[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2xvz93uijv7wg":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":20,"affectedCount":20,"affectedCountStatus":21,"affectedCountLowerBound":22,"affectedCountUnit":23,"hasEnglishDescription":4,"severity":24,"dataClasses":25,"description":32,"seoTitle":33,"seoTitleEn":34,"seoDescription":33,"seoDescriptionEn":35,"logoUrl":36,"isVerified":4,"isSensitive":37,"isSpamList":37,"isMalware":37,"company":38},"68e3266eda11adda488251e5","fresh-menu","FreshMenu Data Breach","freshmenu","freshmenu.com","2016-07-01T00:00:00.000Z","2018-09-10T12:27:19.000Z","2026-07-02T12:26:55.059Z","2026-07-18T23:51:02.811Z","Third party breach","https:\u002F\u002Fwww.inc42.com\u002Fbuzz\u002Ffreshmenu-data-breach\u002F",[16,18,19],"https:\u002F\u002Fwww.bankinfosecurity.com\u002Findian-food-delivery-startup-freshmenu-confirms-data-breach-a-11475","https:\u002F\u002Fwww.thenewsminute.com\u002Farticle\u002Ffreshmenu-data-breach-hacker-selling-details-110k-customers-android-app-88199",110355,"known",null,"unknown","High",[26,27,28,29,30,31],"Device information","Email addresses","Names","Phone numbers","Physical addresses","Purchases","\u003Cp>The FreshMenu data breach is a customer data leak experienced by the India-based food delivery service during the July 2016 period. The verified scope is 110,355 unique customer accounts. The record included device information, email addresses, names, phone numbers, physical delivery addresses, and purchase or order history. It has been reported that the company was aware of the incident but chose not to send notifications to affected customers. Therefore, the incident is significant not only as a technical account security issue but also in terms of customer communication and delivery privacy.\u003C\u002Fp>\u003Cp>Since a FreshMenu account does not include a password or payment card, the risk of direct account takeover is lower compared to password leaks. Nevertheless, the combination of name, email, phone, address, and order history creates a strong dataset for targeted fraud. Attackers can leverage these fields when preparing fake order notifications, delivery updates, returns, coupons, membership campaigns, or customer service messages. The context of the user's past food orders can make the message more convincing.\u003C\u002Fp>\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\u003Cp>The types of data verified in this record are device information, email addresses, names, phone numbers, physical addresses, and purchase history. Device information may provide additional signals about the user session or technical context. Email and phone can be used to contact the user directly. The physical delivery address and order history, on the other hand, can create sensitive context regarding where the person lives or orders food, their routines, and service preferences.\u003C\u002Fp>\u003Cp>Since the password field is not verified, users' priority should be fraud themed around fake communication and delivery rather than the risk of password cracking. If a message correctly uses your name, phone number, address, or previous order context, this alone is not proof of reliability. Messages sending links under the pretext of delivery cancellation, additional payment, campaign coupon, address verification, or return should be checked carefully.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The number of verified unique customers is 110,355. The incident date is recorded as July 1, 2016, and it is associated with the domain name freshmenu.com. FreshMenu is an India-based food delivery service; therefore, the previously seen 'Government' sector and 'United States' country information in the database is incorrect. The record should be evaluated in the context of food delivery and online orders.\u003C\u002Fp>\u003Cp>In this record, the password, password hash value, payment card number, card security code, bank account, official identification document, or private message content are not among the verified data fields. Users should not act as if their card or password has been leaked. However, when the delivery address, phone, and order history are found together, the social engineering risk is real and permanent. The risk description should be established with this limitation.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The people at the highest risk are customers who have ordered food through FreshMenu and are still using the same phone\u002Femail information. Even if the delivery address has changed, the email and phone can remain active for a long time. If the same name, phone, and address combination has been used for other food delivery, shopping, or courier services, attackers can prepare more convincing messages.\u003C\u002Fp>\u003Cp>The risk is more personalized for users with an order history. Messages themed around fake discounts, favorite restaurants, old delivery addresses, payment errors, or membership campaigns may appear real. People who use delivery to their work address or home address should also be careful; because address information can be misused not only online but also through phone calls and under the pretext of physical delivery.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>If you have a FreshMenu account, check account security and registered contact information. Since the password was not verified in this record, an immediate password change is not required for all accounts; however, if the same email address has appeared in other password leaks, a unique password should be set for the relevant accounts. Two-factor authentication should be enabled on the email account and security notifications should be monitored.\u003C\u002Fp>\u003Cp>Before clicking on a link in messages about food delivery, coupons, refunds, address verification, or order cancellation, check through the official app or domain. The caller knowing your name or address is not proof of reliability. If you are asked for additional payment, a one-time code, card information, or account information, stop the request and verify it through the official customer service channel.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>The FreshMenu incident highlights the importance of reducing unnecessary personal data in food delivery and daily service accounts. Users should now close delivery accounts they no longer use, keep registered address and phone information up to date, and use different strong passwords for order services. Since delivery addresses and phone numbers may not change for long periods, old leaks can be used in targeted messages even years later.\u003C\u002Fp>\u003Cp>From the perspective of service providers, customer data should only be retained as long as it is necessary to complete the order, and fields such as order history and delivery address should be protected with strict access control. Providing customers with clear and timely notification when an incident is discovered is part of the security culture. Even if there is no password or card information, the address, phone number, and order history directly affect customer privacy.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>If your email address appears in this record, check the contact information you use for FreshMenu or similar food delivery accounts. Verify unexpected orders, refunds, coupons, or address verification messages through official channels, not via the link. If the same email appears in breaches involving passwords, change the passwords on those accounts and enable two-factor authentication.\u003C\u002Fp>\u003Cp>In the FreshMenu data breach, the verified fields are device information, email, name, phone, delivery address, and order history. Password and payment card are not verified; however, the delivery and order context provides enough material for social engineering. The most accurate action is to be cautious of fake delivery\u002Fcoupon messages, verify through official channels, reduce old delivery accounts, and consider that the same email address could be combined with other breaches.\u003C\u002Fp>","","FreshMenu Data Breach (110.4 Thousand Reported Records)","FreshMenu Data Breach. 110.4 Thousand reported records were reported. Reported data: Device information, Email addresses, Names. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Ffreshmenu_com.webp",false,{"name":39,"sector":40,"country":41,"website":10,"websiteArchiveUrl":33,"websiteStatus":33,"websiteCheckedAt":22},"FreshMenu","Food Delivery","India"]