2026 Deliware — unverified NightBroker leak; exposed demo admin panel, Stripe keys alleged
Data compromised
Actor-claimed six JSON files: users.json (1,572 records), restaurants, orders, promo codes, brands; auth tokens, OTPs, password-reset keys, geolocation, and admin Stripe API keys alleged—mix of test and real data
Technical writeup
Unverified leak claim — June 2026. NightBroker actor claims Deliware (deliware.app) Indian food-delivery database exposed through a demo admin panel. Alleged six JSON files include 1,572 user records with names, phones, emails, DOB, addresses, geolocation, authentication tokens, OTPs, password-reset keys, and an admin settings file with Stripe API keys. Actor notes test/real record mixing; Deliware has not confirmed. BreachHistory indexes 1,572 from actor-cited users.json count as unverified.
Root cause
Threat actor NightBroker claims breach via exposed demo administration panel on Deliware food-delivery app—unverified