LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › German Doner Kebab Data Breach (2025)

MEDIUM severityConfirmedHow we verify

German Doner Kebab Data Breach (2025): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·March 27, 2025

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

German Doner Kebab Data Breach (2025)

Reported March 27, 2025. Approximately 162K people affected.

MEDIUM
Severity
162K
People affected
4
Data types exposed
March 27, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

German Doner Kebab disclosed a data breach on March 27, 2025, exposing email addresses, names, phone numbers, and physical addresses of 162,000 customers. Individuals should check whether their information was involved and take appropriate protective steps.

Severity & verification
MEDIUM severityConfirmed
Contact / identity PII exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the German Doner Kebab Data Breach (2025) breach?
162K accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In March 2025, records allegedly linked to German Doner Kebab appeared on a popular hacking forum, affecting an estimated 162,000 people. The material reportedly included email addresses, names, phone numbers and physical addresses. For anyone who has ordered from or worked with the chain, the practical question is straightforward: whether personal contact details that can be used for phishing, scams or unwanted contact are now circulating beyond the company’s control.

German Doner Kebab later sent a disclosure notice to people it believed were impacted. Public reporting of the incident is limited to these points; method of intrusion, exact duration of exposure and full technical scope remain undisclosed.

Breaking down the breach

According to the available record, data allegedly sourced from German Doner Kebab was published on a popular hacking forum in March 2025. The published set was described as containing 162,000 unique email addresses together with associated names, phone numbers and physical addresses. The date associated with public reporting of the incident is 27 March 2025.

No further technical details—such as how the data left the organisation, whether systems were encrypted, or whether other file types were involved—have been disclosed in the facts available. The organisation’s subsequent action was to issue a disclosure notice to individuals it identified as affected. Attribution of the forum posting remains a claim based on the material’s presentation; no independent forensic confirmation of origin is stated in the public summary.

How a breach like this happens

Incidents that result in customer or contact databases appearing on forums typically follow a small number of common patterns. Attackers may obtain credentials through phishing or credential-stuffing, exploit unpatched software on internet-facing systems, or abuse misconfigured cloud storage or third-party services that hold customer lists. Once inside, they often export databases or CRM extracts that contain names, emails, phones and addresses because those fields are routinely stored for marketing, delivery and loyalty purposes.

The data is then packaged and offered or dumped on criminal forums, either for sale or as a free release. In many cases the organisation only learns of the exposure when the material surfaces publicly or when a security researcher or law-enforcement contact provides notice. No specific threat group is named in connection with this incident, and none should be assumed.

German Doner Kebab and its sector

German Doner Kebab is a fast-casual restaurant chain specialising in doner kebab and related dishes, operating outlets in multiple countries. Like other food-service and quick-service restaurant brands, it typically maintains customer contact records for online ordering, delivery, loyalty programmes, marketing communications and franchise or employment administration.

A breach involving such records is consequential because the sector handles high volumes of personal identifiers that are useful for social-engineering attacks. Customers expect their delivery addresses and phone numbers to remain private; when those details leave the organisation’s control, the trust relationship is damaged and the practical risk of fraud or harassment rises for the individuals concerned.

What data was at risk

The facts name the following data types as exposed: email addresses, names, phone numbers and physical addresses. Approximately 162,000 unique email addresses were reported. No other categories—such as payment-card numbers, passwords, dates of birth or order histories—are listed in the available summary.

Organisations of this type commonly hold additional fields (loyalty points, order preferences, IP logs, staff records), but those elements are not confirmed as part of this release. Exact contents beyond the four named categories therefore remain unconfirmed.

What's at stake

For affected individuals the concrete risks are misuse of contact details: targeted phishing emails or SMS messages that appear to come from the brand, attempts to reset accounts on other services that share the same email, or physical-mail and telephone scams that reference a known address or phone number. Identity-related fraud is less immediate when financial or government identifiers are absent, yet the combination of name, address and phone still supports social-engineering attacks.

For the organisation the stakes include regulatory notification duties, potential complaints or claims from customers, reputational damage, and the cost of investigation and remediation. Because the data was published on a forum, copies may continue to circulate even after the original listing is removed.

What to do if you're exposed

If you have received a notice from German Doner Kebab or believe your details may be among the 162,000 records, practical first steps are limited but useful:

Public detail on this particular incident remains limited to the points above. Further technical findings, if any, would need to come from the organisation or competent authorities.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyGerman Doner Kebab security record
74/100
DoxxScan™ · Moderate doxx risk
B 80Good record

1 reported incident on record.

See German Doner Kebab’s full breach history →

More recent breaches

Pass'Sport Data Breach (2025)December 17, 2025APOIA.se Data Breach (2025)December 16, 2025SoundCloud Data Breach (2025)December 15, 2025Under Armour Data Breach (2025)November 17, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the German Doner Kebab Data Breach (2025) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram