Panera Bread Data Breach - 5.1 Million Accounts Exposed

Panera Bread Data Breach (TL-2026-0031), also tracked as Panera Data Breach, is a medium-severity data breach scored CVSS 6.5, first published 2026-02-02. It is attributed to ShinyHunters (Russia) with high confidence, affects Panera Bread MyPanera Loyalty Program, maps to 17 MITRE ATT&CK techniques (T1003, T1005, T1021), and is covered by 12 detection rules and 40 indicators of compromise.

Key facts for TL-2026-0031

Threat ID
TL-2026-0031
Also known as
Panera Data Breach, Panera Bread Breach 2026
Severity
MEDIUM
CVSS
6.5 (N/A - Data Breach)
Status
MONITORING
Category
DATA_BREACH
First published
2026-02-02
Last reviewed
2026-02-02
Attribution
ShinyHunters
Attribution confidence
HIGH
Nation-state nexus
Russia
Motivation
FINANCIAL
Target sectors
Retail, Food & Beverage, Hospitality
Target regions
North America
Detection rules
12
Indicators of compromise
40

Panera Bread, a major US restaurant chain with 2,100+ locations and $5.9B annual revenue, suffered a ransomware attack that encrypted critical systems and exfiltrated data affecting approximately 5.1 million customers and employees. The attack disrupted operations for multiple days, affecting point-of-sale (POS) systems, online ordering, mobile app, loyalty program (MyPanera with 52M+ members), internal communications, and supply chain management. The breach exposed: names, email addresses, Social Security numbers (employees), dates of birth, physical addresses, loyalty program data, partial payment card information, and employment records. The incident highlights the devastating impact of ransomware on restaurant/retail chains where operational technology (POS, kitchen display systems, inventory management) and customer data systems are deeply interconnected.

How Panera Bread Data Breach works

The Panera Bread ransomware attack represents a critical case study in restaurant/retail sector cybersecurity, where operational technology disruption directly translates to revenue loss and customer data exposure at massive scale.

**The Target:**

Panera Bread Company operates 2,100+ bakery-café locations across the US and Canada with: - $5.9B annual revenue (2023) - 52M+ MyPanera loyalty members (one of the largest restaurant loyalty programs) - 120,000+ employees across corporate, distribution, and restaurant locations - Extensive digital infrastructure: online ordering, mobile app, delivery integration, kiosk ordering - Complex supply chain: fresh-baked goods require daily distribution coordination

**The Attack:**

The ransomware attack encrypted critical systems across Panera's infrastructure:

1. **Point-of-Sale (POS) Systems**: In-store ordering and payment processing disrupted. Locations forced to operate cash-only or close entirely during the outage.

2. **Online Ordering & Mobile App**: Digital ordering channels (representing ~50% of revenue for fast-casual chains) went offline. The Panera mobile app and website were inaccessible for ordering.

3. **MyPanera Loyalty Program**: 52M+ member accounts inaccessible. Loyalty points, rewards, and subscription data affected. The Unlimited Sip Club (subscription coffee/tea program) could not process subscriptions.

4. **Internal Systems**: Corporate email, internal communications, employee scheduling, and HR systems encrypted.

5. **Supply Chain Management**: Fresh bread and ingredient distribution coordination disrupted. With Panera's emphasis on fresh-baked goods, supply chain disruption has outsized operational impact.

**Data Exfiltration:**

Before encryption, the attackers exfiltrated data affecting approximately 5.1 million individuals:

- **Customers**: Names, email addresses, dates of birth, physical addresses, loyalty program data, partial payment card information (last 4 digits, expiration), order history - **Employees**: All customer data plus Social Security numbers, dates of birth, bank account information (direct deposit), tax withholding information, employment records, benefits enrollment - **Corporate**: Internal documents, financial data, vendor agreements, strategic plans

**Impact Assessment:**

- **Revenue Loss**: Multiple days of disrupted or suspended digital ordering (~50% of fast-casual revenue). Individual locations reported 30-70% revenue drops during outage. - **Operational Disruption**: POS failures forced cash-only operation or temporary closures. Kitchen display systems offline disrupted order fulfillment. - **Brand Damage**: Major restaurant chain publicly unable to serve customers erodes brand trust. Competitors (Chipotle, Starbucks) captured diverted customers. - **Regulatory Exposure**: 5.1M affected individuals triggers notification requirements across all 50 US states. Employee SSN exposure triggers enhanced regulatory scrutiny. - **Legal Liability**: Multiple class-action lawsuits filed within weeks of breach disclosure. Employee data exposure (SSN, bank accounts) creates particularly strong legal claims. - **Loyalty Program Trust**: 52M MyPanera members questioning data safety. Subscription program (Unlimited Sip Club) disruption affects recurring revenue.

