Trending: On-device modelsSearch
iHeartGeek
iTECH

Have I Been Pwned loads 3.2m Burger King Russia records

Have I Been Pwned has added the 3.16m-record Burger King Russia data set from the August 2024 Mindbox breach, so customers can now check whether their details were exposed.

Composed editorial card reading 3.2m records from the 2024 Mindbox breach, with rows for 3,155,792 unique email addresses, the email, name, date of birth and phone data classes, the August 2024 attack and the verification

Have I Been Pwned loaded the Burger King Russia breach into its searchable index on 21 September, giving customers of the chain a way to check whether they were caught up in an incident first reported two years ago. The service records 3,155,792 unique email addresses in the data set, which it classes as verified rather than fabricated, and describes the records as spanning 2018 to August 2024.

What the data set contains

Alongside email addresses, the material includes names, dates of birth, phone numbers, genders and approximate geographic locations. Have I Been Pwned does not flag the breach as sensitive and records no attribution to a named attacker, which is the usual shape for an incident reported by the victim and later loaded by the service. Loading it is what makes the records queryable by the people they describe.

How the data got out

The exposure came through Mindbox, a marketing automation platform used by the chain, rather than through Burger King Russia’s own systems. Reporting on the breach began in October 2024, when news of the leak surfaced in Russian media, and Burger King Russia acknowledged the incident at the time, saying the data did not include payment card or passport details. That distinction still matters now the records are searchable: this is customer marketing data, not financial records.

Why the confirmation matters

Three million people can now learn, two years on, that their name, birth date and phone number sit in a file anyone can query. That is the purpose of the service and the reason these loads keep making news: a stolen data set is worth less for what it was on the day it was taken than for what it can be matched against afterwards. Old marketing data is precisely what makes a convincing phishing message, and knowing an address is in the file is the difference between ignoring a strange email and taking it seriously. Have I Been Pwned’s catalogue of loaded breaches now runs past a thousand data sets.

Our opinion

The two-year gap between the attack and the confirmation is the part worth noticing, because it is the normal shape of breach disclosure rather than an unusual one: the data circulated, was reported, was forgotten, and only now can the people in it look themselves up. The other detail worth noticing is where the data sat. Mindbox was a marketing platform serving one client’s loyalty programme, and vendors that small usually hold the richest customer lists in the chain. Nobody needs another warning that breaches happen. What they need is a reason to check, and a service that spends its own money loading a 2024 data set gives them a better one than any statement would.