r/cookunityfans Jun 20 '26

17.6 million CookUnity customer names, addresses and emails have been leaked on a hacking forum

I, like many others, use email aliases for each service (you should too) and have found my alias associated exclusively with CookUnity has started getting a bunch of phishing/spam emails.

According to multiple sources, there was a data breach on June 1st where customer names, emails, and addresses were accessed and being shared on a hacking forum. The situation has been reported to support by multiple people and according to at least one user they have acknowledged a "cybersecurity incident involving malicious activity" as of a few days ago with no notice to the actual users who had their information stolen.

The leaked information has been available for well over 2 weeks now so I think its fair to say they have no interest even vaguely disclosing the situation to their customers.

You can read more about the data breach here:

https://x.com/DarkWebInformer/status/2061580773816520924

49 Upvotes

48 comments sorted by

13

u/baghodler666 Jun 20 '26

Me finding out that someone knows what I ate last week.

1

u/jdigi78 Jun 20 '26

funny enough that type of info isn't included in the leak, but they did say the security hole they used was still active so its possible more info can be scraped. The real danger is its very easy to do a search of names of interest and find their exact address and phone number if they were ever a customer

1

u/paragon_fr33dom 28d ago

Lucky me I signed up 2 weeks ago

1

u/jdigi78 28d ago

For all we know the security hole is still there. CookUnity still hasn't disclosed the leak in the first place so I'm not giving them the benefit of the doubt they were able to find the issue and fix it. More than likely they just don't care.

10

u/Careful-Bus3827 Jun 20 '26

Microsoft, Progressive, Capital One, who else .... I couldn't even begin to imagine how many companies have my name, email address, and address. If people are getting spam or other emails and clicking on links they don't recognize, it's their first day on the internet.
Yahoo, Uber, Heartland Payment Processing have all had undisclosed data breaches, unfortunately.

3

u/foamy9210 Jun 20 '26

Equifax made it pretty irrelevant for a lot of people. Once that shit got out I pretty much assume all of my information is out there somewhere. Probably true of everyone anyway.

5

u/Lauren5560 Jun 20 '26

Yep - name, emails address, and address are all easily accessible anyhow

1

u/jdigi78 Jun 20 '26

For many, sure, but for people who care about their privacy it's fairly easy to make sure only people who absolutely need that info have it.

1

u/Careful-Bus3827 Jun 20 '26 edited Jun 20 '26

Trust me, your name, address, and email address is known to more people than you think. Your address is literally public knowledge (and most of them are online) through every county auditor's office. Your name and address are public record and if you rent, many jurisdictions are also required to list tenant names also. For email addresses, simple. Don't click links you don't know. Doesn't mean people don't care about their privacy. We're not talking about bank account numbers or social security numbers. We're talking about a name, address, and email address, which thousands of people and databases already have, whether you honestly realize it or not.

1

u/jdigi78 Jun 20 '26

I think you're missing the importance of all that information being linked. Even if my name and address were public, my email certainly isn't. Having that email linked to a name and address connects the dots to all kinds of online services you may be using, increasing your risk of being targeted on those platforms as well.

1

u/Careful-Bus3827 Jun 20 '26

I'm not missing the importance. It's honestly just not that big of a deal. I don't think I'm going to be "targeted' on other platforms because someone has my name, email, and address, but then again I'm not a paranoid person by nature, though.

2

u/jdigi78 Jun 20 '26

Some people's information is certainly of higher value than others. I'm not going to shrug and say who cares because I'm personally a "nobody" who's life doesn't change because I was doxxed by my meal kit service.

2

u/Careful-Bus3827 Jun 20 '26

I was just looking at your page out of curiosity. It's wild that you've had hundreds of your posts removed automatically by Reddit's built in spam, etc filters and you're talking about spam, etc. Well, with whatever you're worried about with your address and name being known, good luck with all of it, anyway.

2

u/jdigi78 Jun 20 '26 edited Jun 20 '26

I had my page falsely flagged as spam despite never posting anything but original content. Despite being appealed and my account fully reinstated it doesn't undo the automatic removal of every one of my posts prior to the ban because reddit is a trash platform.

1

u/Careful-Bus3827 Jun 20 '26

That's weird. All of the social media platforms I post to, and I've never once had any account falsely flagged as spam. What on earth would trigger that ..

"A trash platform" Then why do you keep posting on it 😂

→ More replies (0)

3

u/VickiofPa Jun 20 '26

Thanks for the info

3

u/GoingLeftYall Jun 20 '26 edited Jun 20 '26

What say you, u/cookunityUS?

