Menu
US food chain, PF Chang's, investigates possible card breach

US food chain, PF Chang's, investigates possible card breach

Fraudsters are claiming 100 percent of the cards are valid, meaning banks haven't cancelled accounts yet

A large batch of stolen credit card numbers for sale on an underground forum may have come from a breach at P.F. Chang's China Bistro, a US restaurant chain that said on Tuesday it is investigating.

Those selling the stolen data are claiming all of the card numbers are still valid, meaning the data is fairly fresh and that banks haven't yet canceled the accounts, said Alex Holden, CTO of Hold Security, a Wisconsin-based consultancy that monitors secret forums where stolen data is sold.

The company is investigating and law enforcement has been contacted, said a P.F. Chang's representative, Anne Deanovic, via email. "We will provide an update as soon as we have additional information," she wrote.

P.F. Chang's China Bistro also runs Pei Wei Asian Diner, a casual diner. As of January 2012, the company ran close to 400 of both restaurant brands in 23 U.S. states, according to its website.

The breach, first reported by security journalist Brian Krebs, most likely resulted from an attack on point-of-sale (POS) systems, the computerized cash registers used to swipe payment cards, Holden said. It appears the breach started in March and continued through early May, he said.

Cybercriminals have had striking success infecting POS systems with malicious software, which was blamed for the breaches at retailers Target, Neiman Marcus and others over the past eight months.

In those cases, malicious software captured payment card details -- encoded on the black stripe of the card -- right after the card was swiped. Although retailers are required to encrypt card details, in some cases the data is briefly held unencrypted in a computer's memory. The type of malware that can exploit this hole is known as a "RAM scraper."

The card details suspected to be from PF Chang's are for sale on a site known as Rescator, an infamous "carding" website that sells stolen data to other fraudsters, Holden said.

Holden said Rescator was down on Tuesday, but later came back online. It appeared those selling the data did a poor job of mixing up the card numbers. Releasing a big batch of numbers from a single retailer allows banks to more closely hone in on where the breach occurred, he said.

It also means the value of the stolen data may fall quickly if banks decided to cancel payment cards in anticipation of fraud. Rescator is selling card details for US$18 up to $139 each, Holden said. Card details are often priced according to the potential spending limit of the card, with fraudsters hoping to exploit the card before banks cancel it or its holder notices unauthorized charges.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk


Follow Us

Join the newsletter!

Error: Please check your email address.

Tags securitydata breachTargetNeiman MarcusP.F. Chang's China Bistro

Featured

Slideshows

Looking back at the top 15 M&A deals in NZ during 2017

Looking back at the top 15 M&A deals in NZ during 2017

In 2017, merger and acquisitions fever reached new heights in New Zealand, with a host of big name deals dominating the headlines. Reseller News recaps the most important transactions of the Kiwi channel during the past 12 months.

Looking back at the top 15 M&A deals in NZ during 2017
Kiwi channel closes 2017 with After Hours

Kiwi channel closes 2017 with After Hours

The channel in New Zealand came together to celebrate the close of 2017, as the final After Hours played out in front of a bumper Auckland crowd.

Kiwi channel closes 2017 with After Hours
Meet the top performing HP partners in NZ

Meet the top performing HP partners in NZ

HP honoured leading partners across the channel at the Partner Awards 2017 in New Zealand, recognising excellence across the entire print and personal systems portfolio.

Meet the top performing HP partners in NZ
Show Comments