Panera Bread Company
ent_019dee4e28d10e2ce9bc26d23b11a64a
Disclosures
13
State AG · Leak Site · 11 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
136,302
nationwide · State AG IN
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- Panera Bread Company
- Normalized
- panera bread— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 5493008627EIK5RECQ92
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- panerabread.com
Disclosure history (13)newest first
- Washington State AGas victim2026-04-16
Panera, LLC reported a cybersecurity incident where a skilled person used social engineering to gain unauthorized access to an application containing catering order records on January 5, 2026. The breach affected the names and dates of birth of 1,564 Washington residents. Panera detected the access on January 7, 2026, shut it down, notified law enforcement, and mailed notifications on April 16, 2026.
- GLOBALLeak Siteas victim2026-01-26
Records: 14M Records | Updated: 27 Jan 2026 | Note: Don't be the next headline. | Don't be an idiot like this company. Make the right decision, don't be the next headline.
- Vermont State AGas victim2024-10-29
Panera, LLC notified consumers of a security incident on March 23, 2024, involving unauthorized access to internal files containing names and potentially Social Security numbers. A cybersecurity firm was engaged, and law enforcement was notified. Panera offered one year of identity theft protection services. No indication that data was publicly available.
- New Hampshire State AGas victim2024-10-29
Panera, LLC notified the NH Attorney General of a supplemental incident regarding unauthorized access to internal files on March 23, 2024. The investigation identified that personal information, including names, Social Security numbers, and/or Driver's License numbers, of approximately 43 New Hampshire residents was involved. Panera engaged a cybersecurity firm, notified law enforcement, and is offering one year of complimentary credit monitoring and identity protection services through Epiq.
- South Carolina State AGas victim2024-06-14
Panera, LLC notified South Carolina residents of a security incident detected on March 23, 2024. Unauthorized access to internal files resulted in the exposure of names and Social Security numbers of employees. Panera engaged a cybersecurity firm, notified law enforcement, and offered one year of credit monitoring and identity theft insurance to affected individuals.
- Montana State AGas victim2024-06-13
Panera, LLC notified individuals of a security incident detected on March 23, 2024, involving unauthorized access to internal files containing names and Social Security numbers. The incident involved employee information. Panera engaged a cybersecurity firm and notified law enforcement. Affected individuals received one year of credit monitoring.
- California State AGas victim2024-06-13
Panera, LLC notified California residents of a security incident involving unauthorized access to internal files containing employee information, including names and Social Security numbers. The breach occurred between February 9 and March 23, 2024, and was detected on March 23, 2024. Panera engaged a cybersecurity firm, notified law enforcement, and offered one year of identity theft protection services to affected individuals.
- Indiana State AGas victim2024-06-13
Panera LLC reported a data breach to the Indiana Attorney General. The breach occurred on 2024-02-09 and was reported on 2024-06-13. 6,567 Indiana residents were affected. 136,302 individuals affected in total.
- New Hampshire State AGas victim2024-06-13
Panera, LLC notified individuals of a security incident detected on March 23, 2024, involving unauthorized access to internal files. The investigation determined that a file containing names, Social Security numbers, and other employment-related information was accessed. Panera engaged a cybersecurity firm, notified law enforcement, and offered one year of complimentary identity theft protection services. The incident primarily affected employees or former employees.
- Washington State AGas victim2024-06-13
Panera, LLC filed a supplemental notice with the Washington AG regarding a ransomware incident. Unauthorized access occurred between Feb 9 and Mar 23, 2024. The breach affected approx. 811 Washington residents, exposing names, SSNs, driver's licenses, financial account info, health insurance info, and DOBs. Panera engaged a cybersecurity firm, notified law enforcement, and offered 12 months of credit monitoring.
- Massachusetts State AGas victim2024-06-13
Panera, LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-06-13. 444 Massachusetts residents were affected.
- Maine State AGas victim2024-06-13
Panera, LLC reported an external system breach (hacking) occurring between Feb 9 and Mar 23, 2024. Unauthorized access to internal files exposed names and Social Security Numbers of 11 Maine residents. Panera engaged a cybersecurity firm, notified law enforcement, and sent notification letters on June 13, 2024, offering one year of credit monitoring.
- Illinois State AGas victim2024-06-01
PANERA, LLC filed a data-breach notice with the Illinois Attorney General in June 2024 (case 24-06-025). The register records the breach as discovered on March 23, 2024. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.