Bojangles notifies employees of data breach months after intrusion

Organization
Bojangles' Restaurants, Inc.
Exploit
Hacking
Industry
Restaurants

Bojangles' Restaurants, the fried chicken chain based in Charlotte, North Carolina, notified employees in November 2024 that their personal information had been exposed in a network intrusion earlier in the year.

The company said an unauthorized party had access to its systems between 19 February and 12 March 2024. Bojangles did not learn the extent of the compromise until 22 October 2024, and began mailing notification letters on 19 November 2024, roughly eight months after the intrusion ended.

Files involved in the incident contained names, Social Security numbers, driver's license numbers, government issued identification card numbers, financial account information, medical information and health insurance information. Bojangles said the event affected employee information only and did not involve customer data. Those notified were offered complimentary credit monitoring and identity restoration services.

Plaintiffs' firms announced investigations within days of the letters going out, and current and former employees sued in North Carolina, arguing the company had failed to safeguard their information and had waited too long to disclose the breach. Court filings put the volume of exfiltrated employee data at roughly 295 gigabytes and said it surfaced on the dark web shortly after the attack. The North Carolina Business Court later allowed most of the claims to proceed, finding that Bojangles owed employees a duty to exercise reasonable care over their information, while dismissing counts for negligence per se and invasion of privacy.

Sources