HomeSecurityHacker sends mass extortion emails from HungerRush to restaurant customers

Hacker sends mass HungerRush extortion emails to restaurant customers

Restaurant customers using the HungerRush for their point-of-sale (POS) system have reported receiving emails from a threat actor attempting to blackmail the company, warning that restaurant and customer data could be exposed if HungerRush does not respond.

See also: Authorities dismantled the infrastructure of the phishing service Tycoon2FA

HungerRush

HungerRush is a restaurant technology provider that offers software for POS, online ordering, delivery management, and payment processing, helping restaurants manage orders, customer information, and business operations. The company claims to work with over 16,000 restaurants, including Sbarro, Jet's Pizza, Fajita Pete's, and Hungry Howie's.

The attacker began sending the emails early Wednesday morning, with multiple recipients sharing samples. The first email was sent from support@hungerrush.com, urging HungerRush to comply with their extortion demands or risk exposing customer data. The email stated, “You cannot ignore all of my requests and expect me to not take any malicious action. You still have time.” It warned that the data of millions of restaurants and customers was at risk.

A second email, sent three hours later from “2019@hungerrush.com,” escalated the threat, claiming that the attacker had access to data files for millions of customers, including names, emails, passwords, addresses, phone numbers, dates of birth, and credit card information.

See also: Phishing campaign targets Bitpanda users

Hacker sends mass HungerRush extortion emails to restaurant customers

Analysis of the email headers showed that they were delivered using Twilio SendGrid, which customers reported previously being used to send HungerRush restaurant receipts. The headers confirmed that the messages passed SPF, DKIM , and DMARC for the hungerrush.com.

Multiple users on Reddit reported receiving the emails, noting that older digital receipts from restaurants indicated they were using HungerRush's ordering or POS systems. Alon Gal, co-founder and CTO of Hudson Rock, reported on LinkedIn that infostealer files indicated that a HungerRush employee's device was allegedly infected with an infostealer in October 2025, leading to a breach of credentials.

The malicious software is reported to have stolen numerous corporate credentials, including those for NetSuite services, QuickBooks, Stripe dashboards, Bill.com supplier payment systems, Visa Online commercial services, and Salesforce environments.

See also: Starkiller: New phishing kit bypasses MFA

Hacker sends mass HungerRush extortion emails to restaurant customers

It remains unclear whether these stolen credentials are linked to the alleged breach at HungerRush. In the meantime, restaurant customers using the HungerRush POS system should be on guard for possible phishing emails and SMS that could exploit the potentially stolen information.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS