Burger King Russia Breach Exposes 3.2 M Customer Records via Compromised Marketing Platform
What Happened – In August 2024 attackers compromised the Mindbox marketing‑automation platform used by Burger King Russia. The breach surfaced on 21 Sept 2026 in the Have I Been Pwned database, revealing 3,155,792 unique records that include email addresses, names, genders, dates of birth, phone numbers and approximate geolocations collected from 2018 onward. Payment or passport details were not part of the disclosed data.
Why It Matters for Trust & Control Assurance
- This incident illustrates the risk of insufficient third‑party vendor oversight – a control area that continuous assurance programs must monitor and document.
- Demonstrable evidence of vendor security assessments, ongoing monitoring, and incident‑response coordination is essential to maintain a defensible audit trail under frameworks such as NIST CSF 2.0.
- A robust vendor‑risk control program helps organizations prove due‑diligence when regulators or partners request proof of supply‑chain security.
Who Is Affected – Restaurant and quick‑service chains operating in Russia; marketing‑automation service providers; any organization that outsources customer‑engagement platforms.
Recommended Actions
- Conduct an immediate third‑party risk review of Mindbox, confirming the scope of the compromise and any lingering access.
- Update contracts to require continuous security monitoring, breach‑notification clauses, and evidence of periodic security assessments.
- Collect and retain logs, audit reports, and remediation evidence to support audit readiness and potential regulator inquiries.
Source: Have I Been Pwned – Burger King Russia Breach
Technical Notes
- Attack vector: exploitation of a third‑party dependency (Mindbox platform).
- Data types exposed: personal identifiers (email, name, gender, DOB, phone, location). No financial or passport data.
Source: same as above