CHIPOTLE MEXICAN GRILL, INC.
ent_019e619e8e0852a65be3816378074a7f
Disclosures
20
State AG · 12 jurisdictions
Multi-filing incidents
4
incidents joining 2+ filings here
Max affected reported
5,440
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CHIPOTLE MEXICAN GRILL, INC.
- Normalized
- chipotle mexican grill— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 529900REP5VGTPCP1J71
- SEC EDGAR CIK
- 0001058090
- Domain
- None on record
Disclosure history (20)newest first
- Massachusetts State AGas victim2025-12-23
Chipotle Mexican Grill, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-12-23. 31 Massachusetts residents were affected.
- Montana State AGas victim2025-12-23
Chipotle Mexican Grill, Inc. notified employees that between Oct 9-26, 2025, attackers used phishing to compromise Workday payroll accounts. Unauthorized access exposed SSNs, DOBs, and bank routing/account numbers. Chipotle discovered the incident on Nov 7, 2025, restored accounts, and offered Kroll identity monitoring.
- New Hampshire State AGas victim2025-12-23
Chipotle Mexican Grill, Inc. notified the New Hampshire Attorney General of a cybersecurity incident affecting 2 New Hampshire residents. Between October 9 and October 26, 2025, attackers used phishing tactics to gain unauthorized access to employees' Workday payroll accounts. The attackers modified deposit information and accessed personal data including Social Security numbers, dates of birth, and bank account details. Chipotle secured the accounts, launched an investigation, and began mailing notification letters on December 23, 2025, offering one year of credit monitoring services.
- Vermont State AGas victim2025-12-23
Chipotle Mexican Grill, Inc. notified consumers of a phishing incident targeting employee Workday payroll accounts between October 9-26, 2025. Attackers used stolen credentials to access employee profiles, exposing SSNs, dates of birth, and bank routing/account numbers. Chipotle restored accounts, ensured wage payment, and offered Kroll identity monitoring. No network compromise occurred.
- Nebraska State AGas victim2025-12-23
Chipotle Mexican Grill, Inc. notified Nebraska residents that between October 9 and October 26, 2025, unauthorized actors gained access to employee Workday payroll accounts via phishing tactics. The incident affected 4 Nebraska residents, exposing Social Security numbers, dates of birth, and bank routing/account numbers. Chipotle secured accounts, launched an investigation, and began mailing notifications on December 23, 2025, offering one year of credit monitoring.
- Indiana State AGas victim2025-12-23
Chipotle Mexican Grill Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2025-10-09 and was reported on 2025-12-23. 9 Indiana residents were affected.
- Indiana State AGas victim2024-05-24
Messner Reeves LLP on behalf of Chipotle Mexican Grill Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2023-07-17 and was reported on 2024-05-24. 2 Indiana residents were affected. 2,025 individuals affected in total.
- Washington State AGas victim2024-05-24
Messner Reeves LLP, on behalf of client Chipotle Mexican Grill, Inc., reported a ransomware incident. An unknown actor accessed systems between July 17 and August 5, 2023, copying files containing names and dates of birth. 678 Washington residents were notified on May 24, 2024. Messner Reeves engaged forensic investigators, notified law enforcement, and provided one year of credit monitoring.
- New Hampshire State AGas victim2020-10-30
Chipotle Mexican Grill notified the NH Attorney General of unauthorized access to employee email accounts between Jan 19-21, 2020. The incident involved phishing leading to credential compromise. 17 NH residents' names and SSNs were exposed. Chipotle engaged forensic investigators, secured accounts, and offered 1 year of credit monitoring.
- Indiana State AGas victim2020-10-29
Chipotle Mexican Grill reported a data breach to the Indiana Attorney General. The breach occurred on 2020-01-19 and was reported on 2020-10-29. 74 Indiana residents were affected. 5,440 individuals affected in total.
- Maine State AGas victim2020-10-29
Chipotle Mexican Grill reported a phishing incident occurring Jan 19-21, 2020, discovered Sep 30, 2020. 5,440 individuals affected nationwide, including 19 Maine residents. Data exposed: names and Social Security Numbers. Notification sent Oct 29, 2020; credit monitoring offered via Experian.
- Massachusetts State AGas victim2020-10-29
Chipotle Mexican Grill reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2020-10-29. 105 Massachusetts residents were affected. The report records the breach type as electronic.
- Illinois State AGas victim2020-01-01
CHIPOTLE MEXICAN GRILL filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-453). The register records the breach as discovered on January 19, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Montana State AGas victim2017-06-05
Chipotle Mexican Grill reported a supplemental finding regarding a POS malware incident affecting track data from March 24 to April 18, 2017. The malware accessed payment card data at certain locations. Chipotle removed the malware, engaged forensic firms, and supported law enforcement. No specific affected individual count was disclosed in this filing.
- South Carolina State AGas victim2017-05-30
Chipotle Mexican Grill, Inc. reported a supplemental finding from its investigation into a payment card security incident. Malware on POS devices at certain locations accessed track data from magnetic stripe cards between March 24 and April 18, 2017. The company removed the malware and is cooperating with law enforcement and card networks. No specific count of affected individuals was provided in this filing.
- California State AGas victim2017-05-26
Chipotle Mexican Grill reported a payment card security incident involving malware on point-of-sale devices at certain restaurants between March 24, 2017, and April 18, 2017. The malware captured track data from magnetic stripes, including card numbers, expiration dates, verification codes, and sometimes cardholder names. The company removed the malware, engaged cybersecurity firms, and cooperated with law enforcement and payment card networks. No other customer information was indicated to be affected.
- New Hampshire State AGas victim2017-05-26
Chipotle Mexican Grill, Inc. notified the New Hampshire Attorney General of a malware incident affecting POS devices at certain restaurants. Malware accessed payment card track data between March 24 and April 18, 2017. Chipotle discovered the suspicious process on April 5, 2017, and notified customers via website and press release on May 26, 2017. No specific count of affected individuals was provided.
- Massachusetts State AGas victim2017-05-26
Chipotle Mexican Grill, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-05-26. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Oregon State AGas victim2017-05-26
Chipotle Mexixan Grill, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2017-05-26. The breach occurred during 3/24/2017 - 4/18/2017. The breach was discovered on 4/5/2017. Notice was sent on 5/26/2017.
- New Hampshire State AGas victim2008-04-15
Chipotle Mexican Grill, Inc. notified the New Hampshire Attorney General that a laptop containing employee personal information (names, addresses, SSNs, payroll data) was stolen from a USinternetworking, Inc. employee's home in Ohio on March 23, 2008. Approximately 20 New Hampshire residents were affected. The laptop was password-protected. Chipotle offered 2 years of identity theft monitoring via Kroll Inc.