logo

Grubhub serves up security incident with a side of needing to change your password

ID: 4b4ed28e-3465-5fdd-8d16-52f05ebdeff9

STIX ID: report--4b4ed28e-3465-5fdd-8d16-52f05ebdeff9

Feed Name: The Register (Security)

Threat Score
60/100

Date Published: 2025-02-04

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Grubhub disclosed a security incident involving a third-party contractor that resulted in unauthorized access to certain user contact information and some semi-sensitive data (e.g., partial card info) for customers, merchants, and drivers; the company says no full credentials or highly sensitive records (SSNs, driver’s licenses, bank account details) were exposed, that it revoked the vendor's access, rotated hashed internal passwords, engaged forensic experts, and deployed stronger credential and anomaly-detection controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.