← Blog

iFood Breach: 1.2M Users, CPF and Addresses Exposed

Share on X

In early June 2026, iFood—Brazil's dominant food-delivery platform—publicly confirmed a December 2025 data breach affecting approximately 1.2 million users, roughly 2% of its customer base. Hackread and SC Media reported that exposed fields include names, phone numbers, delivery addresses, and CPF (Brazilian tax ID numbers). iFood stated passwords, bank details, and payment card data were not compromised.

43M forum claim vs. company attestation

A separate BreachForums actor claimed ~43.8 million records with a June 10, 2026 ransom deadline. iFood disputed that figure as unverified marketing. BreachHistory catalogs the company-attested 1.2M count; treat megaleak forum numbers as ceilings until Brazil's ANPD or iFood files formal regulatory notices.

What Brazilian users should do

  1. Monitor for phishing SMS or WhatsApp messages citing real delivery addresses or partial CPF digits.
  2. Enable app-based MFA on email accounts used for iFood recovery.
  3. Report suspicious "iFood refund" or "account verification" links to iFood's official support channels only.
  4. Check whether your CPF appears in unrelated credit applications—CPF exposure enables identity fraud in Brazil.

Canonical record: iFood 2026 consumer data breach on BreachHistory. See also iFood's prior 2021 incident on the company timeline.

Sources: Hackread, SC Media