DataBreachCaseFile.com
Investigation OpenNew Hampshire AG filing · December 23, 2025

Chipotle Mexican Grill & Workday Report 2025 Data Breach

Chipotle Mexican Grill and Workday reported a data breach to New Hampshire authorities on December 23, 2025. This incident involved unauthorized access to systems holding personal information, potentially affecting individuals whose data is managed by these entities.

State
New Hampshire
Reported
December 23, 2025

Chipotle Mexican Grill, a prominent national restaurant retailer, and Workday, a major human resources and enterprise management technology provider, formally reported a data breach to the New Hampshire Attorney General's office on December 23, 2025. These organizations typically manage extensive employee and applicant information within their systems, including details necessary for HR administration.

The official filing indicates that unauthorized access to protected information occurred within the systems. While the exact types of personal information involved in this incident are not specified in the public record, it is confirmed that individuals' data was compromised.

If you have received a notification letter regarding this incident, it is crucial to review it carefully. Such letters typically provide specific details about the scope of the exposure and may include information on identity protection services being offered to affected individuals.

To safeguard against potential misuse of your personal information, consider monitoring your financial accounts and credit reports for any suspicious activity. Regularly updating passwords for all online accounts and enabling multi-factor authentication wherever possible are also widely recommended general precautions.

The incident, reported in late 2025, is currently under investigation to determine its full extent and impact. These details come from public regulatory filings with the state of New Hampshire.

What to do if you were affected

These general steps can help limit the risk of identity theft and fraud after any data breach.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Related data breach cases