[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fyjxja822ik2n":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":11,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":27,"seoTitle":28,"seoTitleEn":29,"seoDescription":28,"seoDescriptionEn":30,"logoUrl":31,"isVerified":4,"isSensitive":32,"isSpamList":32,"isMalware":32,"company":33},"68e3266eda11adda4882543a","zomato","Zomato Data Breach","zomato.com","2017-05-17T00:00:00.000Z","2017-09-04T21:06:46.000Z","2026-07-20T01:09:30.482Z","Database leak","https:\u002F\u002Fwww.zomato.com\u002Fblog\u002Fsecurity-notice",[14,16,17],"https:\u002F\u002Fwww.zomato.com\u002Fwho-we-are","https:\u002F\u002Fwww.hackread.com\u002Fzomato-hacked-17-million-accounts-sold-on-dark-web\u002F",16472873,"known",null,"unknown","Critical",[24,25,26],"Email addresses","Passwords","Usernames","\u003Cp>The May 2017 Zomato data breach affected 16,472,873 unique email addresses and exposed usernames and salted password hashes.\u003C\u002Fp>\u003Ch2>Types of Exposed Data and Risks\u003C\u002Fh2>\u003Cp>The verified dataset contained email addresses, usernames and password hashes. Corpus analysis identified the passwords as salted MD5 hashes, although a password hash was not present on every account record. The company said passwords were protected with a one-way algorithm, multiple hashing iterations and a separate salt for each password. \u003Cstrong>The 16,472,873 unique email addresses\u003C\u002Fstrong> represent deduplicated addresses in the verified corpus; the figure does not establish that every record contained a password or that the same number of unique people was affected. Zomato said approximately 60% of users signed in through services such as Google or Facebook, so it did not hold passwords for those accounts. Payment information was stored in a separate vault, and the company stated that no credit-card or payment data was stolen. Telephone numbers, order histories, physical addresses and payment cards are not confirmed data classes for this incident.\u003C\u002Fp>\u003Ch2>Breach Timeline and Technical Details\u003C\u002Fh2>\u003Cp>On 17 May 2017, data claimed to represent roughly 17 million Zomato accounts appeared for sale on a criminal marketplace. Independent checks confirmed that accounts in the published sample were registered with Zomato. The next day, Zomato confirmed that its security team had discovered approximately 17 million user records stolen from its database. Its initial assessment suggested that an employee's development account may have been compromised. A later update said the attacker provided details of the access method and the loophole was closed. Zomato reset passwords for affected users, signed accounts out of the application and website, scanned possible access vectors and said it would strengthen internal access controls. Because the material directly matched Zomato account structures and the company's disclosure, it is not a generic credential collection.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The highest risk applies to people who reused their 2017 Zomato password on email, social media, shopping or another food service. \u003Cstrong>Salted MD5 password hashes\u003C\u002Fstrong> provide more protection than plaintext, while individual salts prevent identical passwords from producing the same stored value. However, MD5 is fast and no longer suitable for password storage. Short, common or previously breached passwords may be recovered through offline guessing. Zomato's incident-time reset prevented old hashes from supporting direct access to Zomato, but account-takeover risk remained wherever the same password survived. Users who signed in through Google or Facebook and had no Zomato password were not affected by the password-hash component; their email and username could still support phishing or account correlation. Presence in the record does not prove that a password was recovered, payment data was exposed or an order was placed through the account.\u003C\u002Fp>\u003Ch2>Immediate Steps to Take\u003C\u002Fh2>\u003Cp>If your 2017-era Zomato password still exists on another service, replace every copy with a long, unique credential. \u003Cstrong>Permanently retire the old Zomato password and its minor variations\u003C\u002Fstrong>; adding a digit or symbol does not create sufficient separation. Prioritize your primary mailbox, social networks, financial services and shopping or food accounts that retain payment methods. Review unfamiliar email sessions, forwarding rules, recovery addresses and connected devices, then enable multi-factor authentication. Do not follow links in messages about refunds, coupons, order problems, payment verification or account security; open the application or official domain independently. Although payment data was not stolen in this incident, attackers may still use fraudulent payment pages to collect new information.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Use a password manager to generate a random, unique credential for every service so recovery of an old hash cannot spread to other accounts. Keep multi-factor authentication enabled on email and critical services, favoring phishing-resistant security keys or device-based methods when available. If you use social sign-in, regularly review sessions, connected applications and recovery options on the Google or Facebook account. Periodically inspect saved payment methods, addresses and active sessions in services such as Zomato. Even when payment data was outside an incident, an email and username can give targeted fraud useful context. Minimize public profile information when old usernames can be correlated across platforms. Do not trust a sender merely because they know a real email address or historical order context. Follow security notices through the official domain.\u003C\u002Fp>\u003Ch2>Check Your Data\u003C\u002Fh2>\u003Cp>Use the secure search field on this page to check every current and historical email address you may have used with Zomato. A match means the address appears among the 16,472,873 unique emails in the verified corpus; it does not prove that a password hash existed on that row, the password was recovered or payment information leaked. If you receive a result, identify other accounts that used the 2017-era password, remove every surviving reuse and review mailbox security history. If you used social sign-in, inspect connected applications and unfamiliar sessions as well. No result is an absolute guarantee because an address may have been written differently, a record may fall outside this dataset or another incident may apply. Enter only the supported identifier in the search field; never submit a password, one-time code, payment card or order information to a breach checker. For suspicious alerts, avoid the embedded link and open the Zomato application or official site directly.\u003C\u002Fp>","","Zomato Data Breach (16.5 Million Reported Records)","Zomato Data Breach. 16.5 Million reported records were reported. Reported data: Email addresses, Passwords, Usernames. Review the scope, risks, and protective…","\u002Fuploads\u002Flogo\u002Fzomato_com.webp",false,{"name":34,"sector":35,"country":36,"website":9,"websiteArchiveUrl":28,"websiteStatus":28,"websiteCheckedAt":20},"Zomato","Food delivery and restaurant discovery","India"]