Panera Bread Sat on a Data Leak for Eight Months

Panera Bread Sat on a Data Leak for Eight Months

Tech News data breach panera-bread privacy security

I ordered a bread bowl from Panera's website last week, the kind of 9pm decision you make when you don't want to put on real pants. Typed in my name, my address, the last four of my card, hit submit, didn't think about it again. Turns out I probably should have thought about it a little.

Brian Krebs put up a post today over at KrebsOnSecurity laying out something pretty ugly: Panera Bread's website had a leak that exposed customer records (name, email, home address, birthday, and the last four digits of saved credit cards) for something like eight months before anyone fixed it. Not eight days. Eight months.

Here's the part that actually gets me, and it isn't even the leak itself. A security researcher named Dylan Houlihan found the flaw and reported it to Panera back in August of last year. Politely, through the right channels, the way you're supposed to. Panera's response, according to the emails Krebs published, was basically to accuse him of running a scam to sell them services. They didn't fix it. They sat on it. It took a reporter calling them up this week asking pointed questions before anything actually got patched, and even then the first "fix" reportedly left the hole partially open for a bit longer.

Panera's own estimate of the damage is something like 10,000 customers affected. Independent researchers who poked at the numbers before the site got locked down put it closer to 37 million records. That gap — between what a company says happened and what a company can actually verify happened — is the whole story here, honestly. Nobody was logging who scraped that endpoint for eight months, so nobody actually knows. "10,000" is a number that sounds responsible. It isn't a number anyone can back up.

I keep coming back to how ordinary this all is now. Panera isn't a tech company, not really, they just also happen to run a website that stores your address and your card info because online ordering is table stakes for a sandwich chain in 2018. Every restaurant, every airline, every pharmacy has some contractor-built ordering system bolted onto the side of the business, and none of them are treating it like the thing it actually is, which is a database full of people's personal information sitting on the open internet. You don't need to be Equifax to leak millions of records anymore. You just need a login form nobody bothered to secure and a support team that ignores researchers on principle.

(Small tangent, not really related: I still reuse the same password across way too many of these ordering sites, the Panera one included, and writing this post is the closest I've come in about two years to actually doing something about it. Probably won't, if I'm honest. Everyone says that though, right up until it's their data in a Krebs post.)

What bugs me most is the "hoax" accusation. Not the bug, bugs happen, code is hard, I get it. But there's a pattern with companies getting a heads-up from an outside researcher and treating the messenger as the threat instead of the message. It happened with Panera and it's happened with plenty of others before them. If your instinct when someone hands you a security problem for free is to threaten them or call them a liar, you've told me everything I need to know about how you'll handle the actual breach when it's real and it's public and reporters are calling.

Anyway. I'm not deleting my Panera account over this, mostly out of laziness, but I did finally change that password tonight, and I'd tell you to do the same if you've ever ordered from them online. Check your statements too. Eight months is a long time for a door to be left open, and nobody's entirely sure who walked through it.