FEDERALItem 8.01 · voluntaryMalwareRansomwareData ExfiltratedData EncryptedPIIIPLowActive
YUM! Brands, Inc.
bd_930c9d1e16f8cabc · schema v1 · pii pii-v1
Full breach record for YUM! Brands, Inc. →Yum! Brands, Inc. disclosed a ransomware attack on January 18, 2023, impacting IT systems and causing temporary disruption to less than 300 UK restaurants. The company took systems offline, engaged forensic professionals, and notified federal law enforcement. While data was exfiltrated, customer databases were reportedly not stolen.
SEC clockMateriality determined Jan 18, 2023 → Filed Jan 19, 20231d ✓ SEC 4-day OK≤1 day discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_05b2f3b76db7eda6Washington State AGfiled 2023-04-07(78d gap)Verified
- bd_670ffb1c99274f7fMaine State AGfiled 2023-04-07(78d gap)Verified
- bd_17c063610aa17e65California State AGfiled 2023-04-13(84d gap)Verified
- bd_712a74721c6ee198New Hampshire State AGfiled 2023-04-13(84d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 85d gap
- bd_01aaa01480a1e00bOregon State AGfiled 2023-04-14(85d gap)Verified
- bd_48c445e8e34473fdMontana State AGfiled 2023-04-14(85d gap)Verified
- bd_edd346b972acb4e0Delaware State AGfiled 2023-04-14(85d gap)Verified
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/1041061/000110465923004769/
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jan 19, 2023
- Raw hash
- c86dde1e69315efe5406c86b40b03552332b6474ab07e1f29785dd89ac0cf765
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- YUM! Brands, Inc.norm: yum brands
- SEC CIK
- 0001041061
- Industry
- Restaurants
Victim entity
- Name
- YUM! Brands, Inc.norm: yum brands
- SEC CIK
- 0001041061
- Industry
- Restaurants
Incident
- Discovered
- Jan 18, 2023
- Materiality determined
- Jan 18, 2023
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIP
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- notified Federal law enforcement
Compliance
- Time to disclose
- ≤1 day(1 days from discovery to filing)
- Compliance flags
- SEC 4-day OK · 1d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: Jan 18, 2023→ Filed: Jan 19, 20231d cal. 4 business days SEC 4-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.