SevenRooms confirms breach after data leak

Share post:

SevenRooms, a restaurant customer relationship management (CRM) platform used by international restaurant chains and hospitality service providers such as MGM Resorts, Bloomin’ Brands, Mandarin Oriental, Wolfgang Puck, and many more, has confirmed a data breach following the sale of stolen data on a hacking forum by a threat actor.

The information was discovered on the hacking forum ‘Breached,’ and the samples include text files containing client data, payment details, reservation information, and more.

According to the seller, there are 86,847 CSV files totaling over 427 GB. The files’ nature suggests that the company may have suffered a database leak as a result of a breach on one of its servers. Its samples include folders named after popular restaurant chains, SevenRooms customers, API keys, promo codes, payment reports, reservation lists, and more.

According to a third-party vendor, SevenRooms confirmed the data breach: “SevenRooms recently learned that a file transfer interface of a third-party vendor was accessed without authorization. This may have affected certain documents transferred to or by SevenRooms, including the exchange of API credentials (now expired), and some guest data, which may include names, email addresses and phone numbers. Our protocol is to not store credit card information in that space. SevenRooms does not collect social security numbers, bank account information, or similarly highly sensitive information from individual guests. We immediately disabled access to the interface, launched an internal investigation, and we currently have no evidence that any of SevenRooms’ proprietary databases were affected. We have retained independent cybersecurity experts to assist with this investigation and will provide additional updates as appropriate.”

The sources for this piece include an article in BleepingComputer.

Featured Tech Jobs

SUBSCRIBE NOW

Related articles

Cyber Security Today, April 24, 2024 – Good news/bad news in Mandiant report, UnitedHealth admits paying a ransomware gang, and more

This episode reports on the danger of using expired open-source packages, a tool used by a Russian hacking group and passw

Google Play introduces new biometric verification with a user warning

Google has recently announced updates to the biometric verification process for Google Play purchases, aiming to bolster security...

Cyber Security Today, Week in Review for week ending Friday April 19, 2024

On this episode Jen Ellis, co-chair of the Ransomware Task Force, talks about ways of fighting one of the biggest cyber threats to IT d

Cyber Security Today, April 19, 2024 – Police bust phishing rental platform, a nine-year old virus found on Ukrainian computers, and more

This episode reports on a threat actor targeting governments in the Middle East with a novel way of hiding malware is going international

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways