ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Pan American Group discloses data breach after suspicious network activity

Pan American Group LLC, one of the largest restaurant franchise operators in the United States, has disclosed that an unknown attacker breached its computer servers and obtained files containing employee information.


The company detected suspicious activity on its network on April 9, 2026, and a subsequent investigation determined that the intruder had gained access to certain servers over a one-day span, from April 8 to April 9, during which files stored on the company’s systems were accessed or acquired. The disclosure was made in a breach notification filed with the California Department of Justice.


Pan American Group did not specify in the notice which categories of information were contained in the accessed files. The company reviewed the affected data to identify what it held and which individuals could be affected, and it stated that the intrusion has not led to any confirmed cases of identity theft or fraud. As a precaution, affected employees are being offered 12 months of free credit monitoring and identity theft protection through CyberScout, a TransUnion company.


Pan American Group operates as a subsidiary of Flynn Group, a large-scale franchise business that oversees thousands of restaurant and fitness locations nationwide. Flynn Group’s holdings include more than 430 Applebee’s restaurants, 280 Taco Bell locations, over 360 Arby’s restaurants, and 930 Pizza Hut and Panera Bread locations, along with Wendy’s franchises and Planet Fitness clubs.


The breach adds to a pattern of cyberattacks targeting major restaurant brands. Hackers have claimed to have leaked data tied to Wendy’s UK and Burger King France franchises in Europe earlier this year, with the allegedly stolen datasets advertised for sale on an underground marketplace. Taco Bell and Pizza Hut have also been targeted previously; a 2023 ransomware attack disrupted operations at roughly 300 restaurants under those brands. That earlier incident, according to a forensic investigation at the time, exposed employee data including full names, driver’s license numbers and other identification numbers.


The restaurant sector is not alone in facing such threats. Rich Products, a major U.S. supplier of frozen foods and bakery goods, suffered a data breach in May after falling victim to a phishing email.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543