made two-factor authentication mandatory, among other measures.

The Register reported at the time that initial reports claimed around 5.6 million lines of data were exposed, including information about a customer's favorite dish and previous order dates. The newest Have I Been Pwned? entry does not mention those details, but if every data line includes one email, name or phone number, the total could be around 5.6 million.

Although the information may be several years old, names, birth dates and genders rarely change and can be used in identity theft, social engineering and similar attacks. Burger King customers, especially in Russia, should be wary of incoming email messages, particularly messages claiming to come from the fast-food chain.