One Food Delivery Password Could Unlock Your Bank Account
HEROIC identified a stealer log collection titled 100k Food base being shared on Telegram. Surfacing in February 2023, this industry-targeted dataset contains 99,548 records harvested from food delivery and dining platform users, exposing email addresses, plaintext passwords, and the URLs of services where those credentials were entered on malware-infected devices.
Why Plaintext Food Service Passwords Are a Bigger Problem Than You Think
The 99,548 passwords in this dump are stored in plaintext—fully readable without any decryption. While food delivery accounts may seem low-stakes, they often contain stored payment methods, home addresses, and phone numbers. More critically, these passwords are a direct gateway to other accounts. Attackers know that the password you use for a pizza delivery app is likely the same one protecting your email or financial services.
What Was Exposed
- Email Addresses — accounts registered with food delivery platforms, restaurant ordering systems, and related services
- Plaintext Passwords — fully unencrypted credentials harvested directly from browser storage
- URLs — food delivery and dining platform login pages where credentials were captured
The Chain Reaction of Password Reuse
Food delivery accounts are a favorite entry point for credential stuffing because users rarely consider them high-security. But attackers do not stop at your DoorDash or UberEats login. They test each of the 99,548 stolen email-password pairs against banks, email providers, cloud storage, and social media. If your food app password matches any of those, attackers gain access to accounts with far greater consequences—from financial theft to full identity compromise.
How Food Service Credentials End Up in Stealer Logs
Infostealer malware does not discriminate between high-value and low-value accounts—it captures everything saved in the victim's browser. Malware strains like Raccoon, Lumma, or Meta Stealer extract all stored credentials, then threat actors sort the resulting logs by industry. Food service credentials are packaged into targeted collections like this one because they appeal to buyers looking for accounts with stored payment cards or to attackers building cross-service credential lists for broader campaigns.
Check If Your Credentials Were Exposed
HEROIC's breach intelligence database contains over 400 billion records from data breaches, stealer logs, and dark web sources. Use HEROIC's free breach scanner to check whether your email appears in the 100k Food base dump or any other known leak. If your credentials are found, change your food delivery passwords immediately, update any other accounts sharing the same password, and enable two-factor authentication on all services that offer it.
Breach Breakdown
99,548 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds