Technology
Panera Bread data breach exposes 5.1M customers
NEWYou can now listen to Fox News articles!
Another major consumer brand has joined the growing list of companies hit by serious data breaches. Panera Bread has confirmed a cybersecurity incident after the hacking group ShinyHunters claimed it stole millions of customer records.
The breach exposes a wide range of personal details, raising real concerns for anyone who has ever placed an order, created an account or shared contact information with the popular bakery chain.
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.
SUBSTACK DATA BREACH EXPOSES EMAILS AND PHONE NUMBERS
Panera Bread confirmed a data breach after hackers claimed they stole millions of customer records containing contact information. (AP Photo)
What happened in the Panera Bread data breach?
ShinyHunters added Panera Bread to its data leak site earlier this year, initially claiming it had stolen more than 14 million customer records. According to the group, the stolen data includes names, email addresses, phone numbers, home addresses and account-related information.
Panera Bread has since confirmed a cybersecurity incident. In a statement to media outlets, the company described the exposed data as customer “contact information” and said it has contacted law enforcement and taken steps to address the incident. Panera has not shared technical details about how the attack occurred or whether customers need to take specific actions.
Even “contact information” can be dangerous in the wrong hands. When combined, these details can be used for identity theft, targeted phishing and highly convincing social-engineering scams.
ShinyHunters claims the attackers accessed Panera’s systems through Microsoft Entra single sign-on (SSO). While Panera has not confirmed that claim, it closely mirrors recent warnings from Okta about a surge in voice-phishing attacks targeting SSO platforms.
In these attacks, criminals pose as IT or helpdesk staff and call employees directly. They pressure targets to approve authentication requests or enter login credentials on fake SSO pages. Once attackers capture session tokens or credentials, they can bypass some forms of multifactor authentication and move laterally through company systems. This approach relies on human trust rather than technical exploits, making it increasingly effective.
How many people were actually affected?
At first glance, claims that 14 million customers were affected suggested an enormous breach. However, researchers at Have I Been Pwned? later clarified that the attackers stole 14 million records, not data tied to 14 million unique individuals.
After reviewing the leaked dataset, researchers now estimate the breach affected approximately 5.1 million unique people. The exposed information includes email addresses along with associated names, phone numbers, and physical addresses.
That distinction matters, but it does not eliminate risk. Once stolen data is released publicly, it can spread quickly across criminal forums and be reused for years.
149 MILLION PASSWORDS EXPOSED IN MASSIVE CREDENTIAL LEAK
The hacking group ShinyHunters leaked stolen Panera customer data online after an attempted extortion failed. (Panera Bread)
Hackers leaked the data after extortion failed
ShinyHunters reportedly attempted to extort Panera Bread before publishing the stolen data. When those efforts failed, the group released a 760MB archive containing millions of customer records on its leak site.
This reflects a broader shift in cybercrime. Instead of locking systems with ransomware, many groups now focus on quietly stealing data and threatening public exposure. These attacks are faster, harder to detect, and often just as profitable.
ShinyHunters has used similar tactics in other high-profile incidents involving Bumble, Match Group, Crunchbase and other consumer platforms.
Lawsuits filed after Panera breach disclosure
The breach has already triggered legal fallout. Multiple class-action lawsuits have been filed in U.S. federal court, alleging that Panera failed to adequately protect customer data.
The lawsuits claim Panera knew or should have known about security weaknesses and seek damages, improved security practices, and long-term identity theft protection for affected customers. Panera has not publicly commented on the litigation.
A troubling pattern for Panera Bread
This is not Panera Bread’s first major security lapse. In 2018, a cybersecurity researcher revealed that Panera had left millions of customer records exposed online in plain text. That incident later led to lawsuits and settlements.
Repeated breaches often point to deeper challenges. Large organizations can struggle to secure cloud services, identity systems, and employee access at scale. When attackers target identity platforms instead of infrastructure, a single mistake can expose millions of records.
We reached out to Panera Bread for a comment, but did not hear back before our deadline.
GRUBHUB CONFIRMS DATA BREACH AMID EXTORTION CLAIMS
Exposed contact details like names, emails, and addresses can fuel phishing scams and identity theft long after a breach becomes public. (Donato Fasano/Getty Images)
7 steps you can take to protect yourself following the Panera data breach
When a major consumer brand suffers a breach, customers often don’t realize the risk until weeks or months later. These steps help limit what attackers can do with your information if your Panera data falls into the wrong hands.
1) Use a strong, unique password for every account
If you ever created a Panera Bread account, reset its password immediately. If you reused that password anywhere else, those accounts are now at risk, too. Attackers routinely test breached passwords across email, shopping and banking sites.
A password manager helps by generating strong, unique passwords for every account and storing them securely so you never need to reuse credentials. Many password managers also alert you if your email or passwords appear in known data breaches, giving you an early warning to lock things down fast.
Our No. 1 password manager pick includes a built-in breach scanner that checks whether your email address or passwords have appeared in known leaks. If you discover a match, immediately change any reused passwords and secure those accounts with new, unique credentials.
Check out the best expert-reviewed password managers of 2026 at Cyberguy.com.
2) Enable two-factor authentication (2FA) wherever possible
Two-factor authentication (2FA) adds a second step to the login process, usually through an app or device you control. Even if someone gets your password through phishing or a breach, 2FA makes it much harder for them to access your account.
3) Be cautious of phishing messages
Cybercriminals often follow up breaches with fake emails or in-app messages pretending to offer help or security updates. Always double-check the sender and avoid clicking links. When in doubt, open the app or website directly rather than responding to the message. Using strong antivirus software adds another layer of protection by flagging malicious links and blocking known threats before they can do harm. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe.
Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android and iOS devices at Cyberguy.com.
4) Limit the personal details you share
When names, email addresses, phone numbers and physical addresses are exposed, identity theft becomes a real risk. Identity theft-protection services monitor your personal information, alert you if it appears on the dark web, and watch for attempts to open new accounts in your name.
If something does go wrong, these services often include recovery support to help freeze accounts, dispute fraud, and guide you through the cleanup process.
See my tips and best picks on how to protect yourself from identity theft at Cyberguy.com.
5) Reduce your digital footprint with a data removal service
Scammers don’t rely on one breach alone. They combine leaked data with information from data broker sites to build detailed profiles. Data removal services help remove your phone number, home address and other personal details from hundreds of these sites.
While no service can erase everything, reducing what’s publicly available makes it much harder for criminals to target you with convincing scams or identity fraud. This is one of the most effective long-term ways to lower your risk after any major breach.
Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com.
Get a free scan to find out if your personal information is already out on the web: Cyberguy.com.
6) Secure your email account
Your email account controls password resets for most services. Protect it with a strong password and 2FA. Regularly review login activity and recovery settings, so attackers can’t use your email to take over other accounts.
7) Watch for account changes after breach news
Not every breach leads to immediate account takeovers. In some cases, attackers quietly test access weeks later. That is why staying alert after breach reports matters. Watch for password reset emails you did not request, profile changes you did not make, or new messages you did not send. Unexpected logouts or security alerts are also red flags. If you notice anything unusual, change your password immediately and review your security settings.
Kurt’s key takeaway
The Panera Bread data breach is another reminder that even familiar brands can become major cyber targets. While Panera says only contact information was exposed, that data is often enough to fuel scams and identity theft long after headlines fade. Staying proactive after breach news is now part of protecting your digital life.
Do you still trust large brands to protect your personal information, or have repeated breaches changed how much data you’re willing to share? Let us know by writing to us at Cyberguy.com.
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.
Copyright 2026 CyberGuy.com. All rights reserved.
Technology
The Sonos Era 100 speaker is down to its lowest price in months
Whether you’re considering starting a Sonos speaker setup, or adding to an existing group, the Sonos Era 100 is worth picking up. The compact, capable smart speaker is currently marked down to $189 ($30 off) at a variety of retailers, including Amazon, Best Buy, and directly from Sonos. If you want an even lower price, Sonos is selling refurbished Era 100 speakers for just $134. They come with fresh accessories and packaging, and sport the same one-year warranty as its new speakers.
