Cyber & AI intelligence
Wasteland.
Briefs indexed2856
Issues29
Published Mondays07:30 CT
▣ Breach BURGER-KING-RUSSIA 2026-09-23

Burger King Russia: Third Party Breach of Mindbox Marketing Platform

"Attackers compromised Mindbox, the marketing automation platform Burger King Russia used to run promotions and loyalty programs, and walked away with personal data on roughly 3.2 million customers stretching back more…"

Attackers compromised Mindbox, the marketing automation platform Burger King Russia used to run promotions and loyalty programs, and walked away with personal data on roughly 3.2 million customers stretching back more than six years. Have I Been Pwned lists the dataset with a precise count of 3,155,792 breached accounts and a breach date of 25 August 2024; the company acknowledged the exposure publicly in October 2024. Burger King Russia told Russian news agency TASS that payment card and passport data sat outside the affected system and were not taken. A caveat on sourcing: every available account of this incident is second-tier reporting or aggregator syndication built on the same Have I Been Pwned listing. No primary victim statement, regulator filing, or CERT advisory is in hand, and the details below should be read with that in mind.

What Happened

The intrusion hit Mindbox, not Burger King Russia's own infrastructure. Mindbox is a marketing automation provider that aggregates and processes customer data on behalf of its clients, which means a single compromise of the vendor exposed records belonging to a brand that never directly controlled the system holding them.

The timeline that the sources agree on runs like this. The attack occurred in August 2024, with HookPhish and the Have I Been Pwned listing both citing 25 August 2024 as the breach date. News of the exposure surfaced publicly in October 2024, roughly two months later, at which point Burger King Russia confirmed that customer data may have been affected. The dataset was subsequently indexed into Have I Been Pwned, which is what drove the September 2026 wave of coverage that all six of these sources belong to.

On the scale of the exposure, the numbers converge but are not identical. HookPhish, Yazoul, and IT Security News all cite 3,155,792 compromised accounts, which is the Have I Been Pwned figure for unique email addresses. LavX and the Chinese-language DBAppSecurity Starmap brief both round to "3.2 million customers." Those are the same number, described differently: unique email addresses are not necessarily unique human beings, and coverage that says "3.2 million users" is inferring one from the other.

The date range of the records is where accounts genuinely diverge. LavX and Starmap state the data reaches back to May 2018 and spans more than six years. HookPhish and IT Security News say simply "2018 to August 2024." Yazoul describes the same window as "nearly six years." Taking May 2018 through August 2024 at face value gives roughly six years and three months, so Yazoul's framing is the outlier and the "more than six years" reading is better supported.

What Was Taken

The field list is consistent across all six sources and matches the Have I Been Pwned record:

Two sources go further. LavX reports that coverage at the time of the original 2024 incident described more than 5.6 million rows of data including customers' favourite dishes and prior order dates, and explicitly notes that the Have I Been Pwned listing does not include those fields. Starmap repeats the 5.6 million row figure and the order-history detail. Treat the row count and the behavioural fields as reported but unconfirmed. The 5.6 million rows and the 3.16 million accounts are not in conflict, since a marketing database routinely holds multiple rows per customer, but no source reconciles them directly.

On what was not taken, the sources are unanimous and traceable to the company itself. Burger King Russia stated the exposed data did not include payment details or passport information, and per LavX added that Mindbox and other third parties never had access to those records in the first place.

That exclusion matters less than it sounds. Name plus date of birth plus phone number plus email is the standard identity-verification quartet still used by banks, telecoms, and government portals for account recovery and knowledge-based authentication. Yazoul makes this point directly: an attacker holding all four can attempt takeovers on unrelated services without ever touching a password. Add approximate location and gender and you have a profile good enough to make a phishing message look like a legitimate restaurant promotion or account notice, and good enough to join this dataset against other breach corpora to enrich identities across sources.

Why It Matters

This is a vendor breach that became a brand breach, and that transfer is the whole story for defenders.

