Data breach
Home Chef
- Records
- 8,717,742
- Breach date
- 10 February 2020Estimated
- Added
- 24 March 2025
What was exposed
4 types of data · 3 more reported
- Email addresses8,717,218
- IP addresses8,609,155
- Names5,783,080
- Phone numbers5,668,226
- PasswordsReported, not counted
- Home addressesReported, not counted
- GenderReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
Home Chef, the Chicago-based meal kit delivery service, suffered a data breach affecting roughly 8.7 million customer records, according to our investigation team. The breach itself is estimated to have occurred on February 10, 2020, but the company did not disclose it publicly until May 2020, after a hacker group began selling the stolen database on a dark web marketplace. The sellers, a group calling itself Shiny Hunters, listed records stolen from eleven companies at once, and priced the Home Chef database at $2,500, according to reporting by BleepingComputer.
February 10, 2020: Our investigation team estimates the breach occurred on this date, a timeline also reflected in Mozilla Monitor's breach record.
May 9, 2020: BleepingComputer reported that Shiny Hunters was selling a database of 8 million Home Chef user records on a dark web marketplace, alongside databases from ten other companies.
May 20, 2020: Home Chef posted a "Data security incident" notice confirming that select customer information had been accessed, and TechCrunch reported the company's confirmation that the notice related to the database being sold online.
What Information Was Compromised?
Our analysis found the following data types in this breach: IP addresses (about 8.6 million records), email addresses (about 8.7 million), phone numbers (about 5.7 million), and names (about 5.8 million), drawn from roughly 8.7 million rows in total.
The company's own data security incident notice confirmed additional fields. According to the notice, which BleepingComputer reviewed and quoted, the accessed information included email addresses, names, phone numbers, encrypted passwords, the last four digits of credit card numbers, and other account information. TechCrunch reported that mailing addresses were also taken, and BleepingComputer's review of the sold database sample showed fields such as gender, age, and subscription details.
Home Chef stated that it does not store complete payment card numbers in its databases, so only the last four digits of card numbers were involved.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The most immediate risk involves the passwords. Home Chef said the passwords were encrypted, but encryption is not always a permanent barrier, and BleepingComputer noted that attackers can sometimes crack password hashes with dedicated software. If a stolen password is cracked and reused on other accounts, those accounts become targets.
Names, email addresses, and phone numbers are valuable to scammers even on their own. With this combination, criminals can craft convincing phishing emails and text messages that appear to come from Home Chef, its payment processor, or another trusted brand, because the message can reference details that make it seem legitimate. Exposed IP addresses and partial card details add further context that can make such schemes more persuasive.
Anyone affected should be skeptical of unexpected messages about orders, payments, or account problems, and should avoid clicking links or calling numbers contained in those messages.
What Is Home Chef Doing in Response?
Home Chef posted a data security incident notice on its website on May 20, 2020, stating that it had recently learned of an incident affecting select customer information. In a statement to BleepingComputer, the company confirmed the notice related to the database being sold online. The company said not all customers were affected and that it would reach out directly to those whose information was taken, according to TechCrunch. The company also emphasized that full payment card numbers were not stored in its databases.
What Should You Do If You Were Affected?
If you had a Home Chef account around the time of the breach, take these steps:
Change your Home Chef password to a strong, unique one you do not use anywhere else.
If you reused that password on other sites, change it at every one of those sites.
Watch for phishing emails or texts that reference Home Chef, food deliveries, or payment issues, and go directly to the company's website instead of following links in messages.
Review payment card and bank statements for charges you do not recognize.
Be cautious with calls or texts claiming to be from Home Chef support; hang up and contact the company through its official channels.
In the news
- BleepingComputer: Home Chef announces data breach after hacker sells 8M user recordsbleepingcomputer.com (opens in a new tab)
- BleepingComputer: Hacker group floods dark web with data stolen from 11 companiesbleepingcomputer.com (opens in a new tab)
- TechCrunch: Home Chef confirms breach after 8 million user records found on the dark webtechcrunch.com (opens in a new tab)
- Mozilla Monitor: Home Chef breach recordmonitor.mozilla.org (opens in a new tab)
