Panera Bread suffered a data breach in which the ShinyHunters extortion group claimed to have stolen data for more than 14 million accounts, then leaked a ~760MB archive after Panera allegedly refused to pay. Have I Been Pwned (HIBP) reviewed the exposed dataset and reported it contains ~5.1 million unique email addresses, indicating the real impact is substantially smaller than initial claims; the leaked data is described as account/contact information including names, phone numbers, and physical addresses. Panera has indicated the exposed data was contact information and said authorities were notified, while public notification to affected individuals was not yet reflected in the reporting.
ShinyHunters told reporters the intrusion leveraged a Microsoft Entra single sign-on (SSO) code, and was tied to a broader vishing campaign targeting SSO accounts at major identity providers (including Okta, Microsoft, and Google) across 100+ organizations. Other items in the set are unrelated: StopICE reported an attack involving abusive texts and alleged DDoS activity rather than the Panera incident, a Texas convenience-store operator (Gulshan Management Services) disclosed a separate ransomware-related data compromise affecting ~377,000 people, and a separate report described a widespread cloud storage renewal/payment phishing campaign.

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
Have I Been Pwned reported that the Panera breach affected about 5.1 million unique accounts, clarifying that the previously cited 14 million figure referred to total records rather than unique customers. Analysis of the leaked dataset also identified more than 26,000 email addresses likely associated with Panera employees.
Panera Bread reportedly notified authorities about the incident and confirmed that the compromised data involved contact information. At the time of reporting, the company had not yet issued a public breach notification or formal public statement.
ShinyHunters told reporters it gained initial access to Panera using a Microsoft Entra single sign-on code obtained through a voice-phishing campaign. The group said the same campaign targeted SSO accounts tied to Okta, Microsoft, and Google across more than 100 organizations.
After an alleged extortion attempt failed, ShinyHunters leaked a roughly 760 MB archive on its data leak site. The leaked data was described as containing customer contact information and included names, email addresses, phone numbers, and physical addresses.
In late January 2026, the ShinyHunters extortion group claimed it had stolen data from Panera Bread and initially said the breach involved more than 14 million records. The claim framed the incident as part of the group's broader activity against multiple organizations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityaffairs.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.