Full Breakdown
Grubhub Confirms Data Breach Linked to Salesloft Drift Attacks
1/16/2026, 11:48:23 PM
Overview of the Breach
Grubhub, a prominent food delivery platform, has confirmed a data breach that allowed unauthorized individuals to access and download data from its systems. The breach is reportedly linked to compromised credentials stemming from the Salesloft Drift security incident, which affected multiple organizations since August 2025. The notorious cybercrime group ShinyHunters is believed to be behind the attack and is currently extorting Grubhub, demanding payment in Bitcoin to prevent the release of sensitive data.
Details of the Incident
Grubhub acknowledged that while unauthorized access occurred, sensitive information such as financial data and order histories was not compromised. The company has engaged a third-party cybersecurity firm and notified law enforcement to investigate the breach. The attack is thought to have exploited OAuth tokens stolen during the Salesloft Drift incident, which involved the theft of credentials from various organizations, including Salesforce and Zendesk.
Extortion Demands
ShinyHunters is reportedly demanding a Bitcoin ransom to prevent the public release of data obtained from Grubhub's Zendesk support system and older Salesforce records. This follows a pattern of behavior from ShinyHunters, which has previously extorted other companies, including a recent incident involving Pornhub. The group has claimed responsibility for stealing approximately 1.5 billion data records from Salesforce, affecting numerous organizations.
Implications for Cybersecurity
The breach highlights the ongoing risks associated with third-party integrations and the exploitation of compromised credentials. Organizations are urged to audit their third-party access privileges and rotate any potentially compromised access tokens immediately. Grubhub's situation underscores the need for heightened security measures, particularly in light of the recent wave of cyberattacks targeting customer support platforms and CRM systems.
Official Statements & Responses
Grubhub stated, "We're aware of unauthorized individuals who recently downloaded data from certain Grubhub systems," emphasizing that sensitive customer financial information and order histories were not affected. The company is taking steps to enhance its security posture following the incident.
Criticism & Opposition
Concerns have been raised regarding the lack of transparency from Grubhub about the specific types of data compromised in the breach. Critics argue that without clear communication, users may remain unaware of potential risks associated with their data.
Conflicting Reports & Gaps
While Grubhub has confirmed the breach, the exact scope and timeline of the incident remain unclear. There is also uncertainty regarding the specific data types that were accessed, which has led to speculation about potential downstream attacks.
Verbatim Quotes
- “We're aware of unauthorized individuals who recently downloaded data from certain Grubhub systems,” — Grubhub
- “The breach is believed to have occurred through credentials stolen during recent Salesloft Drift data theft attacks, where compromised OAuth tokens for Salesloft's Salesforce integration were used to harvest credentials and secrets for follow-up attacks on other platforms.” — Bleeping Computer
- “Implications for Enterprise Security Organizations must rigorously audit third-party access privileges and rotate secrets immediately upon suspicion of compromise.” — Cybersecurity Experts
This incident serves as a reminder of the persistent threats posed by cybercriminals and the importance of robust cybersecurity practices in protecting sensitive data.
