If you've ever had an account or relationship with Panera Bread, it's worth checking whether your personal data was exposed in this incident. Here's what happened, what data was involved, and what to do about it.
What Happened
In April 2018, security journalist Brian Krebs reported that Panera Bread's website had an unsecured API endpoint that exposed customer records in plain text to anyone who queried it directly. The vulnerability had reportedly been live for about eight months before Panera fixed it, following Krebs' initial private disclosure to the company months earlier that was not promptly acted on.
What Data Was Exposed
The exposed data included customer names, email addresses, home addresses, birthdates, and the last four digits of saved payment card numbers. Estimates of the total number of exposed records ranged up to 37 million, though Panera disputed the scale.
Why This Still Matters
Exposed data doesn't expire. It's sold, traded, and reused for years, fueling credential stuffing attacks — automated attempts to reuse your email and password combination across other sites. If you reused a password anywhere, one old exposure can compromise several current accounts.
How to Check If You Were Affected
Use our free breach checker below — enter your email and we'll scan it against known breach databases instantly, no signup required.
What to Do If You Were Affected
- Change any reused password immediately, starting with your most sensitive accounts.
- Enable two-factor authentication wherever it's offered.
- Monitor financial and health accounts closely if that kind of data was involved.
- Watch for phishing — exposed data is often used to craft convincing scam messages.
- Freeze your credit if your SSN or government ID number was exposed.
👉 Check your own exposure in 30 seconds → scan your email free.
Frequently Asked Questions
When did the Panera Bread data exposure happen?
The unsecured API was reportedly live and exposing data for around eight months before it was fixed in April 2018, following public reporting by security journalist Brian Krebs.
What data was exposed in the Panera Bread incident?
Names, email addresses, home addresses, birthdates, and the last four digits of saved payment card numbers were accessible through the unsecured website API.
How many people were affected by the Panera Bread breach?
Estimates varied widely, with some reports suggesting up to 37 million records were potentially exposed, though Panera Bread's own public statements downplayed the scale of the incident.
How do I check if I was affected by the Panera Bread exposure?
Use the free checker at Scan My Shadow with your email address. If it appears, be alert for phishing messages referencing your Panera rewards account or order history.
Did Panera Bread respond adequately to the vulnerability report?
Panera was criticized for taking months to fix the issue after being privately notified, and for initially dismissing the severity of the exposure before ultimately confirming and patching the vulnerability.