ZoomShift Allegedly Breached With Employee and GPS Clock-In Data Exposed

A threat actor claims to have breached workforce management platform ZoomShift, alleging theft of employee information, event logs, and GPS clock-in data.
Screenshot of a forum post alleging a data breach involving ZoomShift. The post claims to offer datasets containing user information and event logs, lists alleged data categories, and includes a download link that has been redacted by BreachNews.
Forum post claiming a breach of ZoomShift and alleging the theft of employee scheduling data, user information, and event logs.

A threat actor has claimed to have breached workforce management platform ZoomShift, alleging the theft of user information and activity logs from the employee scheduling service. The claims have not been independently verified.

Unlike many newly posted breach claims, the actor published what is purportedly the stolen data. BreachNews reviewed portions of the alleged dataset and found records containing user profile information alongside millions of analytics and event log entries. While the data appears internally consistent and aligns with the forum post’s description, BreachNews could not independently verify that it originated from ZoomShift.

Claim centers on employee scheduling platform

ZoomShift provides employee scheduling, time tracking, and workforce management tools used by restaurants, retailers, and hospitality organizations.

According to the forum post, the alleged breach includes approximately 866,000 records containing user information and more than 4.1 million event log entries.

BreachNews’ review found records containing email addresses, internal user and company identifiers, account roles, subscription plans, billing terms, organization size, industry classifications, time zones, device identifiers, IP addresses, country, city, region, referral information, page activity, timestamps, and analytics metadata associated with application usage. BreachNews is not publishing sample records or personally identifiable information contained in the archive.

Large volume of analytics data

Much of the alleged dataset consists of application telemetry recording page views and user activity, including timestamps, URLs, device identifiers, and approximate geographic information associated with user sessions. If authentic, the combination of account information and behavioral data could provide valuable intelligence for phishing, account targeting, or social engineering campaigns.

Second dataset posted by same forum account

The ZoomShift listing was followed by another alleged breach published by the same forum account involving mobile pet grooming platform Groomit. Both posts claim to contain structured JSON datasets with user profile information, device metadata, and analytics-related fields. There is currently no evidence linking the two alleged incidents beyond their publication by the same account.

No public confirmation

The forum account behind the claim has limited posting history, and ZoomShift had not issued any public statement regarding the alleged breach at the time of publication.

Although the published archive appears internally consistent and matches the categories described in the forum post, its authenticity and origin remain unverified. BreachNews will update this article if ZoomShift confirms an incident or additional evidence emerges.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site