ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

SevenRooms announces third-party vendor breach, says PII and banking details were not compromised

SevenRooms, a popular customer management platform for hospitality operators, suffered a data breach that involved a hacker accessing a file transfer interface used by a third-party vendor and exfiltrating customers’ details.As a popular restaurant customer relationship management platform, SevenRooms is used by several restaurant chains and hospitality service providers, including Bloomin’ Brands, Oriental, Mandarin, Wolfgang Puck, MGM Resorts, and many others.The company learned about the data breach after a threat actor posted a sample of the stolen data on the Breached hacking forum on December 15. The hacker claimed to have access to a 427 GB database stolen from SevenRooms that contained information about its customers.
As per the sample posted on the hacking forum, the seller has access to files containing details of big restaurant chains, clients of SevenRooms, API keys, promo codes, payment reports, reservation lists, and more.A SevenRooms spokesperson told BleepingComputer that the data breach occurred as a result of unauthorised access to the systems of one of its vendors.“SevenRooms recently learned that a file transfer interface of a third-party vendor was accessed without authorisation. This may have affected certain documents transferred to or by SevenRooms, including the exchange of API credentials (now expired), and some guest data, which may include names, email addresses, and phone numbers,” the spokesperson told BleepingComputer.Upon identifying the security incident, SevenRooms immediately took steps to mitigate the situation and involved third-party cyber security experts to investigate the matter further. “We immediately disabled access to the interface, and launched an internal investigation, and we currently have no evidence that any of SevenRooms’ proprietary databases were affected.“We have retained independent cybersecurity experts to assist with this investigation and will provide additional updates as appropriate,” the spokesperson added.The company has, however, clarified that credit card information, bank account details, social security numbers, and other sensitive information of its guests weren’t stored on the compromised server and weren’t affected by the security incident.SevenRooms has also clarified that its internal systems were not breached by the threat actor and it remains safe from any unauthorised access.Commenting on the news, Paul Bischoff, Consumer Privacy Advocate at Comparitech, said, “The fact that SevenRooms didn’t disclose the breach until after attackers leaked the data online is not a good look. It means SevenRooms either didn’t know about the breach until the data was leaked, or it knew about it but kept quiet. So, it appears that SevenRooms was either withholding or negligent. SevenRooms has decided to go with the "blame the vendor" PR strategy in response.“Although the breach affected a lot of customers, the data was thankfully not that sensitive. No payment info or other sensitive customer data was leaked. However, some contact information was leaked, so customers should be on the lookout for targeted phishing emails and messages. These messages may impersonate SevenRooms clients or related businesses. Never click on links in unsolicited messages and emails,” Bischoff added.

Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543