Taco Bell, and Pizza Hut operator discloses breach after suspicious network activity
Attackers roamed Pan American Group's servers for a whole day before being kicked out.

Image by Cybernews
- Pan American Group says an unknown attacker accessed servers and obtained employee files in April 2026.
- The company says it has not found identity theft or fraud linked to the incident.
- Affected workers get 12 months of credit monitoring and identity theft protection through CyberScout.
- Flynn Group, a parent company, runs major restaurant brands, including Taco Bell, Pizza Hut, Panera Bread, and Wendy’s franchises.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
One of the largest restaurant franchise operations in the US, which manages Taco Bell, Pizza Hut, and Panera Bread, has admitted to a breach.
Pan American Group LLC, a major Panera Bread franchise operator, has disclosed a data breach after an unknown attacker accessed its servers and obtained files containing employees' information.
According to a breach notice submitted to the California Department of Justice, the company discovered suspicious network activity on April 9th, 2026.
The investigation determined that an unknown actor had accessed certain servers between April 8th and April 9th. During this one-day period, the attacker accessed or acquired files stored on the company’s systems.
However, the publicly shared notice does not clearly enumerate the specific categories of information.
Pan American Group said it subsequently launched an investigation and reviewed the affected files to determine what information they contained and which individuals were potentially affected.
According to the company, the incident has not resulted in identity theft or fraud. Out of caution, the company offered 12 months of complimentary credit monitoring and identity theft protection through CyberScout, a TransUnion company.
Operator of Taco Bell, Pizza Hut, and Wendy’s franchises
Pan America Group is a subsidiary of Flynn Group, a massive franchise operator that runs thousands of restaurants and fitness clubs.
Flynn Group's portfolio includes more than 430 Applebee's locations, 280 Taco Bell restaurants, more than 360 Arby's, and 930 Pizza Hut and Panera Bread locations. The company also manages Wendy’s and Planet Fitness.
The attackers have leaked restaurant giants’ data before
The hackers previously claimed to have leaked Wendy's and Burger King data in 2026. The specific incident involved Wendy's UK and Burger King France franchises in Europe. Allegedly stolen datasets were advertised on an underground marketplace.
The Taco Bell and Pizza Hut brands have also suffered data breaches before. In 2023, the ransomware attack knocked out roughly 300 restaurants.
The company said a forensic investigation found employee data was exposed, including full names, driver's licenses, and other ID numbers.
The US food industry has also suffered from cyberattacks. In May this year, a phishing email led to a data breach of US food giant Rich Products, a major US frozen foods and bakery supplier.