UPDATED 22:58 EDT / OCTOBER 06 2020

SECURITY

Customer records stolen in data breach of Asian food delivery service Chowbus

Asian food delivery service Chowbus, owned by Fantuan Group Inc., has suffered a data breach with hundreds of thousands of customer records stolen.

Exactly how the data breach took place is not known. The stolen data included customer names, email addresses, phone numbers and email addresses. Credit card data was not accessed.

Although the company has confirmed that “some of our user data has been illegally accessed” and that it’s addressing the issue, where the story takes a twist is how customers initially found out about the data breach.

Customers affected by the data breach started to receive emails early Monday labeled “Chowbus data” that contained links to where they could download the stolen company data, the Chicago Tribune reported today. One thread on Reddit details the email and the data sent via the link, with various users chiming in to state that they had also received the same email. The database contained more than 800,000 customer records and 444,000 unique email addresses.

Based in Chicago, Chowbus provides food delivery services in the U.S., Canada and Australia. The data included customer information from Australia and well as North America with Riot Act reporting that information of customers from Canberra were found in the database.

“We are so used to ransomware attacks or other incidents committed for political or financial gain that a data breach at Chowbus is very unusual,” Ilia Sotnikov, vice president of product management at data security firm Netwrix Corp., told SiliconANGLE. “This scenario hasn’t been common before and can be a result of criminal mischief or a desire to harm a company’s reputation.”

By undermining trust in a company’s ability to protect customer data, hackers may encourage victims to turn to competitors, Sotnikov added. “Although there is no information on the root cause of this incident, we may assume that such an attack could have been initiated by an insider, such as a disgruntled employee,” he said.

Stephen Gates, security evangelist and senior solutions specialist at software security company Checkmarx Ltd., noted that such breaches highlight the need for better application security.

“If the breach wasn’t due to a malicious insider, then the likelihood the hack took place via the Chowbus website, or even more probable, their mobile app, is very high,” Gates said. “Organizations must do a better job of finding and remediating software vulnerabilities before their apps go online, not after a breach takes place.”

Image: Chowbus

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.