[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fv8385xxw6a2g":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":28,"seoTitle":29,"seoTitleEn":30,"seoDescription":29,"seoDescriptionEn":31,"logoUrl":32,"isVerified":4,"isSensitive":33,"isSpamList":33,"isMalware":33,"company":34},"68e3266eda11adda48825332","qraved","Qraved 2021 Data Breach","qraved.com","2021-07-09T00:00:00.000Z","2025-04-09T15:43:51.000Z","2026-07-21T19:38:22.234Z","Verified breach record","https:\u002F\u002Fwww.qraved.com\u002F",[14,16],"https:\u002F\u002Fcybernews.com\u002Fsecurity\u002Fbillions-passwords-credentials-leaked-mother-of-all-breaches\u002F",984519,"known",null,"unknown","High",[23,24,25,26,27],"Dates of birth","Email addresses","Names","Passwords","Phone numbers","\u003Cp>The Qraved 2021 data breach concerns user information associated with an Indonesian restaurant discovery and food-focused online service that was exposed on July 9, 2021. The verified record contains 984,519 unique email addresses together with names, phone numbers, dates of birth, and password values stored as MD5 hashes. The dataset was later redistributed as part of a broader corpus of data. That figure represents the verified scope of unique email identifiers; it does not establish 984,519 separate active accounts or prove that every person had every listed field.\u003C\u002Fp>\n\u003Cp>This page explains the confirmed data categories and practical protective actions. There is no reliable confirmation of the initial access method, the technical component involved, payment cards, session tokens, delivery addresses, or government-issued identity data. Those details are therefore not presented as facts. A useful risk assessment takes the confirmed fields seriously without turning unknown details into certainty.\u003C\u002Fp>\n\u003Ch2>Exposed Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The confirmed data classes are email addresses, names, phone numbers, dates of birth, and password values in MD5 hash form. Together, those fields can make targeted phishing messages, social-engineering attempts, and account-matching activity more convincing. A name and contact information do not by themselves prove account compromise, but they can help an attacker create messages that appear to be tailored to a real user.\u003C\u002Fp>\n\u003Cp>The password field was not confirmed as plain-text passwords. However, MD5 is a fast hash method that does not provide adequate protection for modern password storage. Reuse of the same password, or a close variation, on another service increases the chance that guessed values will be tried elsewhere. Dates of birth, names, and phone numbers can also add context to account-recovery questions, support requests, or targeted fraud scenarios.\u003C\u002Fp>\n\u003Cp>Payment-card data, banking information, location history, delivery addresses, session cookies, and government-issued identity documents are not verified data classes for this incident. It would be inaccurate to say that they were exposed. Users should not dismiss the real risk of the confirmed fields, but they also should not be pushed into unnecessary alarm by unverified claims.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Limits\u003C\u002Fh2>\n\u003Cp>The incident is recorded as occurring on July 9, 2021, with a verified scope of 984,519 unique email addresses. It is associated with an Indonesian restaurant-focused service, and the later redistribution of the dataset in a broader corpus does not mean that the initial event happened later or that every record in that broader corpus came from the same service. The number is based on unique email identifiers and should not be read as a one-to-one total of users, customers, or active accounts.\u003C\u002Fp>\n\u003Cp>The verified classes do not prove that every row contained a complete profile. Some rows may have contained only a subset of the listed fields. There is also no reliable detail about the intrusion path, responsible parties, the boundary of affected technical systems, the organisation's response, or how the data was obtained. For that reason, this page stays within the confirmed date, scale, service context, and data types.\u003C\u002Fp>\n\u003Cp>The MD5 classification matters because it does not mean that plain-text passwords were published. It still creates meaningful risk for weak or reused passwords. The practical priority is to protect every account where the same password may have been used and to assess unexpected messages sent to the associated email address with care.\u003C\u002Fp>\n\u003Ch2>Users at Elevated Risk\u003C\u002Fh2>\n\u003Cp>The highest priority applies to people who reused the same or a similar password on email, social, shopping, food, work, or financial services. They should review not only the password associated with Qraved, but every account where the same value was used. Because an email account is a recovery channel for many services, protecting it with a strong, unique password is especially important.\u003C\u002Fp>\n\u003Cp>The presence of names, dates of birth, and phone numbers can make fraudulent account-recovery messages, delivery campaigns, support conversations, or discount notices appear more credible. An attacker who knows that someone may be a customer can try to create urgency. Requests for a password, one-time code, multi-factor approval, or remote device access should not be treated as legitimate merely because they contain personal details.\u003C\u002Fp>\n\u003Cp>Risk is not identical for everyone named in the data. A match does not prove that an account is active today, that a password has been recovered, or that another service has been accessed. It does mean that people who used the service or shared contact details should take password reuse and targeted phishing seriously.\u003C\u002Fp>\n\u003Ch2>Immediate Protective Actions\u003C\u002Fh2>\n\u003Cp>Change the password associated with Qraved first, then replace the same or similar password wherever else it was used with unique values. Start with the email account, financial services, shopping accounts, and social platforms. Long, random, separate passwords for each account reduce the chance that one exposure can spread into unrelated services.\u003C\u002Fp>\n\u003Cp>Enable multi-factor authentication wherever it is available. When supported, an authenticator application or security key can provide a stronger layer than a code sent only by text message. Review account-recovery emails, sign-in notifications, and new-device alerts, and use the official support channel directly for activity you do not recognise.\u003C\u002Fp>\n\u003Cp>Treat delivery offers, password-reset links, account-verification prompts, and other messages received by email, phone, or chat with caution. Open the service address yourself rather than following the link in a message. A legitimate support representative should not ask for your password, a one-time code, or remote access to your device.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Practices\u003C\u002Fh2>\n\u003Cp>A password manager makes it practical to create a different, long password for every service. Older passwords derived from personal information, names, dates of birth, or simple character substitutions are easier to guess. Avoiding reuse is one of the most effective ways to keep an older exposure from creating new risk years later.\u003C\u002Fp>\n\u003Cp>Review the recovery email, linked phone number, and multi-factor options on your primary email account regularly. Closing unused accounts or reducing the personal information kept in old accounts also lowers the available attack surface. Sharing dates of birth and phone numbers only when necessary helps limit the material that can be used in future targeted fraud.\u003C\u002Fp>\n\u003Cp>Follow security notifications, unfamiliar sign-ins, and password-change alerts for services you use. Not every alert is genuine, so open the account directly instead of using a link in the message. Regular checks make the long-term consequences of a single exposure easier to manage.\u003C\u002Fp>\n\u003Ch2>Record Check and User Action\u003C\u002Fh2>\n\u003Cp>You can check whether an email address appears in this record through a trusted breach-checking service. A match indicates that the email address is present in the verified dataset; it does not prove that a current account is compromised, that every data field belongs to you, or that any password has been recovered. Treat the result as a prompt to review passwords and multi-factor protection.\u003C\u002Fp>\n\u003Cp>Use only the email address for a record check. Do not share a password, verification code, identity document, or payment information. If an alert looks suspicious, type the service address yourself, sign in directly, and review recent account activity. That practice helps protect against phishing and fake-support attempts that use the name of a known incident.\u003C\u002Fp>","","Qraved 2021 Data Breach (984.5 Thousand Reported Records)","Qraved 2021 Data Breach. 984.5 Thousand reported records were reported. Reported data: Dates of birth, Email addresses, Names. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fqraved_com.webp",false,{"name":35,"sector":36,"country":37,"website":9,"websiteArchiveUrl":29,"websiteStatus":29,"websiteCheckedAt":19},"Qraved","Food Technology","Indonesia"]