Bumble, Match, Crunchbase, and Panera appear in a new wave of incidents
Reuters compiled incidents reported by several companies in late January, including Bumble, Match Group, Crunchbase and Panera Bread.

News summary
Reuters compiled incidents reported by several companies in late January, including Bumble, Match Group, Crunchbase and Panera Bread. The scope and exact nature varied by organisation.
Campaigns striking multiple companies in a short period typically exploit repeatable techniques, particularly credentials and social engineering. Sharing indicators and reviewing access reduces the exposure window.
Source: Reuters — 27 July 2026
What happened
In late January, Reuters compiled a set of incidents disclosed by several companies across very different sectors: dating apps Bumble and Match Group, business data provider Crunchbase and restaurant chain Panera Bread. Each disclosed its incident separately, with its own scope, timeline and level of detail, and none framed the event as part of a coordinated campaign against the group as a whole.
The exact detail varied by case: some involved unauthorised access to internal systems, others exposure of user or third-party data. None of the companies pointed to a shared root cause, though the timing drew attention from security analysts.
What it teaches a mid-sized business
When several organisations across unrelated sectors disclose incidents within a few weeks, there is often a repeatable explanation behind it: credentials leaked in earlier breaches, targeted phishing campaigns or vulnerabilities in widely used tools. Companies don't need to be connected to share the same weak point.
For a mid-sized business, the practical lesson is twofold: monitor whether its own credentials appear in known leaks, and review access for service accounts and third parties, usually the least watched link in day-to-day operations and often granted more permissions than they actually need.
What to review
Checks that reduce the risk of being caught up in a similar wave:
- Whether there is a periodic review of leaked credentials tied to the company's domain.
- Whether third-party and connected-app access has minimum permissions and an expiry.
- Whether phishing-resistant two-factor authentication is enforced on administrative access.
- Whether there is a clear procedure to notify customers if data is exposed.
Frequently Asked Questions
- Were these incidents linked to each other?
- Reuters did not report a confirmed link between the cases; they were independent disclosures grouped together because of their timing.
- Why group several incidents into one story?
- Because it helps spot patterns: repeated techniques such as phishing or leaked credentials often affect several organisations in parallel.
- What can an SME take from this?
- Check whether its own credentials have appeared in public leaks and strengthen identity verification for critical access.
Is your company prepared for an incident of this nature? At Seintec, we can review access, backups, cloud, endpoints and procedures to reduce exposure and recovery times. Let’s talk.
Contact SeintecRelated service
Cybersecurity
We shield your business so it never stops.