CSIDB logo
Incident

Food Dudes Delivery

Incident posture

Attack window
Apr 2021
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-25 00:00

Linked entities

Victim
Food Dudes Delivery
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Apr 2021
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A breach involving multiple online restaurant ordering platforms compromised approximately 343,000 payment cards through Magecart attacks attributed to the "Keeper" hacking group. The incident impacted two types of platforms: three directly provided ordering infrastructure for individual restaurants, exposing transactions from at least 70 establishments, while two others operated as third-party services for hundreds of restaurants, indirectly enabling card data theft. The attack exploited centralized payment systems, highlighting vulnerabilities in card-not-present transactions during increased online food ordering.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In April 2021, Gemini Advisory reported a series of breaches affecting five online food ordering platforms that compromised approximately 343,000 payment cards over the preceding six months. The incidents impacted hundreds of restaurants through two distinct operational models. Three compromised platforms—including Easy Ordering and E-Dining Express—served as direct ordering infrastructure for individual restaurants, integrating with their physical point-of-sale systems. This allowed cybercriminals to steal payment data directly from at least 70 restaurants using these services. Two other platforms—Grabull and an unnamed entity—functioned as third-party aggregators similar to Grubhub or DoorDash, enabling payment card theft across their broader restaurant networks. The attacks were attributed to the "Keeper" hacking group, which deployed Magecart-based skimming techniques to intercept card-not-present transactions.

The breaches exposed vulnerabilities in centralized ordering systems relied upon by restaurants and consumers during increased pandemic-driven online ordering. Gemini Advisory initially named specific platforms in their April 29 report but later edited the post in early May to remove two company names, citing sensitivity and ongoing investigations. DataBreaches.net correspondingly updated its coverage in September 2021 after being contacted by legal representatives of an unnamed affected firm that disputed Gemini's original characterization. Neither Gemini nor DataBreaches.net retracted their core findings regarding the breach scale or methodology. The incidents highlighted risks for restaurants dependent on third-party platforms and consumers whose payment data was exposed through no direct action of their own, with compromised cards appearing for sale in underground markets.

Sources

Sources available to members: 1 source.

CSIDB