BIMBO BAKERIES USA, INC.
ent_019e6166f2b8e61cd2e8a13b2e065e4e
Disclosures
13
State AG · 8 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
46,064
nationwide · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- BIMBO BAKERIES USA, INC.
- Normalized
- bimbo bakeries usa— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300HOXXHHT7926W92
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
- Corporate parent
- GRUPO BIMBO S A B DE C V— per GLEIF relationship records
Disclosure history (13)newest first
- Texas State AGas victim2026-09-04
Bimbo Bakeries USA based in Irving, Texas, a business – retail or merchant entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-08-19 and reported on 2026-09-04. 3,982 Texas residents were affected. 46,064 individuals affected in total. Types of information involved: Name of individual;Social Security Number Information;Financial Information (e.g. account number, credit or debit card number). Consumers were notified via U.S. Mail.
- Vermont State AGas victim2026-09-04
Bimbo Bakeries USA reported a data breach to the Vermont Attorney General. The breach was reported to the AGO on 2026-09-04. The reporting organization type is Other Commercial. 53 Vermont residents were affected. Categories of data breached: Social Security Numbers, Financial Account Codes, Credit and Debit Account Info.
- California State AGas victim2026-09-04
Bimbo Bakeries USA notified consumers of a data breach involving a zero-day vulnerability in Oracle's E-Business Suite, a third-party vendor application. Unauthorized parties acquired files containing names and Social Security numbers. The breach occurred on August 9, 2025. The company applied patches, investigated the incident, and is offering credit monitoring and fraud assistance to affected individuals.
- Oregon State AGas victim2026-09-04
Bimbo Bakeries USA reported a data breach to the Oregon Attorney General. The breach was reported on 2026-09-04. The breach occurred during 8/9/2025 - 8/9/2025. The breach was discovered on 12/6/2025. 46,064 individuals were affected. Notice was sent on 8/31/2026.
- Washington State AGas victim2026-09-04
Bimbo Bakeries USA, a business sector entity reported a other incident to the Washington Attorney General. The organization became aware of the incident on 2025-10-06 and filed notice on 2026-09-04. 786 Washington residents were affected. 333 days elapsed between awareness and notification. 58 days to identify the breach. 0 days to contain the breach.
- New Hampshire State AGas victim2026-09-04
Bimbo Bakeries USA notified the NH Attorney General of a data security incident involving a zero-day vulnerability in Oracle's eBusiness Suite. Unauthorized parties exploited the vulnerability to access and exfiltrate files containing names, Social Security numbers, and bank account/routing numbers of current and former employees, dependents, and beneficiaries. BBU first learned of the vulnerability on October 6, 2025, and applied patches. The investigation concluded on August 19, 2026, that 94 New Hampshire residents were affected. Notification letters were mailed starting August 31, 2026. Credit monitoring is being offered.
- Massachusetts State AGas victim2026-09-01
Bimbo Bakeries USA notified Massachusetts residents of a data security incident involving its third-party vendor, Oracle. The incident exposed individuals' names and Social Security numbers. The company offered 24 months of credit monitoring and fraud assistance services through Cyberscout. No specific dates for the breach occurrence or discovery were provided in the notice.
- Massachusetts State AGas victim2024-06-06
Bimbo Bakeries USA, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-06-06. 28 Massachusetts residents were affected.
- Vermont State AGas reporting2024-06-06
Bimbo Foods Bakeries Distribution, LLC notified consumers that an unauthorized third party gained remote access to a server on February 13, 2024, obtaining files containing names and Social Security numbers of employees and vendors. The company blocked access, engaged forensic experts, notified law enforcement, and is offering two years of identity monitoring via Experian.
- Indiana State AGas victim2024-06-06
Bimbo Bakeries USA Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2024-02-13 and was reported on 2024-06-06. 6 Indiana residents were affected. 560 individuals affected in total.
- New Hampshire State AGas victim2024-06-05
Bimbo Bakeries USA, Inc. and affiliate Bimbo Foods Bakeries Distribution, LLC notified the NH Attorney General of a security incident where an unauthorized third party gained remote access to a network portion on February 13, 2024. The breach affected 16 New Hampshire residents, involving personal information of employees and vendors. Financial account and credit card data were not involved. The company blocked access, engaged cybersecurity experts, notified law enforcement, and offered credit monitoring.
- Massachusetts State AGas victim2012-05-07
Bimbo Bakeries USA reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2012-05-07. 134 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2012-05-02
Bimbo Bakeries USA reported the theft of a laptop containing the names and Social Security numbers of 22 New Hampshire resident associates. The theft was reported to local authorities on April 14, 2012. Notifications were sent to affected individuals on May 1, 2012, offering 12 months of identity theft monitoring.