Wendy's
ent_72a557b1e0ee6ceb7b1216c9
Disclosures
5
SEC 10-K Item 1C · State AG · 4 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
1,006
nationwide · State AG NH
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Wendy's
- Normalized
- wendy s— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- 0000030697
- Domain
- wendys.com
Disclosure history (5)newest first
- FEDERALSEC 10-K Item 1Cas victim2026-02-23
The Wendy's Company (CIK 0000848324) filed a 10-K Item 1C disclosure stating that no cybersecurity threats materially affected its business in 2025. The filing details a comprehensive cybersecurity risk management strategy, including CIS Controls, regular risk assessments, infrastructure security, dedicated personnel, training, third-party assessments, and an incident response plan. Governance is overseen by the Audit and Technology Committees.
- 🌴South Carolina State AGas victim2016-07-07
South Carolina AG notice for Wendy's regarding a 2016 breach affecting approximately 1,000 state residents. The source document is a placeholder PDF with no narrative content, resulting in low-confidence extraction of all fields.
- 🐻California State AGas victim2016-07-07
Wendy's of Fresno, Inc. reported a cybersecurity incident involving malicious cyber activity targeting payment card information at franchisee-operated restaurants. The breach resulted from compromised service provider remote access credentials, allowing deployment of malware on POS systems. Affected data included cardholder names, card numbers, expiration dates, and verification values. Wendy's disabled the malware, engaged forensic experts and law enforcement, and offered one year of fraud consultation and identity restoration services to affected customers.
- ⛰️New Hampshire State AGas victim2008-01-29
Wendy's International Inc. notified the NH Attorney General of an administrative error by third-party benefits administrator Life Choices Service Center. On Nov 29, 2007, printed 2008 Benefit Confirmation Statements incorrectly included dependent information (names, SSNs, DOBs) for other employees. Wendy's discovered the breach when employees reported incorrect statements. Corrected statements were mailed on Dec 21, 2007. Approximately 1,006 individuals were affected nationwide, including 4 in New Hampshire. Kroll Inc. was engaged to provide identity safeguards.
- ⛰️New Hampshire State AGas victim2007-12-21
State of New Hampshire Attorney General breach notification filed by Wendy's on December 21, 2007. The source document is a PDF attachment that contains no visible text content in the provided extraction. No specific breach details, dates, or data types are discernible from the available text.