ShinyHunters Leaks 5.1 Million Panera Bread Customer Records
ShinyHunters Leaks 5.1 Million Panera Bread Customer Records (TL-2026-0055) is a high-severity data breach scored CVSS 7.5, first published 2026-02-03. It is attributed to ShinyHunters (France) with high confidence, affects Panera Bread Customer Database, maps to 27 MITRE ATT&CK techniques (T1048, T1074, T1078), and is covered by 15 detection rules and 38 indicators of compromise.
Key facts for TL-2026-0055
- Threat ID
- TL-2026-0055
- Severity
- HIGH
- CVSS
- 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
- Status
- ACTIVE
- Category
- DATA_BREACH
- First published
- 2026-02-03
- Last reviewed
- 2026-02-03
- Attribution
- ShinyHunters
- Attribution confidence
- HIGH
- Nation-state nexus
- France
- Motivation
- FINANCIAL
- Target sectors
- Retail, Food Service, Consumer Services, All Sectors (downstream credential stuffing)
- Target regions
- North America, Global (data traded internationally)
- Detection rules
- 15
- Indicators of compromise
- 38
Malware and tooling in ShinyHunters Leaks 5.1 Million Panera Bread Customer Records
Malware and tooling: OpenBullet
ShinyHunters leaked 5.1 million Panera Bread customer records including names, email addresses, phone numbers, loyalty account data, last four digits of payment cards, and order history. This threat focuses on the DATA LEAK LIFECYCLE and DOWNSTREAM IMPACT — how stolen PII is weaponized after a breach: credential stuffing cascades using leaked email/password combinations against other services, identity theft chains combining multiple breach datasets for synthetic identity fraud, dark web pricing and trading economics, victim notification failures and regulatory gaps, and defensive monitoring for exposed records. Distinct from TL-0031 (the breach incident and initial data exposure), this threat covers the POST-BREACH exploitation ecosystem — the months and years after the data is stolen, when the real damage occurs through credential reuse, account takeover, and identity fraud cascades.
How ShinyHunters Leaks 5.1 Million Panera Bread Customer Records works
Panera Breach Data Leak Lifecycle: From Exfiltration to Identity Fraud Cascades
The Breach Data — What Was Stolen:
ShinyHunters exfiltrated 5.1 million customer records from Panera Bread containing: - Full names and email addresses - Phone numbers (mobile and landline) - Loyalty program account data (MyPanera rewards, order history, preferences) - Last four digits of payment cards (partial card data) - Physical addresses (delivery addresses from online orders) - Hashed passwords (varying hash quality — some bcrypt, some weaker algorithms) - Order history and dietary preferences (behavioral profiling data) - Account creation dates and last login timestamps
This data class (PII + behavioral + partial financial) is the most dangerous for downstream exploitation because it enables both automated attacks (credential stuffing) and targeted social engineering (personalized phishing using order history and preferences).
