[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1ffafa2ytzx4m":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":29,"seoTitle":30,"seoTitleEn":31,"seoDescription":30,"seoDescriptionEn":32,"logoUrl":33,"isVerified":4,"isSensitive":34,"isSpamList":34,"isMalware":34,"company":35},"68e3266eda11adda48825141","chowbus","Chowbus Data Breach","chowbus.com","2020-10-05T00:00:00.000Z","2020-10-06T06:07:45.000Z","2026-07-09T18:18:55.393Z","2026-07-18T23:47:22.219Z","Third party breach","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fchowbus-delivery-service-breached-hacker-emails-data-to-users\u002F",[15,17,18],"https:\u002F\u002Fcyberscoop.com\u002Fchowbus-breach-personal-data-customers-linxin-wen\u002F","https:\u002F\u002Fwww.businessinsider.com\u002Fchowbus-data-breach-leaked-information-hundreds-thousands-users-2020-10",444224,"known",null,"unknown","High",[25,26,27,28],"Email addresses","Names","Phone numbers","Physical addresses","\u003Cp>The Chowbus data breach is an incident related to the Asian cuisine-focused food delivery platform, which came to attention in October 2020 when customer data was disclosed unauthorizedly. It has been confirmed that files containing over 800,000 customer records were sent to certain users, and this dataset included 444,224 unique email addresses. This record is tracked as 444,224 affected accounts based on the number of unique emails. The total number of records is not the same as the number of unique emails; it is possible for the same person to appear in multiple rows or for different types of data to be included in the same set.\u003C\u002Fp>\n\u003Cp>Verified data classes are email addresses, names, phone numbers, and physical addresses. Passwords, payment cards, bank information, or order contents are not included in this record as verified data classes. However, the disclosure of both a physical address and a phone number together poses a high practical risk in the context of food delivery. Users can be targeted with scenarios such as fake delivery notifications, address updates, returns, restaurant coupons, payment confirmations, or customer service calls. Therefore, the impact of the incident is not limited to email spam risk; it should also be carefully addressed from the perspective of social engineering based on address and phone.\u003C\u002Fp>\n\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\n\u003Cp>In a Chowbus account, the name, email address, phone number, and physical address can be seen together. These four fields allow an attacker to reach the user directly and personally. The physical address is especially important in the context of food delivery and local restaurants, because users are accustomed to receiving messages about delivery, orders, couriers, returns, or address verification. This habit can make fake messages seem more convincing. The phone number, on the other hand, increases the risk of fraud via text messages and calls.\u003C\u002Fp>\n\u003Cp>In this incident, since the password and payment card were not verified, the direct requirement to change the password is not as strong as in credential-focused breaches. However, it is possible for users to be directed to fake login pages through links received via email and phone. Messages prepared with name and address information may appear like a genuine delivery alert. If additional information, such as the restaurant name, regional information, or delivery habits, is obtained from other sources, the attack can be further personalized. Therefore, even though verified fields are limited, the risk is real and feasible.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified number of affected accounts for this record is 444,224 unique email addresses. It has been reported that the larger dataset associated with the incident contained over 800,000 customer records. This number should not be interpreted as the number of unique users, as it may include duplicate records or different rows belonging to the same person. The Chowbus incident also mentioned restaurant data; however, for this record, the user-side data classes are maintained as name, email address, phone number, and physical address.\u003C\u002Fp>\n\u003Cp>The scope boundaries should be particularly clear. There is no verified data class within this record for passwords, payment cards, bank accounts, official identification numbers, order contents, payment history, or food preferences. The presence of a physical address indicates that the user could be targeted in the context of location and delivery; however, this does not mean that payment information has been compromised. The explanation should make the real communication and address risk visible without unnecessarily causing panic for the user.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The users at the highest risk are those who have shared their delivery address and phone number through Chowbus. These individuals may be targeted with messages such as fake delivery status, address verification, courier communication, restaurant coupon, or return notification. When an email address and phone number are present in the same record, an attacker can communicate through multiple channels. Sending an email first and then following up with a text message or call can make the fraudulent message appear more realistic.\u003C\u002Fp>\n\u003Cp>Users who frequently use local restaurant services may also be more receptive to region-specific campaigns and order-related messages. Revealing a physical address poses a privacy risk, especially for those using their home address. From a corporate perspective, employees using food delivery platforms with their personal phone and email information may result in social engineering messages appearing during working hours or on work devices. Therefore, a breach that appears to be an individual account should also be considered from the standpoint of organizational security.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>Users should not directly click on links in emails and text messages themed around Chowbus or food delivery. Even if the delivery status, refund, address verification, or coupon notification seems real, the transaction should be checked through the official app or a known domain. Even if a caller claims to be a courier, restaurant, or customer service, one-time codes, passwords, payment information, or additional personal information should not be shared. Correctly stating the name and address does not prove that the call is trustworthy.\u003C\u002Fp>\n\u003Cp>If the password used on the Chowbus account is also used on other services, it should be changed; in this case, even if the password is not classified as verified data, password reuse is always a separate risk. Security alerts on the email account should be kept on, and unexpected logins should be monitored. For accounts associated with a phone number, a verification app should be preferred instead of relying solely on SMS-based verification. The user should also be more cautious about shipping, delivery, and payment messages received with address information.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>Food delivery and local service platforms are services frequently used in daily life but hold a large amount of address and contact information. In the long term, users should delete unnecessary old addresses, close unused accounts on these platforms, and avoid leaving excessive personal information in delivery notes whenever possible. Using a separate email address for campaign and order notifications can better protect the main email account. If sharing a phone number is unavoidable, the level of caution against unknown calls and messages should be increased.\u003C\u002Fp>\n\u003Cp>From the perspective of platform providers, the incident shows how quickly the loss of user trust can occur when customer data is exported in bulk files. Access permissions, file sharing, customer data export, and post-incident notification processes must be strictly controlled. Organizations should also inform their employees that fake delivery, courier, meal voucher, and address verification messages can be used for phishing purposes. Messages themed around daily life should be included in training, as they can appear less suspicious than traditional bank or email alerts.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>A match in this record indicates that the associated email address appears on a unique email list linked to the Chowbus data breach. A match does not mean that the password or payment card fields are included in the verified scope of this record. Verified risk is limited to name, email, phone, and physical address fields. Users should act with the understanding that these fields can be used in fake delivery and customer service scenarios.\u003C\u002Fp>\n\u003Cp>The first practical step is to check the contact and address information on the Chowbus account, remove unnecessary old addresses, and assign a unique password to the account. Then, delivery-themed messages received via email and phone should be verified through the official channel. In situations where personal addresses may have been exposed, the user should be cautious of unexpected cash-on-delivery, return, or courier requests. Even if the risk does not involve a direct payment card leak, address-based fraud and social engineering scenarios should be considered realistic.\u003C\u002Fp>","","Chowbus Data Breach (444.2 Thousand Reported Records)","Chowbus Data Breach. 444.2 Thousand reported records were reported. Reported data: Email addresses, Names, Phone numbers. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fchowbus_com.webp",false,{"name":36,"sector":37,"country":38,"website":9,"websiteArchiveUrl":30,"websiteStatus":30,"websiteCheckedAt":21},"Chowbus","Food delivery platform","United States"]