The breach, which occurred in August 2024, involved Mindbox, the platform used by Burger King Russia to handle customer marketing data. Have I Been Pwned, run by security researcher Troy Hunt, ingested the leaked dataset and confirmed the exposure of names, dates of birth, email addresses, phone numbers, genders, and approximate geographic locations.
Burger King acknowledged the incident in October 2024, telling Russian news agency TASS that customer data may be among those affected. The company stressed that no financial or passport details were compromised. “The personal data being verified does not include payment details: public transaction information is not transmitted or stored by third parties,” the company said. “The Mindbox platform and other third parties do not have access to the personal passport or payment information of Burger King customers.”
The stolen records span more than six years, dating back to May 2018. Initial news reports at the time of the attack suggested the leak contained more than 5.6 million lines of data, including information about customers’ favourite dishes and previous order dates, though HIBP made no mention of these specific fields.
Russian cybersecurity outlet Xakep reported that the Mindbox breach may be linked to other incidents, citing sources who claimed a single intruder was responsible. Among the other companies allegedly affected was Detsky Mir, Russia’s largest children’s toy retailer, with more than one million customers reportedly impacted.
The full scope of the data’s subsequent use remains unclear, but the inclusion of the dataset in HIBP means affected individuals can now check whether their details were exposed.