Restaurant search and food delivery service Zomato hacked, says 17M email addresses and hashed passwords were stolen
Restaurant search service Zomato is the latest in a long line of companies to be hacked. The company has revealed that millions of its customer accounts were accessed …
Context & Ripple Effects
Zomato's disclosure puts it in a fast-growing club: consumer platforms whose user databases are worth more to attackers than their payment flows. The immediate sequel came within a day, when Zomato agreed to the hacker's demand — launching a bug bounty program in exchange for deletion of the stolen records — an unusually direct negotiation with the attacker.
The pattern did not stop there. Two years later, the hacker Gnosticplayers claimed millions of EatStreet records as part of a haul spanning dozens of companies, and DoorDash separately confirmed its own breach affecting 4.9M customers, workers, and merchants.
First-order effects
- 17 million Zomato account holders face credential-stuffing risk on any service where they reused passwords, even though the passwords were hashed.
- Zomato must respond to an attacker making demands rather than a silent leak, forcing a public decision about whether to negotiate.
Second-order effects
- By meeting the hacker's terms with a bug bounty program, Zomato effectively prices stolen data — setting a precedent other attackers can shop around to rival delivery platforms.
- Competitors in food delivery inherit the same exposure: DoorDash's later breach shows the sector's customer databases remained a standing target regardless of how Zomato resolved this one.
Third-order effects
- If negotiated deletions become a recognized outcome, data extortion shifts from leak-and-flee toward repeatable ransom-by-bug-bounty, pressuring every consumer platform to pre-build response channels for attackers.
- Food delivery apps accumulate identity graphs (emails, phones, addresses) that make them recurring breach targets independent of their payments security, pushing the industry toward treating user databases as liabilities to minimize.
The trend: Consumer platform breaches are evolving from passive leaks into negotiated extortions, with food delivery apps' rich user databases making them a recurring target class.