-
A hacker is offering 90 million customer records allegedly stolen from Just Eat’s database on a cybercriminal forum.
-
The purported database includes email addresses, hashed passwords, full names, account credentials, and country names. But, they only shared a small portion of the data publicly as proof their listing is legit.
-
For now, the sample hasn’t undergone any validation, so its authenticity remains questionable.
A threat actor is reportedly selling a database allegedly containing data of 90 million Just Eat users in a dark web forum. The database supposedly contains users’ names, email IDs, password hashes, and the actual names of users.
Also, the database user country codes, types of accounts they hold, the date they created the accounts, and email verification status. Extra information, like campaign activity, is also mentioned. The seller put up a small sample for people to see, which isn’t solid enough proof to back up their story.
Most of the time, tiny samples do not prove that a full dataset is real or fresh. There’s a need to analyze a large chunk of the data to know for sure.
However, at the moment, there is no publicly available evidence that Just Eat or the parent company, Just Eat Takeaway.com, was involved in the data breach. No government filing or security alert has confirmed the claim either.
Just Eat’s privacy policy says they process customer information to run their services. They also say they use security measures to protect personal data from harm.
Why we should be Careful About this Claim
Big database listings are common on underground markets. Criminals often recycle old breach data because it can still make money. Some sellers mix several old leaks together and call it a new breach. Others make up huge numbers to get buyers interested.
Security experts say we must check these claims ourselves before believing them. The scale of available stolen credentials is staggering—a global breach exposed 149 million passwords, providing criminals with vast resources for credential stuffing attacks.
A recent study of four major cybercrime forums found that free data is actually posted more often than paid data. Forum leaders themselves are sometimes the biggest suppliers.
The police have been taking action against such forums recently. For instance, in March, Dutch police, in cooperation with Europol and the FBI, arrested the administrators of the forum called LeakBase. This was one of the largest cybercrime forums around.
It had 142,000 registered users and ran for years as a place to trade stolen data. But new forums keep popping up quickly. This lets criminals post fake claims with almost no fact-checking.
What the Data Could Do If It Were Real
Even without actual passwords, this type of data can still cause problems. Password hashes are scrambled versions of passwords, not the real thing. Strong scrambling methods make them very hard to break. Weak or recycled passwords can put your account at risk of credential stuffing attacks.
When paid with names and passwords, email addresses can be a lethal weapon for attackers. They use them to carry out highly-targeted phishing attacks. Account types and email verification status help attackers make their fake messages look more real. These little details make phishing emails seem trustworthy.
Even if the passwords stay protected, big collections of customer data are useful for spam. They also help with targeted scams and account takeovers. This hurts most when people use the same password for many different websites.
How to Protect Yourself
Though this data dump remains unverified, it’s still crucial to observe some measures to keep your account safe from fraud. Doing these judiciously will reduce the risk of falling victim to scams if your personal information appears on the dark web.
First, if you’ve been reusing one login on multiple sites, quickly change your passwords. Use something unique for each of your online accounts. Also, turn on multi-factor authentication anywhere applicable; it adds an extra layer of security to your account.
In addition, it is imperative to monitor your accounts. Check for any login attempts that aren’t from you. One more thing, you shouldn’t share any private information with people claiming to be from Just Eat or any reputable brand through emails, messages, or even calls. These are often phishing attempts.
Companies should also watch for credential abuse. They need to look out for unusual login patterns on their systems.
For now, this 90 million-record Just Eat database is still just a claim. No one has proven it came from a new hack of Just Eat or its parent company. Until security researchers, the company, or regulators check the data, we should not jump to conclusions.
As with many big database posts on cybercrime forums, time will tell. The next few days will show if this becomes a confirmed incident. Or it might just join the long list of recycled and unproven dark web listings. Either way, it’s always good to be cautious and protect your accounts with everything you’ve got.