The Data Leak Lifecycle — 7 Stages of Post-Breach Exploitation:
Stage 1 — Exfiltration & Actor Retention (Day 0-7): - ShinyHunters exfiltrates data via cloud API exploitation - Data stored on actor-controlled infrastructure - Initial quality assessment: record count, data fields, uniqueness - Decision: sell immediately, extort victim, or hold for exclusive use - Panera: ShinyHunters attempted extortion before public leak
Stage 2 — Private Sale & Trading (Day 7-30): - Offered on private channels (Telegram, Discord, private forums) to trusted buyers - Premium pricing for exclusive/first-access buyers: $5,000-$50,000 for full dataset - Bulk buyers: identity fraud rings, credential stuffing operators, SIM swap groups - Data brokers who aggregate and resell to multiple downstream buyers - Partial samples distributed free as proof of authenticity
Stage 3 — Public Leak & Forum Distribution (Day 30-90): - Full dataset posted on breach forums (BreachForums, Exposed.lol, LeakBase) - Free or low-cost access ($10-$100 for full download) - Data indexed by breach aggregators (HIBP, DeHashed, Snusbase, LeakCheck) - Combo lists generated: email:password pairs extracted for credential stuffing - Massive distribution — thousands of copies within hours of public posting
Stage 4 — Credential Stuffing Cascades (Day 30-365): - Email:password pairs from Panera breach tested against other services - Typical password reuse rate: 52-65% of users reuse passwords across services - Automated tools: OpenBullet, SentryMBA, STORM, credential stuffing botnets - Targets: streaming services (Netflix, Disney+, Spotify), e-commerce (Amazon), financial (PayPal, banking), social media - Each successful login = new compromised account for sale or exploitation - Cascade effect: Panera breach → 2-3 million credential reuse attempts → 1-1.7 million additional account compromises
Stage 5 — Identity Theft & Synthetic Fraud (Day 90-730+): - Panera data combined with other breaches for comprehensive identity profiles - Name + email + phone + address + behavioral data = near-complete identity - Synthetic identity fraud: combining real PII elements from multiple victims - Account opening fraud: new credit cards, loans, bank accounts using stolen PII - Tax fraud: filing false returns using stolen SSN + name + address combinations - Medical identity theft: using stolen PII for healthcare fraud - Average identity theft resolution time: 7 months and $1,400 per victim
Stage 6 — Targeted Social Engineering (Ongoing): - Order history enables personalized phishing: 'Your Panera order #12345 has a problem' - Phone numbers enable vishing and smishing campaigns - Email addresses enable spearphishing with Panera-branded lures - Loyalty account data enables account takeover via customer support social engineering - Behavioral preferences enable hyper-targeted advertising fraud
Stage 7 — Long-Tail Exploitation (Years): - Data never expires — PII remains valid for years (name, address, DOB don't change) - Breach data aggregated into master combo lists for ongoing credential stuffing - Data feeds AI-powered profiling for more sophisticated future attacks - Insurance fraud, background check fraud, rental application fraud using stolen PII - Data becomes part of the permanent dark web ecosystem
Dark Web Economics — Pricing the Panera Dataset:
| Data Type | Dark Web Price | Volume Available | |-----------|---------------|------------------| | Full Panera dataset (5.1M records) | $5,000-$15,000 (bulk) | Available on forums | | Individual records with full PII | $1-$5 per record | 5.1M records | | Verified email:password combos | $0.001-$0.01 per pair | ~3M valid pairs | | Valid login credentials (tested) | $5-$15 per account | ~1.5M crackable | | Premium accounts (high loyalty tier) | $10-$30 per account | ~200K accounts | | Combo list (email:password) | $50-$200 for full list | Widely distributed |
Total estimated dark web value: $15,000-$75,000 (direct sale) + millions in downstream fraud.
Victim Notification Failures:
1. Delayed notification: average 74 days between breach discovery and victim notification 2. Inadequate detail: notifications often omit which specific data was compromised 3. Insufficient remediation: 'We recommend changing your password' ignores credential reuse 4. No monitoring provision: many breaches don't offer credit monitoring despite PII exposure 5. Notification fatigue: average person receives 3-5 breach notifications per year — users ignore them 6. Regulatory gaps: different notification requirements across US states (no federal standard)
Defensive Monitoring for Exposed Records:
1. Credential monitoring: check employee/customer credentials against known breach databases 2. Dark web monitoring: continuous scanning for corporate data on forums and marketplaces 3. Authentication anomaly detection: credential stuffing generates distinctive login patterns 4. Account takeover detection: login from new device/location after credential reuse 5. Email-based threat detection: phishing campaigns using breach data for targeting 6. Fraud detection: new accounts opened using stolen PII from the breach 7. Brand monitoring: impersonation sites and phishing campaigns using Panera branding
