Brazil’s Food-Delivery Giant iFood Faces Scrutiny After Data Breach Exposes 1.2 Million Users

Brazil’s leading food-delivery platform, iFood, has revealed that personal information belonging to about 1.2 million users was exposed in a cyberattack.

The company said the breach involved customers’ full names and CPF numbers, Brazil’s taxpayer identification number that is commonly used as a personal ID. iFood stated that no passwords or payment card information were affected.

The incident took place in December 2025, but the company only disclosed it on June 3, 2026, nearly six months later.

iFood defended the delay, saying Brazilian data-protection rules do not require companies to notify users if an incident is not considered to pose a significant risk or harm. However, the decision has sparked debate, with critics questioning whether the exposure of CPF numbers should be treated as low risk.

The company handles around 120 million orders every month and serves about 60 million customers across more than 1,500 cities in Brazil. The affected users represent roughly two percent of its customer base.

Cybersecurity experts warn that CPF numbers can be used by criminals for identity fraud and scams, making the leak a serious concern for affected users.

iFood said it has taken steps to strengthen its security systems and is cooperating with authorities.

The incident is expected to draw attention from Brazil’s data-protection regulator as questions grow over the company’s handling of the breach and the six-month delay in informing the public.

About The Author

Leave a Reply

Your email address will not be published. Required fields are marked *