Grubhub breach traced to a third-party customer support provider
- Organization
- Grubhub
- Exploit
- Third-Party Data Breach
- Industry
- Online Food Delivery
Grubhub disclosed on February 3, 2025 that attackers had reached customer data through an account belonging to a third-party company that supported its customer care operation. The food delivery firm said it had spotted unusual activity in its environment, launched an investigation, and traced the activity to unauthorized access to that provider's account.
Grubhub revoked the compromised account's access and removed the service provider from its systems entirely. It brought in outside cybersecurity specialists to establish the scope of the intrusion, and later sent individual notification letters setting out what had been accessed in each recipient's case.
The exposure reached diners, merchants and delivery drivers who had contacted customer care, as well as users of the company's campus dining service. For those groups the accessed data included names, email addresses and phone numbers and, for a subset of accounts, partial payment card information limited to the card type and the last four digits. The attackers also reached hashed passwords held in older legacy systems.
Grubhub said full payment card numbers, bank account details and Social Security numbers were not involved. The company did not disclose how many people were affected or when the intrusion began. TechCrunch reported that Grubhub works with more than 375,000 merchants and roughly 200,000 delivery providers across the United States.