01Summary
In late January 2026, a dataset containing 5.1 million Panera Bread customer records was discovered on underground forums. The exposed data included customer names, email addresses, phone numbers, physical addresses, and MyPanera loyalty program details. Panera confirmed the incident and stated that payment card information was not affected. The data appeared to originate from a credential stuffing attack or a compromise of Panera's customer database.
02Background
Panera Bread operates over 2,000 bakery-cafe locations across the United States and Canada. Its MyPanera loyalty program has millions of members, making it a valuable target for credential theft and reward abuse.
03Technical analysis
The attack is believed to have involved credential stuffing (using reused passwords from other breaches) or a direct compromise of Panera's customer database. The absence of payment data suggests the attackers targeted loyalty and account information specifically.
- Attack vector
- Credential stuffing or database compromise
- Attack method
- Account takeover and data exfiltration
- Initial access
- Credential stuffing (likely)
- Exfiltration
- Bulk data extraction
04Threat actor
Unknown threat actors likely focused on credential stuffing for financial gain through loyalty reward abuse.
Attribution sources
- Have I Been Pwned
- Panera Bread statements
05Victims and impact
Countries affected
- United States
- Canada
06Data exposed
Data types
- PII
- Names
- Email addresses
- Phone numbers
- Physical addresses
- Loyalty program data
07Financial damage
Reputational damage and potential regulatory fines.
08Timeline
- 2026-01-01Approximate date of compromise.
- 2026-01-31Breach publicly disclosed; 5.1M records listed on HIBP.
09Reaction and fallout
Public reaction
Concern among loyalty program members about reward point theft and account security.
10Significance and legacy
Significance
Highlights continued vulnerability of loyalty program databases to credential stuffing and account takeover attacks in the food service industry.
11Disclosure and media
- Authentication
- HIBP breach confirmation
Publishing organisations
- Have I Been Pwned
- BleepingComputer
12Field notes
- 01The MyPanera loyalty program is the primary target for credential stuffing attacks due to stored reward points and stored payment methods.
13Resolution
Panera confirmed the breach and took steps to secure affected accounts.
14Sources
Official documents
- Panera Bread data breach notification
References
- [1]Have I Been Pwned - Panera Bread breach listing
- [2]BleepingComputer coverage









