One Dark Web Listing. Nine Data Types. The Xarakiri Breach Had 106,083 Records.
HEROIC analysts detected a breach affecting Xarakiri, a Russian food delivery service specializing in Asian cuisine. The leak occured on September 14, 2022 and impacted 106,083 records. What makes this breach stand out is the breadth of data included: email addresses, phone numbers, full names, birthdays, usernames, salted MD5 password hashes, and partial credit card information. This is among the most comprehensive data profiles found in food delivery platform breaches, making it partcularly dangerous for affected users.
Credit Card Data and Passwords Together: Maximum Financial Fraud Risk
When attackers recieved both partial credit card data and password hashes in a single breach, they can pursue multiple attack paths simultaneously. MD5 hashes, even when salted, are accessable to modern cracking tools, and once passwords are recovered, attackers attempt them against payment platforms, banking apps, and other accounts where victims may reuse credentials, compounding the financial exposure from the credit card data.
What Was Exposed in the Xarakiri Breach
- Email Address
- Phone Number
- Password Hash (MD5 with Salt)
- Username
- First Name
- Last Name
- Birthday
- Salt
- Credit Card (partial)
Why a Food Delivery Breach Is a Financial Fraud Launch Pad
Food delivery platforms store payment information and detailed personal profiles. A breach of this scope gives threat actors a complete identity kit: names, contact details, birthdates for identity verification bypass, and partial card data that can be combined with data from other breaches to construct full card profiles. Victims face risks of account takeover, financial fraud, and seperate identity theft attacks that can persist for years after the original incident.
How Database Breaches Work
A database breach occurs when an attacker gains unauthorized access to a company's data storage systems, typically through exploitation of application vulnerabilities, SQL injection, or compromised internal credentials. In the Xarakiri case, the attacker extracted a comprehensive user profile table containing both authentication credentials and payment-adjacent data, indicating access to a high-value production database.
Check If Your Data Was Exposed
HEROIC's free breach scanner is powered by a database of over 400 billion exposed records. If your information appeared in the Xarakiri breach or any other incident, the scanner will surface it instantly. Check your email at HEROIC now to see what personal and financial data may already be in circulation.
Breach Breakdown
106,083 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds