YUM! Brands, Inc.
ent_019e2419b7657f06e9be7dbdffb27ffd
Disclosures
8
State AG · SEC 8-K · 8 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
300,000
as filed · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- YUM! Brands, Inc.
- Normalized
- yum brands— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300JE8XHZZ7OHN517
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (8)newest first
- 🦫Oregon State AGas victim2023-04-14
Yum! Brands, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2023-04-14. The breach occurred during 1/13/2023 - 1/14/2023. The breach was discovered on 3/9/2023. 300,000 individuals were affected. Notice was sent on 4/14/2023.
- 🦬Montana State AGas victim2023-04-14
Yum! Brands, Inc reported a data breach to the Montana Attorney General. The breach was reported on 2023-04-14. The breach occurred on 1/13/2023. 58 Montana residents were affected.
- 💎Delaware State AGas victim2023-04-14
Yum! Brands, Inc. notified Delaware AG of a cybersecurity incident occurring on or around January 13, 2023, involving unauthorized access to systems. The breach exposed personal information of individuals, including names and addresses. Yum! locked down systems, notified federal law enforcement, engaged forensic teams, and deployed enhanced monitoring. The company offered 2 years of complimentary credit monitoring and identity protection services via IDX to affected individuals.
- 🐻California State AGas victim2023-04-13
Yum! Brands, Inc. experienced a cybersecurity incident on or around January 13, 2023 involving unauthorized access to certain of its systems. Upon discovery, the company locked down impacted systems, notified federal law enforcement, engaged digital forensics teams, and deployed enhanced monitoring. A subsequent data review confirmed that personal information belonging to certain individuals was present in affected files. Two years of complimentary credit monitoring and identity protection were offered via IDX.
- ⛰️New Hampshire State AGas victim2023-04-13
Yum! Brands, Inc. reported a ransomware attack occurring on or around January 13, 2023, affecting approximately 621 New Hampshire residents (current/former employees and dependents). Personal information was exposed. Yum! locked down systems, notified law enforcement, engaged forensic experts, and offered 2 years of credit monitoring. Notification letters were sent starting April 14, 2023.
- 🌲Washington State AGas victim2023-04-07
Yum! Brands, Inc., a business sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2023-01-13 and filed notice on 2023-04-07. 1,220 Washington residents were affected. 84 days elapsed between awareness and notification. 0 days to identify the breach. 1 days to contain the breach.
- 🦞Maine State AGas victim2023-04-07
Yum! Brands, Inc. reported a ransomware attack that occurred on January 13, 2023, and was discovered on March 9, 2023. The breach affected 11 Maine residents, compromising their names and driver's license or non-driver identification card numbers. Impacted individuals were notified on April 7, 2023, and offered two years of identity protection services.
- FEDERALSEC 8-Kas victim2023-01-19
Yum! Brands, Inc. disclosed a ransomware attack on January 18, 2023, impacting IT systems and causing temporary disruption to less than 300 UK restaurants. The company took systems offline, engaged forensic professionals, and notified federal law enforcement. While data was exfiltrated, customer databases were reportedly not stolen.
Subsidiary disclosures (4)filed by group companies
◈ These filings were made by or about subsidiaries of YUM! Brands, Inc. — not by YUM! Brands, Inc. itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- 🦬Montana State AGvia PIZZA HUT HOLDINGS, LLC2017-10-16
Pizza Hut reported a data breach to the Montana Attorney General. The breach was reported on 2017-10-16. The breach occurred from 10/1/2017 to 10/2/2017. 255 Montana residents were affected.
- 🌲Washington State AGvia PIZZA HUT HOLDINGS, LLC2017-10-16
Pizza Hut, LLC, a business sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2017-10-05 and filed notice on 2017-10-16. 1,896 Washington residents were affected. 11 days elapsed between awareness and notification. 4 days to identify the breach. 0 days to contain the breach.
- 🦫Oregon State AGvia PIZZA HUT HOLDINGS, LLC2017-10-16
Pizza Hut, LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2017-10-16. The breach occurred during 10/1/2017 - 10/2/2017. The breach was discovered on 10/5/2017. 59,320 individuals were affected. Notice was sent on 10/14/2017.
- 🐻California State AGvia PIZZA HUT HOLDINGS, LLC2017-10-14
Pizza Hut, Inc. disclosed an unauthorized third-party intrusion on its website and mobile application occurring between October 1 and October 2, 2017. The incident compromised customer information including names, billing zip codes, delivery addresses, email addresses, and payment card details (account numbers, expiration dates, and CVV numbers). Pizza Hut halted the intrusion, engaged external cybersecurity consultants, and offered one year of complimentary credit monitoring through Kroll Information Assurance.