Why Restaurant Websites Get Hacked
A restaurant website looks like a small target. It is not. UK food businesses increasingly handle online ordering, table reservations, loyalty schemes, and customer payment data — and all of that makes them attractive to attackers who know that small hospitality businesses rarely invest in security.
The consequences of a breach are severe: payment card data exposed, ICO investigation, GDPR fines, and the kind of press coverage that empties a dining room. This guide explains the specific risks for UK restaurants, takeaways, and food businesses, and what to do about them.
The Specific Risks for Food Businesses
**Online ordering platforms** — if you use a third-party ordering platform (Just Eat, Deliveroo, Uber Eats), your main exposure is through your own website and the data those platforms share back with you. If you run your own ordering system — common for takeaways using WooCommerce or a custom platform — you are handling payment data directly and the risk is substantially higher.
**Table reservation systems** — plugins like OpenTable, ResDiary, or custom booking forms collect name, email, phone number, and sometimes dietary requirements. Dietary requirements are special category data under UK GDPR, which means a breach attracts higher ICO scrutiny and potentially higher fines.
**Customer databases and loyalty schemes** — email marketing lists, loyalty point balances, and customer order history are all personal data. A database containing a few thousand customer records represents real GDPR exposure.
**WordPress vulnerabilities** — many restaurant websites run on WordPress with page builder themes. Outdated plugins, default admin credentials, and unpatched themes are among the most common entry points attackers use against small business websites in the UK.
**Card skimming (Magecart attacks)** — if your website processes payments directly, attackers can inject malicious JavaScript that silently copies card details as customers type them. This is called a Magecart or formjacking attack. It is invisible to the restaurant and the customer until cards start being used fraudulently.
What UK GDPR Requires From Food Businesses
Under the UK GDPR and the Data Protection Act 2018, any business collecting customer data is required to:
- Implement appropriate technical security measures to protect that data - Report a data breach to the ICO within 72 hours of becoming aware of it - Only collect data you actually need (data minimisation) - Have a clear privacy policy explaining what data you collect and how you use it - Obtain valid consent before sending marketing emails
The ICO does not give small businesses a free pass. Enforcement actions have been taken against small hospitality operators. The scale of a fine is proportional to turnover, but even a small fine combined with the reputational damage of a public breach can seriously harm a food business.
Common Security Weaknesses in Restaurant Websites
**Outdated WordPress plugins** — booking plugins, WooCommerce extensions, and gallery plugins that have not been updated in months are a primary attack vector. Attackers scan the internet for known vulnerable plugin versions and target them automatically.
**Weak admin credentials** — the WordPress admin username "admin" with a simple password is guessed within seconds by automated tools.
**No SSL certificate or expired certificate** — all modern websites should run on HTTPS. A missing or expired SSL certificate means customer data submitted through contact forms, booking systems, and payment pages is transmitted unencrypted.
**Missing security headers** — HTTP security headers like Content-Security-Policy, X-Frame-Options, and Strict-Transport-Security defend against cross-site scripting and clickjacking attacks. Most restaurant websites do not have them configured.
**Exposed admin panels** — /wp-admin and /wp-login.php are publicly accessible by default. Without IP allowlisting or two-factor authentication, they are a brute-force target.
**Unprotected contact and booking forms** — forms without rate limiting or CAPTCHA can be abused to send spam, extract data, or test credentials.
Practical Steps for Restaurant Website Security
**Keep WordPress and all plugins updated** — enable automatic minor updates and check for major updates weekly. Remove plugins you are not using. Every inactive plugin is a potential vulnerability.
**Use strong, unique admin credentials** — change the admin username from "admin" to something unique. Use a password manager to generate and store a strong password. Enable two-factor authentication on your WordPress admin account.
**Install a security plugin** — Wordfence or Solid Security (formerly iThemes Security) add firewall rules, login protection, and file integrity monitoring to WordPress sites. A free tier is sufficient for most small restaurants.
**Use a reputable payment gateway** — never process card details directly on your own server if you can avoid it. Use Stripe, Square, or PayPal, which are PCI DSS compliant and handle card data on their infrastructure, not yours.
**Enable HTTPS and check your SSL certificate** — most hosting providers include a free Let's Encrypt certificate. Check that it is installed, not expired, and that your site redirects all HTTP traffic to HTTPS.
**Back up your website** — take weekly backups of both your WordPress files and database, and store them off-server. If your site is compromised or defaced, you need to be able to restore it quickly.
**Audit your contact and booking forms** — confirm that form submissions are only stored as long as necessary, that dietary and health-related data is treated as sensitive, and that you have a process for honouring data deletion requests.
What to Do If Your Restaurant Website Gets Hacked
If you discover or suspect a breach:
1. Take the site offline immediately to prevent further data exposure 2. Contact your hosting provider — they may be able to restore from a clean backup 3. Change all admin passwords immediately 4. If customer payment data or personal data may have been exposed, you are legally required to notify the ICO within 72 hours: report at ico.org.uk 5. Notify affected customers if there is a high risk of harm to them 6. Do not relaunch the site until you have identified how the attacker got in and closed that route
Running a Security Scan on Your Restaurant Website
Before a problem occurs, it is worth understanding your current exposure. Yrzo AI performs 44 automated security checks on your website — covering SSL configuration, security headers, plugin vulnerability indicators, admin panel exposure, cookie security, and more — and delivers a plain-English report explaining what needs fixing.
For a restaurant handling customer bookings and marketing data, a scan costs £99 and takes under 20 minutes. It is the fastest way to know whether your website has obvious weaknesses that could lead to a breach, an ICO investigation, or both.
Run your scan at yrzoai.dev.
Find out if your website has these vulnerabilities
Yrzo AI runs 44 automated security checks and delivers a full report in under 20 minutes. Starting from £399.
Scan your website →