Instacart Data Breach
Instacart Grocery Delivery Service Breach (Salesforce, 2025): 39 Million Customer Email & Phone Records Exposed
Online grocery delivery and pickup service.
Risk Interpretation
Exposure enables phishing, order fraud, delivery impersonation, and household targeting. Grocery history and address data can also reveal family structure, routines, and cultural preferences.
Impact & Downstream Threats
The 2025 incident was part of the Scattered LAPSUS$ Hunters campaign affecting Salesforce cloud environments. Customer email addresses and phone numbers from Instacart were among data published by the group in October 2025. Instacart's response to this specific incident has not been extensively documented in public sources. It is one of more than 30 brands confirmed to have had customer contact data published in that campaign.
- SIM swap attacks where phone numbers are present
- Targeted phishing campaigns using exposed email addresses
Threat Vectors
Breach Intelligence
Executive Summary
Instacart, the U.S. grocery delivery marketplace, had customer data stolen and published by a threat actor calling itself "Scattered LAPSUS$ Hunters" as part of a broader attack campaign targeting Salesforce cloud environments in 2025. The breach affected 39.3 million records. The group released a sample of the stolen database on October 3, 2025, with the full dataset reportedly scheduled for public release on October 10, 2025. Instacart was one of more than 30 brands confirmed to have had customer data exposed in the same campaign. The exposed data includes full names, email addresses, phone numbers, and full mailing addresses, along with Instacart account details such as account type, shopper status, shopper IDs, subscription tier, and regional warehouse assignments. This combination of contact and account data is particularly sensitive because it links personal identifiers to home addresses and shopping behavior, which can reveal household routines, family composition, and consumer habits. Instacart's public response to this specific incident has not been extensively documented. Affected individuals face real risks from phishing attacks, delivery impersonation scams, and targeted fraud. Anyone who receives unexpected communications from parties claiming to represent Instacart should treat them with caution, verify through official channels, and watch for unsolicited contact referencing their address or order history.
About Instacart
Instacart is a U.S.-based grocery delivery and pickup marketplace that connects consumers with personal shoppers at partnering retail stores. The company is publicly traded on the Nasdaq following its 2023 IPO and operates primarily in the United States and Canada. It generates revenue through delivery fees, subscriptions, and advertising sold to consumer packaged goods brands through its platform.
Why They Hold Your Data
Grocery-delivery platforms collect customer identity, phone numbers, addresses, payment-adjacent data, order history, and delivery interactions across e-commerce and logistics workflows.
Recent Developments
Instacart went public in September 2023 and has spent the period since navigating the transition from high-growth startup to public company with investor pressure on profitability. The company has continued building out its advertising business as a higher-margin revenue stream. It has also expanded retailer partnerships and invested in faster delivery infrastructure. Financial performance has been a focus of public reporting, with Instacart managing competition from DoorDash, Uber Eats, and in-house delivery services operated by major grocery chains.
Data Points Exposed
Canonical Fields
email_address, phone_number
Dark Web Verification
- Dataset containing ~39.3M records identified in breach intelligence sources
- Data indexed and searchable across breach notification platforms
- Source: instacart-salesforce-2025
Recommended Actions
⚠️ Do not assume this is low sensitivity.
Protect Yourself
Check If You’re Affected
Enter your email to check if your data appears in this breach.
Get Free Breach Alerts
Be the first to know when new breaches are disclosed.
High-Risk? Get an Exposure Audit
Full-spectrum exposure audits for executives and public figures.
ObscureIQ Advisory
We combine proprietary dark web access with commercial and restricted breach intelligence to verify exposure and assess real-world risk.
- A public-facing individual
- A high-profile executive
- A customer of Instacart
- Or concerned about credential reuse
Powered by the ObscureIQ Breach Intelligence Database
© 2026 ObscureIQ · All Rights Reserved · Data Licensing
Latest from ObscureIQ
What Is Credit Monitoring? And Do I Want It? (Answer: Not Really)
Lock Down Browsers. Wipe Employee Footprints. Win Breach Wars.
Sextortion Spam
