← Pan American Group

2026 Pan American Group — Flynn franchise operator; employee data breach (CA AG)

2026 Unknown records affected Share on X

Data compromised

Employee information in accessed files — categories not itemized in summary notice; 12 months CyberScout credit monitoring offered

Technical writeup

Verified franchise-operator notice — intrusion window April 8–9, 2026; public reporting August 27, 2026. Pan American Group LLC, a Flynn Group subsidiary operating large Panera Bread, Taco Bell, Pizza Hut, and other franchise footprints, detected suspicious activity on April 9 and determined an unknown attacker accessed certain servers over one day and acquired files containing employee information. A California Department of Justice notification was filed; the company reported no confirmed identity-theft cases and offered 12 months of CyberScout/TransUnion monitoring. Pan American had not published a headcount in sources reviewed at indexing. recordsAffected 0 pending census; companyConfirmed true.

Root cause

Suspicious network activity Apr 9, 2026; intruder accessed servers Apr 8–9 and acquired employee files — California AG notification (Teiss Aug 27)

References