Panera's failure to disclose a known security breach: Difference between revisions
m SquidthePlummer moved page Panera Bread Known About Security Breach for 8 Months Yet Choose To Do Nothing to Panera's failure to disclose a known security breach: Misspelled title: As discussed in discussions |
added sources and made other changes |
||
| Line 7: | Line 7: | ||
|Description=Company ignored security risks for 8 months, affecting 37 million users. | |Description=Company ignored security risks for 8 months, affecting 37 million users. | ||
}}{{Cleanup}} | }}{{Cleanup}} | ||
Back in 02 August 2017, security researcher Dylan Houlihan notified [[Panera Bread]] of the breach that allowed hackers to access customers personal information via its website, however the company wouldn't take any action until 8 month later on 02 April 2018. This would eventually result in a lawsuit 3 days later, however it was eventually dismissed by the plaintiffs on June 2018. | Back in 02 August 2017, security researcher Dylan Houlihan notified [[Panera Bread]] of the breach that allowed hackers to access over 37 million customers personal information via its website, however the company wouldn't take any action until 8 month later on 02 April 2018. This would eventually result in a lawsuit 3 days later, however it was eventually dismissed by the plaintiffs on June 2018.<ref>{{Cite web |last=Ms. |first=Smith |date=3 April 2018 |title=Panera Bread blew off breach report for 8 months, leaked millions of customer records |url=https://www.csoonline.com/article/565050/panera-bread-blew-off-breach-report-for-8-months-leaked-millions-of-customer-records.html |url-status=live |archive-url=https://web.archive.org/web/20250618211944/https://www.csoonline.com/article/565050/panera-bread-blew-off-breach-report-for-8-months-leaked-millions-of-customer-records.html |archive-date=18 June 2025 |access-date=29 March 2026 |website=CSO}}</ref><ref>{{Cite web |last=Chappell |first=Bill |date=3 April 2018 |title=For Months, Panera Bread Website Reportedly Exposed Millions Of Customer Records |url=https://www.npr.org/sections/thetwo-way/2018/04/03/599135288/for-months-panera-bread-website-reportedly-exposed-millions-of-customer-records |url-status=live |archive-url=https://web.archive.org/web/20250717104401/https://www.npr.org/sections/thetwo-way/2018/04/03/599135288/for-months-panera-bread-website-reportedly-exposed-millions-of-customer-records |archive-date=17 July 2025 |access-date=29 March 2026 |website=NPR}}</ref> | ||
==Contact with Panera Bread== | |||
On 02 August 2017, Security Researcher Dylan Houlihan first contacted Panera Bread security director Mike Gustavison of a breach after finding it accidentally through their website, containing customers accounts information that includes full name, home address, email address, food preferences, username, phone number, birthday and last four digits of a debit/credit card in plain text.<ref>{{Cite web |last=Houlihan |first=Dylan |date=3 April 2018 |title=No, Panera Bread Doesn’t Take Security Seriously |url=https://medium.com/@djhoulihan/no-panera-bread-doesnt-take-security-seriously-bf078027f815 |url-status=live |archive-url=https://web.archive.org/web/20180403023125/https://medium.com/@djhoulihan/no-panera-bread-doesnt-take-security-seriously-bf078027f815 |archive-date=3 April 2018 |access-date=29 March 2026 |website=Medium}}</ref><ref>{{Cite web |last=Krebs |first=Brian |date=2 April 2018 |title=Panerabread.com Leaks Millions of Customer Records |url=https://krebsonsecurity.com/2018/04/panerabread-com-leaks-millions-of-customer-records/ |url-status=live |archive-url=https://web.archive.org/web/20180402220110/https://krebsonsecurity.com/2018/04/panerabread-com-leaks-millions-of-customer-records/ |archive-date=2 April 2018 |access-date=29 March 2026 |website=KrebsOnSecurity}}</ref> | |||
https://www. | |||
https:// | |||
https://www.csoonline.com/article/565050/panera-bread-blew-off-breach-report-for-8-months-leaked-millions-of-customer-records.html | |||
https://www.npr.org/sections/thetwo-way/2018/04/03/599135288/for-months-panera-bread-website-reportedly-exposed-millions-of-customer-records | |||
https:// | |||
== Contact with Panera Bread == | |||
On 02 August 2017, Security Researcher Dylan Houlihan first contacted Panera Bread security director Mike Gustavison of a breach after finding it accidentally through their website, containing customers accounts information that includes full name, home address, email address, food preferences, username, phone number, birthday and last four digits of a debit/credit card in plain text. | |||
[[File:Pandera Bread hack on website.png|thumb|Hacked Website]] | [[File:Pandera Bread hack on website.png|thumb|Hacked Website]] | ||
[[File:Panera Bread first email.png|center|thumb|First Response ]] | [[File:Panera Bread first email.png|center|thumb|First Response ]] | ||
| Line 32: | Line 18: | ||
[[File:Panera Bread secound email.png|left|thumb|Second Email]] | [[File:Panera Bread secound email.png|left|thumb|Second Email]] | ||
[[File:Panera Bread fourth email.png|center|thumb|250x250px|Fourth Email]] | [[File:Panera Bread fourth email.png|center|thumb|250x250px|Fourth Email]] | ||
