Legal News

Hungry Lion: Customer Data Exposed 9 Months, POPIA Notification Likely

South Africa·Briefly Analysis⏱️ 4 min read

Summary

  • Hungry Lion customer credentials were reportedly exposed online for approximately nine months, impacting consumer-facing web portals.
  • Cybersecurity firm SOCRadar identified 23 records, including 13 customer accounts, suggesting a risk of customer account takeovers stemming from consumer device compromises.
  • The MedusaLocker ransomware group separately claimed a breach of Hungry Lion, alleging access to point-of-sale system data across multiple African locations.
  • The sustained exposure necessitates an assessment of customer notification obligations under South Africa's Protection of Personal Information Act (POPIA).
  • The incident highlights the need for companies to review web portal security and online ordering infrastructure to prevent account takeover risks and ensure POPIA compliance customer credentials.

Customer Credentials Exposed for Months

The sustained exposure of these credentials warrants a critical assessment of whether customers require notification under the Protection of Personal Information Act (POPIA).

Customer credentials associated with Hungry Lion's online portals were reportedly exposed for approximately nine months, according to findings by cybersecurity researchers. This prolonged exposure of Hungry Lion customer data was identified by firms analyzing stealer-log data, which revealed compromised accounts linked to the fast-food chain's consumer-facing web services.

Separately, the MedusaLocker ransomware group claimed a successful attack against Hungry Lion, listing the company on its leak site. MedusaLocker, a ransomware-as-a-service operator, asserted possession of data from a fast-food franchise with 111 locations across South Africa, Botswana, Namibia, Zambia, Zimbabwe, Lesotho, and Mauritius. The group specifically mentioned three point-of-sale (POS) systems: Unity POS (242MB monthly), GAAP POS (daily), and CoSoft POS (145 terminals in Botswana). Cybersecurity website GalaxyWarden quoted this claim directly from MedusaLocker's leak site, noting that it had not been independently verified.

Nature of the Exposure and Conflicting Views

Cybersecurity company SOCRadar's analysis of stealer-log data uncovered 23 distinct records tied to Hungry Lion's .co.za domain. These included 13 identifiable customer accounts and 10 additional numerical IDs whose profile types could not be definitively determined. All these records were linked to the company's consumer-facing web self-service portals and were dated between October 2025 and July 2026, indicating a continuous nine-month period of exposure. SOCRadar concluded that these exposed credentials primarily suggest a risk of customer account takeover rather than a direct breach of Hungry Lion's internal corporate network, with the concentration of data around customer portals pointing to compromises originating from consumers' own devices.

However, KnowBe4 Africa presented a different interpretation of the incident, based on an initial analysis by cybersecurity firm DarkNotify. Their assessment suggested that the ransomware attack impacting Hungry Lion primarily exposed point-of-sale records, rather than personal customer information. SOCRadar also noted that the credential exposure it identified does not explain how MedusaLocker might have gained access to Hungry Lion's systems for its claimed ransomware attack, highlighting that MedusaLocker typically releases stolen data if ransom demands are not met. The targeting of a retail company like Hungry Lion, heavily reliant on customer engagement and data, represents a slightly different profile compared to the more industrial or public sector entities MedusaLocker has recently targeted.

POPIA Compliance and Security Implications

The sustained exposure of these credentials warrants a critical assessment of whether customers require notification under the Protection of Personal Information Act (POPIA). Given that Hungry Lion's online ordering platform and loyalty program aggregate significant customer personal data, the company's systems become an attractive target for threat actors seeking sensitive information. This incident underscores the broader South Africa data exposure legal implications for businesses handling consumer data.

Beyond immediate notification duties, the situation compels a review of Hungry Lion's web portal and online ordering infrastructure to mitigate future risks. The potential for customer account takeover risk, even if originating from customer-side compromises, highlights the need for robust security measures. Anna Collard, SVP content strategy and CISO advisor at KnowBe4 Africa, emphasized that such incidents reveal an organization's post-breach behavior, stressing the importance of fostering a culture where employees feel safe reporting errors quickly to limit damage, rather than facing formal warnings that discourage transparency.

Practical Implications

This incident compels South African legal and compliance professionals to assess their clients' POPIA notification obligations in cases of sustained customer credential exposure, even if originating from customer-side compromises. It also underscores the need to review web portal security and online ordering infrastructure to prevent similar account takeover risks and potential regulatory scrutiny.

Source

Source: Original reporting via cybersecurity researchers

Get Deeper AI analysis

How does this affect you?

Get an AI analysis of this article grounded in your jurisdictions, practice areas, and any policy documents you've uploaded to Wansom.

Get The Latest Legal & Regulatory intelligence in South Africa

Finish Reading the Full Story and the Expert Analysis.

No Credit Card Required.Enter Email to Subscribe

Already have an account? Log in

Wansom is AI and can make mistakes.