Ask Runable forDesign-Driven General AI AgentTry Runable For Free
Runable
Back to Blog
Technology6 min read

Millions of Russian fast food fans hit in Burger King Russia hack | TechRadar

Data stolen years ago finally surfaced on the web Discover insights about millions of russian fast food fans hit in burger king russia hack | techradar.

TechnologyInnovationBest PracticesGuideTutorial
Millions of Russian fast food fans hit in Burger King Russia hack | TechRadar
Listen to Article
0:00
0:00
0:00

Millions of Russian fast food fans hit in Burger King Russia hack | Tech Radar

Overview

News, deals, reviews, guides and more on the newest computing gadgets

Start exploring exclusive deals, expert advice and more

Details

Unlock and manage exclusive Techradar member rewards.

Unlock instant access to exclusive member features.

Get full access to premium articles, exclusive features and a growing list of member rewards.

Millions of Russian fast food fans hit in Burger King Russia hack

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.

Burger King Russia’s 2024 breach via Mindbox exposed 3.2 million customer records, now leaked online

Data includes emails, names, genders, birth dates, phone numbers, and geolocations (2018–2024)

Payment details weren’t compromised; users warned of phishing and identity theft risks

Back in 2024, the Russian arm of Burger King suffered a data breach at the hands of unknown threat actors - now, that data has finally been leaked online.

In October 2024, Burger King told TASS, Russia’s national news agency, that unidentified hackers attacked Mindbox, a domestic marketing automation platform the company had been using.

Through Mindbox, the crooks managed to obtain sensitive company data, including information belonging to the customers.

As a customer data and marketing automation platform, Mindbox helps businesses gather and use customer information for personalized, omnichannel marketing campaigns. Its tools cover email and SMS campaigns, push notifications, loyalty programs, chatbots, and more. According to the company, more than 1,100 businesses use its platform, including L’Oréal, Panasonic, KFC, JBL and United Colors of Benetton.

At the time, there was no word on the nature of the information that was taken, apart from the fact that payment information was not compromised.

Millions of stolen records allegedly dumped online by mystery "Hatman" hacker — Mc Donalds, Vodafone and more see Microsoft Azure records stolen

Lidl customers across Europe hit in suspected data breach - here's what we know

Chick-fil-A reveals data breach — customers warned hackers may have accessed their account info

"Among the victims of the attack may also be the data of customers of the Burger King restaurant chain," the company said at the time.

“Burger King confirms that among the personal data, the accuracy of which is being clarified, there is no information about payment details: open information about transactions is not transmitted or stored by third parties.”

In its 2024 results announcement, Mindbox said the attack was its “first serious information security incident”, which was quickly detected and contained “thanks to threat detection tools.”

In the aftermath of the breach, Mindbox said it “found and eliminated points where employees without access rights to sensitive data could indirectly obtain them,” hinting that the attack was, in fact, an identity-based attack rather than a zero-day exploit.

Massive data breach sees 220 million traveler records exposed — nine years of airline info leaked including passenger and passport details

Carhartt data breach exposed information from 12.9 million user accounts

US healthcare software giant Unlimited Technology Systems admits hackers may have stolen sensitive data of 3.8 million people

The company also “changed development processes to find such points before they get into the product,” and reformed Mindbox's internal role system to make permissions stricter and more granular. It also limited project access scenarios, introduced a mechanism for confirming access by another employee, and introduced mandatory two-factor authentication, among other things.

Today, more details were released on Have I Been Pwned?, a website that aggregates information stolen in various hacks and helps people learn if their email addresses and other information had been compromised in the past. According to the newest entry, more than three million people have had their data exposed in this incident:

“The breach exposed 3.2M unique email addresses along with names, genders, dates of birth, phone numbers and approximate geolocations, with the data spanning 2018 to August 2024,” Have I Been Pwned? writes. “Burger King Russia acknowledged the incident and advised it did not include payment or passport details.”

The latest findings seem to be somewhat in line with what the media reported at the time. According to The Register, initial reports claimed around 5.6 million lines of data as exposed, which included information about a customer’s favorite dish and previous order dates. While this information was not mentioned in the newest report, if every data line includes one email, one name, or one phone number, it could amount to around 5.6 million.

While the information might be a few years old, things like names and birth dates, and genders rarely change, but are vital in identity theft, social engineering, and similar attacks. Burger King users, especially those in Russia, should be wary of incoming email messages, particularly those claiming to come from the fast food chain.

➡️ Read our full guide to the best antivirus

  1. Best overall: Bitdefender Total Security
  2. Best for families: Norton 360 with Life Lock
  3. Best for mobile: Mc Afee Mobile Security

Follow Tech Radar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, Io T, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

The Geekom A5 2027 Edition mini PC could replace your bulky desktop — and our exclusive code drops this office-friendly machine to its lowest price

Hearing odd sounds on PC, but can't trace their source? Epic Games Launcher could be the culprit — and Epic won't let you turn them off, for now

Aftershock's gaming PC contains a cherry blossom tree that blooms as the case heats up and it's one of the most striking things I've ever seen — but so is the price

Meta Muse read a writer’s private messages without permission — and it’s exactly why I’m not ready to hand my life over to AI agents

Chat GPT got GPT-6, but you can't use it in Chat — confused? It's time we talked about the difference between Chat and Work

Tech Radar is part of Future US Inc, an international media group and leading digital publisher. Visit our corporate site.

© Future US, Inc. Full 7th Floor, 130 West 42nd Street, New York, NY 10036.

Key Takeaways

  • News, deals, reviews, guides and more on the newest computing gadgets
  • Start exploring exclusive deals, expert advice and more
  • Unlock and manage exclusive Techradar member rewards
  • Unlock instant access to exclusive member features
  • Get full access to premium articles, exclusive features and a growing list of member rewards

Cut Costs with Runable

Cost savings are based on average monthly price per user for each app.

Which apps do you use?

Apps to replace

ChatGPTChatGPT
$20 / month
LovableLovable
$25 / month
Gamma AIGamma AI
$25 / month
HiggsFieldHiggsField
$49 / month
Leonardo AILeonardo AI
$12 / month
TOTAL$131 / month

Runable price = $9 / month

Saves $122 / month

Runable can save upto $1464 per year compared to the non-enterprise price of your apps.