Yum! Brands announced a ransomware attack on 18 January 2023 affecting certain IT systems. Close to 300 of its UK restaurants closed for one day. The company took systems offline, engaged forensics support and notified federal law enforcement.
Its initial position was that there was no evidence customer databases had been taken. In April, in a filing with the Maine Attorney General, it disclosed that personal information belonging to individuals had been compromised — reported as affecting employees, including names, social security numbers and contact details.
The First Statement Was Accurate And Incomplete
This desk does not read the January statement as misleading. It said customer databases showed no evidence of theft, and that appears to have held.
What it did not say is that a different population had been affected, because in January the company did not yet know. The corpus records the same three-month scoping gap at 23-0512b for PharMerica and 23-1218 for Comcast, and it is the ordinary shape of this work rather than a failure.
Employees Are The Unasked-About Population
A restaurant group’s customers buy a meal and leave a card transaction. Its employees hand over social security numbers, addresses, bank details and employment history, as a condition of the job.
The corpus argues at 25-0807b and 25-0704 that workforce data sits outside most of the consumer-protection framing of breach law, and that an employee cannot decline to provide it or take their data elsewhere. Yum! Brands is the case where the customer headline and the actual victim population were different groups.
A Day Of Closures Is Still A Loss
Three hundred restaurants closing for a day is minor next to the five weeks Jaguar Land Rover lost at 25-0902, and it is not nothing: shift workers not called in, perishable stock, franchisees carrying fixed costs against no revenue.
No regime asks for that figure and this file does not have it, which is the point the corpus makes at 24-1231 about availability harm generally.
Built on Yum! Brands’ own January statement and on contemporaneous reporting of that statement and of the subsequent April disclosure. The 18 January announcement, the response actions and the initial position on customer data are the company’s. The April disclosure of compromised personal information and its characterisation as affecting employees are from reporting of the Maine Attorney General filing; this desk has not read the filing itself. No figure for the number of affected individuals is asserted — none was established in a form this desk can cite. No actor attribution is made. Graded high on the outage and the disclosures. Corrections: corrections@forensicpost.com.