Bimbo Bakeries USA disclosed a data breach related to its Oracle E-Business Suite. The incident occurred on August 9, 2025, and the company later determined that files were accessed on December 6, 2025. The breach was publicly reported to the California Attorney General on September 4, 2026, and affected consumers were notified starting August 31, 2026.
The breach exposed data for 4,345 individuals. Confirmed data types include names, Social Security numbers, dates of birth, wage and compensation information, tax return information, direct deposit account details, mailing addresses, and phone numbers. The affected individuals reside in states including California, Texas, and Massachusetts.
Details can emerge later as investigations continue, and formal notices may be delayed for various reasons. Public plaintiff-side law firms indicate ongoing class action investigation activity related to the breach, though a confirmed filed class action complaint or MDL status has not been found in the available sources.