In April 2018, reports revealed that customer records on PaneraBread.com had been accessible online in plain text. The records reportedly included names, email and physical addresses, birthdays, and the last four digits of payment-card numbers. The number affected was disputed: Panera said 10,000 records, while HoldSecurity estimated 37 million. Neither figure proves how many unique people experienced misuse of their information.
What happened in the Panera Bread data leak?
On April 2, 2018, KrebsOnSecurity reported that PaneraBread.com exposed customer records in a form that could be retrieved from the website. The records appeared to relate to customers who had created online accounts to order food. This was a publicly accessible web-data exposure, not a report of attackers stealing passwords through phishing or breaking into customers’ devices.
Malwarebytes reported the next day that security researcher Dylan Houlihan had contacted Panera in August 2017, but the records remained accessible for at least eight months. After Krebs notified the company in April 2018, Panera briefly took the website offline; according to Malwarebytes, the records were no longer accessible when it returned.
How many customers were affected?
There is no single confirmed count in the cited reporting. The figures refer to different claims and records, so they should not be treated as interchangeable counts of verified individual victims.
#1 Best Overall
| Figure | What it represents |
|---|---|
| 10,000 customer records | Panera’s figure, as reported by Malwarebytes in 2018. |
| 37 million records | HoldSecurity’s estimate, as reported by Malwarebytes in 2018. |
| 37,000,000 victims | The Identity Theft Resource Center’s 2020 database entry for the Panerabread.com incident. This is a database figure, not proof that 37 million unique people had confirmed misuse of their data. |
The ITRC entry identifies August 2, 2017, as the breach date and April 2, 2018, as the report date. Its separate Panera entry dated 2026 concerns a different listing and should not be combined with this 2018 incident.
What information was exposed?
The reports identified these fields in the exposed records:
- Names
- Email addresses
- Physical addresses
- Birthdays
- The last four digits of credit-card numbers
The cited reports do not establish that full card numbers, account passwords, or Social Security numbers were exposed in this incident. That is a limit of what those reports document, not a guarantee about information outside their findings.
What should former or current Panera customers do?
- Watch for targeted scams. Be cautious with unexpected emails, calls, and texts that use personal details or claim to be from Panera, a bank, or a delivery service. Verify requests through a contact method you find independently rather than replying or following an unsolicited link.
- Review financial and account activity. Check payment-card and bank activity, and use available account alerts. Malwarebytes’ 2018 guidance also recommended monitoring credit reports.
- Secure any account that may be compromised. If you believe your MyPanera account has been compromised, Panera’s current privacy policy advises contacting Panera and immediately removing payment information associated with the account, including debit cards, credit cards, gift cards, or other payment methods.
These steps address the practical risks of exposed contact and partial payment details. The reports do not identify a specific action that every customer must take, nor do they establish that every person whose record appeared suffered fraud.
How does Panera’s current privacy policy relate to the 2018 incident?
Panera’s current U.S. privacy policy covers PaneraBread.com, its mobile app, in-cafe systems, and MyPanera. It describes present-day collection of categories such as account and transaction information, device and browser information, geolocation, inferences, and other network activity. It also describes disclosures to service providers, analytics and advertising partners, data brokers, and government authorities in specified circumstances.
Those policy disclosures describe current privacy practices; they are not evidence that all those categories were present in the 2018 exposed records. The policy also says Panera maintains safeguards but cannot guarantee the safety of information transmitted over the internet.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

