- What: iFood confirms data breach affecting 1.2 million users
- Impact: User names, phone numbers, and CPF numbers exposed
Breach iFood confirms data breach affecting 1.2 million users June 4, 2026 Share By SC Staff Adobe Stock As noted by HackRead, Brazilian food delivery app iFood has confirmed a data breach that occurred in December 2025, impacting approximately 1.2 million users, which represents about 2% of its customer base. The company announced on Wednesday, June 3, that the incident involved unauthorized access to sensitive user information. The breach resulted in the exposure of names, phone numbers, addresses, and CPF numbers, which are crucial Brazilian taxpayer identification documents used for various daily transactions. iFood has clarified that passwords, bank details, and credit card information were not compromised. This confirmation follows conflicting reports, including a hacker's claim on BreachForums of stealing around 43.8 million customer records. iFood has strongly refuted these larger numbers, stating no evidence supports such a widespread impact. However, some hackers have suggested the admitted 1.2 million leak is a separate, older incident, and a more recent, larger theft might still be valid. The situation raises concerns under Brazil's data protection law, LGPD. iFood opted not to send formal alerts to affected users, citing ANPD criteria that waive notification if an incident poses no significant risk or harm. Despite this, CPF numbers are valuable for identity fraud, and iFood urges customers to rely solely on official app communications for security. Source: HackRead SC Staff Related Breach DentaQuest data breach exposes sensitive information of 2.6 million accounts SC Staff June 4, 2026 The incident came to light last month when the extortion group ShinyHunters claimed to have stolen over 234 GB of data from the company. Breach World Food Programme reports data breach affecting Palestinian beneficiaries SC Staff June 4, 2026 The World Food Programme confirmed a breach of its self-registration application (SRA) for Palestine, which occurred on May 14. Breach Ultrahuman reports customer wellness data accessed in breach SC Staff June 4, 2026 Ultrahuman confirmed that attackers accessed customer data using credentials stolen from an employee's malware-infected laptop. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Attack Vector You can skip this ad in 5 seconds