Panera Bread·Retail / hospitality·
Customer records were exposed.
Panera acknowledged a breach while the article reports ShinyHunters’ alleged theft and publication of customer personal information. The exact technical root cause is not established in the attached record.
Report freshness and timeline
- First publicly reported
- First disclosed
- Latest attached source
- Radar data checked
Coverage window — Dataset generated Aug 30, 2026, 12:03 UTC
Executive incident brief
- Incident confirmation
- Organization confirmed
- Mechanism
- Entry path: Third-party SaaS application
- Consequence
- Reported: Customer records were exposed.
- Scope
- The complete extent is not established by this record.
1)Incident fact sheet
- Organization
- Panera Bread
- Industry
- Retail / hospitality
- Disclosed
- Third party
- third-party SaaS application
- Affected asset
- third-party SaaS application
- Product / vendor
- Microsoft Entra single sign-on (SSO)
- Country
- US
- Data involved
- Personal data
- Reported impact
- Data exposure · Extortion demand
- Attached evidence
- 7 independent domains · 7 sources
2)Evidence-backed incident path
- 01
Third party
third-party SaaS application
ConfidenceSecondaryExact excerpt
E1“access to a third-party SaaS application”
restaurantbusinessonline.com · Feb 23 - 02
Affected product
Microsoft Entra single sign-on (SSO)
ConfidenceSecondaryExact excerpt
E2“via a Microsoft Entra single sign-on (SSO) code”
bleepingcomputer.com · Feb 02 - 03
Reached
third-party SaaS application
ConfidenceSecondaryExact excerpt
E3“unauthorized access to a third-party SaaS application”
restaurantbusinessonline.com · Feb 23 - 04
Observed
Customer records were exposed.
ConfidenceProbableExact excerpt
E4“exposed 14M records”
bleepingcomputer.com · Feb 02
3)Impact and scope ledger
Established
Supported at the stated evidence level.
Reported
Present in public reporting; not independently established by Radar.
Not publicly established
No qualifying public evidence in the attached record.
- The exact technical root cause
- No ransom payment is stated
- That a Defence review would have prevented this incident
4)Relevance to your product
Third-party access can inherit more reach than the product team intended.
This pattern applies when…
- Products that use third-party SaaS applications and federated identity codes.
Diagnostic questions
- Can an integration reach production secrets or customer data?
- Are scopes narrower than the vendor's full workspace access?
- Can tokens be isolated and revoked without breaking the product?
This incident does not establish your product's risk.
5)Sector context — Retail / hospitality
- 1 incident threads
- 1 incident threads
- 2 incident threads
- 1 incident threads
- 6 incident threads
- 8 incident threads
- 6 incident threads
- 8 incident threads
- 5 incident threads
- 4 incident threads
- 9 incident threads
- 6 incident threads
- Same incident family
- 23 Data breach / intrusion
- Confirmed share
- 32% 18 confirmed · 39 reported
- Display family
- Data breach Used for Radar's public chart taxonomy
Publicly disclosed incidents and reports from to . Historical discovery is partial and does not measure breach probability.
Explore Retail / hospitality in Radar →6)Defence control mapping
What Defence can test
Third-party integration review
- Can an integration reach production secrets or customer data?
- Are scopes narrower than the vendor's full workspace access?
- Can tokens be isolated and revoked without breaking the product?
What cannot be concluded
- This incident does not predict an individual product's risk.
- A mapped control does not establish that a Defence review would have prevented the event.
7)Public evidence ledger
7 attached sources across 7 independent domains. No attached source is marked as an organization or regulator primary source.
- E2, E4bleepingcomputer.comPanera Bread breach impacts 5.1 million accounts, not 14 million customersEstablished press · Feb 02 · CitedEstablished pressCited
Exact excerpt
“names, phone numbers and physical addresses”
- E1, E3restaurantbusinessonline.comPanera faces multiple lawsuits following data breachOther public report · Feb 23 · CitedOther public reportCited
Exact excerpt
“access to a third-party SaaS application”
Does this integration boundary exist in your product?
A bounded review can test the authorized web/API path without assuming this incident predicts your risk.