Menu
Browse

Cyber Incident Victim: SevenRooms

Date

Dec 2022

Location

United States of America

Status

Historical

Timeline
Occurred
Dec 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending
Summary

SevenRooms, a restaurant customer relationship management platform, experienced a data breach stemming from unauthorized access to a third-party vendor's file transfer interface. A threat actor advertised stolen data for sale, including API credentials, promotional codes, payment reports, reservation lists, and guest information such as names, email addresses, and phone numbers. The company confirmed no compromise of its proprietary systems or exposure of highly sensitive data like payment details or Social Security numbers. Access to the affected interface was immediately disabled, an internal investigation initiated with assistance from independent cybersecurity experts, and expired API credentials rendered invalid. Impacted entities likely include the platform's hospitality clients and their customers.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

In December 2022, restaurant customer relationship management platform SevenRooms confirmed a data breach following the appearance of stolen data for sale on the Breached hacking forum. On December 15, a threat actor posted samples of a 427 GB backup database allegedly containing thousands of files related to SevenRooms' clients, which included international restaurant chains and hospitality providers such as MGM Resorts, Bloomin' Brands, Mandarin Oriental, and Wolfgang Puck. The samples featured folders named after specific restaurant chains, API keys, promotional codes, payment reports, and reservation lists. SevenRooms attributed the incident to unauthorized access to a file transfer interface belonging to a third-party vendor, clarifying that its own proprietary systems were not directly breached. The company stated the compromised vendor system contained documents exchanged with SevenRooms, including expired API credentials and guest data such as names, email addresses, and phone numbers. No credit card details, bank account information, Social Security numbers, or similarly sensitive data were stored on the affected servers.

Cyber Incident Image

SevenRooms responded by immediately disabling access to the compromised vendor interface and initiating an internal investigation. The company retained independent cybersecurity experts to assist with the investigation and stated it found no evidence that its core databases were impacted. While the full scope of affected restaurants and customers remained unclear, SevenRooms indicated it would provide updates as the investigation progressed. The breach’s consequences included potential exposure of guest contact information and operational documents like reservation lists, though financial data exposure was explicitly ruled out. The incident highlighted risks associated with third-party vendor systems, as unauthorized access to a single external interface led to the exfiltration of substantial data. SevenRooms emphasized its direct infrastructure remained secure against external compromise throughout the event.

Sources
Sources available to members
1 source