DisclosureLens
Social EngineeringRetail & ConsumerRetailPhishingStolen CredentialsTargetedCustomer Data InvolvedIdentity (basic)MediumContained

Panera Bread Company

bd_ea41a9d3f74599c1 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jan 7, 2026

Filed

Apr 16, 2026

To disclose

14 weeks

Affected

1,564state residents only

Linked

2 filings

Confidence

71%
Full breach record for Panera Bread Company3 incidents on file

Panera, LLC reported a cybersecurity incident where a skilled person used social engineering to gain unauthorized access to an application containing catering order records on January 5, 2026. The breach affected the names and dates of birth of 1,564 Washington residents. Panera detected the access on January 7, 2026, shut it down, notified law enforcement, and mailed notifications on April 16, 2026.

Washington clock WA AG >90d14 weeks discovery → filing
AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.

Incident timeline

undetected · 2 days
discovery → filing · 14 weeks / 99 days

Jan 5, 2026

Begins

Jan 7, 2026

Discovered

Apr 16, 2026

Filed

vs. sector median

+7 wks slower

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Ransomware claims (1)

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.