ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Restaurant CRM platform SevenRooms confirms breach after stolen data appear for sale

The restaurant customer relationship management platform SevenRooms, used by international restaurant chains and hospitality service providers, including MGM Resorts, Bloomin’ Brands, Mandarin Oriental, and Wolfgang Puck, confirmed a data breach after a threat actor started selling stolen data on a hacking forum.

 

A threat actor claimed to have stolen a 427 GB backup database containing thousands of customer information files on December 15 and posted data samples on the Breached hacking forum.

 

The seller’s samples include folders with names like popular restaurant chains, SevenRooms customers, API keys, discount codes, payment reports, and reservation lists. SevenRooms acknowledged that unauthorized access to one of its vendors’ systems led to their data loss.

 

SevenRooms learned that a file transfer interface of a third-party vendor was accessed without authorization. The company clarified that guests’ bank account data, credit card information, social security numbers, or other similarly highly sensitive information was not stored on compromised servers, so it was not exposed in the attack.

 

Furthermore, SevenRooms claimed that there had been no direct breach of its systems, which remain secure against unauthorized external access. They immediately disabled access to the interface and launched an internal investigation led by independent cybersecurity experts. It is unclear what restaurants and customers were affected by this breach.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543