On the same day, the company send the researcher the PGP key, after which he sends the report to Panera Bread and in a follow up reply, ask if the company was successful in decrypting the report, however the company didn't respond. Dylan Houlihan would sent several more responses asking for confirmation of successfully decrypting the PGP key, eventually receiving a response on 09 August confirming the decryption. | On the same day, the company send the researcher the PGP key, after which he sends the report to Panera Bread and in a follow up reply, ask if the company was successful in decrypting the report, however the company didn't respond. Dylan Houlihan would sent several more responses asking for confirmation of successfully decrypting the PGP key, eventually receiving a response on 09 August confirming the decryption. | ||
== Incident == | ==Incident== | ||
[[File:Panera Bread website takedown notice.png|thumb|Website Take down notice]] | [[File:Panera Bread website takedown notice.png|thumb|Website Take down notice]] | ||
8 months later on 02 April 2018, Dylan Houlihan would inform KrebsOnSecurity and Troy Hunt, with Krebs eventually taking on the offer and contacting Panera Bread chief information officers. After contact, Panera Bread website was taken down for about an hour to fix the vulnerability, eventually releasing a statement, stating that the issued has been solved within 2 hours and showcasing their commitment to security.<blockquote>''"Panera takes data security very seriously and this issue is resolved. Following reports of today of a potential problem on our website, we suspended the functionality to repair the issue. Our investigation is continuing, but there is no evidence of payment card information nor a large number of records being access or retrieved."''</blockquote>KrebsonSecurity would respond to this statement soon after on [[X Corp|X]] (formerly Twitter).<blockquote>''"Hey Panera, despite your statements to the contrary, you still haven't fixed this customer info leak. Would you like to revisit the 10k number you just gave to Fox news? <nowiki>https://t.co/AJeiq6Dfd0</nowiki>"''</blockquote>On the same day, KrebsOnSecurity release their report and within 5 minute Panera Bread would release another statement, stating that less than 10,000 were affected by the incidents;<blockquote>''" Our investigation to date indicates that fewer than 10,000 consumers have been potentially affected by this issue, and we are working diligently to finalize our investigation and take the appropriate next steps"''</blockquote>Soon after Panera Bread announcement, it was discovered that the patch wasn't fixed, with KrebsOnSecurity making a post on [[X Corp|X]] (formerly Twitter) refuting the company claims. | 8 months later on 02 April 2018, Dylan Houlihan would inform KrebsOnSecurity and Troy Hunt, with Krebs eventually taking on the offer and contacting Panera Bread chief information officers. After contact, Panera Bread website was taken down for about an hour to fix the vulnerability, eventually releasing a statement, stating that the issued has been solved within 2 hours and showcasing their commitment to security.<blockquote>''"Panera takes data security very seriously and this issue is resolved. Following reports of today of a potential problem on our website, we suspended the functionality to repair the issue. Our investigation is continuing, but there is no evidence of payment card information nor a large number of records being access or retrieved."''</blockquote>KrebsonSecurity would respond to this statement soon after on [[X Corp|X]] (formerly Twitter).<blockquote>''"Hey Panera, despite your statements to the contrary, you still haven't fixed this customer info leak. Would you like to revisit the 10k number you just gave to Fox news? <nowiki>https://t.co/AJeiq6Dfd0</nowiki>"''</blockquote>On the same day, KrebsOnSecurity release their report and within 5 minute Panera Bread would release another statement, stating that less than 10,000 were affected by the incidents;<blockquote>''" Our investigation to date indicates that fewer than 10,000 consumers have been potentially affected by this issue, and we are working diligently to finalize our investigation and take the appropriate next steps"''</blockquote>Soon after Panera Bread announcement, it was discovered that the patch wasn't fixed, with KrebsOnSecurity making a post on [[X Corp|X]] (formerly Twitter) refuting the company claims. | ||
| Line 46: | Line 33: | ||
{{Ph-I-L}} | {{Ph-I-L}} | ||
https://www.classaction.org/blog/panera-bread-facing-lawsuit-over-potential-security-breach | <ref>{{Cite web |last=Shaak |first=Erin |date=6 April 2018 |title=Panera Bread Facing Lawsuit Over Potential Security Breach |url=https://www.classaction.org/blog/panera-bread-facing-lawsuit-over-potential-security-breach |url-status=live |access-date=29 March 2026 |website=ClassAction}}</ref><ref>{{Cite web |last=Bucher |first=Anne |date=7 June 2018 |title=Panera Data Breach Class Action Voluntarily Dismissed by Plaintiffs |url=https://topclassactions.com/lawsuit-settlements/lawsuit-news/panera-data-breach-class-action-voluntarily-dismissed-plaintiffs/ |url-status=live |access-date=29 March 2026 |website=Top Class Action}}</ref> | ||
https://topclassactions.com/lawsuit-settlements/lawsuit-news/panera-data-breach-class-action-voluntarily-dismissed-plaintiffs/ | |||
==Consumer response== | ==Consumer response== | ||
{{Ph-I-ConR}} | {{Ph-I-ConR}} | ||