Restaurant patrons of businesses using HungerRush reported receiving mass extortion emails sent from spoofed/abused @hungerrush.com addresses, warning that restaurant and customer data could be exposed if the company does not respond. The actor claimed access to “millions” of customer records including names, emails, passwords, addresses, phone numbers, dates of birth, and payment card data. Email header analysis indicated the messages were delivered via Twilio SendGrid infrastructure (including o10.e.hungerrush.com / 159.183.129.119), which recipients said had previously been used for legitimate HungerRush receipt emails—suggesting compromise or misuse of HungerRush-linked email-sending capabilities.
Separately, Pathstone Family Office was alleged to have been breached by the ShinyHunters extortion group, which claimed to have exfiltrated 641,000 records containing PII and internal corporate documents and set a deadline for response before publication. As of reporting, Pathstone had not confirmed an incident and ShinyHunters had not released sample data to substantiate the claim; if validated, exposure could include sensitive client and corporate materials (e.g., legal and estate planning documents, contracts) with downstream risks of fraud, impersonation, and reputational harm.

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
Header analysis showed the extortion emails were sent through Twilio SendGrid infrastructure and passed SPF, DKIM, and DMARC checks for the hungerrush.com domain. This suggested the sender may have had access to authorized email-sending infrastructure or compromised credentials.
Customers of restaurants using the HungerRush POS platform reported receiving extortion emails threatening exposure of restaurant and customer data unless HungerRush responded. The messages claimed the attacker held records on millions of customers, including sensitive PII and payment card data.
The extortion group said Pathstone had until March 2 to respond before the stolen data would be published. The threatened exposure reportedly included legal and estate planning documents, financial structures, and client contracts if the claim were genuine.
ShinyHunters allegedly listed Pathstone Family Office as a victim and claimed to have exfiltrated 641,000 records containing personally identifiable information and internal corporate documents. No sample data was provided to validate the claim, and Pathstone had not confirmed a breach.
Hudson Rock's Alon Gal said infostealer logs indicate a HungerRush employee device was infected in October 2025, allegedly exposing numerous corporate credentials. The reported compromise was cited as a possible precursor to later extortion activity, though no direct link was confirmed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcebleepingcomputer.com
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.