Panera Bread contact-information data incident

A Panera Bread incident confirmed by the company and associated with a later-public contact-information corpus. A verified HIBP corpus of unique email addresses and associated contact information, with separate record and account measurements preserved from other sources.

Last modified

Summary

  • Environment: Not publicly identified
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

A Panera Bread incident confirmed by the company and associated with a later-public contact-information corpus. [2][3]

Impact

A verified HIBP corpus of unique email addresses and associated contact information, with separate record and account measurements preserved from other sources. [2][3]

Documented data types include:

  • Names — Names associated with records in the verified HIBP corpus. [2][3]
  • Contact information — Email addresses, phone numbers, and physical addresses associated with records in the verified HIBP corpus. [2][3]

A cited record reports 5,120,000 records (BleepingComputer’s direct count of unique user accounts in the released records; it may represent fewer people because one person may have used multiple accounts). [1]

A cited record reports 5,112,502 records (Unique email addresses represented in the verified HIBP corpus; not a Panera-confirmed count of people, customers, accounts, documents, or total database rows; as of 2026-01-31). [1][2][3]

BleepingComputer found more than 26,000 unique panerabread.com email addresses in the released records and assessed that they likely belonged to Panera Bread employees. [1][3]

After an attempted extortion, an archive associated with Panera Bread was published on the ShinyHunters leak site. [1][2][3]

Panera Bread characterized the data involved as contact information. [2][3]

Timeline

  1. Documented event

    HIBP BreachDate; not established by Panera as an exact intrusion, detection, containment, exfiltration, or publication date.

    [2]
  2. Public disclosure

    Date Reuters published Panera’s emailed confirmation; no separate first-party public-notice date was found.

    [3]
  3. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT&CK technique.

Actors

  • ShinyHunters

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

Panera Bread confirmed to Reuters by email that an incident occurred. Panera Bread said it alerted authorities about the incident. The evidence ledger retains 2 disputed claims with the original citations rather than silently resolving the conflict. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1][2][3]