Menu
Browse

Cyber Incident Victim: FreshMenu

Date:

Jul 2016

Location:

India

Summary

An Indian online food platform experienced a data breach compromising over 110,000 customer accounts, exposing personal details including usernames, email addresses, contact numbers, and order histories, though the company disputed the inclusion of physical addresses and order data. The organization acknowledged awareness of the incident but deliberately withheld disclosure for approximately two years, citing a belief that the limited breach warranted prioritizing vulnerability remediation over customer notification; subsequent investigations confirmed no passwords or financial data were accessed, and the company later issued a public apology while engaging external security experts to audit systems.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On July 1, 2016, Indian online food delivery platform FreshMenu suffered a data breach compromising 110,355 customer accounts. The incident exposed personally identifiable information including usernames, email addresses, contact numbers, device information, and food order histories. While third-party breach index HaveIBeenPwned.com reported physical addresses and detailed order histories were also compromised, FreshMenu later disputed these specific claims. The company became aware of the breach shortly after it occurred but made a deliberate decision not to notify affected customers. This non-disclosure persisted for over two years until September 10, 2018, when HaveIBeenPwned.com publicly revealed the incident through social media, criticizing FreshMenu's failure to warn users. The breach notification service stated FreshMenu had acknowledged prior awareness of the compromise when contacted but maintained its position against customer notification, citing the perceived limited scope of the incident as justification for withholding information.

Cyber Incident Image

Following public exposure of the breach, FreshMenu issued a formal apology on its website in September 2018, acknowledging the two-year delay in disclosure. Company leadership apologized for breaching customer trust and explained their initial response focused exclusively on vulnerability remediation rather than transparency. FreshMenu confirmed immediate corrective actions taken in 2016 to patch the exploited security flaw and prevent recurrence, while emphasizing no financial data or account passwords were compromised. The organization engaged an unnamed white-hat security specialist to conduct post-breach system audits and reiterated commitments to strengthen data protection measures. Despite these assurances, the delayed notification deprived customers of timely opportunity to monitor potential misuse of their exposed personal information over the two-year concealment period.

Sources
Sources available to members
1 source