← Deliware

2026 Deliware — unverified NightBroker leak; exposed demo admin panel, Stripe keys alleged

2026 1.6K records affected Share on X

Data compromised

Actor-claimed six JSON files: users.json (1,572 records), restaurants, orders, promo codes, brands; auth tokens, OTPs, password-reset keys, geolocation, and admin Stripe API keys alleged—mix of test and real data

Technical writeup

Unverified leak claim — June 2026. NightBroker actor claims Deliware (deliware.app) Indian food-delivery database exposed through a demo admin panel. Alleged six JSON files include 1,572 user records with names, phones, emails, DOB, addresses, geolocation, authentication tokens, OTPs, password-reset keys, and an admin settings file with Stripe API keys. Actor notes test/real record mixing; Deliware has not confirmed. BreachHistory indexes 1,572 from actor-cited users.json count as unverified.

Root cause

Threat actor NightBroker claims breach via exposed demo administration panel on Deliware food-delivery app—unverified

References