People search iFood data breach timeline because millions of customers entrust payment and identity data to everyday transactions. BreachHistory indexes 3 iFood-linked incidents, with headline counts up to 43.8M+ in catalog rows. This page maps every attested event through 2026 with internal links to canonical records.
Why iFood breach history matters
iFood operates in Retail (Brazil). Across indexed rows, recurring themes include ransomware and extortion, unverified actor or scraping claims. Understanding the chronological pattern helps security teams, customers, and regulators separate confirmed disclosures from forum marketing.
Full timeline through 2026
2026 — bacen 43.8M customer-record extortion claim (unverified)
Unverified claim — treat actor counts cautiously. Unverified leak-site / extortion claim — observed May 28, 2026. Dark Web Informer reported actor bacen advertising a pay-or-leak listing against Brazilian food-delivery giant iFood, citing roughly 43.8 million customer records with CPF national IDs, names, emails, phones, and credit-card data, plus user/admin samples. iFood had not publicly addressed this specific listing in sources reviewed. This claim is cataloged separately from iFood's company-confirmed ~1.2 million-user breach (Dec 2025 activity, disclosed Jun Exposed categories include Actor-claimed: ~43,847,219 customer records including CPF, names, emails, phones, credit-card data, account fields—unverified. BreachHistory cites approximately 43.8M+ affected records in this row. See the ifood-bacen-extortion 2026 record and canonical BreachHistory entry.
2025 — confirmed breach; 1.2M users (Dec 2025; disclosed June 2026)
Unverified claim — treat actor counts cautiously. Brazilian food-delivery platform iFood confirmed in early June 2026 that a December 2025 incident affected approximately 1.2 million users (~2% of its base)—names, phone numbers, addresses, and CPF tax IDs—while stating passwords, bank details, and card data were not taken. Hackread and SC Media noted a separate BreachForums actor claimed ~43.8 million records with a June 10, 2026 ransom deadline, which iFood disputed as unverified. BreachHistory uses the company-attested 1.2M figure. Exposed categories include Names, phones, addresses, CPF numbers per company notice. BreachHistory cites approximately 1.2M+ affected records in this row. See the ifood-consumer-data 2026 record and canonical BreachHistory entry.
2021 — — User data
Cataloged incident. Hacked. User data. Exposed categories include Names, emails, addresses, and other PII. No attested victim count is published for this row yet. See the ifood2021 and canonical BreachHistory entry.
Patterns and analysis
- Ransomware and extortion — appears across multiple iFood catalog entries; prioritize controls that address this class of failure.
- Unverified actor or scraping claims — appears across multiple iFood catalog entries; prioritize controls that address this class of failure.
- Record-count hygiene — BreachHistory indexes actor-cited figures separately from company-confirmed totals; read each row's technicalWriteup before treating counts as fact.
- 2026 monitoring — New disclosures roll into this timeline as they are verified or labeled unverified per catalog policy.
What to do if you may be affected
- Step 1: Enable phishing-resistant MFA on every account tied to this brand.
- Step 2: Use unique passwords and a password manager—breach rows often involve credential reuse.
- Step 3: Monitor official company breach notices and regulator filings, not dark-web downloads.
- Step 4: Use virtual card numbers for online checkout where your bank supports it.
- Step 5: Bookmark the iFood company page for new 2026+ disclosures.
Canonical BreachHistory hub
Explore every indexed row: breachhistory.com/ifood · Latest: ifood-bacen-extortion2026.
Sources: BreachHistory catalog (3 rows for iFood), company and regulator disclosures cited in individual breach records.