Pan American Group Data Breach Exposes Social Security Numbers

Published
August 27, 2026
Updated
August 27, 2026
Pan American Group Data Breach Exposes Social Security Numbers
Pan American Group
Affected by the data breach? You may be entitled to compensation. Submit a claim today.

Pan American Group LLC, a restaurant operator that runs Panera Bread bakery-café locations in Kansas and Missouri, disclosed a data breach that occurred in April 2026.

The company is a wholly owned subsidiary of Flynn Restaurant Group, one of the largest franchise operators in the United States, headquartered in Independence, Ohio. Notably, the Apple American Group, the Bell American Group and the Hut American Group reported data breaches, although it remains unclear if the incidents are connected.

The breach was reported to the California Attorney General on Aug. 24, 2026, and to the Massachusetts Office of Consumer Affairs and Business Regulation on Aug. 26, 2026. Pan American Group began notifying consumers on Aug. 24, 2026.

On April 9, 2026, Pan American Group detected suspicious activity on its computer network. The company took steps to secure its systems and launched a comprehensive investigation to determine the full nature and scope of the activity.

The investigation found that an unknown actor gained access to certain company servers between April 8, 2026, and April 9, 2026. During that window, the actor accessed or acquired certain files stored on those servers. The company then conducted a review of the involved files to determine what personal information they contained and to whom it belonged.

The types of personal information exposed included Social Security numbers, medical records, financial account information, driver's license numbers and credit or debit card numbers.

According to the notification, the breach involved information primarily affected current or former employees rather than restaurant customers.

Pan American Group's response to the breach

Pan American Group is offering affected individuals complimentary credit monitoring and identity theft protection services through CyberScout, a TransUnion company.

To enroll, affected individuals can visit the CyberScout activation page and enter the unique code included in their notification letter. Enrollment must be completed within 90 days of the date of the letter.

For additional questions, affected individuals can contact the company's dedicated assistance line Monday through Friday between 8 a.m. and 8 p.m. EST, excluding U.S. holidays. The phone number for the assistance line is included in each individual's notification letter.

Individuals may also write to Pan American Group LLC at Attn: Legal Department, 6200 Oak Tree Blvd., Suite 250, Independence, OH 44131 or call 216-525-2775.

SUBMIT YOUR CLAIM TO THE LAW FIRM HANDLING THIS INVESTIGATION

Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info
  • Affected information types not yet disclosed

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image