SevenRooms Data Breach (2022): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
The SevenRooms Data Breach (2022) (reported December 11, 2022) exposed Email addresses, Names and Purchases belonging to roughly 1.2M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
In December 2022, more than a million people connected to restaurants that use SevenRooms learned that their personal details had been swept into a large data exposure. Over 400GB of material tied to the restaurant customer-management platform was offered for sale on a popular hacking forum, and the haul was reported to include 1.2 million unique email addresses along with names and purchase records. For diners, loyalty members and anyone who has booked or paid through a venue that relies on the service, the practical question is straightforward: what of theirs is now in circulation, and what should they do about it.
Public reporting dated 11 December 2022 attributes the incident to unauthorised access of a file-transfer interface belonging to a third-party vendor. Exact technical timelines and the full list of affected venues remain limited in the open record, yet the scale and the data types already named make the episode consequential for ordinary customers.
Inside the incident
According to contemporaneous accounts, in December 2022 a trove exceeding 400GB of data belonging to SevenRooms was posted for sale on a well-known hacking forum. The material was described as containing 1.2 million unique email addresses together with names and purchase information. SevenRooms stated that the breach resulted from unauthorised access to “a file transfer interface of a third-party vendor.”
No further public detail has been supplied on the precise date the access occurred, the duration of the intrusion, or the identity of any threat actor. The figure of 1.2 million people affected and the named data categories—email addresses, names and purchases—are the concrete elements confirmed in the reporting. Whether additional fields were present inside the 400GB archive has not been independently itemised in the available summary.
How a breach like this happens
Incidents that begin with a third-party file-transfer interface typically follow a familiar pattern. Organisations often rely on external vendors to move large batches of customer or operational data. Those transfer systems—whether managed file-transfer appliances, SFTP gateways or cloud-based exchange portals—are attractive targets because they are designed to handle bulk information and may sit outside the organisation’s primary security perimeter.
Attackers commonly obtain credentials through phishing, credential-stuffing, or exploitation of unpatched software on the vendor side. Once inside, they can enumerate directories, compress archives and exfiltrate them. Because the vendor serves multiple clients, a single compromised interface can expose data belonging to many downstream customers. In the absence of strong multi-factor authentication, network segmentation or continuous monitoring of transfer logs, such access can persist long enough for large volumes to be copied. The subsequent appearance of the data on a criminal forum is the point at which the theft becomes visible to the wider public; the underlying intrusion may have occurred weeks or months earlier.
None of these general mechanics identifies a specific group in the SevenRooms case; they simply describe how unauthorised access to a third-party transfer channel frequently unfolds across the industry.
SevenRooms and its sector
SevenRooms is a restaurant customer-management platform used by hospitality businesses to handle reservations, guest profiles, marketing lists and purchase histories. Platforms of this type sit at the intersection of front-of-house operations and back-office analytics: they store contact details so venues can confirm bookings, personalise service and run loyalty or promotional campaigns, and they record what guests ordered or spent so restaurants can understand demand.
Because the same system may serve hundreds or thousands of individual restaurants and hotel groups, a single upstream breach can touch diners across many brands and cities. The sector as a whole holds precisely the kinds of information—names, emails and transaction records—that are useful both for legitimate marketing and for fraud or phishing once they leave authorised control. That concentration of guest data is why an incident at a platform provider carries wider consequences than a breach confined to one independent restaurant.
What was likely exposed
The facts name three categories that were included in the material offered for sale: email addresses, names and purchases. The archive was reported to contain 1.2 million unique email addresses. Beyond those explicit items, the precise contents of the full 400GB set have not been itemised in the public summary, so any additional fields remain unconfirmed.
Organisations that operate restaurant guest-management systems commonly hold reservation histories, phone numbers, loyalty identifiers, marketing preferences and sometimes partial payment references. It is not established that every one of those elements was present in this particular exposure; readers should treat only the named types—emails, names and purchases—as confirmed by the reporting.
Why it matters
For affected individuals the immediate risks are practical rather than abstract. Email addresses paired with names enable targeted phishing that impersonates a familiar restaurant or booking service. Purchase records can reveal dining habits, price points and frequency of visits, information that can be used to craft more convincing social-engineering messages or to attempt account takeovers on related loyalty programmes. Even without payment-card numbers, the combination of identity and transaction context lowers the barrier for fraudsters.
For SevenRooms and the restaurants that rely on it, the episode raises operational and trust questions: how guest data is shared with vendors, how transfer channels are monitored, and how quickly customers are notified. Reputational damage and the cost of remediation are real, yet they remain secondary to the concrete exposure faced by the 1.2 million people whose details appeared in the forum listing.
If your data was in this breach
If you have booked or dined at a venue that uses SevenRooms, treat the possibility of exposure as real and take a few measured steps:
- Change passwords on any accounts that share the same email address, and enable multi-factor authentication where it is offered.
- Watch for phishing messages that reference recent restaurant visits, reservations or loyalty points; verify directly with the venue rather than clicking links.
- Review bank and card statements for unfamiliar charges, even though payment-card data was not named among the confirmed exposed fields.
- Consider placing a fraud alert with credit-reporting services if you later notice suspicious activity tied to your identity.
- Run a free exposure scan of your email address to check whether it has appeared in this or other known breach datasets.
Public detail on the full scope remains limited, so continued vigilance is the most reliable response available to individuals.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
RailYatri Data Breach (2022)Gemini Data Breach (2022)Activision Data Breach (2022)CoinTracker Data Breach (2022)Latest breaches
Read GalaxyWarden’s full analysis of the SevenRooms Data Breach (2022) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.