On July 2, 2025, the ransomware group blacknevas added the Lithuanian restaurant chain Čili to its leak site, claiming that it had exfiltrated internal files containing customer data from the company behind cili.lt and its mobile ordering app.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Cili
Get alerted the next time Cili files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Cili’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details of the Breach
Public reporting indicates that Čili, which operates restaurants, bistros, coffee shops and drive-ins across Lithuania and Latvia, suffered a ransomware attack in which attackers copied internal databases. The exposed information includes customer addresses, email addresses, mobile phone numbers, shopping history and banking card details. The exact number of affected customers remains unknown. The group published proof of the exfiltration on its dark-web leak site, following its standard practice of posting stolen data when victims do not meet ransom demands.
Why This Matters for You and Your Family
When a restaurant chain you order from loses control of names, addresses, phone numbers and payment card data, the risk reaches beyond that single company. Addresses and mobile phones can be used to locate you or your family members. Email addresses and passwords reused from other services become immediate targets for account takeovers. Shopping history reveals patterns that help attackers build convincing phishing messages. If your children use the same email or phone number for their gaming accounts, those profiles can be linked back to your household address within minutes. A single breach like this can quietly feed months of identity theft, spam, scams and physical risks if the data spreads across criminal marketplaces.
The Doxxing and Identity-Chain Risk
Attackers rarely stop at one database. They combine the Čili records with information from earlier breaches to create an identity chain that links your email, phone, home address, family names and online handles. Once that chain exists, doxxing becomes straightforward: an attacker can publish your address alongside your children’s usernames or expose your full shopping history to embarrass or intimidate you. Credential leaks of this type frequently cascade into gaming account takeovers, because children often reuse the same passwords or recovery phone numbers that appear in adult-facing breaches. The result is a widening circle of exposure that can affect every member of the household.