The wireless speaker has a rich, detailed sound profile, with room-filling audio despite its small size. You might be able to improve the sound further with the Sonos Trueplay feature, which uses either your phone or the speaker’s built-in microphone to automatically tune it to your space. The Era 100 can easily connect with other speakers in the Sonos ecosystem for multi-room play, even with different Sonos models.
The Era 100 has expanded functionality from previous entry-level Sonos speakers, adding in Bluetooth and USB-C wired audio, as well as improved onboard controls. While the speaker features built-in voice assistant support for both Sonos and Alexa, you can flip a switch on its back to cut power to the microphone.
Technology
Carnival breach may put your travel data at risk
NEWYou can now listen to Fox News articles!
Carnival Corporation has confirmed a data breach affecting nearly 6 million people, and the fallout could reach travelers who may not think of themselves as Carnival customers.
The company says the incident involved a social engineering attack on a single user account. In other words, someone fooled an employee and gained access to part of Carnival’s IT system.
For cruise customers, the real concern starts after the breach. Stolen personal details can help scammers write messages that feel far more believable. Here is what may have been exposed, what Have I Been Pwned found in the leaked data and what you can do now to protect yourself.
Join CyberGuy Live: Lock Down Your Phone in 30 Minutes (Saturday, June 13, 10 a.m. ET)
- Your phone holds your email, passwords, photos, banking apps and personal data. In this free, live online class, Kurt the CyberGuy will walk you step by step through simple phone security fixes you can do in real time. You’ll learn how to improve your privacy settings, spot the latest phone scams, use trusted security tools and walk away with a simple checklist to stay protected. Register here: CyberGuyLive.com
MAJOR CRUISE LINE HACK EXPOSES SENSITIVE DATA OF NEARLY 6 MILLION TRAVELERS
Carnival says exposed data may include names, addresses, emails, phone numbers, dates of birth and government-issued ID numbers. (iStock)
What information was exposed in the Carnival breach?
Carnival Corporation says the breach began with a social engineering attack on a single user account. An unauthorized actor gained access to a limited part of the company’s IT system. Carnival says it immediately blocked the activity, brought in third-party security experts and alerted law enforcement.
A Carnival Corporation spokesperson told CyberGuy,
“In April, we identified unauthorized access to a limited part of our IT system caused by a social engineering attack on a single user account. We immediately blocked the activity, engaged third-party security experts and alerted law enforcement. Our investigation found certain personal information was illegally accessed. We’re notifying affected individuals and deeply regret any concern this causes. Protecting the privacy and security of personal data is a priority for us and we’ve added new layers of security and monitoring on top of the comprehensive protections already in place. We’ll also continue advancing our defenses against evolving threats.”
State breach reporting shows 5,995,277 people were affected. Carnival says the impacted data varies by individual. However, the company says the information known to be involved includes names, addresses, email addresses, phone numbers, dates of birth and government-issued identification numbers, such as driver’s license numbers and passport numbers.
What Have I Been Pwned found in the leaked Carnival data
Have I Been Pwned also analyzed the data published by ShinyHunters and said it contained 8.7 million records with 7.5 million unique email addresses. That data appeared tied to Holland America’s Mariner Society loyalty program and included names, dates of birth, email addresses, genders, geographic locations, salutations and loyalty program details.
That means this breach could affect you even if you think of yourself as a Holland America customer, not a Carnival customer. Even without a credit card number, this type of data can create problems. Criminals can use it to build fake emails, texts and calls that sound like they came from a real cruise brand. For example, a scammer could mention loyalty points, an upcoming trip, a refund or a cabin upgrade. That one familiar detail may be enough to get you to click.
What ShinyHunters claimed about Carnival
Carnival has not publicly confirmed that ShinyHunters carried out the attack. However, the extortion gang claimed responsibility in April 2026 and said it stole millions of records and internal corporate data.
ShinyHunters has also been tied to broader data theft and extortion activity involving Salesforce customers. The group often pressures companies by threatening to leak or sell stolen information.
The FBI has warned victims not to pay ransom demands from the group. Paying does not guarantee stolen data will be deleted. It also does not stop criminals from trying to extort victims again.
For you, the concern is what happens next. Once your data leaks, scammers may try to use it in emails, texts or calls that sound more believable than the usual junk.
