[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f211a0yri4x61y":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":21,"affectedCount":21,"affectedCountStatus":22,"affectedCountLowerBound":23,"affectedCountUnit":24,"hasEnglishDescription":4,"severity":25,"dataClasses":26,"description":36,"seoTitle":37,"seoTitleEn":38,"seoDescription":37,"seoDescriptionEn":39,"logoUrl":40,"isVerified":4,"isSensitive":41,"isSpamList":41,"isMalware":41,"company":42},"68e3266eda11adda488251a4","eat-street","EatStreet Data Breach","eatstreet","eatstreet.com","2019-05-03T00:00:00.000Z","2019-07-19T11:29:35.000Z","2026-07-02T12:26:55.059Z","2026-07-18T23:50:10.228Z","Unauthorized database access","https:\u002F\u002Foag.ca.gov\u002Fsystem\u002Ffiles\u002FEatStreet%20Delivery%20r3prf.pdf",[16,18,19,20],"https:\u002F\u002Fwww.restaurantdive.com\u002Fnews\u002Featstreet-suffers-data-breach\u002F557226\u002F","https:\u002F\u002Fsecurityaffairs.com\u002F87313\u002Fcyber-crime\u002Featstreet-security-breach.html","https:\u002F\u002Fwww.twingate.com\u002Fblog\u002Ftips\u002Featstreet-data-breach",6353564,"known",null,"unknown","Critical",[27,28,29,30,31,32,33,34,35],"Dates of birth","Email addresses","Genders","Names","Partial credit card data","Passwords","Phone numbers","Physical addresses","Social media profiles","\u003Cp>The EatStreet data breach is an extensive customer and partner data incident affecting 6,353,564 accounts on the United States-based online food ordering service. It was reported that unauthorized access began on May 3, 2019, and was detected and terminated on May 17, 2019. During this period, it is understood that customer, restaurant, and delivery partner information in the database was accessed. The record should be considered high-risk not only due to email leakage but also because of address, phone number, date of birth, partial credit card data, and passwords in bcrypt hash format.\u003C\u002Fp>\n\u003Cp>The verified data categories are birth dates, email addresses, gender information, full names, partial credit card data, passwords, phone numbers, physical addresses, and social media profiles. It is noted that passwords are stored as bcrypt hashes; while this offers better protection than plain text passwords, it does not completely eliminate the risk of password reuse. The term partial credit card data does not mean that the full card information of each user has definitely been leaked. Since notifications to partners also mention financial fields such as bank account and routing numbers, restaurant and delivery partners also need to check their financial accounts.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The data aggregation in the EatStreet record creates multi-layered risk. When an email address, phone number, full name, and physical address are found together, an attacker can directly reach the user and send fake delivery, order, return, or card verification messages. Date of birth and gender information provide additional context that can be misused in account recovery processes or authentication questions. Social media profiles, on the other hand, can help match the person with their other online accounts.\u003C\u002Fp>\n\u003Cp>Even if the password field is in bcrypt hash format, the risk continues. Bcrypt is a modern and slow hash algorithm, but weak or reused passwords can still be a target for attackers. Partial credit card data may not pose as definite a financial risk as full card information; however, when combined with the card's last digits, billing address, or phone number, it can strengthen fake bank calls and payment verification frauds. On the partner side, the risk of bank account and routing information should also be taken into consideration.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified main scope for this record is 6,353,564 accounts. The incident date is recorded as May 3, 2019; it has been reported that unauthorized access was detected and stopped on May 17, 2019. Data classes are broad, but it should not be assumed that every field exists for every user. Customer, restaurant partner, and delivery partner records may have different fields. Therefore, the description should not use definitive statements implying that all users' bank account data or full card numbers were leaked.\u003C\u002Fp>\n\u003Cp>The main data classes verified within the scope of public query include date of birth, email, gender, name, partial credit card data, password, phone, physical address, and social media profile. In partner notifications, fields such as delivery service name, partner name, email, phone, and bank\u002Frouting information appear; these fields should be evaluated on a per-partner basis. On the customer side, partial card data and billing\u002Fdelivery context increase the risk of social engineering. This distinction is important to ensure that the correct precautions are taken without unnecessarily alarming the user.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The highest risk group consists of customers who place orders through EatStreet and reuse the same password on other accounts. Email, phone, address, and order context allow the attacker to prepare delivery or payment messages that appear realistic. If partial card data is also included, the user can be more easily persuaded during fake bank or card verification calls. Birth dates can make it easier to guess weak verification questions used in account recovery processes.\u003C\u002Fp>\n\u003Cp>Restaurant and delivery partners are also at high risk. Since partner notifications contain financial fields such as bank account and routing numbers, this group should not be limited to password or email security alone. Business account payments, bank transactions, and unauthorized money transfer attempts should be monitored. Restaurant employees or business owners who register with a corporate email address can be targeted with fake invoices, payment updates, and platform support messages.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>If the password used on the EatStreet account has been repeated on another account, it should be changed immediately. Although using a Bcrypt hash is a good technical protection, it does not make repeated passwords secure. Unique passwords should be used for email, social media, food delivery, shopping, and payment-linked accounts, and two-factor authentication should be enabled. The same or similar password roots should also be avoided; attackers can try variations based on leaked password hints.\u003C\u002Fp>\n\u003Cp>Customers should carefully monitor card transactions, suspicious delivery messages, and account verification requests. It is useful to enable suspicious transaction alerts from your card provider. Since address and phone information may have been leaked, attention should be paid not only to emails but also to text messages and calls. Restaurants and delivery partners should check bank account transactions, examine whether there are any unexpected changes in payment instructions, and review authorized users on business accounts.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>The EatStreet incident demonstrates that customer data and partner financial data should be protected under the same security framework in food ordering and delivery ecosystems. Organizations should closely monitor database access, not retain unnecessary fields, regularly clean up old records, and limit card data to tokens or last digits whenever possible. Strong methods like bcrypt should be used for password storage, but alongside this, a strong password policy and multi-factor authentication should also be implemented.\u003C\u002Fp>\n\u003Cp>On the user side, a long-term approach is to separate food ordering, shopping, and payment accounts with unique passwords and not to share profile information unnecessarily. Data such as address, phone number, and date of birth are difficult to change, so once they are leaked, they can be used in targeted fraud for a long time. Businesses and partners should strengthen role-based access, transaction approval, and bank movement monitoring processes on platforms containing financial account information.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>If your email address appears in this record, check not only your EatStreet account but also all accounts using the same password. Be cautious of suspicious food orders, deliveries, returns, and bank or card verification messages. Partial credit card data and address information can make fake customer service conversations seem convincing. If you see an unknown transaction on your card, contact your card provider directly and do not click on links in the message.\u003C\u002Fp>\n\u003Cp>If you are a restaurant or delivery partner, also review financial account transactions and payment settings. Notifications containing bank account or routing information belong to the partner context; therefore, it is important to verify that no unauthorized changes have been made to business accounts. The EatStreet data breach shows that when customer profile data, partial financial data, and password hashes are combined, it can pose long-term social engineering and account security risks.\u003C\u002Fp>","","EatStreet Data Breach (6.4 Million Reported Records)","EatStreet Data Breach. 6.4 Million reported records were reported. Reported data: Dates of birth, Email addresses, Genders. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Featstreet_com.webp",false,{"name":43,"sector":44,"country":45,"website":10,"websiteArchiveUrl":37,"websiteStatus":37,"websiteCheckedAt":23},"EatStreet","Food delivery","United States"]