CHIPOTLE MEXICAN GRILL, INC.
bd_9dea3cac1f766061 · schema v1 · pii pii-v1
Full breach record for CHIPOTLE MEXICAN GRILL, INC. →6 incidents on fileChipotle Mexican Grill notified the NH Attorney General of unauthorized access to employee email accounts between Jan 19-21, 2020. The incident involved phishing leading to credential compromise. 17 NH residents' names and SSNs were exposed. Chipotle engaged forensic investigators, secured accounts, and offered 1 year of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 19, 2020
Begins
Oct 30, 2020
Filed
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Indiana State AGbd_3cdbb8d2fa676db92020-10-29 · +1dVerified
- Maine State AGbd_4da7461077382b6a2020-10-29 · +1dCandidate
- Massachusetts State AGbd_571dddc7897f3bfb2020-10-29 · +1dVerified
Filing propagation · 4 filings · 4 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.