Millions of Russian fast food fans hit in Burger King Russia hack
Burger King Russia’s 2024 breach via Mindbox exposed 3.2 million customer records, now leaked online Data includes emails, names, genders, birth dates, phone numbers, and geolocations (2018–2024) Payment details weren’t compromised; users warned of phishing and identity theft risks Back in 2024, the Russian arm of Burger King suffered a data breach at the hands of unknown threat actors - now, that data has finally been leaked online.
In October 2024, Burger King told TASS, Russia’s national news agency, that unidentified hackers attacked Mindbox, a domestic marketing automation platform the company had been using.
Through Mindbox, the crooks managed to obtain sensitive company data, including information belonging to the customers.
As a customer data and marketing automation platform, Mindbox helps businesses gather and use customer information for personalized, omnichannel marketing campaigns.
Its tools cover email and SMS campaigns, push notifications, loyalty programs, chatbots, and more.
According to the company, more than 1,100 businesses use its platform, including L’Oréal, Panasonic, KFC, JBL and United Colors of Benetton.
One victim in a supply-chain attack At the time, there was no word on the nature of the information that was taken, apart from the fact that payment information was not compromised.
"Among the victims of the attack may also be the data of customers of the Burger King restaurant chain," the company said at the time.
“Burger King confirms that among the personal data, the accuracy of which is being clarified, there is no information about payment details: open information about transactions is not transmitted or stored by third parties.” The details about the hack were also not disclosed.
We don’t know if the platform contained a zero-day, or if a company employee had their login credentials or session tokens exposed.
Third-party supply chain attacks such as this one are common and often rather disruptive, affecting numerous companies using the same tools.
For Mindbox, however, there have been no reports of additional victims.
In its 2024 results announcement, Mindbox said the attack was its “first serious information security incident”, which was quickly detected and contained “thanks to threat detection tools.” In the aftermath of the breach, Mindbox said it “found and eliminated points where employees without access rights to sensitive data could indirectly obtain them,” hinting that the attack was, in fact, an identity-based attack rather than a zero-day exploit.
The company also “changed development processes to find such points before they get into the product,” and reformed Mindbox's internal role system to make permissions stricter and more granular.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.techradar.com — the content belongs to TechRadar.