Menu
US Wendy's hack was bigger than thought and exposed credit card data

US Wendy's hack was bigger than thought and exposed credit card data

The company has published a list of the affected restaurants

A data breach that hit Wendy's fast food restaurants was more than three times bigger than originally disclosed and exposed customer credit card data.

The company said Thursday that malware installed in point-of-sale systems was discovered at over 1,000 of its franchised U.S. restaurants -- a big jump from the "fewer than 300 stores" it said in May had been affected.

Hackers gained access to the machines using remote access credentials of a third-party service provider, Wendy’s said.

The breach began in fall 2015 and wasn't discovered until early this year. As part of its investigation, the company discovered a second malware variant had infected its systems.

That second malware targeted "cardholder name, credit or debit card number, expiration date, cardholder verification value, and service code," the company said.

The restaurants affected were all franchise operations and are listed on a website. Wendy's said it's owned and operated restaurants do not appear to have been exposed to the same malware.

The company is one of the latest U.S. brands to have been hit by similar cyber attacks. In recent years, hackers pulled off data breaches against Target and Home Depot, also using login credentials from third-parties.

Hacking attacks against point-of-sale systems, especially at retailers, have become all too common, said Ziv Mador, vice president of security research at Trustwave.

Many of these attacks are conducted by stealing the login credentials used in company web interfaces designed to maintain the point-of-sale systems, he said. Once access is gained, a hacker can easily deliver malware disguised as a security patch.

Retailers tend to reuse the login credentials across their stores, so it can be easy for the hackers to expand their attack, Mador said.

Wendy's is encouraging customers to look out for unauthorized charges on their credit cards.


Follow Us

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Events

Featured

Slideshows

Channel kicks 2021 into gear as After Hours returns to Auckland

Channel kicks 2021 into gear as After Hours returns to Auckland

After Hours made a welcome return to the channel social calendar with a bumper crowd of partners, distributors and vendors descending on The Pantry at Park Hyatt in Auckland to kick-start 2021.

Channel kicks 2021 into gear as After Hours returns to Auckland
The Kiwi channel gathers for the 2020 Reseller News Women in ICT Awards

The Kiwi channel gathers for the 2020 Reseller News Women in ICT Awards

Hundreds of leaders from the New Zealand IT industry gathered at the Hilton in Auckland on 17 November to celebrate the finest female talent in the Kiwi channel and recognise the winners of the Reseller News Women in ICT Awards (WIICTA) 2020.

The Kiwi channel gathers for the 2020 Reseller News Women in ICT Awards
Show Comments