Russian Burger King patrons have been left with a bad taste after cyber crooks flame-broiled 3.2 million customers in a whopper of a breach, serving up their personal data for anyone hungry enough to consume it. Troy Hunt’s Have I Been Pwned (HIBP) slurped up all the data leaked after the August 2024 attack on Mindbox, Burger King Russia’s marketing platform, concluding that miscreants had grilled the platform and extracted tasty morsels of customers’ basic personal information. The attackers flipped names, dates of birth, email addresses, and phone numbers, with a side order of genders and approximate geographic locations. Burger King acknowledged the situation in October 2024, confirming no financial or passport data was affected. “The data of Burger King restaurant chain customers may also be among those affected by the attack,” the company told Russian news service TASS. “Burger King confirms that the personal data being verified does not include payment details: public transaction information is not transmitted or stored by third parties. “The Mindbox platform and other third parties do not have access to the personal passport or payment information of Burger King customers.” The information stolen in the breach was well-seasoned: it spanned more than six years, dating back to May 2018. News reports at the time suggested that the leaks contained more than 5.6 million lines of data, and included information about a customer’s favorite dish and previous order dates, although HIBP made no mention of these. Russian cybersecurity news outlet Xakep cited sources tying the breach at Mindbox to other break-ins, and claimed it was the work of a single intruder. Among the other stores allegedly affected was Detsky Mir, Russia’s largest retailer of children’s toys, with more than 1 million reportedly affected. ®