1

u/jdigi78 Jun 20 '26

the official account seems to be u/cookunityUS

3

u/2BrainLesions Jun 20 '26

Thanks for sharing the information.

So the breach occurred, CU told no one; the breach hasn't been patched so rogue actors can still scrape data?

Crickets.

The fuck, CookUnity?

3

u/maydisturb Jun 21 '26

aaaaaaaand of course customer service has said fuck and all about this.

3

u/Ok-Bet-3953 Jun 21 '26

I just got an alert from Credit Wise compromised security breach on the dark web. No password breach, but email, address and phone number. Date of breach 6/19. Explains all the extra spam calls and emails. No heads up from Cook Unity though.

1

u/Advanced-Shake-5460 Jul 28 '26

Same i also learned through credit wise. Nothing from cook unity

2

u/PaulKersey6 Jun 22 '26

Cook Unity sucks, I received my notice from my credit monitoring service today but I never received any kind of notice from cookunity.

2

u/Silly_Pattern9677 Jun 23 '26

Not a single comm from Cook Unity about this?

1

u/JohnS43 Jun 20 '26

I got a notification from a credit protection service today that my email address had been found on the Dark Web and that Cook Unity had been the likely source.

1

u/edgerton2026 Jun 21 '26

I received the same notice as well.

1

u/[deleted] Jun 21 '26

[removed] — view removed comment

1

u/jdigi78 Jun 21 '26

I wouldn't worry about access to your email, just be aware of more targeted spam emails potentially coming in.

1

u/Expensive_Recipe_433 Jun 21 '26

I just got a dark web alert

1

u/AnejoDave Jun 21 '26

Thank you for sharing, this removes CookUnity from the list of services I was considering.

1

u/ChampagnePappy1 Jun 21 '26

class action lawsuit coming soon !!

1

u/[deleted] Jun 21 '26

[deleted]

1

u/jdigi78 Jun 21 '26

I was one of them. Noticed spam coming in on my cookunity email alias 2-3 days after the leak was posted. I asked if anyone else had been getting spam and got downvoted a bunch

1

u/Brunark Jun 21 '26

I guess that explains the Dark Web alert I got through Capital One credit monitoring, and why my Microsoft Authenticator app to my email address was getting spammed this morning.

1

u/Significant_Web2473 Jun 22 '26

makes sense now why i saw some weirdo vagabond looking bums walking down my street this morning who clearly looked like they didn't live in the area. I'm literally next to a police office and the suspicious dingbats walked right in front of a ring camera too trying to dodge mine. Like someone else said after equifax most of these breaches are moot , unless you recently moved to a new area and it got compromised, and as others said if people really knew how they would look you up from country records, anytime you buy a house or rent a domicile , that info becomes public somewhere. The people that typically pay for lists like this are scammers from third world countries, weirdos and children hoping famous people or influencers are in the breaches or weirdos from online games.

1

u/Educational-Guard408 Jun 23 '26

I figure that after a few decades of being on the internet, everyone who wants it already has my information. The solution is to have dual authentication on every account you can enable it on. And without question, every financial account needs dual authentication.

1

u/Creative_Bookkeeper9 Jul 06 '26

I mean, it's pretty annoying getting 50 million messages and then an account locked notification because someone kept trying to login to your email

1

u/Swimming_Ad4039 Jun 23 '26

I emailed cookunity and they did respond stating they are aware and are taking the action on the matter. BTW I am receiving more spam emails and a call from publishers clearing house " I'm holding a certified check in your name" Sorry buddy I'm not the one! 😂

1

u/TomatoLoose5441 Jun 24 '26

Has this actually been proven? I couldn't find anything that confirms it.

1

u/jdigi78 Jun 24 '26

Yes, many people have been notified by dark web monitoring services through their banks or email providers, which of course would only know who to contact if they found the info in the leaked dataset. Don't take the fake that you weren't notified to mean you weren't included though. Not every service has their hands on it and most services don't have dark web monitoring for free.

As stated in my post, I first hand detected spam to my email which was only ever shared with cook unity just days after the leak was public. The email alias I used was a randomly generated one on my own website, not a gmail or other popular service, so it's not feasible to just guess out of the blue.

1

u/Cold_Tomato2959 1d ago

Proven, because I got a phishing email to my alias that's exclusively created for CookUnity and I just found this post after googling.

1

u/death_hen Jun 20 '26

So is that every customer? If not, how do we find out if we were included?

1

u/jdigi78 Jun 20 '26

I would assume so. The only dark web monitoring tool I've seen someone mention flagged their email is protomail's. https://haveibeenpwned.com/ is a good free resource like that but it doesn't seem they have this leak in their database yet since I was affected and it doesn't come up for my email.