**Root Cause Analysis:**

Restaurant chains face unique cybersecurity challenges: - **Flat Network Architecture**: POS systems, back-office, corporate, and customer-facing systems often share network segments without adequate segmentation - **Franchise/Corporate Split**: Mixed ownership models create inconsistent security practices across locations - **High Employee Turnover**: Restaurant industry turnover rates (~75% annually) create credential management challenges - **Legacy POS Systems**: Many locations run aging POS hardware/software with limited security capabilities - **Digital Transformation Speed**: Rapid adoption of online ordering, delivery integration, and loyalty programs expanded attack surface faster than security could keep pace

**Industry Context:**

The Panera breach follows a pattern of major restaurant/retail ransomware incidents: - **Yum! Brands (2023)**: KFC/Taco Bell/Pizza Hut parent hit by ransomware, 300 UK locations closed - **Dine Brands (2023)**: IHOP/Applebee's parent experienced data breach - **MOVEit (2023)**: Multiple restaurant chains affected via supply chain compromise - **Colonial Pipeline effect**: Critical infrastructure ransomware demonstrates operational technology vulnerability

The restaurant sector is increasingly targeted because: (1) high revenue makes ransom payment likely, (2) operational disruption creates urgency to pay, (3) massive customer databases provide data monetization value, and (4) security maturity lags behind digital transformation pace.

MITRE ATT&CK techniques used in TL-2026-0031

credential-access

T1003 OS Credential Dumping

collection

T1005 Data from Local System; T1213 Data from Information Repositories

lateral-movement

T1021 Remote Services

discovery

T1046 Network Service Discovery

execution

T1059 Command and Scripting Interpreter

defense-evasion

T1078 Valid Accounts

persistence

T1136 Create Account

initial-access

T1190 Exploit Public-Facing Application; T1566 Phishing

impact

T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery

exfiltration

T1567 Exfiltration Over Web Service

resource-development

T1588 Obtain Capabilities

reconnaissance

T1591 Gather Victim Org Information; T1596 Search Open Technical Databases

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Panera Bread Data Breach

  • Panera Bread — MyPanera Loyalty Program
    Vulnerable versions: All registered customers

Remediation for Panera Bread Data Breach

Immediate actions

  • Alert employees who may have Panera accounts to change passwords
  • Monitor authentication logs for credential stuffing patterns
  • Block known malicious IPs performing credential stuffing
  • Warn users about potential phishing emails impersonating Panera

Workarounds

  • Check Have I Been Pwned for exposure
  • Change passwords on any accounts using same credentials as Panera
  • Enable account alerts for suspicious activity

Longer-term hardening

  • Implement breach monitoring for employee email addresses
  • Enforce unique passwords via password manager policies
  • Enable MFA on all corporate accounts
  • Regular security awareness training on phishing recognition

Weaknesses (CWE) in Panera Bread Data Breach

CWE-200, CWE-312

Timeline of Panera Bread Data Breach

  • Restaurant sector ransomware attacks accelerate: Yum! Brands (KFC/Taco Bell/Pizza Hut) hit by ransomware forcing 300 UK location closures. Dine Brands (IHOP/Applebee's) experiences data breach. MOVEit supply chain compromise affects multiple restaurant chains. Pattern established: high revenue + operational urgency + massive customer databases = lucrative ransomware targets. Verizon DBIR notes Accommodation and Food Services sector increasing in targeted attacks.
  • Panera Bread operates 2,100+ locations with extensive digital infrastructure: online ordering (~50% of revenue for fast-casual), mobile app, MyPanera loyalty program (52M+ members), Unlimited Sip Club subscription, delivery integration (DoorDash, Uber Eats), and kiosk ordering. Digital transformation expanded attack surface significantly. Employee count: 120,000+ across restaurants, distribution, and corporate.
  • Ransomware attack hits Panera Bread. Attackers encrypt critical systems: POS terminals across 2,100+ locations, online ordering platform, mobile app, MyPanera loyalty database, corporate email and internal communications, employee management systems, and supply chain coordination. Data exfiltrated before encryption: 5.1M individuals' personal information including customer loyalty data and employee SSN/bank accounts. Multiple locations forced to cash-only operation or temporary closure.
  • Multi-day operational disruption continues. Online ordering and mobile app remain offline. Individual locations report 30-70% revenue drops. Supply chain coordination disrupted — fresh-baked goods distribution affected. Competitors capture diverted customers. Franchise operators report significant financial losses from POS downtime. Corporate employee scheduling, HR, and communication systems still encrypted.
  • Panera Bread begins breach notification process for 5.1M affected individuals across all 50 US states. Employee notifications include SSN and bank account exposure with enhanced identity monitoring (24 months). Customer notifications detail loyalty data, partial payment card, and personal information exposure. Multiple class-action lawsuits filed. Regulatory investigations initiated by state attorneys general. Brand reputation impact assessment ongoing.
  • Systems restored from backups. Enhanced security measures implemented: network segmentation between POS, corporate, and customer systems; mandatory credential reset across all accounts; EDR deployment acceleration; incident response plan updated with restaurant-specific ransomware playbook. Ongoing regulatory compliance across 50-state notification requirements. Identity monitoring services activated for all 5.1M affected individuals.
  • As of 2026-05-29, the Panera ~5.1M-account breach (ShinyHunters, ~Dec 2025, disclosed Jan 2026) is concluded at Panera but data was leaked on the actor's dark-web site after no ransom was paid, leaving PII permanently exposed. ShinyHunters/SLSH remains active per Feb 2026 Krebs/Mandiant and the May 2026 IC3 PSA despite arrests, so downstream phishing/credential-stuffing risk warrants continued monitoring.

Sources cited for Panera Bread Data Breach

Threats related to Panera Bread Data Breach

Detection coverage for TL-2026-0031

As of 2026-02-02, Threadlinqs Intelligence publishes 12 detection rule(s) for TL-2026-0031 across Splunk SPL, Microsoft KQL and Sigma, covering 40 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats