Pan America Group Discloses Network Breach Impacting Customer Data
Pan America Group LLC, a subsidiary of Flynn Group which oversees major brands including Applebee’s, Arby’s, Wendy’s, Planet Fitness, Taco Bell, Pizza Hut, and Panera Bread reported a cybersecurity incident involving unauthorized access to its systems. The company detected suspicious network activity on April 9, 2026, prompting an immediate investigation.
According to a notice filed with the California Department of Justice, an unknown threat actor accessed certain servers between April 8 and April 9, 2026, and exfiltrated files containing sensitive data. While the company confirmed that personal information may have been compromised, it did not disclose specifics about the affected data types in the filing. Pan America stated that no evidence of fraud or identity theft has been linked to the breach.
In response, the company secured its systems, enhanced existing safeguards, and is offering complimentary identity monitoring services to impacted individuals. The method of intrusion and the identity of the threat actor remain undisclosed. Cybersecurity researchers have not observed any claims of responsibility for the attack.
The incident follows earlier breaches this year involving Flynn Group brands, including claims by a threat actor known as ‘Eliasxy’, who advertised stolen datasets from Wendy’s UK and Burger King France on a dark web forum. However, no direct connection to the Pan America breach has been established.
America's Pizza Company, LLC cybersecurity rating report: https://www.rankiteo.com/company/america-s-pizza-company-llc
Flynn Planet Fitness cybersecurity rating report: https://www.rankiteo.com/company/flynn-planet-fitness
Flynn Arby's cybersecurity rating report: https://www.rankiteo.com/company/flynn-arbys
Flynn Panera cybersecurity rating report: https://www.rankiteo.com/company/flynn-panera
Flynn Taco Bell cybersecurity rating report: https://www.rankiteo.com/company/flynn-tacobell
"id": "AMEFLYFLYFLYFLY1787812478",
"linkid": "america-s-pizza-company-llc, flynn-planet-fitness, flynn-arbys, flynn-panera, flynn-tacobell",
"type": "Breach",
"date": "4/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Impacted individuals (number '
'undisclosed)',
'industry': 'Restaurant and Fitness Franchises',
'name': 'Pan America Group LLC',
'type': 'Subsidiary'},
{'industry': 'Restaurant',
'name': 'Applebee’s',
'type': 'Brand'},
{'industry': 'Restaurant',
'name': 'Arby’s',
'type': 'Brand'},
{'industry': 'Restaurant',
'name': 'Wendy’s',
'type': 'Brand'},
{'industry': 'Fitness',
'name': 'Planet Fitness',
'type': 'Brand'},
{'industry': 'Restaurant',
'name': 'Taco Bell',
'type': 'Brand'},
{'industry': 'Restaurant',
'name': 'Pizza Hut',
'type': 'Brand'},
{'industry': 'Restaurant',
'name': 'Panera Bread',
'type': 'Brand'}],
'customer_advisories': 'Offered complimentary identity monitoring services to '
'impacted individuals',
'data_breach': {'data_exfiltration': 'Yes',
'personally_identifiable_information': 'Potentially',
'sensitivity_of_data': 'High (personal information)',
'type_of_data_compromised': 'Sensitive data, personal '
'information'},
'date_detected': '2026-04-09',
'description': 'Pan America Group LLC, a subsidiary of Flynn Group which '
'oversees major brands including Applebee’s, Arby’s, Wendy’s, '
'Planet Fitness, Taco Bell, Pizza Hut, and Panera Bread, '
'reported a cybersecurity incident involving unauthorized '
'access to its systems. The company detected suspicious '
'network activity on April 9, 2026, prompting an immediate '
'investigation. An unknown threat actor accessed certain '
'servers between April 8 and April 9, 2026, and exfiltrated '
'files containing sensitive data. While personal information '
'may have been compromised, no evidence of fraud or identity '
'theft has been linked to the breach.',
'impact': {'data_compromised': 'Sensitive data, personal information',
'identity_theft_risk': 'Potential risk (no evidence yet)',
'systems_affected': 'Certain servers'},
'investigation_status': 'Ongoing',
'references': [{'source': 'California Department of Justice'}],
'regulatory_compliance': {'regulatory_notifications': 'Filed notice with '
'California Department '
'of Justice'},
'response': {'communication_strategy': 'Filed notice with California '
'Department of Justice, offered '
'complimentary identity monitoring '
'services',
'containment_measures': 'Secured systems',
'incident_response_plan_activated': 'Yes',
'remediation_measures': 'Enhanced existing safeguards'},
'title': 'Pan America Group Network Breach Impacting Customer Data',
'type': 'Data Breach'}