Threat actors advertised multiple items on underground forums, including an alleged leak of a “Wendy’s International Franchise Database.” The dataset was described as containing franchise/location records (names, addresses, emails, coordinates) and operational metadata (hours, ordering/pickup/delivery flags, venue status, timezone/locale), with some records reportedly updated as recently as February 2026. Reporting also highlighted alleged exposure of technical and integration details, including Worldpay configuration elements (Apple Pay/Google Pay merchant IDs), Stripe pk_live publishable keys, and a Sentry DSN, which could increase risk via telemetry manipulation and infrastructure inference; the leak was also linked to a shared multi-brand ordering stack, with QikServe cited as likely underlying infrastructure, and no public confirmation from Wendy’s or the platform provider at the time of publication.
Separately, a threat actor listing advertised a low-cost ($30) alleged WhatsApp exploit/script claiming cross-platform disruption on Android and iOS, including app crash triggers, group chat freezing, and “call/video call bombing,” plus other spam/disruption features. The seller claimed the tool could be run without a VPS and with only a virtual number connection, suggesting low barriers to use and potential for nuisance/availability attacks against WhatsApp users if the claims are valid.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
On 2026-02-23, reporting on the alleged Wendy’s dataset said the exposed material appeared current through February 2026 and may include Worldpay configuration data, Stripe publishable keys, and a Sentry DSN. At the time of reporting, no public acknowledgment had been issued by Wendy’s US, Wendy’s UK, or The Access Group.
On 2026-02-23, SOCRadar published findings on several newly observed forum posts, including the alleged Wendy’s franchise database leak, the WhatsApp exploit listing, and two AI-themed services marketed for illicit use: “Origin GPT” and an automated AI outbound-calling platform. The report highlighted their potential use in hacking assistance, phishing, voice fraud, and social engineering.
By 2026-02-23, threat intelligence researchers observed a dark web forum post advertising a $30 script that allegedly crashes WhatsApp on Android and disrupts iOS chats, with added features such as call/video-call bombing and “pair spam.” The seller claimed the tool could be run via Termux on Android and operated using only a virtual phone number.
On 2026-02-22, a threat actor allegedly posted and offered for download a dataset described as the “Wendy’s International Franchise Database.” The listing claimed exposure of franchise operational data, contact and location details, and technical configuration material including payment integration information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
socradar.io
Open sourcecybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.