HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICLowContained
PANDA RESTAURANT GROUP, INC.
bd_3d9a2a9805277794 · schema v1 · pii pii-v1
Full breach record for PANDA RESTAURANT GROUP, INC. →Panda Restaurant Group, Inc. reported a data security incident affecting corporate systems. Unauthorized access occurred between March 7-11, 2024, detected on March 10, 2024. The incident involved personal information including names combined with other identifiers. Panda engaged third-party cybersecurity experts and law enforcement, implemented additional technical safeguards, and offered credit monitoring services to affected individuals.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_28c67d8711a3fbf3Montana State AGfiled 2024-04-30(1d gap)Verified
- bd_85d0ceb84fc96f32Oregon State AGfiled 2024-04-30(1d gap)Candidate
- bd_c07d2797b8024e12Maine State AGfiled 2024-04-30(1d gap)Verified
- bd_c2419f61ec499a4eCalifornia State AGfiled 2024-04-30(1d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 1d gap
- bd_d5c83441424d123cWashington State AGfiled 2024-04-30(1d gap)Verified
- bd_e3f5a9f8a02bb159Vermont State AGfiled 2024-04-30(1d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/panda-restaurant-group-20240429.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 29, 2024
- Raw hash
- 396c96e30121f0024a839841eb0f0713605907afb52395ef7128fb119aeb96c1
Reporting entity
- Name
- PANDA RESTAURANT GROUP, INC.norm: panda restaurant
Victim entity
- Name
- PANDA RESTAURANT GROUP, INC.norm: panda restaurant
Incident
- Discovered
- Mar 10, 2024
- Materiality determined
- Apr 15, 2024
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- worked with law enforcement who are conducting an active investigation into the unauthorized actor responsible for this incident
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 7 weeks(50 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.