German Doner Kebab Data Breach (2025): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
German Doner Kebab disclosed a data breach on March 27, 2025, exposing email addresses, names, phone numbers, and physical addresses of 162,000 customers. Individuals should check whether their information was involved and take appropriate protective steps.
In March 2025, records allegedly linked to German Doner Kebab appeared on a popular hacking forum, affecting an estimated 162,000 people. The material reportedly included email addresses, names, phone numbers and physical addresses. For anyone who has ordered from or worked with the chain, the practical question is straightforward: whether personal contact details that can be used for phishing, scams or unwanted contact are now circulating beyond the company’s control.
German Doner Kebab later sent a disclosure notice to people it believed were impacted. Public reporting of the incident is limited to these points; method of intrusion, exact duration of exposure and full technical scope remain undisclosed.
Breaking down the breach
According to the available record, data allegedly sourced from German Doner Kebab was published on a popular hacking forum in March 2025. The published set was described as containing 162,000 unique email addresses together with associated names, phone numbers and physical addresses. The date associated with public reporting of the incident is 27 March 2025.
No further technical details—such as how the data left the organisation, whether systems were encrypted, or whether other file types were involved—have been disclosed in the facts available. The organisation’s subsequent action was to issue a disclosure notice to individuals it identified as affected. Attribution of the forum posting remains a claim based on the material’s presentation; no independent forensic confirmation of origin is stated in the public summary.
How a breach like this happens
Incidents that result in customer or contact databases appearing on forums typically follow a small number of common patterns. Attackers may obtain credentials through phishing or credential-stuffing, exploit unpatched software on internet-facing systems, or abuse misconfigured cloud storage or third-party services that hold customer lists. Once inside, they often export databases or CRM extracts that contain names, emails, phones and addresses because those fields are routinely stored for marketing, delivery and loyalty purposes.
The data is then packaged and offered or dumped on criminal forums, either for sale or as a free release. In many cases the organisation only learns of the exposure when the material surfaces publicly or when a security researcher or law-enforcement contact provides notice. No specific threat group is named in connection with this incident, and none should be assumed.
German Doner Kebab and its sector
German Doner Kebab is a fast-casual restaurant chain specialising in doner kebab and related dishes, operating outlets in multiple countries. Like other food-service and quick-service restaurant brands, it typically maintains customer contact records for online ordering, delivery, loyalty programmes, marketing communications and franchise or employment administration.
A breach involving such records is consequential because the sector handles high volumes of personal identifiers that are useful for social-engineering attacks. Customers expect their delivery addresses and phone numbers to remain private; when those details leave the organisation’s control, the trust relationship is damaged and the practical risk of fraud or harassment rises for the individuals concerned.
What data was at risk
The facts name the following data types as exposed: email addresses, names, phone numbers and physical addresses. Approximately 162,000 unique email addresses were reported. No other categories—such as payment-card numbers, passwords, dates of birth or order histories—are listed in the available summary.
Organisations of this type commonly hold additional fields (loyalty points, order preferences, IP logs, staff records), but those elements are not confirmed as part of this release. Exact contents beyond the four named categories therefore remain unconfirmed.
What's at stake
For affected individuals the concrete risks are misuse of contact details: targeted phishing emails or SMS messages that appear to come from the brand, attempts to reset accounts on other services that share the same email, or physical-mail and telephone scams that reference a known address or phone number. Identity-related fraud is less immediate when financial or government identifiers are absent, yet the combination of name, address and phone still supports social-engineering attacks.
For the organisation the stakes include regulatory notification duties, potential complaints or claims from customers, reputational damage, and the cost of investigation and remediation. Because the data was published on a forum, copies may continue to circulate even after the original listing is removed.
What to do if you're exposed
If you have received a notice from German Doner Kebab or believe your details may be among the 162,000 records, practical first steps are limited but useful:
- Treat unsolicited emails, texts or calls that reference the brand or your personal details with caution; verify any request through official channels rather than links or numbers supplied in the message.
- Change passwords on any accounts that reuse the same email address, and enable multi-factor authentication where available.
- Monitor bank and card statements for unexpected activity even though payment data is not listed among the exposed fields.
- Consider placing a fraud alert with credit-reference agencies if you live in a jurisdiction that offers that service.
- Run a free exposure scan of your email address against known breach datasets to see whether the same address has appeared in other incidents.
Public detail on this particular incident remains limited to the points above. Further technical findings, if any, would need to come from the organisation or competent authorities.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Pass'Sport Data Breach (2025)APOIA.se Data Breach (2025)SoundCloud Data Breach (2025)Under Armour Data Breach (2025)Latest breaches
Read GalaxyWarden’s full analysis of the German Doner Kebab Data Breach (2025) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.