logo

Grubhub confirms hackers stole data in recent security breach

ID: 579e924b-3f32-57cd-bf5d-0a23c681d433

STIX ID: report--579e924b-3f32-57cd-bf5d-0a23c681d433

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-01-15

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Grubhub confirmed unauthorized individuals downloaded data from certain systems and sources told BleepingComputer that the ShinyHunters group is extorting the company, demanding Bitcoin to prevent release of older Salesforce records and newer Zendesk data; Grubhub says no financial information or order history were affected, is working with a third-party cybersecurity firm, and has notified law enforcement. The report links the breach to credential/secrets theft tied to the Salesloft/Drift incidents that have been used to harvest access tokens and secrets for follow-on attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.