Jollibee investigated a data breach affecting 11 million customers
- Organization
- Jollibee Foods Corporation
- Exploit
- Hacking
- Industry
- Food Service
Jollibee Foods Corporation, the Philippine operator of Jollibee, Chowking, Greenwich, Red Ribbon and Mang Inasal as well as local franchises of Burger King, Yoshinoya and Panda Express, confirmed on June 22, 2024 that it was investigating unauthorised access involving customer data from its delivery service.
The disclosure followed a June 20 post on a cybercrime forum by a seller using the alias Sp1d3r, who advertised records said to cover 32 million Jollibee customers along with roughly 600 million rows of delivery, sales order and transaction data. The Cyber Express reported that the advertised fields included names, addresses, telephone numbers, email addresses and hashed passwords. The company did not confirm the seller's figures.
Jollibee said its e-commerce platforms were unaffected and remained operational, and that it had deployed enhanced security measures and was working with authorities and outside experts. Chief financial officer Richard Shin said the group was addressing the incident.
The National Privacy Commission said Jollibee notified it on the morning of June 22 and that roughly 11 million data subjects, mostly customers, were affected, with the exposed information including dates of birth and senior citizen identification numbers. The regulator said all eight brands in the group were involved. Jollibee asked for 20 additional days to complete its internal investigation.