The German Doner Kebab Leak Exposed 162K UAE Customer Records
HEROIC analysts found a database breach linked to German Doner Kebab, the international fast-food franchise, first surfacing on a hacking forum on March 27, 2025. The leak affected 162,364 customer records, primarily tied to UAE-based customers. Data exposed in the incident included full names, email addresses, and phone numbers, the kind of personal contact information that feeds directly into fraud and phishing campaigns.
Why the German Doner Kebab Data Creates Immediate Risk
Restaurant chains collect large amounts of customer contact data through loyalty programs, online orders, and delivery apps. That data is valuable to attackers precisely because customers rarely expect to be targeted through a food brand. With a full name, email address, and verified phone number, a criminal can send convincing fake promotions, harvest credentials through fake login pages, or sell the data in bulk to other threat actors. The UAE context adds another dimension since cross-border fraud using regional contact lists is a common tactic in targeted smishing and telephon scam operations.
What Was Exposed in the German Doner Kebab Breach
- Email Address
- Phone Number
- First Name
- Last Name
Why This Matters for Customers
A breach like this has consequences that extend well beyond a single company. Credential stuffing attacks use exposed email addresses to test passwords across banking apps, shopping sites, and email providers. Account takeover is the next step when attackers find a match, often gaining access to financial accounts or loyalty point balances. Identity theft becomes easier when names and contact details are combined with other datasets circulatng on dark web forums. Financial fraud is a real risk, especially for customers who reuse passwords or have linked payment methods to their accounts.
How a Database Breach Works
A database breach happens when attackers gain unauthorized access to a company's stored customer data. This often occurs through vulnerabilities in web applications, poorly secured APIs, or stolen login credentials for internal systems. Once attackers are in, they can extract entire customer tables in minutes. That data is then posted to criminal forums for sale, often appearing within days of the intrusion. For food and hospitality brands, databases that power online ordering and loyalty programs are common targets because they are frequently internet-facing and contain rich personal information.
Check If You Are Affected by the German Doner Kebab Breach
If you have ever ordered from German Doner Kebab online or signed up for their loyalty program, your contact information may be part of this dataset. HEROIC's free breach scanner covers 400 billion compromised records and can tell you in seconds whether your email has been exposed. Run a free scan now and stay ahead of the threat.
Breach Breakdown
162,364 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds