Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
underground-data-leakmass-credential-exposurebreach-disclosure-notificationvoice-social-engineering

Panera Bread Data Breach Linked to ShinyHunters Extortion Leak

Updated 3mo agoFirst seen Feb 2, 20263 sources

Panera Bread suffered a data breach in which the ShinyHunters extortion group claimed to have stolen data for more than 14 million accounts, then leaked a ~760MB archive after Panera allegedly refused to pay. Have I Been Pwned (HIBP) reviewed the exposed dataset and reported it contains ~5.1 million unique email addresses, indicating the real impact is substantially smaller than initial claims; the leaked data is described as account/contact information including names, phone numbers, and physical addresses. Panera has indicated the exposed data was contact information and said authorities were notified, while public notification to affected individuals was not yet reflected in the reporting.

ShinyHunters told reporters the intrusion leveraged a Microsoft Entra single sign-on (SSO) code, and was tied to a broader vishing campaign targeting SSO accounts at major identity providers (including Okta, Microsoft, and Google) across 100+ organizations. Other items in the set are unrelated: StopICE reported an attack involving abusive texts and alleged DDoS activity rather than the Panera incident, a Texas convenience-store operator (Gulshan Management Services) disclosed a separate ransomware-related data compromise affecting ~377,000 people, and a separate report described a widespread cloud storage renewal/payment phishing campaign.

Share:
Panera Bread Data Breach Linked to ShinyHunters Extortion Leak
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Feb 2, 20265mo ago

HIBP revises Panera breach impact to 5.1 million unique accounts

Have I Been Pwned reported that the Panera breach affected about 5.1 million unique accounts, clarifying that the previously cited 14 million figure referred to total records rather than unique customers. Analysis of the leaked dataset also identified more than 26,000 email addresses likely associated with Panera employees.

Panera confirms breach to authorities and says contact information was exposed

Panera Bread reportedly notified authorities about the incident and confirmed that the compromised data involved contact information. At the time of reporting, the company had not yet issued a public breach notification or formal public statement.

Attackers say Panera access came through Microsoft Entra SSO vishing

ShinyHunters told reporters it gained initial access to Panera using a Microsoft Entra single sign-on code obtained through a voice-phishing campaign. The group said the same campaign targeted SSO accounts tied to Okta, Microsoft, and Google across more than 100 organizations.

Jan 28, 20265mo ago

Panera allegedly refuses extortion demand and stolen data is leaked

After an alleged extortion attempt failed, ShinyHunters leaked a roughly 760 MB archive on its data leak site. The leaked data was described as containing customer contact information and included names, email addresses, phone numbers, and physical addresses.

ShinyHunters claims Panera Bread breach affecting over 14 million records

In late January 2026, the ShinyHunters extortion group claimed it had stolen data from Panera Bread and initially said the breach involved more than 14 million records. The claim framed the incident as part of the group's broader activity against multiple organizations.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

10 LINKEDOpen in app
Threat actors
1 linked
Organizations
9 linked
Have I Been PwnedBleepingComputerMicrosoft CorporationPanera BreadOktaGoogleSecurity AffairsFox BusinessHold Security
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.