Chipotle Mexican Grill Confirms 2025 Data Breach in Montana
Chipotle Mexican Grill reported a data security incident to Montana authorities, confirming unauthorized access to certain systems on October 9, 2025. This event potentially exposed personal information for individuals who received a notification letter from the company. The official filing was made public on December 23, 2025, while the investigation continues.
- State
- Montana
- Breach date
- October 9, 2025
- Reported
- December 23, 2025
Chipotle Mexican Grill, Inc., the national fast-casual restaurant chain, formally reported a data security incident to the Montana Attorney General's office. The company confirmed that unauthorized access to certain systems occurred on or around October 9, 2025. This official filing was made public on December 23, 2025.
While the specific types of information involved were not detailed in the public filing, the company's notification suggests that personal information may have been compromised. Individuals who received a data breach notification letter from Chipotle Mexican Grill are those potentially affected by this incident.
If you received such a letter, it indicates your data was identified as potentially exposed. This information is provided to help you verify the official record of the breach reported by Chipotle Mexican Grill with state regulators.
To protect yourself, it is advisable to review your account statements for any unusual activity. Consider placing a fraud alert or freezing your credit with major reporting agencies. Also, be cautious of any unsolicited communications requesting personal details, as these could be phishing attempts.
The company has indicated that an investigation into the incident is ongoing. Further specific details about the scope and impact of the breach would be communicated directly to affected individuals through official notification letters.
What to do if you were affected
These general steps can help limit the risk of identity theft and fraud after any data breach.
Stay alert to targeted scams
Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.
Keep your notification letter
Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.
Related data breach cases
- MemberSource Credit Union
- GrayRobinson P.A.
- County of Murray dba Murray County Medical Center
- Total Wireless
- Central Ozarks Medical Center
- Brett Robinson Vacation Rentals
- Standard Sales Company, LP
- Clackamas Community College
- Fortine School District
- TrailWest Bank 2
- Dot Foods, Inc.
- First Federal Savings & Loan Association of Pascagoula Moss Point
- Garten Services, Inc.
- Covenant Health, Inc.