New data from the Have I Been Pwned (HIBP) service sheds light on the cyberattack that hit American restaurant chain Panera Bread . According to the updated analysis , the data breach did not affect 14 million customers, as initially leaked, but about 5.1 million unique accounts .

This correction does not diminish the seriousness of the incident, especially considering the scope and type of data exposed, but also the fact that the attack is part of a broader, coordinated campaign by the notorious cyber extortion ShinyHunters.
Panera Bread: A food giant in the crosshairs
Panera Bread was founded in 1987 and today operates nearly 2,300 bakery-cafes in 48 states in the United States and Ontario, Canada, either under the Panera Bread brand or as Saint Louis Bread Co.. With millions of customers and a strong digital presence through loyalty programs and online ordering, it is an attractive target for cybercriminal groups.
See also: NationStates suffered a data breach
In late January, ShinyHunters claimed to have stolen data from more than 14 million user accounts. When Panera did not give in to the extortion demands, the group posted a roughly 760MB on the dark web, containing documents and databases attributed to the company.
What does the data analysis show?
As Have I Been Pwned explains, the 14 million refers to the total number of files stolen , not individual individuals. After cross-referencing and decompression of the data, approximately 5,120,000 unique email addresses, along with information such as names, phone numbers, and physical addresses.
This difference is important for understanding the scale of the breach, but experts point out that even five million accounts constitute one of the largest data breaches in the hospitality industry in recent years.

Workers are also targeted
Of particular concern is the fact that, according to research by BleepingComputer, more than 26,000 unique email addresses with the domain panerabread.com were identified in the leaked data . This indicates that employees of the company were likely affected, with personal data exposed outside of internal systems.
See also: New wave of extortion attacks targeting exposed MongoDB databases
Panera Bread, although it has not yet issued an official public statement or notifications to customers, has confirmed the incident to authorities, stating that the data involved mainly concerns contact information.
Vishing and SSO abuse: The new weapon of ShinyHunters
ShinyHunters revealed that initial access to Panera's systems was gained through a single sign-on (SSO) account in Microsoft Entra. The attack is part of a broader campaign voice phishing (vishing), where attackers trick employees into giving them access credentials.
The same campaign reportedly targeted more than 100 high-profile organizations, leveraging SSO platforms from Okta, Microsoft, and Google, highlighting the new generation of threats.

It is not an isolated incident
Panera Bread isn't the only company targeted. In the same wave of attacks, ShinyHunters also breached Match Group, owner of popular dating apps like Tinder, Hinge, and OkCupid, while in December, an attack on SoundCloud, affecting nearly 30 million accounts.
It's worth noting that Panera has previously faced a serious cybersecurity incident. In March 2024, a ransomware attack caused widespread IT outages, and employees were later informed that their personal data had been stolen.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: CERT Polska: Details on cyberattacks on wind and photovoltaic parks
Another bell for businesses
The Panera Bread case clearly demonstrates that social engineering and SSO attacks are now a critical risk for large organizations. Even when the numbers are revised downward, the point remains: data protection and staff training are not optional, but necessary prerequisites in an environment where cyberattacks are becoming increasingly targeted and professional.
source: www.bleepingcomputer.com
