HackingRetail & ConsumerHospitalityRetailData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedPIILowContained
YUM! Brands, Inc.
bd_17c063610aa17e65 · schema v1 · pii pii-v1
Full breach record for YUM! Brands, Inc. →Yum! Brands, Inc. experienced a cybersecurity incident on or around January 13, 2023 involving unauthorized access to certain of its systems. Upon discovery, the company locked down impacted systems, notified federal law enforcement, engaged digital forensics teams, and deployed enhanced monitoring. A subsequent data review confirmed that personal information belonging to certain individuals was present in affected files. Two years of complimentary credit monitoring and identity protection were offered via IDX.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_712a74721c6ee198New Hampshire State AGfiled 2023-04-13Verified
- bd_01aaa01480a1e00bOregon State AGfiled 2023-04-14(1d gap)Verified
- bd_48c445e8e34473fdMontana State AGfiled 2023-04-14(1d gap)Verified
- bd_edd346b972acb4e0Delaware State AGfiled 2023-04-14(1d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 84d gap
- bd_05b2f3b76db7eda6Washington State AGfiled 2023-04-07(6d gap)Verified
- bd_670ffb1c99274f7fMaine State AGfiled 2023-04-07(6d gap)Verified
- bd_930c9d1e16f8cabcSEC 8-Kfiled 2023-01-19(84d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-565517
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 13, 2023
- Raw hash
- de5f2a7bb072703914c4651b0091543ac37dac60d7177064cd24d7e35e29a727
Reporting entity
- Name
- YUM! Brands, Inc.norm: yum brands
Victim entity
- Name
- YUM! Brands, Inc.norm: yum brands
- Industry
- Retail & ConsumerllmHospitalityllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated CollectionT1074 Data Staged
- Threat actor
- External
- Regulator citations
- Notified federal law enforcement authoritiesNotification submitted to California Attorney GeneralNotification addresses Maryland, North Carolina, Rhode Island, DC, Iowa, New York, Oregon, South Carolina, Kentucky, Massachusetts, and New Mexico residents
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.