An attacker has hacked the food delivery service Chowbus and sent several emails to customers telling them to download their data via a link.
Chowbus is a food delivery service (mainly Asian food) that allows customers to order food from local restaurants in the US, Australia , and Canada.
At 1:33 a.m. yesterday, Chowbus customers began receiving mysterious emails titled “Chowbus data,” which simply said in their text, “Download Chowbus data here.” The email included download links for both a database of users and restaurants used by the food delivery service.

According to many customers who received these emails, the links led to text files (CSV) containing the exported databases for Chowbus.
The first CSV contained the names, phone numbers, supplies, and addresses of 4,300 restaurants that partner with the food delivery service.
The second database contained 803,350 Chowbus user information, including their email address, name, phone number, and address.
In an email to customers, Chowbus explained that it was investigating the breach, but the exposed data did not contain financial information or passwords.
"At approximately 1:30 a.m. CDT on October 5, we learned that some of our user data had been made available online. As soon as we became aware of this incident, our security team quickly took steps to address the issue."
“The stolen data included customer names, email addresses, and phone numbers.”
“Fortunately, the data did not contain any credit card information or Chowbus account passwords, and we are confident that this information is secure,” the company said.
If you are a ChowBus customer, you can check if your information was exposed in the breach using the Have I Been Pwned data breach notification website.
To do this, simply go to https://haveibeenpwned.com, enter your email address in the search field, and click the “pwned?” button.
The website will check its databases for your email and report any data breaches it finds.