Why the Carnival breach could put you at risk
Travel scams work because they catch you when you are excited, rushed or distracted. Maybe you booked a cruise years ago. Maybe you joined a loyalty program and forgot about it. Maybe you sailed with Holland America, Princess Cruises or another Carnival-owned brand. That old account can still have value to criminals.
Carnival has also dealt with several cybersecurity incidents before. The company disclosed breaches in March 2020 and June 2021 after attackers accessed employee email accounts. Ransomware incidents in August 2020 and December 2020 also exposed personal information tied to Carnival customers and employees.
That history does not mean every Carnival customer will face fraud. But it does show why old travel accounts deserve attention. A loyalty account can reveal more than points. It can connect your name, email, birthday, travel history and brand preferences.
That gives scammers more ways to sound convincing. A fake email may claim your loyalty points are expiring. A text may say you qualify for a refund. A caller may say your account needs verification. Those tricks can lead to stolen passwords, malware, fake payment pages or identity theft attempts.
HOW TO PROTECT YOUR ONLINE PRIVACY AND SECURITY ON YOUR NEXT CRUISE VACATION
Carnival Corporation confirmed a data breach affecting nearly 6 million people after a social engineering attack on a single user account. (Patrick Connolly/Orlando Sentinel/Tribune News Service via Getty Images)
Ways to stay safe after the Carnival breach
If you receive a Carnival breach notice, read it closely so you know what information may have been involved. Some impacted data may include government-issued identification numbers, so take these steps to lock down your accounts, spot fake cruise messages and reduce the chances that scammers can use your personal details against you.
1) Review Carnival’s offer for credit monitoring
Carnival says it is offering eligible U.S. individuals two years of complimentary credit monitoring. If you receive a notice, use the contact details in that notice or Carnival’s official breach webpage. Do not trust random links in emails, texts or search ads claiming to help you enroll.
2) Change your cruise account passwords
Go directly to the official website or app. Do not click a link from an email or text. Use a strong, unique password for every travel account. A password manager can help you create and store better passwords. Check out the best expert-reviewed password managers of 2026 at Cyberguy.com.
3) Turn on two-factor authentication
Two-factor authentication (2FA) adds another layer of protection. Even if someone steals your password, they still need a second approval. Use an authentication app when possible. Text codes help, but they can be weaker if a scammer tries a SIM swap attack.
4) Watch for fake cruise emails and texts
Be suspicious of messages about refunds, loyalty points, upgrades, cancellations or account verification. Scammers love urgent wording. They want you to click before you think. Instead, go straight to the company’s website or app. Check your account there.
5) Use a data removal service
A data removal service will not undo the Carnival breach. However, it can help remove your personal information from data broker and people-search sites. That can make it harder for scammers to combine leaked breach data with your home address, phone number, relatives’ names or other details found online. Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com.
6) Use strong antivirus protection
Breaches often lead to phishing emails with dangerous links or attachments. Strong antivirus protection can help block malicious websites, scam pages and malware before they do damage. Also, keep your phone, tablet and computer updated. Security updates close holes that criminals try to exploit. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com.
7) Do not share personal details with callers
If someone calls and claims to represent a cruise line, do not give out your date of birth, payment details or login codes. Hang up and call the company using a number from its official website.
10 SIGNS YOUR PERSONAL DATA IS BEING SOLD ONLINE
Travelers can reduce risk after the Carnival breach by changing passwords, enabling two-factor authentication and monitoring credit reports. (Daniel de la Hoz/Getty Images)
8) Monitor your bank and credit card accounts
Check your statements for charges you do not recognize. Small test charges can show up before larger fraud attempts. Report suspicious activity right away. Many banks also let you lock a card from the app while you investigate.
9) Consider a credit freeze
A credit freeze can block criminals from opening new credit accounts in your name. You can freeze your credit for free with Equifax, Experian and TransUnion. You can also lift the freeze when you need to apply for credit.
10) Review your credit reports
Check your credit reports for accounts, addresses or inquiries you do not recognize. You can get free weekly credit reports from the three major credit bureaus at AnnualCreditReport.com.
11) Watch for misuse of your ID documents
Because Carnival says some impacted data may include driver’s license or passport numbers, be extra cautious with messages asking you to “verify” your identity. Do not upload a photo of your ID through a link in an email or text. Go directly to the official company, bank or government website instead.
12) Consider identity theft protection
Identity theft protection can help monitor your personal information, credit files and financial activity for warning signs of fraud. Some plans also include breach or dark web monitoring, which can alert you if your email address or other personal details appear in known leaks. See my tips and best picks on Best Identity Theft Protection at Cyberguy.com
13) Save the breach notice
Keep a copy of any notice you receive from Carnival. It may explain what information was involved and what support the company offers. Be careful with fake settlement or claim websites. Scammers often create lookalike pages after major breaches.
Kurt’s key takeaways
The Carnival data breach shows why travel accounts need the same care as banking, shopping and email accounts. A cruise may last a week, but the data you shared can stick around for years. Take a few minutes now to tighten your accounts. Change reused passwords, watch for cruise-themed scams and consider freezing your credit if you want stronger protection.
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
Have travel companies earned enough trust to keep collecting so much personal data, or should loyalty programs start asking for far less? Let us know by writing to us at Cyberguy.com.
Sign up for my FREE CyberGuy Report
- Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
- For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com – trusted by millions who watch CyberGuy on TV daily.
- Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.
Copyright 2026 CyberGuy.com. All rights reserved.
Technology
Valve says it’s ready to launch the Steam Machine this summer
Valve now says that the delayed Steam Machine PC and Steam Frame VR headset are set to launch sometime this summer. In a Thursday blog post detailing its Verified programs for both pieces of hardware, Valve concludes by saying that “We’re excited for players to try your titles on the new Steam hardware once they launch this summer.”
When the company originally announced the Machine and Frame alongside its new Steam Controller late last year, it said that it would start shipping the new gadgets in early 2026. But in February, the company announced that the ongoing memory and storage crunch had forced it to revisit its pricing and shipping plans. And in March, Valve said in a blog post that it would be “shipping all three products this year” — though that was after the company initially said in the post that “we hope to ship in 2026,” which it removed in an update.
Valve opted to release the Steam Controller on its own, putting it up for sale in early May. For the Machine and Frame, while “summer” isn’t exactly a specific date, it narrows the window for when the products might finally come out.
Ahead of actually launching the devices, Valve is redesigning the Steam store and sharing information about the Verified programs for the hardware so that developers can prepare their games. Like with the Steam Deck, if a game is verified for the Machine or the Frame, the badge signals that the game should work well without any tweaks from the user.
For the Machine, the requirements for a game to be verified are “nearly identical” to what they are for the Steam Deck. With the Machine being “roughly six times as powerful” as the Deck, in theory, many more games will be verified for it. Valve also says that it’s testing “every title on Machine that fell below our performance requirements on Deck.”
For the Frame, Valve’s verified badge will signify games that run well while being played natively on the headset — as opposed to games that work well streamed to the headset, which the Frame is also capable of. “Like Steam Deck Verified, the Steam Frame Standalone Verified program focuses on the experience customers will have with the device out-of-the-box in standalone mode,” Valve says.
Now, we just need Valve to share exactly when the Steam Machine and Steam Frame will be released and how much they might cost. After last week’s price hikes for the Steam Deck, I’m gearing up for sticker shock.
-
News17 minutes agoDemocrat Xavier Becerra wins the top spot in November’s race for California governor
-
Los Angeles, Ca2 hours agoMan wanted for deadly Los Angeles road rage shooting extradited from Mexico
-
Detroit, MI2 hours ago‘I could have died’: 14-year-old speaks out after surviving shooting during ‘teen takeover’ in Detroit
-
San Francisco, CA2 hours agoDriver Who Raped Woman After She Mistook His Car For An Uber Convicted By Bay Area Jury
-
Dallas, TX2 hours agoHouse fire on Dallas Court in Rockford leaves more than $100K in damage
-
Miami, FL2 hours agoWildlife officers investigate raccoon attack in North Miami
-
Boston, MA2 hours agoBoston Pride for the People Parade is set to step off, with history, protest in mind
-
Denver, CO3 hours agoHow a Christian Braun Trade to the Mavericks Could Help Nuggets