Grubhub Hack Exposes Campus Diners, Those Who Contacted Customer Service

From PC Mag: If you use Grubhub, some of your data may have been lost to a hacker. On Monday, the food delivery app reported a breach involving user names, email addresses, and phone numbers.

Grubhub didn't say how many customers were affected. But the hacker accessed contact information for "campus diners," a food delivery program exclusively for college students, and “diners, merchants, and drivers who interacted with our customer care service."

The culprit was able to view the last four digits of the payment cards for some campus diners.

No user login data or full payment card information was looted. But the hacker did access passwords for older, internal Grubhub systems, risking a wider breach of the food delivery app’s databases. Fortunately, the culprit was only able to view passwords in a hashed format, which can effectively scramble the login information. In response, Grubhub said it "proactively rotated any passwords that we believed might have been at risk."

View: Full Article