HackingCustomer Data InvolvedPIIIDENTITY_BASICLowContained
YUM! Brands, Inc.
bd_edd346b972acb4e0 · schema v1 · pii pii-v1
Full breach record for YUM! Brands, Inc. →Yum! Brands, Inc. notified Delaware AG of a cybersecurity incident occurring on or around January 13, 2023, involving unauthorized access to systems. The breach exposed personal information of individuals, including names and addresses. Yum! locked down systems, notified federal law enforcement, engaged forensic teams, and deployed enhanced monitoring. The company offered 2 years of complimentary credit monitoring and identity protection services via IDX to affected individuals.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_01aaa01480a1e00bOregon State AGfiled 2023-04-14Verified
- bd_48c445e8e34473fdMontana State AGfiled 2023-04-14Verified
- bd_17c063610aa17e65California State AGfiled 2023-04-13(1d gap)Verified
- bd_712a74721c6ee198New Hampshire State AGfiled 2023-04-13(1d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 85d gap
- bd_05b2f3b76db7eda6Washington State AGfiled 2023-04-07(7d gap)Verified
- bd_670ffb1c99274f7fMaine State AGfiled 2023-04-07(7d gap)Verified
- bd_930c9d1e16f8cabcSEC 8-Kfiled 2023-01-19(85d gap)Candidate
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/04/Yum-Notification-Letter.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 14, 2023
- Raw hash
- b1464c30f84737f34eac2d9d144f96d199c08ac1d1ccbb1c2be24027fb7066b3
Reporting entity
- Name
- YUM! Brands, Inc.norm: yum brands
Victim entity
- Name
- YUM! Brands, Inc.norm: yum brands
Incident
- Discovered
- Jan 13, 2023
- Materiality determined
- —
- Notification sent
- Apr 14, 2023
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- notified federal law enforcement authorities
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 13 weeks(91 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.