Burger King Russia's own systems, by all available accounts, were not touched. The company nonetheless owns the customer notification, the reputational damage, and whatever regulatory exposure follows, because the data was theirs regardless of whose server it sat on. Cyberindemnity frames the incident squarely as a supply chain problem: when a marketing automation provider aggregates customer records across many clients, a single compromise cascades outward into every one of those client relationships at once.

The six year retention window is the second lesson, and it is self-inflicted. There is no marketing rationale for a promotions platform holding granular per-customer records dating to May 2018. Cyberindemnity notes that a collection window that wide suggests retention policy and vendor data governance drifted out of alignment with basic minimisation principles. Every additional year of retained history is additional blast radius for a breach that has not happened yet.

Third, this appears not to be an isolated hit. Starmap cites Russian security outlet Xakep reporting that the attack may have been carried out by a single intruder and that it is linked to data leaks at several other retailers including Detsky Mir, which reportedly saw more than a million users affected. This is a single-source claim relayed through a second source and should be treated as a lead rather than a finding. If it holds, the relevant threat model is not "Burger King was targeted" but "a marketing and retail data ecosystem was systematically harvested," and other brands sharing that vendor footprint should be checking their own exposure.

The Attack Technique

No source in this set identifies an initial access vector. None names a CVE, a credential compromise, an exposed API, or a misconfiguration. Cyberindemnity discusses plausible failure modes for this class of incident, including inadequate access controls, but presents them as general categories rather than findings about Mindbox specifically. Starmap's phrasing that attackers "exploited a platform vulnerability" is not supported by any technical detail and should be read as generic summary language, not attribution of a specific flaw.

What can be said: the target was a third-party SaaS platform holding aggregated customer data, the access was sufficient to extract a full historical dataset rather than a recent slice, and the intrusion went undetected or at least unreported for roughly two months between the August 2024 breach date and the October 2024 public acknowledgement. Whether anyone other than Burger King Russia's customer base was affected within Mindbox itself is not addressed by any source here. If a technical root cause was ever published, it is not in this reporting.

What Organizations Should Do

  1. Inventory which vendors hold your customer PII, and what fields. The organisations most exposed here are the ones that could not have answered, before October 2024, exactly what Mindbox held. Build the list, keep it current, and tie every entry to a named internal owner.

  2. Enforce retention limits contractually and verify them. A marketing platform does not need six years of per-customer order history and birthdates. Write maximum retention windows into vendor contracts, require deletion attestation, and audit against it rather than trusting the attestation.

  3. Minimise what you send in the first place. Date of birth, gender, and geolocation are frequently pushed to marketing platforms by default because the integration supports the fields, not because any campaign uses them. Strip fields the vendor does not demonstrably need; data never transmitted cannot be leaked.

  4. Require breach notification SLAs from vendors, in writing. Two months elapsed between intrusion and public disclosure here. Contract for notification within 24 to 72 hours of vendor awareness, and define "awareness" so it cannot be gamed.

  5. Pre-build your customer notification and anti-phishing response. Breached customers will be phished using exactly the data that leaked, in messages that look like legitimate brand promotions. Have the notification template, the "we will never ask you for X" messaging, and the abuse-reporting channel ready before you need them.

  6. Treat the leaked field set as an authentication problem, not just a privacy one. If your helpdesk or account-recovery flow verifies identity using name, date of birth, phone number, or email, that flow is now weaker for 3.16 million people. Move to possession-based or out-of-band verification.

  7. Check downstream exposure if you share this vendor footprint. Given the reported link to leaks at other Russian retailers, organisations using the same or comparable marketing platforms in that market should assume adjacency and hunt accordingly rather than waiting for a Have I Been Pwned listing to tell them.

Sources: Well-done hack flames 3.2 million Burger King Russia users LavX News | Critical Alert: Recent Burger King Russia Data Breach | Burger King Russia Breach: 3.2M Emails & Phone Numbers Leaked | Mindbox - Burger King Russia Leak: Restoring Trust and Fixing Third... | Burger King Russia - 3,155,792 breached accounts - IT Security News | 俄罗斯汉堡王320万用户数据遭泄露 - 安全星图平台