Addresses, proxy numbers and door codes among exposed data

Shinsegae Food says fewer than 1% of franchises affected

[Shinsegae Food website]
[Shinsegae Food website]

A personal data breach has occurred at delivery subcontractors used by No Brand Burger, the burger chain operated by Shinsegae Food.

According to Shinsegae Food, an unauthorized external party accessed the systems of Fly Co., a delivery subcontractor for No Brand Burger, around Aug. 14, exposing some customers' personal data.

Fly detected the unauthorized access around 7 p.m. on Saturday, Aug. 15, and confirmed the data leak around 3 p.m. three days later, on Tuesday, Aug. 18.

Shinsegae Food said it was notified of the breach by Fly and became aware of it around 2:40 p.m. on Friday, Aug. 21.

The exposed customer data includes delivery addresses and proxy phone numbers, with names removed. Some entries also included shared-entrance door codes and notes left at the time of ordering.

For franchise operators, the leaked data included names, dates of birth, business names, contact numbers, business registration numbers and addresses.

"This was not an incident that occurred at the corporate level, but at a subcontractor that individual franchises had contracted with independently," a Shinsegae Food official said. "Fewer than 1 percent of franchises were affected."

After learning of the breach, Shinsegae Food suspended its subcontracting arrangement with Fly and has begun the reporting process with the Personal Information Protection Commission and other relevant authorities. The company said it plans to support affected customers through the appropriate procedures if any harm is confirmed.

Shinsegae Food advised customers to change their shared-entrance door codes if possible, and urged them not to respond to any requests for additional personal information or money made via text message, phone call or email by individuals impersonating delivery workers.


spa@heraldcorp.com