Skip to content
NetarxImpact Database
Vishing (Voice Phishing)UnknownAlleged

ShinyHunters claim 14M Panera Bread records after Entra SSO vishing

Panera Bread · Hospitality · United States · January 2026

What happened

ShinyHunters listed Panera Bread on its leak site in late January 2026, claiming roughly 14 million customer records totalling about 760MB compressed. Reporting attributes the access to a Microsoft Entra single sign-on compromise achieved through voice phishing. Panera Bread has not publicly confirmed the incident, and the claimed record count is unverified.

How the deception worked

The crew phoned staff while impersonating IT or a trusted service provider and talked them through a fake Entra sign-in flow, capturing the password and then the MFA code or push approval needed to complete the login. Urgency around a supposed account or migration problem carried the call. With a valid Entra session the attackers reached customer data stores and exfiltrated names, email and postal addresses, phone numbers and account details before opening an extortion negotiation. Payment card data and passwords were reportedly not included.

The control that would have caught it· our reading, not a claim from the sources

Number matching alone does not stop a real-time relay; phishing-resistant MFA plus a strict rule that IT never asks for codes by phone is the control that holds.

Sources (2)

  1. ShinyHunters Claims 14M Panera Bread Records Exposed in Data Breach
    TechRepublic·techrepublic.comOpen ↗
  2. Over 100 Organizations Targeted in ShinyHunters Phishing Campaign
    SecurityWeek·securityweek.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.