2026 Grubhub — data download from systems; ShinyHunters extortion (Zendesk / Drift chain)
Data compromised
Undisclosed downloaded datasets; company denied financial data and order history; Zendesk support context cited in secondary reporting
Technical writeup
In mid-January 2026, U.S. food-delivery platform Grubhub confirmed to press that unauthorized individuals had downloaded data from certain Grubhub systems, stating it had investigated and stopped the activity and that sensitive categories such as financial information and order history were not affected. Industry reporting cited ShinyHunters as the extortion-oriented group pressuring the company, with sources alleging demands related both to legacy Salesforce-era material tied to prior campaigns and to newer Zendesk-oriented support data. Journalists linked follow-on access narratives to secrets exposed in the broader Salesloft Drift / OAuth token theft wave affecting many Salesforce-connected organizations in 2025. Grubhub said it was working with a third-party cybersecurity firm and law enforcement; detailed victim counts and exact data classes were not published in initial statements.
Root cause
Unauthorized data download; supply-chain / stolen-credential chain cited in press (Salesloft Drift–linked); ShinyHunters extortion per reporting