Confirmed breach. Intrusion Jan 13, 2023–Jan 14, 2023, discovered Jan 13, 2023 — the first regulatory filing landed 6 days later. 301,910 individuals reported across the linked filings.
Yum! Brands, Inc. disclosed a ransomware attack on January 18, 2023, impacting IT systems and causing temporary disruption to less than 300 UK restaurants. The company took systems offline, engaged forensic professionals, and notified federal law enforcement. While data was exfiltrated, customer databases were reportedly not stolen.
SEC 4-day OK · 1d
49 days
Breach discoveredconflicts with Jan 13, 2023AG web form
Mar 9, 2023
Reported by MAINE AG, OREGON AG filings
Most recent
7 State AG filingsApr 7, 2023 – Apr 14, 2023ExpandCollapse
WAMECANHORMTDE
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Yum! Brands, Inc., a business sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2023-01-13 and filed notice on 2023-04-07. 1,220 Washington residents were affected. 84 days elapsed between awareness and notification. 0 days to identify the breach. 1 days to contain the breach.
Affected (this filing): 1,220
WA AG >30d
🦞Maine State AGlinked via same-victim cross-source · 95%
Yum! Brands, Inc. reported a ransomware attack that occurred on January 13, 2023, and was discovered on March 9, 2023. The breach affected 11 Maine residents, compromising their names and driver's license or non-driver identification card numbers. Impacted individuals were notified on April 7, 2023, and offered two years of identity protection services.
Affected (this filing): 11
ME AG ≤30d · 29d
🐻California State AGlinked via same-victim cross-source · 95%
Yum! Brands, Inc. experienced a cybersecurity incident on or around January 13, 2023 involving unauthorized access to certain of its systems. Upon discovery, the company locked down impacted systems, notified federal law enforcement, engaged digital forensics teams, and deployed enhanced monitoring. A subsequent data review confirmed that personal information belonging to certain individuals was present in affected files. Two years of complimentary credit monitoring and identity protection were offered via IDX.
⛰️New Hampshire State AGlinked via same-victim cross-source · 100%
Yum! Brands, Inc. reported a ransomware attack occurring on or around January 13, 2023, affecting approximately 621 New Hampshire residents (current/former employees and dependents). Personal information was exposed. Yum! locked down systems, notified law enforcement, engaged forensic experts, and offered 2 years of credit monitoring. Notification letters were sent starting April 14, 2023.
Affected (this filing): 621
🦫Oregon State AGlinked via same-victim cross-source · 95%
Yum! Brands, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2023-04-14. The breach occurred during 1/13/2023 - 1/14/2023. The breach was discovered on 3/9/2023. 300,000 individuals were affected. Notice was sent on 4/14/2023.
Affected (this filing): 300,000
OR AG ≤45d
🦬Montana State AGlinked via same-victim cross-source · 95%
Yum! Brands, Inc reported a data breach to the Montana Attorney General. The breach was reported on 2023-04-14. The breach occurred on 1/13/2023. 58 Montana residents were affected.
Affected (this filing): 58
💎Delaware State AGlinked via same-victim cross-source · 95%
Yum! Brands, Inc. notified Delaware AG of a cybersecurity incident occurring on or around January 13, 2023, involving unauthorized access to systems. The breach exposed personal information of individuals, including names and addresses. Yum! locked down systems, notified federal law enforcement, engaged forensic teams, and deployed enhanced monitoring. The company offered 2 years of complimentary credit monitoring and identity protection services via IDX to affected individuals.