Five Guys Holdings, Inc.
ent_019ebb55d04131eccf2f4cc836393794
Disclosures
19
State AG · Leak Site · 7 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
37,529
nationwide · State AG IN
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- Five Guys Holdings, Inc.
- Normalized
- five guys— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300XWT8G8Q3Z3HJ19
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- fiveguys.com
Disclosure history (19)newest first
- California State AGas victim2023-10-27
Five Guys Enterprises, LLC reported unauthorized access to two employee email accounts. Access to the first account occurred between March 20, 2023, and March 31, 2023; access to the second occurred between May 31, 2023, and June 7, 2023. The investigation determined that emails or attachments contained names and other personal information. Five Guys engaged a cybersecurity firm, secured the accounts, and offered one year of credit monitoring and identity protection services via IDX.
- Maine State AGas victim2023-10-27
Five Guys Enterprises, LLC / Five Guys Operations, LLC reported a business email compromise incident in Maine affecting 3 residents. The breach occurred between March 20 and June 7, 2023, and was discovered on June 7, 2023. The incident involved the acquisition of Social Security Numbers. Notification was sent on October 27, 2023, offering one year of credit monitoring and identity theft protection services through IDX.
- Indiana State AGas victim2023-10-27
Five Guys Enterprises, LLC, Five Guys Operations, LLC reported a data breach to the Indiana Attorney General. The breach occurred on 2023-03-20 and was reported on 2023-10-27. 27 Indiana residents were affected. 5,874 individuals affected in total.
- New Hampshire State AGas victim2023-10-27
Five Guys Enterprises, LLC notified the New Hampshire Attorney General of a security incident involving unauthorized access to two employee email accounts. The unauthorized access occurred between March 20, 2023, and June 7, 2023. The investigation determined that the name and Social Security number of three New Hampshire residents were accessed. Five Guys provided one year of credit monitoring and identity theft protection services to the affected individuals.
- Massachusetts State AGas victim2023-10-27
Five Guys Enterprises, LLC / Five Guys Operations, LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-10-27. 18 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2023-10-27
Five Guys Enterprises, LLC notified individuals of a security incident involving unauthorized access to two employee email accounts between March and June 2023. The attacker likely obtained credentials via phishing. The investigation, completed on September 20, 2023, confirmed that some emails contained names and variable data elements. Affected individuals were offered one year of credit monitoring and identity protection services.
- GLOBALLeak Siteas victim2023-02-04
Five Guys Enterprises, LLC is a food-chain
- Indiana State AGas victim2022-12-29
Five Guys Enterprises, LLC, Five Guys Operations, LLC reported a data breach to the Indiana Attorney General. The breach occurred on 2022-09-17 and was reported on 2022-12-29. 110 Indiana residents were affected. 37,529 individuals affected in total.
- Massachusetts State AGas victim2022-12-29
Five Guys Enterprises, LLC / Five Guys Operations, LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-12-29. 93 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2022-12-29
Five Guys Enterprises, LLC reported unauthorized access to a file server on September 17, 2022. The incident involved employment-related information, including names and other data submitted during the hiring process. The company engaged a cybersecurity firm, notified law enforcement, and offered one year of credit monitoring and identity protection services to affected individuals.
- Montana State AGas victim2022-12-29
Five Guys Enterprises, LLC notified affected individuals of a September 17, 2022 security incident involving unauthorized access to a file server containing employment-related PII. The company engaged forensic investigators, notified law enforcement, and provided one year of credit monitoring services to affected individuals.
- New Hampshire State AGas victim2022-12-29
Five Guys Enterprises and Five Guys Operations notified the NH Attorney General of unauthorized access to a file server on September 17, 2022. The investigation determined that the name and Social Security number of 22 New Hampshire residents were accessed. Notification letters were mailed beginning December 29, 2022, and one year of credit monitoring was provided.
- Maine State AGas victim2022-12-29
Five Guys Enterprises, LLC and Five Guys Operations, LLC reported an external system breach that occurred on September 17, 2022, and was discovered on December 8, 2022. The incident affected 37,529 individuals, compromising their names and Social Security numbers. In response, the company offered one year of complimentary credit monitoring and identity theft protection services through IDX.
- Massachusetts State AGas victim2018-12-12
Five Guys Holdings Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-12-12. 38 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2018-12-03
Five Guys Holdings, Inc. filed a supplemental notice with the New Hampshire Attorney General regarding a phishing incident that compromised an employee's email account. The incident, initially discovered on August 6, 2018, resulted in unauthorized access to personal information of approximately 3 New Hampshire residents. Five Guys engaged forensic investigators, secured the account, and offered credit monitoring services.
- California State AGas victim2018-11-30
Five Guys Enterprises, LLC reported that an employee fell victim to a phishing email, resulting in unauthorized access to their email account between May 23, 2018, and August 6, 2018. The company discovered the incident on August 6, 2018. The breach potentially exposed personal information of employees and vendors. Five Guys secured the account, engaged a cybersecurity firm, and offered one year of identity monitoring services.
- New Hampshire State AGas victim2018-11-06
Five Guys Holdings, Inc. notified the NH AG of a phishing incident on Aug 6, 2018, compromising an employee email. Access may have exposed PII of 5 NH residents (employees/vendors), including SSNs and financial data. Five Guys engaged forensic investigators, secured the account, and offered 1-year credit monitoring. Investigation into full scope was ongoing at time of filing.
- California State AGas victim2018-11-02
Five Guys Enterprises, LLC notified California residents that an employee fell victim to a phishing email on August 6, 2018, resulting in unauthorized access to their email account. The incident occurred between May 23, 2018, and August 6, 2018. Affected data may include names, dates of birth, Social Security numbers, addresses, hire/termination dates, and 401K contribution information. Five Guys secured the account, engaged a cybersecurity firm, and offered one year of Experian IdentityWorks to affected employees.
- Montana State AGas victim2018-11-02
Five Guys Enterprises, LLC notified Montana residents that on August 6, 2018, an employee fell victim to a phishing email, leading to unauthorized access of their email account. The attacker accessed personal information including names, SSNs, dates of birth, and financial data for employees and vendors. Five Guys secured the account, engaged forensic investigators, and offered one year of Experian IdentityWorks.