Panera Bread breach impacts 5.1 million accounts, not 14 million customers
嗯,用户让我帮忙总结一篇文章的内容,控制在100字以内,而且不需要用“文章内容总结”之类的开头。首先,我得仔细阅读这篇文章,了解它的主要信息。 文章讲的是美国连锁餐厅Panera Bread的数据泄露事件。最初报道说有1400万客户受影响,但后来Have I Been Pwned网站指出实际受影响的账户是510万个。这个数据泄露事件是由一个叫做ShinyHunters的勒索团伙造成的,他们通过钓鱼攻击获取了微软的SSO代码,进而入侵了Panera的系统。 此外,文章还提到ShinyHunters还攻击了Match Group和SoundCloud等公司。Panera方面则确认了数据泄露,并表示泄露的信息主要是联系信息。 接下来,我需要将这些信息浓缩到100字以内。重点包括:数据泄露影响510万账户,最初报道为1400万;ShinyHunters通过钓鱼攻击入侵;涉及其他公司如Match Group和SoundCloud;Panera确认泄露并说明情况。 要注意不要遗漏关键点,同时保持语言简洁明了。可能需要调整句子结构,确保信息完整且符合字数限制。 </think> 美国连锁餐厅 Panera Bread 遭遇数据泄露事件,最初报道称 1400 万客户受影响,但实际受影响账户为 510 万。勒索团伙 ShinyHunters 通过钓鱼攻击获取微软 SSO 代码入侵系统,并泄露了包含姓名、电话号码和地址等信息的文档。该团伙还攻击了 Match Group 和 SoundCloud 等公司。Panera 确认数据泄露并表示涉及联系信息。 2026-2-2 14:0:27 Author: www.bleepingcomputer.com(查看原文) 阅读量:0 收藏

Panera Bread

The data breach notification service Have I Been Pwned says that a data breach at the U.S. food chain Panera Bread affected 5.1 million accounts, not 14 million customers as previously reported.

Founded in 1987, the company operates nearly 2,300 bakery-cafes across 48 U.S. states and in Ontario, Canada, under the names Panera Bread or Saint Louis Bread Co.

Have I Been Pwned's report comes after the ShinyHunters extortion gang claimed in late January that they had stolen a wide range of personally identifiable information (PII) and contact information for over 14 million Panera Bread user accounts. The cybercrime group has since leaked an archive of nearly 760 MB of documents on its dark web leak site, containing data stolen from Panera Bread.

Wiz

"These files were leaked on the ShinyHunters DLS because the victim did not pay a ransom or cooperate and comply with the ShinyHunters group," the extortion gang says in a text file added to the leaked archive.

ShinyHunters told BleepingComputer that they gained access to Panera's systems via a Microsoft Entra single sign-on (SSO) code. The attack was part of a new ShinyHunters voice phishing (vishing) campaign targeting single sign-on (SSO) accounts at Okta, Microsoft, and Google across more than 100 high-profile organizations.

"In January 2026, Panera Bread suffered a data breach that exposed 14M records," said data breach notification service Have I Been Pwned over the weekend. "After an attempted extortion failed, the attackers published the data publicly, which included 5.1M unique email addresses along with associated account information such as names, phone numbers and physical addresses."

While other news outlets have reported immediately after ShinyHunters claimed the attack that the breach affected 14 million Panera Bread customers, the extortion gang's website explained that that number refers to records stolen during the attack. According to BleepingComputer's count, these stolen records contain personal information for roughly 5,120,000 unique user accounts, which may represent fewer customers, since each affected individual may have used more than one account.

BleepingComputer also found more than 26,000 unique panerabread.com email addresses, likely belonging to Panera Bread employees whose PII was stolen in the breach.

Panera Bread entry on ShinyHuntes leak site
ShinyHunters leak site (BleepingComputer)

While Panera Bread has yet to file data breach notifications or issue a statement about the incident, it has notified authorities and confirmed the breach, saying that "the data involved is contact information."

As part of the same series of vishing attacks, ShinyHunters has also breached the online dating giant Match Group, which owns multiple popular dating services, including Tinder, Match.com, Hinge, Meetic, and OkCupid.

Match Group has since confirmed that the attackers stole a "limited amount of user data" after ShinyHunters leaked 1.7 GB of compressed files allegedly containing internal documents and around 10 million records of Hinge, OkCupid, and Match user information.

Audio streaming platform SoundCloud also confirmed a ShinyHunters attack in December, following widespread reports of users encountering 403 "Forbidden" errors when connecting via VPN. The attack led to a data breach affecting 29.8 million accounts, as Have I Been Pwned revealed last week.

BleepingComputer reached out to Panera Bread with questions about the December 2025 incident, but a response was not immediately available.

Panera Bread also notified employees of a data breach in June 2024 after threat actors stole their personal information in a March 2024 ransomware attack that triggered a nationwide IT outage.

tines

The future of IT infrastructure is here

Modern IT infrastructure moves faster than manual workflows can handle.

In this new Tines guide, learn how your team can reduce hidden manual delays, improve reliability through automated response, and build and scale intelligent workflows on top of tools you already use.


文章来源: https://www.bleepingcomputer.com/news/security/panera-bread-data-breach-impacts-51-million-accounts-not-14-million-customers/
如有侵权请联系:admin#unsafe.sh