
Panera Bread Breach
Jan 26, 2026
9,080,219 rows
What happened in the Panera Bread Breach?
DataBreach.com Team · January 27th 2026, 7:00 pm EST
In late January 2026, the ShinyHunters hacking group claimed responsibility for a significant data breach targeting Panera Bread, alleging the theft of over 14 million records. According to reports from The Register, the group bypassed security measures using a stolen Microsoft Entra single-sign-on (SSO) code, a technique consistent with their aggressive 2026 campaign of voice phishing (vishing) IT help desks. The stolen data reportedly spans 760 MB of compressed files containing sensitive customer information, including names, email and home addresses and phone numbers. This incident was part of a broader wave of attacks by the group-which also claimed breaches of CarMax and Edmunds in the same week-highlighting a critical vulnerability in how organizations manage identity access and SSO credentials.










