HackingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
PANDA RESTAURANT GROUP, INC.
bd_e3f5a9f8a02bb159 · schema v1 · pii pii-v1
Full breach record for PANDA RESTAURANT GROUP, INC. →Panda Restaurant Group, Inc. notified consumers of a data security incident detected on March 10, 2024. Unauthorized access occurred between March 7-11, 2024, affecting personal information including names and government identifiers (SSN, driver's license). The company engaged third-party cybersecurity experts and law enforcement, implemented technical safeguards, and offered credit monitoring services.
Vermont clock⏱ VT AG >14 bday7 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_28c67d8711a3fbf3Montana State AGfiled 2024-04-30Verified
- bd_85d0ceb84fc96f32Oregon State AGfiled 2024-04-30Candidate
- bd_c07d2797b8024e12Maine State AGfiled 2024-04-30Verified
- bd_c2419f61ec499a4eCalifornia State AGfiled 2024-04-30Verified
Show 2 more filings ↓Show fewer ↑up to 1d gap
- bd_d5c83441424d123cWashington State AGfiled 2024-04-30Verified
- bd_3d9a2a9805277794New Hampshire State AGfiled 2024-04-29(1d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-04-30-panda-restaurant-group-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 30, 2024
- Raw hash
- 5a1ad9f5928bd8abc7beb9142620e22071396d43cd687889d547d960f99c46a3
Reporting entity
- Name
- PANDA RESTAURANT GROUP, INC.norm: panda restaurant
Victim entity
- Name
- PANDA RESTAURANT GROUP, INC.norm: panda restaurant
Incident
- Discovered
- Mar 10, 2024
- Materiality determined
- —
- Notification sent
- Apr 30, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified Vermont Attorney General
Compliance
- Time to disclose
- 7 weeks(51 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.