Food ordering app EatStreet discloses breach; hacker Gnosticplayers, who has stolen 1B+ user records from 45 companies this year, claims 6M+ were from EatStreet
Context & Ripple Effects
Gnosticplayers is running breach-and-extort at industrial scale: over 1 billion records claimed from 45 companies this year alone, with EatStreet's 6M+ the latest disclosure forced into the open. The playbook has precedent in food delivery — Zomato was hit in 2017 with 17M email addresses exposed, then struck an unusual deal launching a bug bounty program in exchange for the stolen data's deletion after the initial 17M-record Zomato hack.
The difference is scale and disposition: where Zomato's attacker negotiated, Gnosticplayers accumulates across dozens of victims at once, making EatStreet one entry on a ledger rather than a bespoke negotiation. Later coverage shows where unsold loot ends up — dumps of records from Dave, Wattpad and others given away free on forums.
First-order effects
- EatStreet must notify and reset credentials for its user base while disputing or confirming the 6M+ claim, since the disclosure came via the hacker's tally rather than its own detection.
- Every other company in Gnosticplayers' claimed 45-victim list faces the same forced-disclosure clock, with the hacker controlling the timing of each reveal.
Second-order effects
- Food-ordering and consumer-app peers now weigh the Zomato template — trading a bug bounty program for deletion — against paying nothing and betting the data never surfaces, a choice Gnosticplayers' volume makes more urgent.
- Buyers of bulk credential data get a fresh supply of food-delivery accounts with saved addresses and payment context, feeding account-takeover attempts against overlapping users of other apps.
Third-order effects
- If single actors can credibly claim a billion records a year, breach response shifts from per-incident forensics to proving data provenance — which records are real, from whom, and whether 'deletion' promises mean anything.
- Consumer delivery platforms, holding dense profiles of home addresses and ordering habits, become a standing target class alongside social and fintech apps, pushing regulators toward sector-specific scrutiny of what these apps retain.
The trend: Breach-and-extort is consolidating into high-volume operations where hackers amass records across dozens of companies simultaneously, forcing victims to respond to disclosures timed by the attacker.