iMenu360 Data Breach (2022): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
The iMenu360 Data Breach (2022) (reported August 11, 2022) exposed Email addresses, Latitude and longitude pairs, Names and Phone numbers belonging to roughly 3.4M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
In late 2022, records tied to roughly 3.4 million customers of iMenu360, a platform used for online restaurant ordering, were reported as exposed. The material included names, email addresses, phone numbers, physical addresses, and latitude-longitude pairs associated with ordering activity. For people who placed orders through restaurants that used the service, that combination of contact and location detail can create lasting practical risk even years after the initial exposure.
Public reporting of the incident is dated August 11, 2022. What is known comes from the appearance of those customer records rather than from a detailed public account by the company. Numerous attempts to reach iMenu360 about the matter between April and August 2023 received no response, leaving affected individuals with limited official confirmation or guidance.
Breaking down the breach
According to the available record, approximately 3.4 million customer records from iMenu360 were exposed in or around late 2022. The data appeared to originate from ordering systems that used the platform. Named data types included email addresses, physical addresses, names, phone numbers, and latitude and longitude pairs.
The public report is dated August 11, 2022. Beyond the scale of the records and the categories of information listed, further operational detail—such as the precise technical method of exposure, the exact window of unauthorized access, or whether the data was later removed from circulation—is not disclosed in the facts available. Contact efforts directed at the organisation between April and August 2023 did not yield a response, so there is no published company statement confirming, correcting, or expanding on those points.
How a breach like this happens
Incidents that expose customer databases from online ordering or similar service platforms typically follow a small number of familiar patterns. Attackers may obtain credentials for an administrative or database interface, exploit an unpatched vulnerability in a web application or API, or find a misconfigured storage location that was left reachable without adequate authentication. In other cases, a compromised third-party integration or a stolen backup can surface the same kind of bulk customer file.
Once a large structured file of customer records is obtained, it is often copied, shared, or listed in places where researchers and criminals alike can encounter it. The presence of consistent fields—names paired with emails, phones, and addresses—makes the material useful for fraud and social engineering regardless of how the initial access occurred. No specific threat group is attributed in the reporting on this incident, and the exact pathway here remains undisclosed.
Who is iMenu360?
iMenu360 has described itself as an online ordering platform used by restaurants and similar food-service businesses. Organisations in this sector typically sit between the customer placing an order and the restaurant fulfilling it. They commonly process or store account and delivery details so that repeat orders, confirmations, and logistics can run smoothly.
Because the platform sits in the middle of everyday ordering, a single exposure can touch customers of many different restaurants rather than only one brand. That concentration of contact and location data is why a breach affecting millions of records on such a service carries consequences beyond any single merchant’s own systems.
What data was at risk
The facts name the following categories as exposed: email addresses, latitude and longitude pairs, names, phone numbers, and physical addresses. These fields were associated with customer records from ordering systems using the platform. No other data types are listed in the available record, and there is no public confirmation of payment-card numbers, passwords, or order histories in this incident.
Exact contents beyond the named fields remain unconfirmed. Organisations that run online ordering commonly hold delivery addresses, phone numbers for order status, and email addresses for receipts; the reported exposure aligns with that pattern, but readers should treat only the listed categories as established for this event.
The real-world impact
For individuals, the combination of name, email, phone, physical address, and geographic coordinates supports several concrete harms. Fraudsters can craft convincing phishing or smishing messages that reference a real restaurant order or a real neighbourhood. Address and coordinate data can aid physical-world targeting or identity-verification abuse. Phone and email pairs are routinely used to reset accounts elsewhere or to seed spam and scam campaigns that persist long after the original leak.
For the organisation and the restaurants that relied on it, an exposure of this scale can erode customer trust, trigger contractual or regulatory scrutiny, and create ongoing support burdens when people seek clarity that has not been publicly supplied. Because outreach between April and August 2023 went unanswered, affected people have had little official channel through which to confirm their status or receive tailored advice.
Were you affected?
If you ordered food through a restaurant that used iMenu360, treat the possibility of exposure seriously even if you have not received a notice. Practical first steps include:
- Watch for unexpected messages that reference food orders, deliveries, or account problems; verify directly with the restaurant or platform rather than clicking links in unsolicited email or texts.
- Be cautious with any request for payment, password, or personal confirmation that arrives by phone or email and claims to relate to an old order.
- Consider placing a fraud alert or credit freeze if you see signs of identity misuse, and document any suspicious contact.
- Update passwords on related accounts if you reused credentials, and enable multi-factor authentication where available.
- Run a free exposure scan of your email address to check whether your information has surfaced in known breach data sets.
Public detail on this incident remains limited. Monitoring your accounts and treating unsolicited contact with care remain the most reliable steps available while official confirmation stays sparse.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
RailYatri Data Breach (2022)Gemini Data Breach (2022)SevenRooms Data Breach (2022)Activision Data Breach (2022)Latest breaches
Read GalaxyWarden’s full analysis of the iMenu360 Data Breach (2022) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.