HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Panera Bread Company
bd_a6a8257617c25f57 · schema v1 · pii pii-v1
Full breach record for Panera Bread Company →Panera, LLC filed a supplemental breach notification with the New Hampshire Attorney General regarding unauthorized access to internal files on March 23, 2024. The incident affected approximately 43 New Hampshire residents, exposing names, Social Security numbers, and/or Driver’s License numbers. Panera engaged a cybersecurity firm, notified law enforcement, and offered one year of credit monitoring via Epiq to affected individuals.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_8e51ab7a2ba7264fVermont State AGfiled 2024-10-29Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/panera-20241029.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 29, 2024
- Raw hash
- 45d05427fdfb560f87e54dd6ed4e90cc42577ec114446db1c8d6c50c6916916c
Reporting entity
- Name
- Panera Bread Companynorm: panera bread
- Domain
- panerabread.com
Victim entity
- Name
- Panera Bread Companynorm: panera bread
- Domain
- panerabread.com
Incident
- Discovered
- Mar 23, 2024
- Materiality determined
- —
- Notification sent
- Jun 13, 2024
- Affected individuals
- 43
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Notified law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 31 weeks(220 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.