Burger King Russia breach: 3.2 million customer records added to Have I Been Pwned

No passwords, no card details – but names, birthdates and phone numbers for millions of customers have surfaced two years after the fact, with no word from the company itself.

Padlock on laptop with light trails
Photo · FlyD / Unsplash

The claim

Have I Been Pwned (HIBP) has quietly added a new entry to its database: a breach attributed to Burger King’s Russian operation, running the site burgerkingrus.ru, affecting 3.2 million accounts. HIBP marks the breach as “verified”, meaning its own checks matched the leaked data against real, functioning accounts. The catch is the timeline: the breach itself is dated August 2024, but it only appeared on HIBP’s radar on 21 September 2026 - a gap of more than two years between the apparent theft and the public disclosure.

What was actually taken

According to HIBP’s listing, the exposed fields are dates of birth, email addresses, genders, geographic locations, names and phone numbers. Notably absent from that list: passwords, payment card numbers or order histories. That distinction matters. This isn’t the kind of breach that hands attackers the keys to your online banking or lets them log into other services using stolen credentials - there’s nothing here suggesting password reuse is the immediate danger.

What it is good for, in the wrong hands, is profiling and targeting. A dataset combining full names, birthdates, phone numbers, email addresses and rough location is exactly the raw material used for convincing phishing texts, “your order has an issue” scam calls, or SIM-swap style social engineering, where knowing a few real personal details makes a fake message far more believable.

So who is actually at risk

Anyone who signed up for an account, loyalty scheme or delivery service on burgerkingrus.ru is the relevant population here - not Burger King customers globally. Burger King’s Russian operation has run somewhat separately from the wider international brand for some time, and there’s nothing in the HIBP record or on the site itself confirming this incident is connected to any other Burger King market. UK Burger King customers who have never used the Russian site have no direct exposure from this specific dataset.

What we don’t know

This is where scepticism is warranted. There is no public statement from Burger King Russia acknowledging the incident, no evidence of customer notifications being sent, and no sign of regulatory involvement reported anywhere in the source material. HIBP’s “verified” tag confirms the data is real and matches genuine accounts - it does not confirm how the data was obtained, whether it has been fixed, or whether the company even knows about it yet. Given the two-year lag between breach date and disclosure, it’s entirely possible this data has already circulated in criminal circles for some time before reaching a public breach index.

What to do about it

If you’ve ever used burgerkingrus.ru, the practical step is to check your email address against HIBP and treat any unexpected calls, texts or emails referencing that account with suspicion, especially ones asking you to “verify” personal details or click a link. Since passwords weren’t part of the leak, there’s no urgent need to rotate credentials tied to this specific incident - though it’s always sound practice not to reuse passwords across sites regardless.

The takeaway

This is a real, verified data exposure affecting millions of accounts tied to Burger King’s Russian arm, but it’s contact and demographic information rather than anything that enables direct account takeover or financial fraud. The bigger concern is the silence around it: no confirmation, no notification, no regulator on record - which, for those affected, is arguably more telling than the breach itself.

Sources