CSIDB logo
Incident

FreshMenu

Incident posture

Attack window
Jul 2016
Location
India
Status
Historical
CIA posture
Available to members
Updated
2025-12-10 00:00

Linked entities

Victim
FreshMenu
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jul 2016
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

An Indian online food platform experienced a data breach compromising over 110,000 customer accounts, exposing personal details including usernames, email addresses, contact numbers, and order histories, though the company disputed the inclusion of physical addresses and order data. The organization acknowledged awareness of the incident but deliberately withheld disclosure for approximately two years, citing a belief that the limited breach warranted prioritizing vulnerability remediation over customer notification; subsequent investigations confirmed no passwords or financial data were accessed, and the company later issued a public apology while engaging external security experts to audit systems.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On July 1, 2016, Indian online food delivery platform FreshMenu suffered a data breach compromising 110,355 customer accounts. The incident exposed personally identifiable information including usernames, email addresses, contact numbers, device information, and food order histories. While third-party breach index HaveIBeenPwned.com reported physical addresses and detailed order histories were also compromised, FreshMenu later disputed these specific claims. The company became aware of the breach shortly after it occurred but made a deliberate decision not to notify affected customers. This non-disclosure persisted for over two years until September 10, 2018, when HaveIBeenPwned.com publicly revealed the incident through social media, criticizing FreshMenu's failure to warn users. The breach notification service stated FreshMenu had acknowledged prior awareness of the compromise when contacted but maintained its position against customer notification, citing the perceived limited scope of the incident as justification for withholding information.

Following public exposure of the breach, FreshMenu issued a formal apology on its website in September 2018, acknowledging the two-year delay in disclosure. Company leadership apologized for breaching customer trust and explained their initial response focused exclusively on vulnerability remediation rather than transparency. FreshMenu confirmed immediate corrective actions taken in 2016 to patch the exploited security flaw and prevent recurrence, while emphasizing no financial data or account passwords were compromised. The organization engaged an unnamed white-hat security specialist to conduct post-breach system audits and reiterated commitments to strengthen data protection measures. Despite these assurances, the delayed notification deprived customers of timely opportunity to monitor potential misuse of their exposed personal information over the two-year concealment period.

Sources

Sources available to members: 1 source.

CSIDB