A threat actor has claimed to have breached workforce management platform ZoomShift, alleging the theft of user information and activity logs from the employee scheduling service. The claims have not been independently verified.
Unlike many newly posted breach claims, the actor published what is purportedly the stolen data. BreachNews reviewed portions of the alleged dataset and found records containing user profile information alongside millions of analytics and event log entries. While the data appears internally consistent and aligns with the forum post’s description, BreachNews could not independently verify that it originated from ZoomShift.
Claim centers on employee scheduling platform
ZoomShift provides employee scheduling, time tracking, and workforce management tools used by restaurants, retailers, and hospitality organizations.
According to the forum post, the alleged breach includes approximately 866,000 records containing user information and more than 4.1 million event log entries.
BreachNews’ review found records containing email addresses, internal user and company identifiers, account roles, subscription plans, billing terms, organization size, industry classifications, time zones, device identifiers, IP addresses, country, city, region, referral information, page activity, timestamps, and analytics metadata associated with application usage. BreachNews is not publishing sample records or personally identifiable information contained in the archive.
Large volume of analytics data
Much of the alleged dataset consists of application telemetry recording page views and user activity, including timestamps, URLs, device identifiers, and approximate geographic information associated with user sessions. If authentic, the combination of account information and behavioral data could provide valuable intelligence for phishing, account targeting, or social engineering campaigns.
Second dataset posted by same forum account
The ZoomShift listing was followed by another alleged breach published by the same forum account involving mobile pet grooming platform Groomit. Both posts claim to contain structured JSON datasets with user profile information, device metadata, and analytics-related fields. There is currently no evidence linking the two alleged incidents beyond their publication by the same account.
No public confirmation
The forum account behind the claim has limited posting history, and ZoomShift had not issued any public statement regarding the alleged breach at the time of publication.
Although the published archive appears internally consistent and matches the categories described in the forum post, its authenticity and origin remain unverified. BreachNews will update this article if ZoomShift confirms an incident or additional evidence emerges.












