CHIPOTLE MEXICAN GRILL, INC.
bd_692231074c35f09d · schema v1 · pii pii-v1
Full breach record for CHIPOTLE MEXICAN GRILL, INC. →6 incidents on fileChipotle Mexican Grill, Inc. notified the New Hampshire Attorney General of a cybersecurity incident affecting 2 New Hampshire residents. Between October 9 and October 26, 2025, attackers used phishing tactics to gain unauthorized access to employees' Workday payroll accounts. The attackers modified deposit information and accessed personal data including Social Security numbers, dates of birth, and bank account details. Chipotle secured the accounts, launched an investigation, and began mailing notification letters on December 23, 2025, offering one year of credit monitoring services.
J jump to incidentP pin to compareR raw source
Incident timeline
Oct 9, 2025
Begins
Nov 7, 2025
Discovered
Dec 23, 2025
Filed
vs. sector median
1 wks faster
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Massachusetts State AGbd_04001ac07564bde82025-12-23Verified
- Montana State AGbd_28c1c96ff38337602025-12-23Candidate
- Vermont State AGbd_8063b49c48b0050a2025-12-23Verified
- Nebraska State AGbd_b01a572368c8c9592025-12-23Verified
Show 1 more filing ↓Show fewer ↑
- Indiana State AGbd_ec293b586c8c99662025-12-23Verified
Filing propagation · 6 filings · 6 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.