Grubhub·Retail / hospitality·
Data was downloaded from Grubhub systems.
Grubhub acknowledged unauthorized downloading of data from internal systems, with reporting linking access to Zendesk and older Salesforce data. The exact technical root cause is not established in the attached record.
Report freshness and timeline
- Incident occurred
- First disclosed
- Latest attached source
- Radar data checked
Coverage window — Dataset generated Aug 30, 2026, 12:03 UTC
Executive incident brief
- Incident confirmation
- Organization confirmed
- Mechanism
- Entry path: Stolen Credentials
- Consequence
- Reported: Data was downloaded from Grubhub systems.
- Scope
- The complete extent is not established by this record.
1)Incident fact sheet
- Organization
- Grubhub
- Industry
- Retail / hospitality
- Disclosed
- Event date
- Entry path
- Stolen Credentials
- Third party
- Salesloft
- Affected asset
- certain Grubhub systems
- Product / vendor
- Zendesk
- Country
- US
- Reported impact
- Data exposure · Extortion demand
- Attached evidence
- 9 independent domains · 9 sources
2)Evidence-backed incident path
- 01
Entry path
Initial access involved stolen credentials.
ConfidenceSecondaryExact excerpt
E1“believed to have occurred through credentials stolen during recent Salesloft Drift data theft attacks”
scworld.com · Jan 16 - 02
Third party
Salesloft
ConfidenceSecondaryExact excerpt
E2“credentials stolen during recent Salesloft Drift data theft attacks”
scworld.com · Jan 16 - 03
Affected product
Zendesk
ConfidenceSecondaryExact excerpt
E3“Grubhub uses Zendesk for its customer support chat system”
scworld.com · Jan 16 - 04
Reached
certain Grubhub systems
ConfidenceSecondaryExact excerpt
E4“downloaded data from certain Grubhub systems”
bleepingcomputer.com · Jan 15 - 05
Observed
Data was downloaded from Grubhub systems.
ConfidenceProbableExact excerpt
E5“downloaded data from certain Grubhub systems”
bleepingcomputer.com · Jan 15
3)Impact and scope ledger
Established
Supported at the stated evidence level.
Reported
Present in public reporting; not independently established by Radar.
Not publicly established
No qualifying public evidence in the attached record.
- The exact technical root cause
- Whether any payment was made
- That a Defence review would have prevented this incident
4)Relevance to your product
One durable credential can carry yesterday's access into today's product.
This pattern applies when…
- Products that use OAuth tokens to access SaaS customer-data systems.
- Teams that test token lifetime, scope, revocation, and third-party identity paths.
Diagnostic questions
- Can a credential retain access beyond its intended lifetime or role?
- Are sessions isolated across users, tenants and recovery paths?
- Can tokens be rotated or revoked without leaving a parallel route open?
This incident does not establish your product's risk.
5)Sector context — Retail / hospitality
- 1 incident threads
- 1 incident threads
- 2 incident threads
- 1 incident threads
- 6 incident threads
- 8 incident threads
- 6 incident threads
- 8 incident threads
- 5 incident threads
- 4 incident threads
- 9 incident threads
- 6 incident threads
- Same incident family
- 7 Credential / identity compromise
- Confirmed share
- 32% 18 confirmed · 39 reported
- Display family
- Credentials Used for Radar's public chart taxonomy
Publicly disclosed incidents and reports from to . Historical discovery is partial and does not measure breach probability.
Explore Retail / hospitality in Radar →6)Defence control mapping
What Defence can test
Identity and session testing
- Can a credential retain access beyond its intended lifetime or role?
- Are sessions isolated across users, tenants and recovery paths?
- Can tokens be rotated or revoked without leaving a parallel route open?
Also relevant: API security testing
What cannot be concluded
- This incident does not predict an individual product's risk.
- A mapped control does not establish that a Defence review would have prevented the event.
7)Public evidence ledger
9 attached sources across 9 independent domains. No attached source is marked as an organization or regulator primary source.
- E4, E5bleepingcomputer.comGrubhub confirms hackers stole data in recent security breachSpecialist reporting · Jan 15 · CitedSpecialist reportingCited
Exact excerpt
“downloaded data from certain Grubhub systems”
- E1, E2, E3scworld.comGrubhub confirms data breach, faces extortion demandsSpecialist reporting · Jan 16 · CitedSpecialist reportingCited
Exact excerpt
“the company is now facing extortion demands”
Show all 9 sourcesShow the first six sources
Does this access boundary exist in your product?
A bounded review can test the authorized web/API path without assuming this incident predicts your risk.