EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/2026-panera-bread-data-breach
055/430

File EL-0376HighResolvedData Breach / Credential Theft / Account Takeover

Panera Bread Data Breach

Also filed as Panera Bread Customer Data Leak · Panera Loyalty Program Breach

A data breach at Panera Bread exposed over 5 million customer accounts, with stolen data including names, email addresses, phone numbers, and loyalty program information.

  • #food-beverage
  • #pii
  • #loyalty-program
  • #credential-stuffing
  • #january-2026
Notoriety7/10
Event
1 Jan 2026
Disclosed
31 Jan 2026
Target
Panera Bread
Scale
5.1M people
Status
Resolved

01Summary

In late January 2026, a dataset containing 5.1 million Panera Bread customer records was discovered on underground forums. The exposed data included customer names, email addresses, phone numbers, physical addresses, and MyPanera loyalty program details. Panera confirmed the incident and stated that payment card information was not affected. The data appeared to originate from a credential stuffing attack or a compromise of Panera's customer database.

02Background

Panera Bread operates over 2,000 bakery-cafe locations across the United States and Canada. Its MyPanera loyalty program has millions of members, making it a valuable target for credential theft and reward abuse.

03Technical analysis

The attack is believed to have involved credential stuffing (using reused passwords from other breaches) or a direct compromise of Panera's customer database. The absence of payment data suggests the attackers targeted loyalty and account information specifically.

Attack vector
Credential stuffing or database compromise
Attack method
Account takeover and data exfiltration
Initial access
Credential stuffing (likely)
Exfiltration
Bulk data extraction

04Threat actor

Unknown threat actors likely focused on credential stuffing for financial gain through loyalty reward abuse.

Attribution sources

  • Have I Been Pwned
  • Panera Bread statements

05Victims and impact

Countries affected

  • United States
  • Canada

06Data exposed

Data types

  • PII
  • Names
  • Email addresses
  • Phone numbers
  • Physical addresses
  • Loyalty program data

07Financial damage

Reputational damage and potential regulatory fines.

08Timeline

  1. 2026-01-01Approximate date of compromise.
  2. 2026-01-31Breach publicly disclosed; 5.1M records listed on HIBP.

09Reaction and fallout

Public reaction

Concern among loyalty program members about reward point theft and account security.

10Significance and legacy

Significance

Highlights continued vulnerability of loyalty program databases to credential stuffing and account takeover attacks in the food service industry.

11Disclosure and media

Authentication
HIBP breach confirmation

Publishing organisations

  • Have I Been Pwned
  • BleepingComputer

12Field notes

  1. 01The MyPanera loyalty program is the primary target for credential stuffing attacks due to stored reward points and stored payment methods.

13Resolution

Panera confirmed the breach and took steps to secure affected accounts.

14Sources

Official documents

  • Panera Bread data breach notification

References

  1. [1]Have I Been Pwned - Panera Bread breach listing
  2. [2]BleepingComputer coverage
Fact sheetEL-0376

Dates

Event
1 Jan 2026
Started
1 Jan 2026
Discovered
31 Jan 2026
Disclosed
31 Jan 2026
Ongoing
No

Target

Organisation
Panera Bread Company
Type
Food & Beverage Company
Sector
Fast Casual Restaurant
Country
United States

Actor

Motivation
Financial gain through credential theft and loyalty reward abuse.
Attribution
Low
Arrested
No
Convicted
No

Data

People
5,100,000
Records
5,100,000
Sensitivity
High
Published
Yes
Sold (dark web)
Yes

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.