Pan American Group LLC has disclosed a data breach after an unknown attacker accessed company servers and obtained files containing employee information.

The Taco Bell operator breach occurred in April 2026. Pan American Group says it found suspicious activity on April 9 and later confirmed that an attacker had accessed certain servers between April 8 and April 9.

The company has not identified any identity theft or fraud connected to the incident so far. It is offering affected workers a year of free credit monitoring and identity-theft protection.

Attacker accessed servers for one day

Pan American Group submitted a notice about the data incident to the California Department of Justice.

The company said an unknown party accessed or acquired files stored on its systems during the one-day intrusion. However, the public notice does not specify the types of personal information contained in the affected files.

After detecting the activity, Pan American Group launched an investigation and reviewed the files to identify the information involved and the people who may be affected.

Employees receive credit monitoring

Pan American Group said it is offering 12 months of credit monitoring and identity-theft protection through CyberScout, a TransUnion company.

The company provided the service as a precaution. It said it had not found evidence that the Taco Bell operator breach had resulted in identity theft or fraud.

Workers whose information may have been involved should review the company’s notice carefully and remain alert for unexpected account activity, phishing attempts or suspicious messages.

Pan American Group belongs to Flynn Group

Pan American Group is part of Flynn Group, a large US franchise operator with restaurant and fitness businesses.

Flynn Group operates thousands of locations across several brands. Its portfolio includes Applebee’s, Taco Bell, Arby’s, Pizza Hut, Panera Bread, Wendy’s and Planet Fitness franchises.

The incident concerns Pan American Group’s systems, rather than a breach directly attributed to every restaurant brand within the wider Flynn Group portfolio.

Restaurant sector remains a target

Restaurant groups store employee, customer and business data across point-of-sale systems, payroll platforms and connected corporate networks. That data can make franchise operators attractive targets for cybercriminals.

Taco Bell and Pizza Hut have faced cybersecurity incidents in the past. In 2023, a ransomware attack affected hundreds of restaurant locations and reportedly exposed employee data, including names and identification details.

The latest disclosure shows why restaurant operators need to respond quickly to suspicious network activity and investigate potentially exposed files before misuse occurs.


0 responses to “Taco Bell Operator Discloses Employee Data Breach”