Low Calories Allegedly Breached, Exposing Customer, Subscription and Invoice Data Across the Middle East

A cybercriminal claims to have breached Low Calories, a meal subscription and delivery service operating across Egypt, Saudi Arabia, and the UAE, and is allegedly offering access to customer and business information.

According to the claim, the information allegedly obtained includes customer names, phone numbers, email addresses, physical addresses, subscription details, meal plans, delivery schedules, driver information, subscription status, and invoice and billing information.

The claimed data also includes payment details, discounts, taxes, branch information, thousands of invoice images, and other internal documents. The cybercriminal has reportedly published sample invoice images as alleged evidence of the compromise.

Why This Matters

The main concern is not only the information itself, but how different pieces of data could be combined and used against customers.

For example, if criminals know a customer’s name, address, meal plan, recent delivery information, and invoice details, they could potentially create highly convincing phishing messages or impersonate the service.

A message that refers to a real order or delivery may appear much more trustworthy than a typical scam message. This could increase the risk of targeted phishing, impersonation, and fraud.

What Customers Should Do

Customers should be cautious with unexpected calls, WhatsApp messages, emails, invoices, payment requests, and links that appear to come from the service.

If a suspicious message is received, do not click the included link to verify it. Instead, open the official Low Calories app or website directly and check the account or order information there.

Customers should also never share passwords, one-time passwords (OTPs), or payment information simply because someone appears to know their personal or order details.

Important Verification Notice

The reported breach, the data allegedly obtained, and the reported contents of the information have not been independently verified. They should therefore be treated as claims until confirmed by Low Calories or another reliable and independent source.

The incident is a reminder that personal information does not need to include a password to become valuable to cybercriminals. When different pieces of customer information are combined, they can potentially be used to make scams appear legitimate and much harder to recognize.