DEFENCE / RADAR

Public snapshot

Grubhub·Retail / hospitality·

Data was downloaded from Grubhub systems.

Grubhub acknowledged unauthorized downloading of data from internal systems, with reporting linking access to Zendesk and older Salesforce data. The exact technical root cause is not established in the attached record.

Report freshness and timeline

Incident occurred
First disclosed
Latest attached source
Radar data checked

Coverage windowDataset generated Aug 30, 2026, 12:03 UTC

Executive incident brief

Incident confirmation
Organization confirmed
Mechanism
Entry path: Stolen Credentials
Consequence
Reported: Data was downloaded from Grubhub systems.
Scope
The complete extent is not established by this record.

1)Incident fact sheet

Organization
Grubhub
Industry
Retail / hospitality
Disclosed
Event date
Entry path
Stolen Credentials
Third party
Salesloft
Affected asset
certain Grubhub systems
Product / vendor
Zendesk
Country
US
Reported impact
Data exposure · Extortion demand
Attached evidence
9 independent domains · 9 sources

2)Evidence-backed incident path

  1. 01

    Entry path

    Initial access involved stolen credentials.

    ConfidenceSecondary
    Exact excerpt

    believed to have occurred through credentials stolen during recent Salesloft Drift data theft attacks

    scworld.com · Jan 16
    E1
  2. 02

    Third party

    Salesloft

    ConfidenceSecondary
    Exact excerpt

    credentials stolen during recent Salesloft Drift data theft attacks

    scworld.com · Jan 16
    E2
  3. 03

    Affected product

    Zendesk

    ConfidenceSecondary
    Exact excerpt

    Grubhub uses Zendesk for its customer support chat system

    scworld.com · Jan 16
    E3
  4. 04

    Reached

    certain Grubhub systems

    ConfidenceSecondary
    Exact excerpt

    downloaded data from certain Grubhub systems

    bleepingcomputer.com · Jan 15
    E4
  5. 05

    Observed

    Data was downloaded from Grubhub systems.

    ConfidenceProbable
    Exact excerpt

    downloaded data from certain Grubhub systems

    bleepingcomputer.com · Jan 15
    E5

3)Impact and scope ledger

Not publicly established

No qualifying public evidence in the attached record.

  • The exact technical root cause
  • Whether any payment was made
  • That a Defence review would have prevented this incident

4)Relevance to your product

One durable credential can carry yesterday's access into today's product.

This pattern applies when…

  • Products that use OAuth tokens to access SaaS customer-data systems.
  • Teams that test token lifetime, scope, revocation, and third-party identity paths.

Diagnostic questions

  1. Can a credential retain access beyond its intended lifetime or role?
  2. Are sessions isolated across users, tenants and recovery paths?
  3. Can tokens be rotated or revoked without leaving a parallel route open?

This incident does not establish your product's risk.

5)Sector context — Retail / hospitality

57 incident threads in the 365-day public record
  1. 1 incident threads
  2. 1 incident threads
  3. 2 incident threads
  4. 1 incident threads
  5. 6 incident threads
  6. 8 incident threads
  7. 6 incident threads
  8. 8 incident threads
  9. 5 incident threads
  10. 4 incident threads
  11. 9 incident threads
  12. 6 incident threads
Same incident family
7
Credential / identity compromise
Confirmed share
32%
18 confirmed · 39 reported
Display family
Credentials
Used for Radar's public chart taxonomy

Publicly disclosed incidents and reports from to . Historical discovery is partial and does not measure breach probability.

Explore Retail / hospitality in Radar →

6)Defence control mapping

What Defence can test

Identity and session testing

  • Can a credential retain access beyond its intended lifetime or role?
  • Are sessions isolated across users, tenants and recovery paths?
  • Can tokens be rotated or revoked without leaving a parallel route open?

Also relevant: API security testing

What cannot be concluded

  • This incident does not predict an individual product's risk.
  • A mapped control does not establish that a Defence review would have prevented the event.

7)Public evidence ledger

9 attached sources across 9 independent domains. No attached source is marked as an organization or regulator primary source.

  1. E4, E5
    bleepingcomputer.comGrubhub confirms hackers stole data in recent security breachSpecialist reporting · Jan 15 · Cited
    Specialist reportingCited
    Exact excerpt
    downloaded data from certain Grubhub systems
  2. E1, E2, E3
    scworld.comGrubhub confirms data breach, faces extortion demandsSpecialist reporting · Jan 16 · Cited
    Specialist reportingCited
    Exact excerpt
    the company is now facing extortion demands
  3. S3
    news.lavx.huGrubhub Breach Highlights Supply Chain Risk from Salesloft Drift Attacks | LavX NewsOther public report · Jan 15 · Attached
    Other public reportAttached
  4. S4
    beyondmachines.netGrubhub Reports Cyberattack, Possible ExtortionOther public report · Jan 16 · Attached
    Other public reportAttached
  5. S5
    safepasswordgenerator.netGrubHub Data Breach 2026: What Was Stolen & What To Do NowOther public report · Jan 18 · Attached
    Other public reportAttached
  6. S6
    enterprisesecuritytech.comGrubhub Confirms Data Breach as Hackers Demand Extortion Using Stolen SaaS CredentialsOther public report · Jan 20 · Attached
    Other public reportAttached
Show all 9 sourcesShow the first six sources
  1. S7
    foxnews.comGrubhub confirms data breach amid extortion claimsEstablished press · Jan 27 · Attached
    Established pressAttached
    Exact excerpt
    stolen data
  2. S8
    aquiva.comGrubhub Breach: Salesforce OAuth Tokens and Connected App Risk · AquivaOther public report · Jan 29 · Attached
    Other public reportAttached
  3. S9
    ezprotect.ioWhy Stolen OAuth Tokens Are Still Opening Doors to Salesforce Customer Data - EzProtectOther public report · Feb 09 · Attached
    Other public reportAttached

Does this access boundary exist in your product?

A bounded review can test the authorized web/API path without assuming this incident predicts your risk.

Each report separates what public reporting establishes from what remains unknown. It does not turn another company's incident into a prediction of your risk. Dataset coverage: . View methodology →