LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › iMenu360 Data Breach (2022)

HIGH severityConfirmedHow we verify

iMenu360 Data Breach (2022): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·August 11, 2022

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

iMenu360 Data Breach (2022)

Reported August 11, 2022. Approximately 3.4M people affected.

HIGH
Severity
3.4M
People affected
5
Data types exposed
August 11, 2022
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The iMenu360 Data Breach (2022) (reported August 11, 2022) exposed Email addresses, Latitude and longitude pairs, Names and Phone numbers belonging to roughly 3.4M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityConfirmed
Contact / identity PII exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the iMenu360 Data Breach (2022) breach?
3.4M accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In late 2022, records tied to roughly 3.4 million customers of iMenu360, a platform used for online restaurant ordering, were reported as exposed. The material included names, email addresses, phone numbers, physical addresses, and latitude-longitude pairs associated with ordering activity. For people who placed orders through restaurants that used the service, that combination of contact and location detail can create lasting practical risk even years after the initial exposure.

Public reporting of the incident is dated August 11, 2022. What is known comes from the appearance of those customer records rather than from a detailed public account by the company. Numerous attempts to reach iMenu360 about the matter between April and August 2023 received no response, leaving affected individuals with limited official confirmation or guidance.

Breaking down the breach

According to the available record, approximately 3.4 million customer records from iMenu360 were exposed in or around late 2022. The data appeared to originate from ordering systems that used the platform. Named data types included email addresses, physical addresses, names, phone numbers, and latitude and longitude pairs.

The public report is dated August 11, 2022. Beyond the scale of the records and the categories of information listed, further operational detail—such as the precise technical method of exposure, the exact window of unauthorized access, or whether the data was later removed from circulation—is not disclosed in the facts available. Contact efforts directed at the organisation between April and August 2023 did not yield a response, so there is no published company statement confirming, correcting, or expanding on those points.

How a breach like this happens

Incidents that expose customer databases from online ordering or similar service platforms typically follow a small number of familiar patterns. Attackers may obtain credentials for an administrative or database interface, exploit an unpatched vulnerability in a web application or API, or find a misconfigured storage location that was left reachable without adequate authentication. In other cases, a compromised third-party integration or a stolen backup can surface the same kind of bulk customer file.

Once a large structured file of customer records is obtained, it is often copied, shared, or listed in places where researchers and criminals alike can encounter it. The presence of consistent fields—names paired with emails, phones, and addresses—makes the material useful for fraud and social engineering regardless of how the initial access occurred. No specific threat group is attributed in the reporting on this incident, and the exact pathway here remains undisclosed.

Who is iMenu360?

iMenu360 has described itself as an online ordering platform used by restaurants and similar food-service businesses. Organisations in this sector typically sit between the customer placing an order and the restaurant fulfilling it. They commonly process or store account and delivery details so that repeat orders, confirmations, and logistics can run smoothly.

Because the platform sits in the middle of everyday ordering, a single exposure can touch customers of many different restaurants rather than only one brand. That concentration of contact and location data is why a breach affecting millions of records on such a service carries consequences beyond any single merchant’s own systems.

What data was at risk

The facts name the following categories as exposed: email addresses, latitude and longitude pairs, names, phone numbers, and physical addresses. These fields were associated with customer records from ordering systems using the platform. No other data types are listed in the available record, and there is no public confirmation of payment-card numbers, passwords, or order histories in this incident.

Exact contents beyond the named fields remain unconfirmed. Organisations that run online ordering commonly hold delivery addresses, phone numbers for order status, and email addresses for receipts; the reported exposure aligns with that pattern, but readers should treat only the listed categories as established for this event.

The real-world impact

For individuals, the combination of name, email, phone, physical address, and geographic coordinates supports several concrete harms. Fraudsters can craft convincing phishing or smishing messages that reference a real restaurant order or a real neighbourhood. Address and coordinate data can aid physical-world targeting or identity-verification abuse. Phone and email pairs are routinely used to reset accounts elsewhere or to seed spam and scam campaigns that persist long after the original leak.

For the organisation and the restaurants that relied on it, an exposure of this scale can erode customer trust, trigger contractual or regulatory scrutiny, and create ongoing support burdens when people seek clarity that has not been publicly supplied. Because outreach between April and August 2023 went unanswered, affected people have had little official channel through which to confirm their status or receive tailored advice.

Were you affected?

If you ordered food through a restaurant that used iMenu360, treat the possibility of exposure seriously even if you have not received a notice. Practical first steps include:

Public detail on this incident remains limited. Monitoring your accounts and treating unsolicited contact with care remain the most reliable steps available while official confirmation stays sparse.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyiMenu360 security record
74/100
DoxxScan™ · Moderate doxx risk
B- 78Above-average record

1 reported incident on record.

See iMenu360’s full breach history →

More recent breaches

RailYatri Data Breach (2022)December 26, 2022Gemini Data Breach (2022)December 13, 2022SevenRooms Data Breach (2022)December 11, 2022Activision Data Breach (2022)December 4, 2022

Latest breaches

Read GalaxyWarden’s full analysis of the iMenu360 Data Breach (2022) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram