Ethical Hacking News
A threat actor sent mass emails to HungerRush customers claiming that restaurant and customer data could be exposed unless the company responded to their demands. The emails used Twilio SendGrid, which passed authentication checks for the hungerrush.com domain.
HungerRush, a popular POS platform used by over 16,000 restaurants worldwide, has been targeted by a malicious hacker. The hacker is mass-mailing extortion emails to HungerRush patrons, threatening to expose customer data if demands are not met. The emails claim that the hacker has access to sensitive data records containing names, emails, passwords, and credit card information. Although the emails passed authentication checks, it is unclear if they were sent from an authorized source. A recent incident showed that a HungerRush employee's device was infected with an infostealer in October 2025, leading to credential compromise. - HungerRush spokesperson: "HungerRush has investigated and confirmed that these events are not related" Customers of restaurants using the HungerRush POS system should be on high alert for potential phishing emails and SMS texts that abuse potentially stolen information.
HungerRush, a popular point-of-sale (POS) platform used by over 16,000 restaurants worldwide, has been targeted by a malicious hacker who is mass-mailing extortion emails to its patrons. The emails, which were sent early this Wednesday morning, threaten that if the company fails to respond to their demands, customer data could be exposed.
According to reports from multiple recipients on Reddit, the first email was sent from support@hungerrush.com and prompted HungerRush to stop ignoring the hacker's requests or risk having malicious actions taken. The email warned that "every restaurant and customer of said restaurants' data which is in the millions is in jeopardy here and I can't even get a response back."
However, three hours later, another email was sent from 2019@hungerrush.com, which escalated the threat and claimed that the hacker has access to sensitive data records containing names, emails, passwords, addresses, phone numbers, dates of birth, and credit card information. The emails were delivered using Twilio SendGrid, a platform commonly used by companies to send transactional and marketing emails.
BleepingComputer's analysis of the email headers showed that they passed SPF, DKIM, and DMARC authentication checks for the hungerrush.com domain. However, this does not necessarily mean that the emails were legitimate or sent from an authorized source.
In a recent incident reported by Alon Gal, co-founder and CTO of Hudson Rock, it was discovered that a HungerRush employee's device had been infected with an infostealer in October 2025. This led to the compromise of numerous corporate credentials, including those for NetSuite, QuickBooks-related services, Stripe dashboards, Bill.com vendor payment systems, Visa Online commercial services, and Salesforce environments. - HungerRush spokesperson: "HungerRush has investigated and confirmed that these events are not related"
Regardless, customers of restaurants using the HungerRush POS system should be on high alert for potential phishing emails and SMS texts that abuse potentially stolen information.
Related Information:
https://www.ethicalhackingnews.com/articles/Hacker-Mass-Mails-HungerRush-Extortion-Emails-to-Restaurant-Patrons-ehn.shtml
https://www.bleepingcomputer.com/news/security/hacker-mass-mails-hungerrush-extortion-emails-to-restaurant-patrons/
https://x.com/BleepinComputer/status/2029266747581166078
https://x.com/newarks_twt/status/2029075780832248035
https://www.onlinethreatalerts.com/article/2026/3/4/hungerrush-scam-email/
Published: Wed Mar 4 13:48:53 2026 by llama3.2 3B Q4_K_M
Update: At 15:33 CST 3/5/2026, we recieved the following note on behalf HungerRush:
Based on its investigation to date, HungerRush has determined that late Monday, March 2nd, compromised credentials associated with a third-party vendor working with the company were used to gain unauthorized access to its email marketing service.
As a result, certain customer contact information (including names, email addresses, mailing addresses, and phone numbers) was accessed and used to send unauthorized email messages to certain merchants and consumers.
At this time, the company’s investigation has not identified evidence that sensitive personal or financial information (such as passwords, dates of birth, Social Security numbers, or payment card information) was accessed or compromised. HungerRush also notes that it does not store credit card data within its systems.
The investigation has not identified evidence that other HungerRush systems were compromised, and the activity appears to have been limited to the email marketing service. HungerRush has also not identified evidence of compromise affecting its ordering platform, payment infrastructure, or other production systems.
The company also notes that this incident is not related to claims previously referenced in your article regarding reports from Alon Gal, and its investigation has not identified evidence linking those reports to this event. ...
As a precautionary measure, HungerRush disabled access to the affected email service to prevent additional unauthorized messages from being sent while the investigation continues.
The company says it will continue to provide updates as more information becomes available.