MITRE ATT&CK techniques used in TL-2026-0055
exfiltration
T1048 Exfiltration Over Alternative Protocol; T1567 Exfiltration Over Web Service
collection
T1074 Data Staged; T1119 Automated Collection; T1213 Data from Information Repositories; T1530 Data from Cloud Storage
defense-evasion
T1078 Valid Accounts; T1550 Use Alternate Authentication Material; T1684.001 Impersonation
discovery
credential-access
T1110 Brute Force; T1528 Steal Application Access Token; T1552 Unsecured Credentials; T1555 Credentials from Password Stores; T1606 Forge Web Credentials
impact
T1485 Data Destruction; T1491 Defacement; T1531 Account Access Removal; T1657 Financial Theft
initial-access
resource-development
T1584 Compromise Infrastructure; T1588 Obtain Capabilities; T1608 Stage Capabilities
reconnaissance
T1589 Gather Victim Identity Information; T1591 Gather Victim Org Information; T1593 Search Open Websites/Domains; T1596 Search Open Technical Databases
Affected products and versions in ShinyHunters Leaks 5.1 Million Panera Bread Customer Records
- Panera Bread — Customer Database
Vulnerable versions: Customer PII systems
Fixed in: N/A - breach confirmed
Remediation for ShinyHunters Leaks 5.1 Million Panera Bread Customer Records
Patches
- NIST SP 800-63B — Digital Identity Guidelines: screen passwords against known breach databases
- PCI DSS 4.0 — Requirement 8.3.6: passwords must be checked against known compromised password lists
- State breach notification laws — comply with notification timelines (varies: 30-90 days depending on state)
Immediate actions
- Check all corporate email addresses against HaveIBeenPwned and breach aggregators — identify employees exposed in Panera breach
- Force password reset for any employee accounts using email addresses found in the Panera breach dataset
- Enable MFA on all accounts where Panera-exposed email addresses are used — prevents credential stuffing account takeover
- Monitor authentication logs for credential stuffing patterns: high-volume failed logins from distributed IPs targeting exposed email addresses
- Alert customers/employees exposed in the breach to check their credentials across ALL services, not just Panera
Workarounds
- Password manager adoption campaign — eliminates password reuse (the primary downstream risk)
- Breach notification enrichment: tell users WHICH services may be affected by credential reuse, not just 'change your password'
- Canary accounts in breach datasets — insert honeypot credentials that alert when used in credential stuffing
- Dark web monitoring services for corporate email domains (SpyCloud, Recorded Future, Flare)
Longer-term hardening
- Deploy credential screening at registration and login — check passwords against known breach databases in real-time (NIST 800-63B requirement)
- Implement dark web monitoring for corporate domains and employee PII on breach forums and marketplaces
- Deploy account takeover detection: login from new device/location + credential match to known breach = high-risk session
- Implement rate limiting and CAPTCHA on login endpoints to slow credential stuffing attacks
- Adopt passwordless authentication (FIDO2/passkeys) to eliminate password reuse as an attack vector entirely
- Develop breach response playbook that includes downstream credential reuse assessment — not just 'change your Panera password'
Weaknesses (CWE) in ShinyHunters Leaks 5.1 Million Panera Bread Customer Records
CWE-200, CWE-359
Timeline of ShinyHunters Leaks 5.1 Million Panera Bread Customer Records
- ShinyHunters emerges as prolific data broker, selling stolen databases on RaidForums. Early targets: Tokopedia (91M), Wattpad (271M), Microsoft GitHub repos. Establishes reputation as high-volume data theft operator. Business model: exfiltrate → extort → sell → leak.
- Dark web breach economy grows: 22 billion records exposed in 2021 breaches. Average data breach cost: $4.24M (IBM). Credential stuffing attacks increase 300% as breach data fuels automated account takeover. Password reuse rate: 52-65% across consumers.
- ShinyHunters breaches Panera Bread via cloud infrastructure exploitation. 5.1 million customer records exfiltrated: names, emails, phone numbers, partial payment data, loyalty accounts, order history, hashed passwords. Data quality is high — behavioral data (order preferences) enables targeted social engineering.
- ShinyHunters contacts Panera with extortion demand before public leak. Ransom demanded for non-disclosure of stolen data. Panera's response and negotiation details not fully public. Pattern: ShinyHunters uses extortion before leak as standard operating procedure.
