DataBreachCaseFile.com
Investigation OpenNH AG filing · December 23, 2025

Chipotle Mexican Grill and Workday File NH Data Breach Report

Chipotle Mexican Grill, Inc. and Workday have filed a data breach notification with New Hampshire regulators, reporting an incident that potentially exposed personal information. The filing, dated December 23, 2025, indicates an ongoing investigation into the scope of the event. Individuals who may have received a direct notification letter should review it for specific details and recommended actions.

State
NH
Reported
December 23, 2025

Chipotle Mexican Grill, Inc., in conjunction with Workday, has submitted a data breach notification to the State of New Hampshire. This disclosure, dated December 23, 2025, formally informs regulators of a security incident impacting personal information. Details surrounding the nature and scope of this event are currently under investigation, as stated in the public filing.

While specific categories of compromised data were not detailed in the public record, the filing confirms that personal information was involved. The notification does not specify how many individuals might be affected by this breach, nor does it provide an exact date when the security incident occurred. The investigation into these aspects is still active.

This notification serves as a formal record that an incident affecting data security has occurred, as reported by the involved organizations to state authorities. Public data breach registries like this one compile such filings to offer transparency and a central reference for affected parties.

Individuals who receive direct notification letters from Chipotle Mexican Grill, Inc. or Workday should review them carefully for specific advice. As a general precaution, it is wise to remain vigilant for unexpected communications or suspicious activity. Consider monitoring any accounts linked to services used with these organizations for unauthorized access.

Implementing strong, unique passwords for online accounts and enabling multi-factor authentication whenever available are recommended security practices. Be cautious of phishing attempts via email or text messages that might try to exploit concerns related to data breaches. If you receive a letter, follow the guidance provided by the notifying entity.

What to do if you were affected

These general steps can help limit the risk of identity theft and fraud after any data breach.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Source: NH Attorney General filing

Related data breach cases