HomeIntelligenceBrief
BREACH BRIEF 🟠 High Breach

Burger King Russia Breach Exposes 3.2 M Customer Records via Compromised Marketing Platform

An August 2024 attack on the Mindbox marketing automation platform used by Burger King Russia leaked over 3 million customer records. The breach underscores the need for continuous third‑party risk monitoring to satisfy audit and regulatory expectations.

Verisq™ Intelligence · 📅 September 21, 2026 · 📰 haveibeenpwned.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
haveibeenpwned.com

Burger King Russia Breach Exposes 3.2 M Customer Records via Compromised Marketing Platform

What Happened – In August 2024 attackers compromised the Mindbox marketing‑automation platform used by Burger King Russia. The breach surfaced on 21 Sept 2026 in the Have I Been Pwned database, revealing 3,155,792 unique records that include email addresses, names, genders, dates of birth, phone numbers and approximate geolocations collected from 2018 onward. Payment or passport details were not part of the disclosed data.

Why It Matters for Trust & Control Assurance

  • This incident illustrates the risk of insufficient third‑party vendor oversight – a control area that continuous assurance programs must monitor and document.
  • Demonstrable evidence of vendor security assessments, ongoing monitoring, and incident‑response coordination is essential to maintain a defensible audit trail under frameworks such as NIST CSF 2.0.
  • A robust vendor‑risk control program helps organizations prove due‑diligence when regulators or partners request proof of supply‑chain security.

Who Is Affected – Restaurant and quick‑service chains operating in Russia; marketing‑automation service providers; any organization that outsources customer‑engagement platforms.

Recommended Actions

  • Conduct an immediate third‑party risk review of Mindbox, confirming the scope of the compromise and any lingering access.
  • Update contracts to require continuous security monitoring, breach‑notification clauses, and evidence of periodic security assessments.
  • Collect and retain logs, audit reports, and remediation evidence to support audit readiness and potential regulator inquiries.

Source: Have I Been Pwned – Burger King Russia Breach

Technical Notes

  • Attack vector: exploitation of a third‑party dependency (Mindbox platform).
  • Data types exposed: personal identifiers (email, name, gender, DOB, phone, location). No financial or passport data.

Source: same as above

📰 Original Source
https://haveibeenpwned.com/Breach/BurgerKingRussia

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →