
HIBP confirms 3.2M Burger King Russia customer records exposed in 2024 breach
Have I Been Pwned has added the data of 3.2 million Burger King Russia customers to its database, confirming the scale of an August 2024 attack on Mindbox, the chain's marketing platform.
Have I Been Pwned (HIBP), the breach-notification service run by security researcher Troy Hunt, has added the data of 3.2 million Burger King Russia customers to its database, confirming the scale of an attack that first came to light in 2024.
The records come from a breach of Mindbox, the marketing platform used by the Russian Burger King chain. The intrusion took place in August 2024 and was publicly acknowledged by the restaurant operator two months later.
What the leaked records contain
According to HIBP, the exposed data includes customer names, dates of birth, email addresses and phone numbers, along with gender and approximate geographic location. The information spans more than six years, reaching back to May 2018, meaning it also covers accounts created long before the attack itself.
Media reports published in 2024 put the leak at more than 5.6 million lines of data and said it also contained details such as a customer's favourite dish and previous order dates. HIBP does not list those fields.
The company's response
When the incident became public in October 2024, Burger King told Russian news agency TASS that customers' data "may also be among those affected by the attack", while stressing that no payment or passport information was involved.
"The Mindbox platform and other third parties do not have access to the personal passport or payment information of Burger King customers," the company said.
Links to other break-ins
Russian cybersecurity outlet Xakep, citing its sources, tied the Mindbox breach to several other intrusions and attributed them to a single intruder. Among the allegedly affected companies was Detsky Mir, the country's largest retailer of children's goods, where more than one million records were reported to be involved.
The two-year gap between the attack and confirmation of its scale points to a familiar problem: personal data collected by marketing and loyalty platforms often goes unnoticed for years, and by the time victims learn about it, the information has long been in circulation. Names, birth dates and phone numbers are enough to build convincing phishing messages or to test stolen credentials against other services, even without payment details.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.