Bimbo Bakeries
ent_1b96712afb611b1f0544cdd7
Disclosures
1
Leak Site · 1 jurisdiction
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
—
no filed count in sample
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- Bimbo Bakeries
- Normalized
- bimbo bakeries— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300N6Y0KCXXY6UX04
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- grupobimbo.com.mx
Unverified threat-actor claim — not a regulatory filing
Attribution, victim identity, and counts shown here derive from a threat actor's public extortion-blog claims, aggregated by ransomware.live. They have not been validated by the victim or any regulator. Treat them as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Disclosure history (1)newest first
Subsidiary disclosures (newest 10)filed by group companies
◈ These filings were made by or about subsidiaries of Bimbo Bakeries — not by Bimbo Bakeries itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- Texas State AGvia BIMBO BAKERIES USA, INC.2026-09-04
Bimbo Bakeries USA based in Irving, Texas, a business – retail or merchant entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-08-19 and reported on 2026-09-04. 3,982 Texas residents were affected. 46,064 individuals affected in total. Types of information involved: Name of individual;Social Security Number Information;Financial Information (e.g. account number, credit or debit card number). Consumers were notified via U.S. Mail.
- Vermont State AGvia BIMBO BAKERIES USA, INC.2026-09-04
Bimbo Bakeries USA reported a data breach to the Vermont Attorney General. The breach was reported to the AGO on 2026-09-04. The reporting organization type is Other Commercial. 53 Vermont residents were affected. Categories of data breached: Social Security Numbers, Financial Account Codes, Credit and Debit Account Info.
- California State AGvia BIMBO BAKERIES USA, INC.2026-09-04
Bimbo Bakeries USA notified consumers of a data breach involving a zero-day vulnerability in Oracle's E-Business Suite, a third-party vendor application. Unauthorized parties acquired files containing names and Social Security numbers. The breach occurred on August 9, 2025. The company applied patches, investigated the incident, and is offering credit monitoring and fraud assistance to affected individuals.
- Oregon State AGvia BIMBO BAKERIES USA, INC.2026-09-04
Bimbo Bakeries USA reported a data breach to the Oregon Attorney General. The breach was reported on 2026-09-04. The breach occurred during 8/9/2025 - 8/9/2025. The breach was discovered on 12/6/2025. 46,064 individuals were affected. Notice was sent on 8/31/2026.
- Washington State AGvia BIMBO BAKERIES USA, INC.2026-09-04
Bimbo Bakeries USA, a business sector entity reported a other incident to the Washington Attorney General. The organization became aware of the incident on 2025-10-06 and filed notice on 2026-09-04. 786 Washington residents were affected. 333 days elapsed between awareness and notification. 58 days to identify the breach. 0 days to contain the breach.
- New Hampshire State AGvia BIMBO BAKERIES USA, INC.2026-09-04
Bimbo Bakeries USA notified the NH Attorney General of a data security incident involving a zero-day vulnerability in Oracle's eBusiness Suite. Unauthorized parties exploited the vulnerability to access and exfiltrate files containing names, Social Security numbers, and bank account/routing numbers of current and former employees, dependents, and beneficiaries. BBU first learned of the vulnerability on October 6, 2025, and applied patches. The investigation concluded on August 19, 2026, that 94 New Hampshire residents were affected. Notification letters were mailed starting August 31, 2026. Credit monitoring is being offered.
- Massachusetts State AGvia BIMBO BAKERIES USA, INC.2026-09-01
Bimbo Bakeries USA notified Massachusetts residents of a data security incident involving its third-party vendor, Oracle. The incident exposed individuals' names and Social Security numbers. The company offered 24 months of credit monitoring and fraud assistance services through Cyberscout. No specific dates for the breach occurrence or discovery were provided in the notice.
- Massachusetts State AGvia BIMBO BAKERIES USA, INC.2024-06-06
Bimbo Bakeries USA, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-06-06. 28 Massachusetts residents were affected.
- Vermont State AGvia BIMBO BAKERIES USA, INC.2024-06-06
Bimbo Foods Bakeries Distribution, LLC notified consumers that an unauthorized third party gained remote access to a server on February 13, 2024, obtaining files containing names and Social Security numbers of employees and vendors. The company blocked access, engaged forensic experts, notified law enforcement, and is offering two years of identity monitoring via Experian.
- Indiana State AGvia BIMBO BAKERIES USA, INC.2024-06-06
Bimbo Bakeries USA Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2024-02-13 and was reported on 2024-06-06. 6 Indiana residents were affected. 560 individuals affected in total.