CHIPOTLE MEXICAN GRILL, INC.
ent_019e619e8e0852a65be3816378074a7f
Disclosures
8
State AG · 7 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
5,440
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CHIPOTLE MEXICAN GRILL, INC.
- Normalized
- chipotle mexican grill— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 529900REP5VGTPCP1J71
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (8)newest first
- 🦬Montana State AGas victim2025-12-23
Chipotle Mexican Grill, Inc. reported a data breach to the Montana Attorney General. The breach was reported on 2025-12-23. The breach occurred from 10/09/2025 to 10/26/2025. 15 Montana residents were affected.
- ⛰️New Hampshire State AGas victim2025-12-23
Chipotle Mexican Grill, Inc. notified the New Hampshire Attorney General of a cybersecurity incident affecting 2 New Hampshire residents. Between October 9 and October 26, 2025, attackers used phishing tactics to gain unauthorized access to employees' Workday payroll accounts. The attackers modified deposit information and accessed personal data including Social Security numbers, dates of birth, and bank account details. Chipotle secured the accounts, launched an investigation, and began mailing notification letters on December 23, 2025, offering one year of credit monitoring services.
- 🍁Vermont State AGas victim2025-12-23
Chipotle Mexican Grill, Inc. notified consumers of a phishing incident targeting employee Workday payroll accounts between October 9-26, 2025. Attackers used stolen credentials to access employee profiles, exposing SSNs, dates of birth, and bank routing/account numbers. Chipotle restored accounts, ensured wage payment, and offered Kroll identity monitoring. No network compromise occurred.
- 🏎️Indiana State AGas victim2025-12-23
Chipotle Mexican Grill Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2025-10-09 and was reported on 2025-12-23. 9 Indiana residents were affected.
- 🦞Maine State AGas victim2020-10-29
Chipotle Mexican Grill reported a phishing incident occurring Jan 19-21, 2020, discovered Sep 30, 2020. 5,440 individuals affected nationwide, including 19 Maine residents. Data exposed: names and Social Security Numbers. Notification sent Oct 29, 2020; credit monitoring offered via Experian.
- 🦬Montana State AGas victim2017-06-05
Chipotle Mexican Grill reported a data breach to the Montana Attorney General. The breach was reported on 2017-06-05. The breach occurred from 3/24/2017 to 4/18/2017.
- 🐻California State AGas victim2017-05-26
Chipotle Mexican Grill, Inc. reported a payment card security incident involving malware operating on POS devices at certain restaurants between March 24, 2017, and April 18, 2017. The malware accessed track data from magnetic stripe cards. Chipotle removed the malware, engaged forensic firms, and notified law enforcement and payment card networks. No other customer information was affected. The breach was reported to the California Attorney General's office on May 26, 2017.
- 🦫Oregon State AGas victim2017-05-26
Chipotle Mexixan Grill, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2017-05-26. The breach occurred during 3/24/2017 - 4/18/2017. The breach was discovered on 4/5/2017. Notice was sent on 5/26/2017.