Panera Bread data breach (2026): what was exposed and what to do
We publish these pages from public notices and reporting so you can understand what was exposed. Everything here is already public. Always confirm with the organization named in your notice.
Panera Bread data breach (2026): what was exposed and what to doBy Delist Editorial Team · Updated September 28, 2026 · Corrections
September 28, 2026
What happened
Panera Bread (U.S. bakery-cafe chain; also Saint Louis Bread Co. in some markets) appeared in public breach reporting in January–February 2026 after the ShinyHunters extortion group claimed a large theft and later published an archive on its leak site.
Early headlines repeated an actor figure of about 14 million records. Have I Been Pwned and BleepingComputer later clarified the honest consumer-scale lock: the published data included about 5.1 million unique email addresses, with associated account contact fields. BleepingComputer’s February 2, 2026 story stressed 5.1 million accounts, not 14 million customers—the 14 million figure referred to rows/records in the stolen set, not unique people. HIBP’s Panera Bread entry lists 5.1M affected addresses, breach timing January 2026, added January 31, 2026, and notes that after extortion failed the attackers published the data publicly. SecurityWeek (February 3, 2026), SecurityAffairs, and Cyberinsider repeated the same HIBP-unique lock.
HIBP states Panera subsequently confirmed that “the data involved is contact information” and that authorities were notified. SecurityWeek reported that Panera confirmed the intrusion to Reuters, describing stolen material as contact information. A full multi-state AG consumer-mail program was not the center of early coverage the way formal insurance BA notices are—prefer any letter you actually receive.
SecurityWeek also attributed the intrusion method to a compromised Microsoft Entra SSO code obtained via voice phishing—treat that as press/researcher reporting on actor tradecraft, not a substitute for an official technical postmortem.
(Separate historical note: Panera also had a 2024 employee/ransomware-related incident discussed in older coverage, and a much older 2018 website leak covered by Krebs/Reuters. Do not merge those events with this 2026 customer-contact leak.)
Sources
- Panera Bread – Have I Been Pwned breach entry (5.1M unique; added Jan 31, 2026)
- Panera Bread breach impacts 5.1 million accounts, not 14 million customers – BleepingComputer (Feb 2, 2026)
- Hackers Leak 5.1 Million Panera Bread Records – SecurityWeek (Feb 3, 2026)
- Panera Bread breach affected 5.1 Million accounts, HIBP Confirms – SecurityAffairs
- Panera Bread data breach exposed personal info of 5.1 million customers – Cyberinsider
What data was exposed
Per HIBP and clarifying press (BleepingComputer, SecurityWeek, SecurityAffairs, Cyberinsider):
- Email addresses (~5.1 million unique)
- Names
- Phone numbers
- Physical addresses
Press also noted tens of thousands of unique @panerabread.com addresses consistent with employee/contact rows in the set. Passwords / payment-card primary accounts were not the headline inventory in the HIBP summary for this incident—rely on any official notice for edge cases. Actor “14M records” is not a unique-customer census.
Breach details
| Detail | Value |
|---|---|
| Breach name | Panera Bread (actor leak / HIBP listing) |
| Date | Incident / publication window January 2026 (HIBP: breach occurred January 2026) |
| Disclosed | Actor claims late January 2026; HIBP added Jan 31, 2026; clarifying press Feb 2–3, 2026 |
| Accounts affected | ~5.1 million unique emails (HIBP). Actor “14M records” ≠ unique customers. |
| Domain | panerabread.com |
This summary is compiled from public notices and reporting available when this page was last updated. Figures reflect what those sources report and may change as investigations continue. If something here looks wrong or you think your information is involved, contact our support team.
We report breaches as a factual record to help people check their exposure. Inclusion here is not an allegation of wrongdoing or negligence by Panera Bread; it reflects a publicly reported security incident.
For whether your information was involved and for official remediation offers, rely on notices from the organization named above (or from anyone they say will contact you) — not this page alone.
What to do now
Based on the contact fields named:
- Treat texts/emails that cite a Panera account, reward balance, or “breach refund” as possible phishing; use the official app/site you already trust.
- Change passwords if you reused a Panera password elsewhere; enable MFA where available.
- Watch for SIM-swap / account-takeover style SMS that recite your phone or home address.
- Ignore “14 million customers” scare headlines when deciding what applied to you—the honest lock is ~5.1M unique emails with contact fields.
- Keep any official notice if one arrives.
Short checklist: first 48 hours after a data breach.
How this shows up on the open web
Names, phones, emails, and home addresses are exactly what people-search and data-broker sites already assemble. After a contact-heavy restaurant leak, scam messages can sound local and personal. Run a free open-web scan to see which people-search and broker sites expose your personal data. Delist does not claim to have scanned Panera’s systems or this dump, and it does not remove dump copies.
Related reading: how to remove yourself from data brokers and what is people-search removal.
My email is in the Panera 5.1M HIBP listing—what first?
Ignore “14 million customers” headlines; the honest lock is ~5.1M unique emails with contact fields. Change reused passwords and watch for local-sounding phishing.
Frequently asked questions
Was it 14 million customers or 5.1 million?
Use ~5.1 million unique email addresses (Have I Been Pwned). The ~14 million figure referred to records/rows in the stolen set as claimed by the actors—not unique customers. BleepingComputer’s February 2, 2026 story and SecurityWeek’s February 3 coverage make that distinction explicit.
What data types were confirmed in public listings?
HIBP lists email addresses, names, phone numbers, and physical addresses. HIBP notes Panera confirmed the involved data was contact information and that authorities were notified; SecurityWeek reported the same confirmation to Reuters.
Is this the same as Panera’s 2024 employee incident?
No. Keep the 2024 ransomware/employee reporting (and the older 2018 website leak) separate from this January 2026 customer-contact leak and HIBP listing.
Can Delist remove my Panera row from the leak?
No. Delist does not scrub restaurant systems or breach dumps. A free scan checks open-web people-search and broker listings only.
What to do after a breach
- A company emailed me about a breach: what should I do?
- Dark web data versus data brokers
- What to do after a data breach
- First 48 hours after a data breach
- How to remove yourself from data brokers
- What is people-search removal?
A free Delist scan checks open-web exposure we support: people-search sites, public records, data brokers, and breach-source signals. Signals are not live listings, and this is not removing you from a dump, a DMV database, or a vendor's private ID store.
More breaches
Free personal data exposure scan
We search the open web for your personal data and show what’s exposed. The scan is free. Removal and monitoring require a paid plan.