Chipotle Mexican Grill Discloses Montana Data Breach Filing
Chipotle Mexican Grill, Inc. reported a data security incident to the Montana Attorney General on December 23, 2025. This filing indicates unauthorized access to company systems on October 9, 2025, potentially involving personal information. Individuals who received a notification letter should review its contents and consider protective measures.
- State
- Montana
- Breach date
- October 9, 2025
- Reported
- December 23, 2025
Chipotle Mexican Grill, Inc. filed an official notice with the Montana Attorney General on December 23, 2025, detailing a data security incident. The company reported that unauthorized access to certain systems occurred on October 9, 2025. This disclosure is part of the company's regulatory obligations following such an event.
While the specific types of personal information involved were not detailed in the public filing, the incident potentially affects individuals whose data is stored within Chipotle's systems. The filing indicates that those who received a notification letter from Chipotle may have had their information exposed.
As a national restaurant chain, Chipotle routinely handles various forms of customer data through its point-of-sale systems and online ordering platforms. This incident prompts individuals to be vigilant regarding their personal information following such a compromise. The company is currently investigating the full scope of the event.
If you received a data breach notification from Chipotle Mexican Grill, Inc., it is important to review the letter carefully for any specific recommendations provided. Consider placing a fraud alert or security freeze on your credit reports with the three major credit bureaus (Equifax, Experian, TransUnion).
Additionally, monitor your financial accounts and credit reports for any suspicious activity. Be cautious of unsolicited communications, especially those asking for personal information, and consider changing passwords for online accounts. These steps can help protect against potential misuse of your personal information.
What to do if you were affected
These general steps can help limit the risk of identity theft and fraud after any data breach.
Stay alert to targeted scams
Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.
Keep your notification letter
Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.
Related data breach cases
- MemberSource Credit Union
- GrayRobinson P.A.
- County of Murray dba Murray County Medical Center
- Total Wireless
- Central Ozarks Medical Center
- Brett Robinson Vacation Rentals
- Standard Sales Company, LP
- Clackamas Community College
- Fortine School District
- TrailWest Bank 2
- Dot Foods, Inc.
- First Federal Savings & Loan Association of Pascagoula Moss Point
- Garten Services, Inc.
- Covenant Health, Inc.