DisclosureLens
HackingRetail & ConsumerRetailStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedIdentity (basic)PIILowResolved

Five Guys Holdings, Inc.

bd_0fc4fab3c6c56102 · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

Oct 27, 2023

To disclose

Affected

Not disclosed

Linked

6 filings

Confidence

66%
Full breach record for Five Guys Holdings, Inc.5 incidents on file

Five Guys Enterprises, LLC reported unauthorized access to two employee email accounts. Access to the first account occurred between March 20, 2023, and March 31, 2023; access to the second occurred between May 31, 2023, and June 7, 2023. The investigation determined that emails or attachments contained names and other personal information. Five Guys engaged a cybersecurity firm, secured the accounts, and offered one year of credit monitoring and identity protection services via IDX.

Leak gap clock Leak >180d
no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.

Incident timeline

Mar 20, 2023

Begins

Oct 27, 2023

Filed

This filing is one of 6 about the same incident.View merged incident
A leak claim by alphv about this victim predates this filing by 265 days.View originating leak claim

Linked disclosures

Why this link?

Regulatory filings (5) · sorted by filing gap

Show 1 more filing

Filing propagation · 6 filings · 6 states

View merged incident ↗
Maine State AGOct 27 · first
Indiana State AGOct 27 · first
New Hampshire State AGOct 27 · first
Massachusetts State AGOct 27 · first
Montana State AGOct 27 · first
California State AGOct 27 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.