
Pan American Group LLC, one of the largest restaurant franchise operators in the United States, has disclosed that an unknown attacker breached its computer servers and obtained files containing employee information.
The company detected suspicious activity on its network on April 9, 2026, and a subsequent investigation determined that the intruder had gained access to certain servers over a one-day span, from April 8 to April 9, during which files stored on the company’s systems were accessed or acquired. The disclosure was made in a breach notification filed with the California Department of Justice.
Pan American Group did not specify in the notice which categories of information were contained in the accessed files. The company reviewed the affected data to identify what it held and which individuals could be affected, and it stated that the intrusion has not led to any confirmed cases of identity theft or fraud. As a precaution, affected employees are being offered 12 months of free credit monitoring and identity theft protection through CyberScout, a TransUnion company.
Pan American Group operates as a subsidiary of Flynn Group, a large-scale franchise business that oversees thousands of restaurant and fitness locations nationwide. Flynn Group’s holdings include more than 430 Applebee’s restaurants, 280 Taco Bell locations, over 360 Arby’s restaurants, and 930 Pizza Hut and Panera Bread locations, along with Wendy’s franchises and Planet Fitness clubs.
The breach adds to a pattern of cyberattacks targeting major restaurant brands. Hackers have claimed to have leaked data tied to Wendy’s UK and Burger King France franchises in Europe earlier this year, with the allegedly stolen datasets advertised for sale on an underground marketplace. Taco Bell and Pizza Hut have also been targeted previously; a 2023 ransomware attack disrupted operations at roughly 300 restaurants under those brands. That earlier incident, according to a forensic investigation at the time, exposed employee data including full names, driver’s license numbers and other identification numbers.
The restaurant sector is not alone in facing such threats. Rich Products, a major U.S. supplier of frozen foods and bakery goods, suffered a data breach in May after falling victim to a phishing email.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543