YUM! Brands, Inc.
ent_019e2419b7657f06e9be7dbdffb27ffd
Disclosures
12
State AG · SEC 8-K · 12 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
300,000
nationwide · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- YUM! Brands, Inc.
- Normalized
- yum brands— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300JE8XHZZ7OHN517
- SEC EDGAR CIK
- 0001041061
- Domain
- None on record
Disclosure history (12)newest first
- Oregon State AGas victim2023-04-14
Yum! Brands, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2023-04-14. The breach occurred during 1/13/2023 - 1/14/2023. The breach was discovered on 3/9/2023. 300,000 individuals were affected. Notice was sent on 4/14/2023.
- Massachusetts State AGas victim2023-04-14
Yum! Brands, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-04-14. 1,602 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2023-04-14
Yum! Brands, Inc. disclosed a cybersecurity incident occurring on or around January 13, 2023, involving unauthorized access to systems. Personal information was exposed. The company locked down systems, notified law enforcement, engaged forensic teams, and deployed enhanced monitoring. Complimentary credit monitoring and identity protection services for two years were offered to affected individuals.
- Indiana State AGas victim2023-04-14
Yum! Brands, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2023-01-04 and was reported on 2023-04-14. 15,406 Indiana residents were affected.
- Delaware State AGas victim2023-04-14
Yum! Brands, Inc. experienced a cybersecurity incident involving unauthorized access to certain systems on or around January 13, 2023. The company contained the incident, engaged forensic investigators, and notified law enforcement. A review determined that some personal information was exposed. The company is offering two years of complimentary credit monitoring and identity protection services via IDX. No evidence of identity theft or fraud was found at the time of notification.
- California State AGas victim2023-04-13
Yum! Brands, Inc. experienced a cybersecurity incident on or around January 13, 2023 involving unauthorized access to certain of its systems. Upon discovery, the company locked down impacted systems, notified federal law enforcement, engaged digital forensics teams, and deployed enhanced monitoring. A subsequent data review confirmed that personal information belonging to certain individuals was present in affected files. Two years of complimentary credit monitoring and identity protection were offered via IDX.
- New Hampshire State AGas victim2023-04-13
Yum! Brands, Inc. experienced a ransomware attack on or around January 13, 2023, resulting in unauthorized access to certain systems. The incident affected approximately 621 New Hampshire residents, who are current or former employees or their dependents. Exposed data included personal information such as names and potentially other identifiers. Yum! contained the incident, engaged forensic experts, notified law enforcement, and offered two years of credit monitoring to affected individuals.
- South Carolina State AGas victim2023-04-13
Yum! Brands, Inc. notified South Carolina consumers of a cybersecurity incident occurring on or around January 13, 2023. Unauthorized access to systems exposed personal information. Yum! locked down systems, notified law enforcement, engaged forensic investigators, and offered 2 years of credit monitoring.
- Washington State AGas victim2023-04-07
Yum! Brands, Inc. reported a ransomware incident occurring Jan 13-14, 2023, discovered Jan 13, 2023. The breach affected personal information of 1,220 Washington residents. Yum! locked down systems, notified law enforcement, engaged forensic investigators, and deployed enhanced monitoring. Affected individuals received 2 years of credit monitoring.
- Maine State AGas victim2023-04-07
Yum! Brands, Inc. reported a ransomware attack that occurred on January 13, 2023, and was discovered on March 9, 2023. The breach affected 11 Maine residents, compromising their names and driver's license or non-driver identification card numbers. Impacted individuals were notified on April 7, 2023, and offered two years of identity protection services.
- FEDERALSEC 8-Kas victim2023-01-19
Yum! Brands, Inc. disclosed a ransomware attack on January 18, 2023, impacting IT systems and causing temporary disruption to less than 300 UK restaurants. The company took systems offline, engaged forensic professionals, and notified federal law enforcement. While data was exfiltrated, customer databases were reportedly not stolen.
- Illinois State AGas victim2023-01-01
YUM! BRANDS, INC. filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-253). The register records the breach as discovered on March 9, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
Subsidiary disclosures (6)filed by group companies
◈ These filings were made by or about subsidiaries of YUM! Brands, Inc. — not by YUM! Brands, Inc. itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- Massachusetts State AGvia PIZZA HUT HOLDINGS, LLC2017-10-16
Pizza Hut, LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-10-16. 138 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGvia PIZZA HUT HOLDINGS, LLC2017-10-16
Pizza Hut notified Montana residents of a data breach occurring October 1-2, 2017, where unauthorized access compromised customer names, addresses, and payment card details. The company engaged Kroll for credit monitoring services.
- Washington State AGvia PIZZA HUT HOLDINGS, LLC2017-10-16
Pizza Hut, LLC notified the Washington AG of an unauthorized third-party intrusion affecting customer data from Oct 1-2, 2017. Discovered Oct 5, 2017. Impacted ~1,896 WA residents. Data included names, addresses, emails, and payment card info (CVV/account). Pizza Hut engaged Kroll for investigation and offered 1 year of credit monitoring.
- Oregon State AGvia PIZZA HUT HOLDINGS, LLC2017-10-16
Pizza Hut, LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2017-10-16. The breach occurred during 10/1/2017 - 10/2/2017. The breach was discovered on 10/5/2017. 59,320 individuals were affected. Notice was sent on 10/14/2017.
- New Hampshire State AGvia PIZZA HUT HOLDINGS, LLC2017-10-14
Pizza Hut, Inc. notified the New Hampshire Attorney General of a cybersecurity incident affecting approximately 48 state residents. Unauthorized access occurred between October 1 and 2, 2017, compromising customer names, addresses, and payment card details. Pizza Hut engaged external consultants, notified customers via email and mail, and provided one year of credit monitoring.
- California State AGvia PIZZA HUT HOLDINGS, LLC2017-10-14
Pizza Hut, Inc. disclosed an unauthorized third-party intrusion on its website and mobile application occurring between October 1 and October 2, 2017. The incident compromised customer information including names, billing zip codes, delivery addresses, email addresses, and payment card details (account numbers, expiration dates, and CVV numbers). Pizza Hut halted the intrusion, engaged external cybersecurity consultants, and offered one year of complimentary credit monitoring through Kroll Information Assurance.