Skip to main content
  1. Home
  2. Computing
  3. Mobile
  4. News

Zomato hacked, 17 million users’ accounts compromised by data theft

Add as a preferred source on Google

Update: Zomato says it’s been able to “open a line of communication with the hacker” who has been “very cooperative with us.” It said the hacker wanted the company to “acknowledge security vulnerabilities in our system and work with the ethical hacker community to plug the gaps.” It added that the hacker has agreed to “destroy all copies of the stolen data” and remove it from the dark web marketplace, but continued to urge affected users to change their passwords as a precaution.

Early on Thursday, online restaurant guide Zomato revealed it’d been hit by hackers, estimating that login details had been stolen from 17 million of its 120 million users.

Recommended Videos

In a post on its site the India-based company said the “recent” discovery involved the theft of “email addresses and hashed passwords.” It insisted that no payment-related information had been nabbed in the attack as that data is held separately and wasn’t targeted.

However, the company said it would “strongly advise” all of its users to reset their passwords as a precautionary measure, and also to reset it with any other services where the same password is used. For the 17 million users Zomato could positively identify as having been directly affected, the company said it’d forced a password change and was notifying them of the move so they could then reset it themselves.

The service, founded in 2008, is a Yelp-like user-reviewed directory of more than 1.2 million popular restaurants, cafes, and bars in more than 10,000 cities across 24 countries, many of which are located in the United States. The service also offers food deliveries and lets you book tables. Digital Trends included Zomato in its “best apps” listings back in 2013.

Later on Thursday, Zomato updated its post, reminding its users that those who login via services such as Facebook and Google needn’t worry about the breach, as it holds no login information for such users. “We don’t have any passwords for these accounts; therefore, these users are at zero risk,” the company confirmed.

Zomato promised its users that “over the next couple of days and weeks” it’ll be working to “plug any more security gaps that we find in our systems,” while at the same time “further enhancing security measures for all user information stored within our database.”

So just to reiterate, if you’re a Zomato user, for peace of mind go and change your password now, as well as on any other services where you use the same password.

Trevor Mogg
Contributing Editor
Not so many moons ago, Trevor moved from one tea-loving island nation that drives on the left (Britain) to another (Japan)…
Your favorite Edge extension may stop working soon as Microsoft follows Chrome’s lead
Microsoft has announced the transition to Manifest V3, gradually phasing out older browser extensions.
Microsoft Edge on PC and Mobile Featured

Microsoft Edge is finally making the same controversial move that Google Chrome did earlier this year, and it could mean the end of some of the browser's most popular ad blockers. Microsoft has announced that Edge is officially transitioning its extensions ecosystem to Manifest Version 3 (MV3), Google's newer extension platform that promises better security, privacy, and performance. As part of that shift, the browser will gradually stop supporting older Manifest V2 (MV2) extensions over the coming months, meaning legacy extensions such as the original uBlock Origin will eventually stop working in Edge.

What is Manifest V3, and why is Microsoft adopting it?

Read more
Help, I’m talking to my computer. It’s remarkably convenient and utterly embarrassing.
Oh look, I have become the guy who randomly starts talking while staring at his computer.
Person using a laptop.

A decade ago, Google introduced voice typing with the Gboard app on Android, and a year later, the perk landed on iPhones with the keyboard app. I never paid much attention to it. The biggest reason was that it was just not accurate. 

The big promise was a whole new way of interacting with our phones, but it was never good enough to make me quit tapping, or swiping on an on-screen keyboard. Fast forward to 2026, I'm talking to my computer. In fact, this whole article was dictated and copy-pasted in WordPress. 

Read more
Cloudflare’s new browser Kitesurf is designed for AI agents to browse the internet
AI agents just got their own browser that lets them browse the internet more efficiently.
cloudflare-kitesurf-browser-for-ai

Cloudflare just entered the AI-browser race with a twist. Instead of building another Chrome alternative for people, the company launched Kitesurf, a cloud-hosted browser made only for AI agents. Since autonomous AI systems are increasingly the ones doing the actual browsing and scrolling online, Cloudflare just made its to claim that space.

https://twitter.com/Cloudflare/status/2085372860650913898

Read more