In a recent incident, Grubhub disclosed that personal data of both its customers and drivers has been exposed due to unauthorized access linked to a third-party contractor. While the exact extent of the breach remains undisclosed, the compromised information includes names, email addresses, phone numbers, and partial credit card details. The company claims that only a limited number of users were affected and has taken immediate measures to secure their systems by terminating the involved account's access and removing the contractor from their network.
This security breach stems from an incident involving one of Grubhub's support team contractors whose account was accessed without authorization. This intrusion allowed unauthorized individuals to gain access to contact information for campus diners, as well as other users, merchants, and drivers who interacted with Grubhub's customer care services. In addition, hashed versions of passwords for some internal systems were also obtained by the contractor.
In response to this breach, Grubhub has implemented several measures to enhance their cybersecurity protocols. They have partnered with a leading cybersecurity firm to conduct a thorough investigation into the incident. Furthermore, they have rotated all relevant passwords to fortify credential security and prevent any potential future breaches. Enhanced monitoring systems have also been deployed across their internal services to detect anomalies more effectively.
Despite these actions, Grubhub has not provided identity theft protection services to those affected by the breach. This incident comes at a critical time as Grubhub is currently in the process of being sold by its parent company, Just Eat, for $650 million. As investigations continue, the company emphasizes its commitment to safeguarding user data and ensuring robust security measures are in place moving forward.
Grubhub's proactive steps following the breach indicate a serious commitment to enhancing their security infrastructure. By engaging forensic experts, strengthening password protocols, and implementing advanced monitoring systems, they aim to restore trust among their users. Although no direct compensation or identity theft protection has been offered yet, the company continues to assure its stakeholders of ongoing efforts to mitigate risks and protect sensitive information.