Desk live·
ForensicPost
Ransomware/Availability/File 23-0118

Yum! Brands Closed 300 UK Restaurants for a Day, Then Found Employee Data Had Gone

In January the company said there was no evidence customer data was taken, and it was right. In April it disclosed that employees’ personal information had been — the population nobody asks about when a restaurant group is attacked.

Constructed geometry · not a chart of case data
JurisdictionUnited Kingdomthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetYum! Brands
ActorUnattributed
S. Rosler10 min readConfidence: high2 sources reviewed

Yum! Brands announced a ransomware attack on 18 January 2023 affecting certain IT systems. Close to 300 of its UK restaurants closed for one day. The company took systems offline, engaged forensics support and notified federal law enforcement.

Its initial position was that there was no evidence customer databases had been taken. In April, in a filing with the Maine Attorney General, it disclosed that personal information belonging to individuals had been compromised — reported as affecting employees, including names, social security numbers and contact details.

The First Statement Was Accurate And Incomplete

This desk does not read the January statement as misleading. It said customer databases showed no evidence of theft, and that appears to have held.

What it did not say is that a different population had been affected, because in January the company did not yet know. The corpus records the same three-month scoping gap at 23-0512b for PharMerica and 23-1218 for Comcast, and it is the ordinary shape of this work rather than a failure.

Employees Are The Unasked-About Population

A restaurant group’s customers buy a meal and leave a card transaction. Its employees hand over social security numbers, addresses, bank details and employment history, as a condition of the job.

The corpus argues at 25-0807b and 25-0704 that workforce data sits outside most of the consumer-protection framing of breach law, and that an employee cannot decline to provide it or take their data elsewhere. Yum! Brands is the case where the customer headline and the actual victim population were different groups.

A Day Of Closures Is Still A Loss

Three hundred restaurants closing for a day is minor next to the five weeks Jaguar Land Rover lost at 25-0902, and it is not nothing: shift workers not called in, perishable stock, franchisees carrying fixed costs against no revenue.

No regime asks for that figure and this file does not have it, which is the point the corpus makes at 24-1231 about availability harm generally.

How we reported this

Built on Yum! Brands’ own January statement and on contemporaneous reporting of that statement and of the subsequent April disclosure. The 18 January announcement, the response actions and the initial position on customer data are the company’s. The April disclosure of compromised personal information and its characterisation as affecting employees are from reporting of the Maine Attorney General filing; this desk has not read the filing itself. No figure for the number of affected individuals is asserted — none was established in a form this desk can cite. No actor attribution is made. Graded high on the outage and the disclosures. Corrections: corrections@forensicpost.com.

Sources
  1. Yum! Brands January 18, 2023 StatementYum! Brands
  2. Yum Brands Discloses Data Breach Following Ransomware AttackSecurityWeek
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary