Online food ordering and delivery platform GrubHub disclosed a data breach that exposed customer and driver information.
An investigation revealed that attackers compromised an account associated with a third-party support services provider, which was promptly locked out and removed by GrubHub.
Compromised data included names, emails, phone numbers, partial card info, and hashed passwords from legacy systems. Passwords were reset for affected accounts.
No passwords associated with Grubhub Marketplace accounts were accessed, but customers are advised to use unique passwords as a precaution.