DataBreachCaseFile.com
Investigation OpenMontana AG filing · December 23, 2025

Chipotle Mexican Grill Discloses Montana Data Breach Filing

Chipotle Mexican Grill, Inc. reported a data security incident to the Montana Attorney General on December 23, 2025. This filing indicates unauthorized access to company systems on October 9, 2025, potentially involving personal information. Individuals who received a notification letter should review its contents and consider protective measures.

State
Montana
Breach date
October 9, 2025
Reported
December 23, 2025

Chipotle Mexican Grill, Inc. filed an official notice with the Montana Attorney General on December 23, 2025, detailing a data security incident. The company reported that unauthorized access to certain systems occurred on October 9, 2025. This disclosure is part of the company's regulatory obligations following such an event.

While the specific types of personal information involved were not detailed in the public filing, the incident potentially affects individuals whose data is stored within Chipotle's systems. The filing indicates that those who received a notification letter from Chipotle may have had their information exposed.

As a national restaurant chain, Chipotle routinely handles various forms of customer data through its point-of-sale systems and online ordering platforms. This incident prompts individuals to be vigilant regarding their personal information following such a compromise. The company is currently investigating the full scope of the event.

If you received a data breach notification from Chipotle Mexican Grill, Inc., it is important to review the letter carefully for any specific recommendations provided. Consider placing a fraud alert or security freeze on your credit reports with the three major credit bureaus (Equifax, Experian, TransUnion).

Additionally, monitor your financial accounts and credit reports for any suspicious activity. Be cautious of unsolicited communications, especially those asking for personal information, and consider changing passwords for online accounts. These steps can help protect against potential misuse of your personal information.

What to do if you were affected

These general steps can help limit the risk of identity theft and fraud after any data breach.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Related data breach cases