- Panera breach data posted on public breach forums. Full 5.1M dataset available for download. Breach aggregators (HIBP, DeHashed, Snusbase) index the data. Combo lists (email:password) generated and distributed across credential stuffing communities. The data enters permanent dark web circulation.
- Credential stuffing cascade begins: Panera email:password pairs tested against major services (Netflix, Amazon, PayPal, banking). Estimated 52-65% password reuse rate yields 2.6-3.3M valid credentials on other services. Each compromised account generates additional fraud and data theft.
- Identity theft chains emerge: Panera data combined with other breaches to build comprehensive identity profiles. Name + email + phone + address + behavioral data from Panera, cross-referenced with SSN from healthcare breaches and financial data from payment breaches. Synthetic identity fraud operations use aggregated profiles.
- Victim notification analysis: average 74-day delay between breach discovery and notification. Panera notification inadequately describes credential reuse risk. No guidance to check other accounts. No credit monitoring offered for PII exposure. Notification fatigue: users receive 3-5 breach notifications per year and ignore them.
- Dark web pricing stabilizes: individual Panera records $1-5 each, bulk dataset $5K-15K, verified email:password combos $0.001-0.01, premium loyalty accounts $10-30 each. Data remains commercially valuable 2+ years after breach. PII never expires — names and addresses remain valid indefinitely.
- Verizon DBIR 2025: credential reuse accounts for 44% of all breaches. Average person has 100+ online accounts but uses only 5-7 unique passwords. Breach data from incidents like Panera fuels a perpetual cycle: breach → credential stuffing → more breaches → more data for stuffing.
- Long-tail exploitation: Panera data still actively traded and used 2.5 years after breach. Data aggregated into master combo lists with billions of credentials from multiple breaches. AI-powered profiling uses behavioral data (order preferences, dietary habits) for targeted advertising fraud and social engineering.
- Passkey/FIDO2 adoption accelerates as industry response to credential stuffing epidemic. Password reuse becomes impossible with passkeys. However, adoption remains below 15% of consumer accounts. The credential stuffing economy persists for the 85% still using passwords.
- Threadlinqs analysis: The Panera breach lifecycle demonstrates that data theft is not an event — it is an ecosystem. 5.1M records fuel credential stuffing cascades, identity theft chains, and targeted social engineering for YEARS after the initial breach. The breach notification 'change your Panera password' advice is catastrophically inadequate — the real damage is credential reuse across 100+ services. The stolen data IS the weapon. Passwords are the ammunition. The only defense is eliminating password reuse entirely via password managers or passwordless authentication.
- As of 2026-05-29, this remains ACTIVE: the 5.1M Panera records (HIBP-confirmed, ~77% reused emails) are permanently public and weaponized via credential stuffing and extortion texts, with Panera offering no notification program. ShinyHunters/Scattered LAPSUS$ Hunters stays operational (Canvas/Instructure extortion May 2026); 2025 arrests hit only affiliates, and there is no CVE to patch.
Sources cited for ShinyHunters Leaks 5.1 Million Panera Bread Customer Records
- HaveIBeenPwned — Panera Bread Data Breach Notification
- MITRE ATT&CK — Gather Victim Identity Information (T1589)
- CISA — Scattered Spider Advisory AA23-320A
- FTC — Data Breach Response Guide for Businesses
- Verizon — 2025 Data Breach Investigations Report (DBIR)
- Identity Theft Resource Center — 2025 Annual Data Breach Report
- SpyCloud — Annual Identity Exposure Report
- MITRE ATT&CK — Credential Stuffing (T1110.004)
Threats related to ShinyHunters Leaks 5.1 Million Panera Bread Customer Records
Detection coverage for TL-2026-0055
As of 2026-02-03, Threadlinqs Intelligence publishes 15 detection rule(s) for TL-2026-0055 across Splunk SPL, Microsoft KQL and Sigma, covering 38 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.