Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPIIMediumContained
CHIPOTLE MEXICAN GRILL, INC.
bd_8063b49c48b0050a · schema v1 · pii pii-v1
Full breach record for CHIPOTLE MEXICAN GRILL, INC. →Chipotle Mexican Grill, Inc. notified consumers of a phishing incident targeting employee Workday payroll accounts between October 9-26, 2025. Attackers used stolen credentials to access employee profiles, exposing SSNs, dates of birth, and bank routing/account numbers. Chipotle restored accounts, ensured wage payment, and offered Kroll identity monitoring. No network compromise occurred.
Vermont clock⏱ VT AG >14 bday7 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_28c1c96ff3833760Montana State AGfiled 2025-12-23Candidate
- bd_692231074c35f09dNew Hampshire State AGfiled 2025-12-23Verified
- bd_ec293b586c8c9966Indiana State AGfiled 2025-12-23Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-12-23-chipotle-mexican-grill-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 23, 2025
- Raw hash
- 726148cd51e2eee20997c1f242516f769ba9a5a5b9ac041fde62512b32a6abad
Reporting entity
- Name
- CHIPOTLE MEXICAN GRILL, INC.norm: chipotle mexican grill
Victim entity
- Name
- CHIPOTLE MEXICAN GRILL, INC.norm: chipotle mexican grill
Incident
- Discovered
- Nov 7, 2025
- Materiality determined
- —
- Notification sent
- Dec 23, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPII
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 7 weeks(46 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.