
Researchers found Hungry Lion-linked customer credentials in stealer logs over about nine months, alongside a separate MedusaLocker ransomware claim.
A cyber incident involving the fast-food chain has produced two different security stories that should not be collapsed into one.
First, the fast-food chain has been named on a MedusaLocker ransomware leak site, where the group claims to hold data taken from the company. Second, security researchers have identified credentials associated with Hungry Lion's consumer-facing web portals in stealer-log data stretching from October 2025 to July 2026.
Those facts are concerning. They do not, however, prove that the customer credentials came from a breach of Hungry Lion's corporate network.
That distinction matters because credential-stealing malware often runs on customers' own devices. A compromised laptop or phone can leak usernames and passwords for websites the victim uses without the website operator itself being hacked.
SOCRadar said it identified 23 records associated with Hungry Lion's South African domain: 13 customer accounts and 10 numerical IDs whose profile type could not be determined. The records were tied to consumer-facing self-service portals and covered roughly nine months.
The security company's interpretation is that the data points to a customer account-takeover risk, not evidence of direct compromise of Hungry Lion's corporate systems.
Separately, the MedusaLocker ransomware group has claimed data from the company. Researchers have cautioned that the gang's leak-site description is the attacker's claim and has not been independently verified in full.
There is also disagreement about what the ransomware incident exposed. Analysis cited by KnowBe4 Africa suggests point-of-sale records may be involved rather than customers' personal information.
For customers, the practical risk is straightforward: reused passwords can turn a credential stolen on one infected device into access across multiple accounts. Changing that password is useful, but changing the same password anywhere else it was reused is more important.
For the company, the legal question is more complicated. POPIA requires notification where there are reasonable grounds to believe personal information held by a responsible party has been accessed or acquired by an unauthorised person.
Determining whether that threshold has been crossed requires knowing what data was actually accessed, where it came from and whether Hungry Lion's own systems or processors were involved.
Hungry Lion says on its website that it uses cryptographic techniques and access controls to protect customer information and that it will notify affected customers as soon as practicably possible where it believes unauthorised access may have occurred, unless law enforcement or regulators prevent it.
The incident is a useful reminder that online ordering and loyalty systems are now part of a restaurant chain's security perimeter, even when the initial compromise happens outside its network.
These platforms collect names, contact details, order histories and account credentials. That makes them valuable to criminals and creates account-takeover risk when passwords are harvested elsewhere.
Companies cannot stop every customer device from being infected with infostealer malware. They can reduce the consequences through multifactor authentication, breached-password detection, rate limiting, suspicious-login monitoring and forced resets when credential dumps surface.
The Hungry Lion case is therefore not neatly described as either "the company was hacked" or "nothing happened". There is a ransomware claim, there is evidence of customer credentials circulating, and there are still unanswered questions about how those two things relate.
Until those questions are resolved, precision matters more than a dramatic breach headline.
Source: SA Tech News




