Security

Chipotle: Hackers did to our registers what our burritos did to your colon

Fast food chain cops to POS malware breach


Fast-food chain Chipotle says hackers infected its point of sale terminals to gain access to card data from stores in 47 states and Washington, DC.

The self-described "Mexican Grill" says that the malware was active earlier this year from March 24 to April 18, when it was detected, triggering the company to issue an alert.

"The malware searched for track data (which sometimes has cardholder name in addition to card number, expiration date, and internal verification code) read from the magnetic stripe of a payment card as it was being routed through the POS device," Chipotle said in its latest summary of the incident.

"There is no indication that other customer information was affected."

That last sentence is a bit puzzling, as a fraudster who has payment card numbers, dates, and security codes would have little need for any other info.

Chipotole says that while the compromised stores are located in every state save Alaska, Hawaii and South Dakota, not every location was breached. Chipotle's disclosure page includes a section to check individual stores.

Chipotle recommends that anyone who paid with a card at one of the compromised stores keep a close eye on bank statements and consider having an alert placed to their credit file to catch possible fraud.

The fast food chain is far from alone in falling victim to this type of scam. Hackers have targeted the POS terminals of dozens of retailers, restaurants, and hotel chains with malware payloads that collect and transmit the payment card data of customers, often resulting in the theft of thousands of card numbers. ®

Send us news
15 Comments

Europol: Five pay-per-infect suspects cuffed, some spill secrets to cops

Officials teased more details to come later this year

Oracle faces Texas-sized lawsuit over alleged cloud snafu and radio silence

Victims expect to spend considerable time and money over privacy incident, lawyers argue

CISA spots spawn of Spawn malware targeting Ivanti flaw

Resurge an apt name for malware targeting hardware maker that has security bug after security bug

China’s FamousSparrow flies back into action, breaches US org after years off the radar

Crew also cooked up two fresh SparrowDoor backdoor variants, says ESET

Check Point confirms breach, but says it was 'old' data and crook made 'false' claims

Explanation leaves a 'lot of questions unanswered,' says infosec researcher

Cardiff's children's chief confirms data leak 2 months after cyber risk was 'escalated'

Department director admits Welsh capital's council still trying to get heads around threat of dark web leaks

Infosec pro Troy Hunt HasBeenPwned in Mailchimp phish

16,000 stolen records pertain to former and active mail subscribers

23andMe's genes not strong enough to avoid Chapter 11

CEO steps down after multiple failed attempts to take the DNA testing company private

Oracle Cloud says it's not true someone broke into its login servers and stole data

Despite evidence to the contrary as alleged pilfered info goes on sale

Names, bank info, and more spills from top sperm bank

Cyber-crime is officially getting out of hand

'Uber for nurses' exposes 86K+ medical records, PII in open S3 bucket for months

Non-password-protected, unencrypted 108GB database … what could possibly go wrong

Allstate Insurance sued for delivering personal info on a platter, in plaintext, to anyone who went looking for it

Crooks built bots to exploit astoundingly bad quotation website and made off with data on thousands