Groomit Allegedly Breached With Customer Data Claimed Exposed

A threat actor claims to have breached Groomit, publishing a dataset containing customer information that BreachNews reviewed but could not independently attribute to the company.
Screenshot of a forum post alleging a data breach involving Groomit. The post claims approximately 43,870 customer records containing personally identifiable information, lists the alleged data categories, and includes a download link that has been redacted by BreachNews.
Forum post alleging a breach of Groomit and claiming the theft of approximately 43,870 customer records containing contact information, device metadata, and analytics data.

A threat actor has claimed to have breached Groomit, a mobile pet grooming platform that connects customers with professional groomers across the United States and Canada. The claims have not been independently verified.

Unlike many low-detail breach posts, the actor published what it claims is the stolen dataset. BreachNews reviewed the archive and confirmed it contains approximately 43,870 JSON records with a consistent structure matching the categories described in the forum post. However, BreachNews could not independently verify that the data originated from Groomit.

Dataset contains customer profile information

According to the forum post, the alleged dataset contains approximately 37,323 unique email addresses and more than 15,500 customer profiles with combinations of names, phone numbers, and postal codes.

BreachNews’ review of the archive found records containing fields for email addresses, first and last names, phone numbers, ZIP or postal codes, city, country, region, IP addresses, internal user identifiers, referral codes, signup dates, anonymous analytics identifiers, and device metadata including operating system, platform, language, and carrier information.

The records also include analytics metadata consistent with customer signup and application activity. BreachNews is not publishing sample records or personally identifiable information contained in the archive.

Second dataset posted by same forum account

The Groomit listing follows another alleged breach published earlier the same day by the same forum account involving workforce management platform ZoomShift.

Both posts claim to include structured JSON datasets containing user profile information, device metadata, and analytics-related fields. At present, there is no evidence linking the two alleged incidents beyond their publication by the same account.

No public confirmation

The forum account responsible for the post has limited posting history, and Groomit had not issued any public statement regarding the alleged breach at the time of publication.

Although the published archive appears internally consistent and aligns with the actor’s description, its authenticity and origin remain unverified. BreachNews will update this article if Groomit confirms an incident or additional evidence emerges.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site