Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

Drive-thru data theft: Taco Bell and Pizza Hut franchiser deep fried by data breach

The franchise operator for major US fast food chains Pizza Hut, Taco Bell and Panera Bread has disclosed a cyber incident that it first discovered back in April.

Thu, 27 Aug 2026
Drive-thru data theft: Taco Bell and Pizza Hut franchiser deep fried by data breach

Pan America Group LLC, revealed the incident in a notice filed with the California Department of Justice, saying that it noted suspicious activity on its network on April 9 this year.

“On April 9, 2026, we became aware of suspicious network activity and promptly took steps to secure our systems. In response, we also launched a comprehensive investigation to determine the full nature and scope of the activity,” Pan America wrote in the letter, which appeared to be formatted to address customers.

“The investigation determined that an unknown actor accessed certain servers between April 8, 2026 and April 9, 2026, and accessed or acquired certain files during that time.”

 
 

The company added that a review of the files involved in the incident determined that data belonging to individuals may have been impacted.

While the statement includes a section outlining the data involved, the letter filed with the California Department of Justice does not include those details.

“Upon learning of this event, we immediately took steps to secure our systems and conducted an investigation to confirm the nature and scope of the activity and determine who may be affected,” the letter continues.

“Additionally, while we have safeguards in place to protect data in our care, we have taken steps to further enhance these protections and continue to monitor these safeguards as part of our ongoing commitment to data security.

“We are notifying individuals about this matter and providing guidance about free resources that are available to assist with monitoring relevant accounts, credit reports, and how to place a fraud alert or security freeze on one’s credit file. We are also offering complimentary identity monitoring services.”

According to the company, the incident did not lead to fraud or identity theft cases. The group did not provide details of how the threat actor breached its network, nor did it name the threat actor behind the incident.

Cyber Daily has not yet observed any threat actors taking responsibility for the incident.

Pan America’s parent company, Flynn Group, manages Applebees, Arbys, Wendy’s and Planet Fitness, as well as Taco Bell, Pizza Hut and Panera Bread.

Early this year, a threat actor by the name of ‘Eliasxy’ claimed to have breached both Wendy’s UK and Burger King France, advertising the sale of stolen datasets on an infamous dark web forum.

“Today I have uploaded the Burger King France Franchise Enterprise Database for you to download. Thanks for reading and enjoy,” the threat actor said back in February, providing a sample containing franchise operations, employee details such as phone numbers, emails and addresses, delivery partners, details of senior staff, job application data and opening hours.

Shortly after, the threat actor claimed an incident on Wendy’s UK.

“Yooo today we struck again. This time it's Wendy’s and in the database you’ll find plenty of information such as first name, last name, address, email system used, Surface and many other details.”

It is unclear if the same threat actor is behind the Pan America incident.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags: