[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fon813rftk97g":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":11,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":16,"affectedCount":16,"affectedCountStatus":17,"affectedCountLowerBound":18,"affectedCountUnit":19,"hasEnglishDescription":4,"severity":20,"dataClasses":21,"description":26,"seoTitle":14,"seoTitleEn":27,"seoDescription":14,"seoDescriptionEn":28,"logoUrl":29,"isVerified":4,"isSensitive":30,"isSpamList":30,"isMalware":30,"company":31},"68e3266eda11adda48825163","creams-cafe","Creams Cafe Data Breach","creamscafe.com","2025-05-01T00:00:00.000Z","2025-07-23T04:31:05.000Z","2026-07-18T23:49:09.287Z","Third party breach","",[],159652,"known",null,"unknown","High",[22,23,24,25],"Email addresses","Names","Phone numbers","Physical addresses","\u003Cp>Creams Cafe is a retail food service operating as a dessert cafe chain based in the United Kingdom, working with customer order and contact information. In May 2025, it was claimed that approximately 160,000 customer records were breached; email, name, phone, and physical address fields were verified.\u003C\u002Fp>\u003Cp>Since this record does not contain payment or password fields, it should be addressed not in terms of account takeover, but in terms of delivery, order, and customer communication risks. Although the company's public response to the incident is limited, multiple affected users have verified the accuracy of the data.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>Data categories tracked in Creams Cafe records should be considered as email addresses, name and surname information, phone numbers, and physical addresses. Email addresses can be used for targeted phishing, password reset schemes, and account matching across different services. Name and surname information makes fake support, fake delivery, fake invoice, and customer service messages more convincing. Phone numbers allow for personalized fraud scenarios via SMS, calls, and messaging apps. Physical addresses can be used in delivery, invoice, subscription, and local service-themed social engineering messages.\u003C\u002Fp>\u003Cp>The cafe and delivery context can facilitate sending users fake orders, returns, coupons, delivery verification, or customer service messages. Name, phone, and address information contribute to making the message appear genuine.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>This record is associated with the domain creamscafe.com and the May 2025 period. The scope is limited to email addresses, full names, phone numbers, and physical addresses. Passwords, payment cards, purchase details, or health information are not verified data classes for this record.\u003C\u002Fp>\u003Cp>Areas not included in this record should not be described as if they have leaked. Fields such as full payment card, official ID, private message, health data, bank information, or device content should only be added to the risk assessment when they are explicitly present in the record. The text is based on verifiable data classes and the known boundaries of the incident.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>Creams Cafe customers who store delivery address and phone information in their accounts, users who respond quickly to promotional and order messages, and people who use the same email address for different retail accounts are at higher risk.\u003C\u002Fp>\u003Cp>Users who use the same email address on different services, repeat old passwords, do not separate work and personal accounts, or share phone and address information on numerous platforms are at higher risk. In data collection or B2B profile registrations, the risk should also be assessed based on the profile effect consolidated from different sources rather than a single account.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Users should verify coupons, returns, delivery, or payment links received on behalf of Creams Cafe through the official channel. Since there is no password, the priority is not account change, but being careful against personalized scam messages using phone and address information.\u003C\u002Fp>\u003Cp>Users in the positive match area should update their passwords on accounts where they use the same or similar passwords, enable two-factor authentication where possible, and check their recent sessions. For records that do not contain passwords but include communication or profile data, caution should be exercised against unexpected calls, offers, returns, partnerships, and verification messages.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>In the long term, the habit of using a password manager, unique passwords, two-factor authentication, and removing unnecessary personal information from accounts reduces risk. Reusing the same email address across different platforms makes it easier to combine data from different breaches; using a separate email or alias for critical accounts can be considered.\u003C\u002Fp>\u003Cp>Unnecessary address and phone records in food and delivery accounts should be regularly cleaned. Users should not trust short links in promotional and delivery messages and should carry out account transactions directly through the official site or application.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>LeakData check indicates whether the queried email address is present in this record. A positive result does not necessarily mean that all data fields definitely belong to that user; however, it is a sufficient warning for precautionary measures. A negative result only indicates that there is no match in this dataset and does not eliminate the possibility of appearing in other breaches.\u003C\u002Fp>\u003Cp>A positive result indicates that the email address appears in the Creams Cafe customer data. This result does not imply a payment card or password leak; however, due to the context of the address and phone number, caution should be taken regarding fraudulent delivery and coupon messages.\u003C\u002Fp>","Creams Cafe Data Breach (159.7 Thousand Reported Records)","Creams Cafe Data Breach. 159.7 Thousand reported records were reported. Reported data: Email addresses, Names, Phone numbers. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fcreamscafe_com.webp",false,{"name":32,"sector":33,"country":34,"website":9,"websiteArchiveUrl":14,"websiteStatus":14,"websiteCheckedAt":18},"Creams Cafe","Food Service \u002F Dessert Retail","United Kingdom"]