About 17 million Zomato user records were stolen from their database which includes email addresses and hashed passwords, the company said on Thursday.
"No payment information or credit card data has been stolen/leaked. Payment related information on Zomato is stored separately from this (stolen) data in a highly secure PCI Data Security Standard (DSS) compliant vault," Zomato said in a blog post on Thursday.
So far, it looks like an internal (human) security breach -- some employee's development account got compromised, the post added.
As a precaution, the company has reset the passwords for all affected users and logged them out of the app and website.
The team at Zomato was actively scanning all possible breach vectors and closing any gaps.
The hashed password cannot be converted/decrypted back to plain text -- so the sanctity of password is intact in case users' use the same password for other services.
"But if you are paranoid about security like us, we encourage you to change your password for any other services where you are using the same password," the post read.
"Over the next couple of days and weeks, tha company will further enhance security measures for all user information stored within our database and will add a layer of authorisation for internal teams having access to this data to avoid the possibility of any human breach," Zomato said.
This is not the first time that Zomato has been hacked.
In 2015, the company was hacked by a white hat hacker who reported the details back to the company which later addressed the weaknesses.
This time, the details may be sold online.
--IANS
anuj/na/vm
Disclaimer: No Business Standard Journalist was involved in creation of this content
You’ve reached your limit of {{free_limit}} free articles this month.
Subscribe now for unlimited access.
Already subscribed? Log in
Subscribe to read the full story →
Smart Quarterly
₹900
3 Months
₹300/Month
Smart Essential
₹2,700
1 Year
₹225/Month
Super Saver
₹3,900
2 Years
₹162/Month
Renews automatically, cancel anytime
Here’s what’s included in our digital subscription plans
Exclusive premium stories online
Over 30 premium stories daily, handpicked by our editors


Complimentary Access to The New York Times
News, Games, Cooking, Audio, Wirecutter & The Athletic
Business Standard Epaper
Digital replica of our daily newspaper — with options to read, save, and share


Curated Newsletters
Insights on markets, finance, politics, tech, and more delivered to your inbox
Market Analysis & Investment Insights
In-depth market analysis & insights with access to The Smart Investor


Archives
Repository of articles and publications dating back to 1997
Ad-free Reading
Uninterrupted reading experience with no advertisements


Seamless Access Across All Devices
Access Business Standard across devices — mobile, tablet, or PC, via web or app
