Chipotle Mexican Grill Reports Data Breach in Montana
Chipotle Mexican Grill, Inc. filed notice of a data security incident with Montana regulators on December 23, 2025. The breach, which occurred on October 9, 2025, involved unspecified personal information, and the investigation is ongoing. Individuals potentially affected should remain vigilant.
- State
- MT
- Breach date
- October 9, 2025
- Reported
- December 23, 2025
Chipotle Mexican Grill, Inc. has publicly reported a data security incident impacting personal information in Montana. The company filed official notification of this breach with state regulators on December 23, 2025, concerning an event that occurred on October 9, 2025.
According to the public filing, the specific types of personal information exposed during this incident remain unspecified. The number of individuals potentially affected by this breach was also not detailed in the report. Chipotle Mexican Grill, Inc. has indicated that the incident is currently under investigation.
For individuals who may have received a direct notification from Chipotle Mexican Grill, Inc., this public record confirms the reported incident. It serves as a verification point for those seeking official information regarding the breach.
Although the exposed data types are not specified, it is always prudent to take general protective measures. Consider monitoring your financial accounts and credit reports for any unusual activity. Be cautious of unsolicited communications, such as emails or texts, that request personal details, as these could be phishing attempts.
These details are derived from the official data breach filing made by Chipotle Mexican Grill, Inc. with state regulatory bodies, providing a factual account of the reported incident.
What to do if you were affected
These general steps can help limit the risk of identity theft and fraud after any data breach.
Stay alert to targeted scams
Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.
Keep your notification letter
Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.
Source: MT Attorney General filing
Related data breach cases
- MemberSource Credit Union
- GrayRobinson P.A.
- First Advantage Corporation
- County of Murray dba Murray County Medical Center
- Total Wireless
- Central Ozarks Medical Center
- Clackamas Community College
- Standard Sales Company, LP
- Brett Robinson Vacation Rentals
- Fortine School District
- TrailWest Bank 2
- Dot Foods, Inc.
- Garten Services, Inc.
- First Federal Savings & Loan Association of Pascagoula Moss Point