THE WENDY'S COMPANY
ent_019e5eeb246e1d358e30e8440daa76f5
Disclosures
3
SEC 10-K Item 1C · State AG · 3 jurisdictions
Incidents
—
no linked incident in sample
Max affected reported
—
no filed count in sample
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- THE WENDY'S COMPANY
- Normalized
- the wendy s— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 529900M0JIUCMWVKHG76
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (3)newest first
- FEDERALSEC 10-K Item 1Cas reporting2026-02-23
The Wendy's Company (CIK 0000848324) filed a 10-K Item 1C disclosure stating that no cybersecurity threats materially affected its business in 2025. The filing details a comprehensive cybersecurity risk management strategy, including CIS Controls, regular risk assessments, infrastructure security, dedicated personnel, training, third-party assessments, and an incident response plan. Governance is overseen by the Audit and Technology Committees.
- 🦬Montana State AGas victim2016-07-07
Wendy's reported a data breach to the Montana Attorney General. The breach was reported on 2016-07-07. The breach occurred from 11/30/2015 to 6/8/2016.
- 🌲Washington State AGas victim2016-07-06
Wendy's, a business sector entity reported a malware incident to the Washington Attorney General. The organization became aware of the incident on 2016-05-01 and filed notice on 2016-07-06. 66 days elapsed between awareness and notification. 151 days to identify the breach. 38 days to contain the breach.