DEFENCE / RADAR

Public snapshot

Panera Bread·Retail / hospitality·

Customer records were exposed.

Panera acknowledged a breach while the article reports ShinyHunters’ alleged theft and publication of customer personal information. The exact technical root cause is not established in the attached record.

Report freshness and timeline

First publicly reported
First disclosed
Latest attached source
Radar data checked

Coverage windowDataset generated Aug 30, 2026, 12:03 UTC

Executive incident brief

Incident confirmation
Organization confirmed
Mechanism
Entry path: Third-party SaaS application
Consequence
Reported: Customer records were exposed.
Scope
The complete extent is not established by this record.

1)Incident fact sheet

Organization
Panera Bread
Industry
Retail / hospitality
Disclosed
Third party
third-party SaaS application
Affected asset
third-party SaaS application
Product / vendor
Microsoft Entra single sign-on (SSO)
Country
US
Data involved
Personal data
Reported impact
Data exposure · Extortion demand
Attached evidence
7 independent domains · 7 sources

2)Evidence-backed incident path

  1. 01

    Third party

    third-party SaaS application

    ConfidenceSecondary
    Exact excerpt

    access to a third-party SaaS application

    restaurantbusinessonline.com · Feb 23
    E1
  2. 02

    Affected product

    Microsoft Entra single sign-on (SSO)

    ConfidenceSecondary
    Exact excerpt

    via a Microsoft Entra single sign-on (SSO) code

    bleepingcomputer.com · Feb 02
    E2
  3. 03

    Reached

    third-party SaaS application

    ConfidenceSecondary
    Exact excerpt

    unauthorized access to a third-party SaaS application

    restaurantbusinessonline.com · Feb 23
    E3
  4. 04

    Observed

    Customer records were exposed.

    ConfidenceProbable
    Exact excerpt

    exposed 14M records

    bleepingcomputer.com · Feb 02
    E4

3)Impact and scope ledger

Not publicly established

No qualifying public evidence in the attached record.

  • The exact technical root cause
  • No ransom payment is stated
  • That a Defence review would have prevented this incident

4)Relevance to your product

Third-party access can inherit more reach than the product team intended.

This pattern applies when…

  • Products that use third-party SaaS applications and federated identity codes.

Diagnostic questions

  1. Can an integration reach production secrets or customer data?
  2. Are scopes narrower than the vendor's full workspace access?
  3. Can tokens be isolated and revoked without breaking the product?

This incident does not establish your product's risk.

5)Sector context — Retail / hospitality

57 incident threads in the 365-day public record
  1. 1 incident threads
  2. 1 incident threads
  3. 2 incident threads
  4. 1 incident threads
  5. 6 incident threads
  6. 8 incident threads
  7. 6 incident threads
  8. 8 incident threads
  9. 5 incident threads
  10. 4 incident threads
  11. 9 incident threads
  12. 6 incident threads
Same incident family
23
Data breach / intrusion
Confirmed share
32%
18 confirmed · 39 reported
Display family
Data breach
Used for Radar's public chart taxonomy

Publicly disclosed incidents and reports from to . Historical discovery is partial and does not measure breach probability.

Explore Retail / hospitality in Radar →

6)Defence control mapping

What Defence can test

Third-party integration review

  • Can an integration reach production secrets or customer data?
  • Are scopes narrower than the vendor's full workspace access?
  • Can tokens be isolated and revoked without breaking the product?

What cannot be concluded

  • This incident does not predict an individual product's risk.
  • A mapped control does not establish that a Defence review would have prevented the event.

7)Public evidence ledger

7 attached sources across 7 independent domains. No attached source is marked as an organization or regulator primary source.

  1. E2, E4
    bleepingcomputer.comPanera Bread breach impacts 5.1 million accounts, not 14 million customersEstablished press · Feb 02 · Cited
    Established pressCited
    Exact excerpt
    names, phone numbers and physical addresses
  2. E1, E3
    restaurantbusinessonline.comPanera faces multiple lawsuits following data breachOther public report · Feb 23 · Cited
    Other public reportCited
    Exact excerpt
    access to a third-party SaaS application
  3. S3
    itbrief.co.ukPanera breach exposes 14m in wave of SaaS extortion attacksOther public report · Feb 02 · Attached
    Other public reportAttached
  4. S4
    securitybrief.asiaPanera breach exposes 14m in wave of SaaS extortion attacksOther public report · Feb 02 · Attached
    Other public reportAttached
  5. S5
    securitybrief.co.nzPanera breach exposes 14m in wave of SaaS extortion attacksOther public report · Feb 02 · Attached
    Other public reportAttached
  6. S6
    securitybrief.newsPanera breach exposes 14m in wave of SaaS extortion attacksOther public report · Feb 02 · Attached
    Other public reportAttached
Show all 7 sourcesShow the first six sources
  1. S7
    itbrief.inPanera breach exposes 14m in wave of SaaS extortion attacksOther public report · Feb 02 · Attached
    Other public reportAttached

Does this integration boundary exist in your product?

A bounded review can test the authorized web/API path without assuming this incident predicts your risk.

Each report separates what public reporting establishes from what remains unknown. It does not turn another company's incident into a prediction of your risk. Dataset coverage: . View methodology →