In January 2026, Panera, LLC experienced a data breach that affected approximately 5.1 million unique individuals. The ShinyHunters group claimed responsibility for the direct cyberattack on Panera's network. The incident was not a vendor or third-party breach.
The exposed data included names, email addresses, phone numbers, home addresses, and account details. Social Security numbers, medical data, or financial payment information were not confirmed as exposed in the primary breach files. The breach impacted customers across the entire United States. While some individuals reported receiving a "NOTICE OF DATA BREACH" letter, Panera has not publicly acknowledged mass notification. Extortion emails and texts referencing Panera began flowing to affected users in late January 2026.
Details can emerge later, and notices may be delayed.