HungerRush Customers Targeted in Mass Extortion Email Campaign
Mar 4, 2026 // 22:40 - Niko Dunn


A threat actor is currently mass-mailing extortion emails to restaurant patrons who have used the HungerRush point-of-sale (POS) and online ordering platform. The emails claim that the company has been breached and threaten to expose customer data if HungerRush does not comply with the attacker’s demands. 

Key Details of the Incident

  • Target Audience: Customers of major restaurant chains using HungerRush, including Sbarro, Jet’s Pizza, Fajita Pete’s, and Hungry Howie’s.
  • Potential Source: Security researchers suggest an employee device was infected with an infostealer in October 2025, potentially compromising credentials for platforms like NetSuite, QuickBooks, Stripe, and Salesforce.
  • Email Content: Recipients have reported receiving messages that reference their past digital receipts, indicating the attacker likely has access to order history or customer contact lists.
  • Scale: HungerRush provides technology to over 16,000 restaurants, putting a significant number of patrons at risk of receiving these messages. 

Recommended Actions for Patrons

If you receive one of these extortion emails, security experts and government agencies recommend the following:

  • Do Not Pay: Paying extortionists provides no guarantee that your data will be protected and encourages further attacks.
  • Ignore and Report: Do not click links or open attachments, as these may lead to further phishing sites or malware.
  • Monitor Accounts: Be alert for subsequent phishing attempts via SMS or email that might use your personal details to gain further access to your financial accounts.
  • Update Security: If you use the same password for your restaurant accounts and other sensitive services, change them immediately. 

HungerRush has been contacted regarding the incident but has not yet confirmed the full extent of a system breach. 

#campaign  #customers  #email  #extortion  #hungerrush  #mass  #news  #targeted   —   News