CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Panera Bread Breach Affects 5.1 Million Accounts via SSO Compromise

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

The ShinyHunters extortion gang breached Panera Bread's systems via a Microsoft Entra single sign-on (SSO) compromise, exposing 5.1 million unique user accounts. The breach included personally identifiable information (PII) such as names, phone numbers, and physical addresses. The initial claim of 14 million affected customers was clarified to refer to stolen records, not unique accounts. The breach was part of a broader vishing campaign targeting SSO accounts at Okta, Microsoft, and Google across over 100 organizations. Panera Bread has confirmed the breach but has not yet issued a public statement.

Timeline

  1. 02.02.2026 15:46 1 articles · 23h ago

    ShinyHunters Breaches Panera Bread via SSO Compromise

    In January 2026, ShinyHunters breached Panera Bread's systems via a Microsoft Entra single sign-on (SSO) compromise, exposing 5.1 million unique user accounts. The breach included PII such as names, phone numbers, and physical addresses. The initial claim of 14 million affected customers was clarified to refer to stolen records, not unique accounts. Panera Bread has confirmed the breach but has not yet issued a public statement.

    Show sources

Information Snippets