ProSushi Security Breach Exposes 164K Customer Records
HEROIC's DarkHive intelligence system discovered the ProSushi data breach, exposing 164,048 records. The breach occured in December 2023, affecting this Russia-based sushi restaurant and food delivery service. The leaked data includes phone numbers, MD5 hashed passwords, gender, and birthday information, creating risks of targeted account takeover and identity fraud for affected customers.
Why This Is Dangerous
The ProSushi breach exposes a concerning combination of personal identifiers alongside MD5 hashed passwords. MD5 is an outdated hashing algorithm that modern cracking tools can reverse rapidly, especially for common passwords. Once attackers recover plaintext passwords, they combine them with phone numbers to test access on banking apps, food delivery platforms, and other services. Birthday and gender data allow attackers to answer common account security questions, making account recovery attacks significantly more effective against victims of this breach.
What Was Exposed
- Phone Number
- Password Hash (MD5)
- Gender
- Birthday
Why This Matters
Phone numbers combined with birthdates create a particularly dangerous data combination because many financial and government services use this information for identity verification. Attackers can use ProSushi customer data to attempt SIM swapping attacks, which redirect phone numbers to attacker-controlled devices. This can bypass two-factor authentication on banking and email accounts, leading to financial theft and account takeover. Customers who recieve unexpected calls about thier ProSushi account or notice unusual mobile carrier activity should take immediate security precautions.
How Database Breach Works
Russian food delivery and restaurant platforms have been targeted by cybercriminals seeking consumer PII for fraud purposes. A database breach typically occurs when attackers exploit vulnerabilities in the web application or delivery management software, gaining unauthorized access to the backend database. The use of MD5 password hashing at ProSushi represents a fundamental security failure, as this algorithm has been considered cryptographically weak for over a decade. Modern security standards require bcrypt, scrypt, or Argon2 for password storage, which are designed to be computationally expensive and resistant to bulk cracking attacks.
Check If You Are Affected
HEROIC offers a free identity scanner that searches over 400 billion records, including data from breaches like ProSushi. Visit heroic.com to scan your email address and find out if your information was exposed.
Breach Breakdown
164,048 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds