[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2cusbyaasift2":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":20,"affectedCount":20,"affectedCountStatus":21,"affectedCountLowerBound":22,"affectedCountUnit":23,"hasEnglishDescription":4,"severity":24,"dataClasses":25,"description":32,"seoTitle":33,"seoTitleEn":34,"seoDescription":33,"seoDescriptionEn":35,"logoUrl":36,"isVerified":4,"isSensitive":37,"isSpamList":37,"isMalware":37,"company":38},"68e3266eda11adda488251a1","eatigo","Eatigo Data Breach","eatigo.com","2018-10-16T00:00:00.000Z","2021-08-25T03:42:31.000Z","2026-07-02T12:26:55.059Z","2026-07-18T23:50:07.943Z","Legacy database exposure","https:\u002F\u002Fwww.channelnewsasia.com\u002Fsingapore\u002Featigo-fined-data-breach-users-personal-data-sold-pdpc-3342326",[15,17,18,19],"https:\u002F\u002Fwww.straitstimes.com\u002Ftech\u002Fpersonal-data-from-28-million-eatigo-accounts-stolen-put-up-for-sale-online","https:\u002F\u002Fprivasec.com\u002Fblog\u002Fdata-breach-redmart-eatigo\u002F","https:\u002F\u002Fwww.twingate.com\u002Fblog\u002Ftips\u002Featigo-data-breach",2789609,"known",null,"unknown","Critical",[26,27,28,29,30,31],"Email addresses","Genders","Names","Passwords","Phone numbers","Social media profiles","\u003Cp>The Eatigo data breach is a high-risk personal data incident affecting 2,789,609 accounts related to an old database of the restaurant reservation service. From a record system perspective, the breach date is recorded as October 16, 2018; the data came to official attention in 2020 when it was put up for sale on an online forum and it was noted that the old database had not been adequately tracked during the platform transition. Therefore, the incident is not only an old user profile issue; it is a risk table containing restaurant reservations, phone numbers, email addresses, and weakly hashed password data all together.\u003C\u002Fp>\n\u003Cp>The verified data categories are email addresses, gender information, first and last names, passwords, phone numbers, and social media profiles. It is stated that the passwords are stored not in plain text but in unsalted MD5 hash format. This distinction is important: the hash format does not necessarily mean that an attacker can see the password directly, but MD5 is fast and weak for modern standards. If the password was reused or is weak, attackers may try to crack these hashes to attempt access to other accounts.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The email address, phone number, and name-surname information in the Eatigo record make it easier to reach the user directly. In the context of restaurant reservations, it makes social engineering scenarios such as fake reservation confirmations, cancellation notices, discount coupons, account verification, or customer service messages more convincing. When gender information and social media profiles are also added, the attacker can send more personalized messages to the targeted person.\u003C\u002Fp>\n\u003Cp>The password field is one of the most critical risks. Unsalted MD5 hash is weaker compared to modern password storage methods strengthened with a unique salt value. This does not mean that every password can be instantly cracked, but the risk significantly increases for common password lists and reused passwords. When combined with a phone number, password risk can enhance not only email-based phishing but also fake call and SMS scams.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified main scope for this record is 2,789,609 accounts. The technical context of the incident is related to an old database not being properly maintained in inventory after a platform transition and remaining accessible from the internet. Although the sale of the data was noticed in 2020, the last update of the database and the context of the incident point to the 2018 period. Therefore, the date of the breach should not be confused with the date it became publicly visible.\u003C\u002Fp>\n\u003Cp>The verified data classes are email addresses, genders, names, passwords, phone numbers, and social media profiles. Payment card information is not in the verified scope for this incident; company statements indicated that credit card information is not stored in the system. Although more detailed statements about social media-linked fields appear in different sources, in this record the data class should be kept as social media profiles. This way, both the risk becomes visible and unverified additional fields are not presented to the user as definitive information.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The highest risk group consists of people who use the password from their Eatigo account on other services as well. If the same email and password combination is repeated on social media, email, food delivery, shopping, or loyalty program accounts, an old restaurant reservation record can spread to other accounts. Phone number and name-surname information can also help an attacker directly reach the user to initiate a fake security or reservation process.\u003C\u002Fp>\n\u003Cp>Users making restaurant reservations in Singapore, Hong Kong, Thailand, and the region can also be targeted with local campaigns and reservation language. If a person has linked their Eatigo account with their social media profile, an attacker can collect more context from this profile to personalize the message. For users registered with a corporate email address, the risk can extend to their work account; messages coming under the pretext of restaurant reservations or events can turn into phishing attempts targeting employees.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>If your email address appears in the Eatigo record, the first step is to make sure that the password used for the Eatigo account is not used in any other account. If the same or similar password has been used, passwords for email, social media, food delivery, shopping, and payment-linked accounts should be changed immediately. New passwords should be unique and stored with a password manager. Simply adding a number to the end of the old password is not sufficient.\u003C\u002Fp>\n\u003Cp>Be cautious with text messages and calls, considering that your phone number and name-surname information might also have been leaked. Do not click directly on links that come under the pretext of reservation cancellation, restaurant discounts, account verification, or security checks. If you need to access your account, type the address into the browser manually or use the official app. Enable this protection for accounts that support two-factor authentication and check for unknown sessions in your email account.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>The Eatigo incident shows that old databases and systems left behind during platform transitions can pose serious risks. Organizations should keep their data inventory up to date, shut down unused databases, and isolate backup and legacy environments with access controls. On the password storage side, old methods like unsalted MD5 should not be used; strong, salted, and slow hash algorithms should be preferred. Personal data should only be stored for the necessary period, and old records should be regularly cleaned.\u003C\u002Fp>\n\u003Cp>Long-term strategy on the user side is to never reuse passwords, not share phone numbers on unnecessary accounts, and limit social media connections. If restaurant, travel, shopping, and delivery accounts are managed with separate email addresses, a leak on one service will be harder to connect to other profiles. Organizations should also reduce employees' use of work email on personal services and carry out leaked password checks together with phishing awareness.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>If your email address appears in this record, check not only your Eatigo account but also any other accounts you use during the same period with the same password or phone number. Even if the password is stored in hash form, using the same password elsewhere is a serious risk due to the unsalted MD5 weakness. The combination of phone number and social media profile can be used for fake support messages or personalized phishing attempts.\u003C\u002Fp>\n\u003Cp>The correct action is to make the password unique, enable two-step verification on important accounts, and not to act on suspicious reservations and security messages without verification. It should be remembered that the payment card information is not verified within this record; however, the combination of email, phone, name, social media profile, and weakly hashed password alone is serious enough. These steps reduce the transfer of the Eatigo data breach to other accounts and your current identity security.\u003C\u002Fp>","","Eatigo Data Breach (2.8 Million Reported Records)","Eatigo Data Breach. 2.8 Million reported records were reported. Reported data: Email addresses, Genders, Names. Review the scope, risks, and protective steps.","\u002Fuploads\u002Flogo\u002Featigo_com.webp",false,{"name":39,"sector":40,"country":41,"website":9,"websiteArchiveUrl":33,"websiteStatus":33,"websiteCheckedAt":22},"Eatigo","Food tech","Singapore"]