SevenRooms confirms breach after data leak

Share post:

SevenRooms, a restaurant customer relationship management (CRM) platform used by international restaurant chains and hospitality service providers such as MGM Resorts, Bloomin’ Brands, Mandarin Oriental, Wolfgang Puck, and many more, has confirmed a data breach following the sale of stolen data on a hacking forum by a threat actor.

The information was discovered on the hacking forum ‘Breached,’ and the samples include text files containing client data, payment details, reservation information, and more.

According to the seller, there are 86,847 CSV files totaling over 427 GB. The files’ nature suggests that the company may have suffered a database leak as a result of a breach on one of its servers. Its samples include folders named after popular restaurant chains, SevenRooms customers, API keys, promo codes, payment reports, reservation lists, and more.

According to a third-party vendor, SevenRooms confirmed the data breach: “SevenRooms recently learned that a file transfer interface of a third-party vendor was accessed without authorization. This may have affected certain documents transferred to or by SevenRooms, including the exchange of API credentials (now expired), and some guest data, which may include names, email addresses and phone numbers. Our protocol is to not store credit card information in that space. SevenRooms does not collect social security numbers, bank account information, or similarly highly sensitive information from individual guests. We immediately disabled access to the interface, launched an internal investigation, and we currently have no evidence that any of SevenRooms’ proprietary databases were affected. We have retained independent cybersecurity experts to assist with this investigation and will provide additional updates as appropriate.”

The sources for this piece include an article in BleepingComputer.

SUBSCRIBE NOW

Related articles

Cyber Security Today, Week in Review for week ending Friday May 17, 2024

Welcome to Cyber Security Today. This is the Week in Review for the week ending Friday, May 17th,...

Cyber Security Today, May 17, 2024 – Malware hiding in Apache Tomcat servers

Malware hiding in Apache Tomcat servers, new backdoors found, and more Welcome to Cyber Security Today. It's Friday, May...

MIT students exploit blockchain vulnerability to steal 25 million dollars

Two MIT students have been implicated in a highly sophisticated cryptocurrency heist, where they reportedly exploited a vulnerability...

Cyber Security Today, May 15, 2024 – Ebury botnet still exploits Linux servers, Microsoft, SAP and Apple issue security updates

The Ebury botnet continues to exploit Linux servers, Microsoft, SAP and Apple issue security updates, and more. Welcome to...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways