GrubHub hack

9 April 2025 2 minutes Author: Newsman

Cybercriminals claim to have gained access to more than 70 million records from delivery service GrubHub, including 17 million hashed passwords, email addresses, and phone numbers. The breach, believed to have occurred in February 2025, was the result of an intervention by a third-party contractor.

A GrubHub leak has been listed for sale on a hacker forum. The attackers claim to have obtained more than 1 gigabyte of data, including:

– usernames
– email addresses
– passwords hashed with the SHA1 algorithm — an outdated algorithm that is vulnerable to collision attacks
– phone numbers

Analysts have confirmed the authenticity of the sample records. This data can be used for phishing campaigns, identity theft and credential stuffing attacks – attempts to gain access to other accounts using the same logins and passwords.

GrubHub is one of the largest food delivery platforms in the US, serving more than 4,000 cities, cooperating with 375,000 partner restaurants and having an annual turnover of almost $2 billion. The hack was another case where service providers become a vulnerable link in the cybersecurity chain. SHA1, used for hashing passwords, has been deprecated for several years due to its low resistance to hacking.

If the hackers’ information is confirmed, this will be one of the largest data leaks in the online delivery sector. GrubHub risks losing the trust of millions of customers and millions of users – being subjected to phishing attacks. The incident highlights the vulnerability of large technology companies due to unreliable external links. Users are advised to change their passwords immediately and enable two-factor authentication.

Other related articles
News
Read more
Head of hosting firm Aeza arrested in Russia
The CEO of Aeza Group, a company linked to the pro-Kremlin Doppelgänger campaign and hosting malware, was detained in Russia. The defendants are also suspected of supporting a darknet drug store. This confirms the interconnection of Russian information operations with the criminal world.
155
News
Read more
Ukraine has developed an interceptor drone to combat the Shahed
A new drone-interceptor has been created in Ukraine to destroy the "Shahed", which has already neutralized more than 20 targets. The UAV can reach speeds of up to 200 km/h and climb to a height of up to 5 km, and can work against reconnaissance drones. The drone was demonstrated to Belgian Prime Minister Bart de Wever, as part of Ukraine's cooperation with Thales Belgium. This development will replace expensive missiles when intercepting drones and increase the effectiveness of Ukrainian air defense.
136
News
Read more
Cyberattack disrupts death row inmate’s trial
A cyberattack on the Arizona public defender’s office has disrupted the hearing in the case of death row inmate Ralph Menzies. Legal documents have been lost, and the hearing has been postponed until May. The case is complicated by the defendant’s alleged mental disorder. The death penalty in the United States is retained in 24 states, including Utah, which even provides for the possibility of execution. The incident proved that cyberattacks can have a real impact on justice.
134
Found an error?
If you find an error, take a screenshot and send it to the bot.