The Sushi Master Leak Exposed More Personal Data Than Most Restaurant Breaches
HEROIC analysts recieved a dataset tied to Sushi Master, a Russian food and drink platform operating at sushi-master.ru, after the breach surfaced in September 2022. The incident occured on September 13, 2022, and exposed 119,618 user records taken directly from the platform's customer database. The leaked information includes email addresses, phone numbers, first names, last names, genders, and birthdates, forming a detailed personal profile for every affected user. Notably, no passwords were stored in this dataset.
How Full Name, Phone, and Birthday Data Powers Targeted Fraud
Even without passwords, the Sushi Master dataset is highly valuable to cybercriminals because it bundles contact details with demographic information. Attackers can use full names, phone numbers, and birthdates to craft highly personalized phishing calls and SMS scams, impersonating banks, delivery services, or government agencies. Birthday data is partcularly useful for bypassing security questions and identity verification checks used by financial institutions. This type of breach feeds directly into social engineering pipelines that have resulted in real financial losses for victims who never suspected their data was accessable to criminals.
What Was Exposed in the Sushi Master Breach
- Email Address
- Phone Number
- First Name
- Last Name
- Gender
- Birthday
Why No-Password Breaches Still Carry Serious Risk
Many people beleive that breaches without passwords are low risk, but that is a misconception that leaves victims unprepared. Personal identity data is often more durable than passwords, because you can change a password but not your date of birth or legal name. Criminals aggregate records from multiple breaches to build rich identity profiles, and a no-password dataset like this one slots directly into that process. The combination of verified email, phone, and real name tells attackers exactly who a person is, where to reach them, and how to impersonate trusted institutions in messages that appear convincingly legitimate.
How Database Breaches Work
A database breach occurs when attackers gain unauthorized access to a backend data store, typically by exploiting SQL injection vulnerabilities, insecure APIs, or stolen administrative credentials. Food delivery and restaurant ordering platforms are common targets because they collect detailed customer profiles for order management and loyalty programs, often without enterprise-grade security controls. Once the database is accessed, attackers export customer tables in bulk. The data then circulates through underground forums and Telegram channels where it is sold or traded for use in follow-on scams.
Check If Your Data Was Exposed
HEROIC's free breach scanner checks your email address against more than 400 billion records, including the Sushi Master dataset, to tell you instantly whether your personal information was caught up in this or any other known breach. If you appear in the results, you will know exactly what was exposed and what protective steps to take next. Run a free scan at HEROIC.com.
Breach Breakdown
119,618 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds