However the article is unnecessarily sensationalist in banding around GDPR data breaches. Much of the article intimates there has been a Deliveroo data breach, whereas in fact the most likely explanation is attackers reusing passwords leaked from other breaches. This is acknowledged towards the end of the article but quickly glossed over.
If consumers are reusing exposed passwords this makes life tricky for Deliveroo. Maybe they should be using Troy Hunt's "Pwned passwords" to protect new user signups:
https://www.troyhunt.com/ive-just-launched-pwned-passwords-v...