Chipotle Says Hackers Hit Most Restaurants in Data Breach

Advertisement
By Reuters | Updated: 29 May 2017 12:15 IST
Highlights
  • Hackers used malware to steal payment data from Chipotle restaurants
  • Chipotle said it did not know how many customers were affected
  • Stolen data included account numbers and internal verification codes

Hackers used malware to steal customer payment data from most of Chipotle Mexican Grill Inc's restaurants over a span of three weeks, the company said on Friday, adding to woes at the chain whose sales had just started recovering from a string of food safety lapses in 2015.

Chipotle said it did not know how many payment cards or customers were affected by the breach that struck most of its roughly 2,250 restaurants for varying amounts of time between March 24 and April 18, spokesman Chris Arnold said via email.

A handful of Canadian restaurants were also hit in the breach, which the company first disclosed on April 25.

Advertisement

Stolen data included account numbers and internal verification codes. The malware has since been removed.

Advertisement

The information could be used to drain debit card-linked bank accounts, make "clone" credit cards, or to buy items on certain less-secure online sites, said Paul Stephens, director of policy and advocacy at the non-profit Privacy Rights Clearinghouse.

The breach could once again threatens sales at its restaurants, which only recently recovered after falling sharply in late 2015 after Chipotle was linked to outbreaks of E. coli, salmonella and norovirus that sickened hundreds of people.

Advertisement

An investigation into the breach found the malware searched for data from the magnetic stripe of payment cards.

Arnold said Chipotle could not alert customers directly as it did not collect their names and mailing addresses at the time of purchase.

Advertisement

The company posted notifications on the Chipotle and Pizzeria Locale websites and issued a news release to make customers aware of the incident.

Linn Freedman, an attorney at Robinson & Cole LLP specializing in data breach response, said Chipotle was putting the burden on the consumer to discover possible fraudulent transactions by notifying them through the websites.

"I don't think you will get to all of the customers who might have been affected," she said.

Security analysts said Chipotle would likely face a fine based on the size of the breach and the number of records compromised.

"If your data was stolen through a data breach that means you were somewhere out of compliance" with payment industry data security standards, Julie Conroy, research director at Aite Group, a research and advisory firm.

"In this case, the card companies will fine Chipotle and also hold them liable for any fraud that results directly from their breach," said Avivah Litan, a vice president at Gartner Inc specialising in security and privacy.

Chipotle did not immediately comment on the prospect of a fine.

Retailer Target Corp in 2017 agreed to pay $18.5 million to settle claims stemming from a massive data breach in late 2013.

Hotels and restaurants have also been hit. They include Trump Hotels, InterContinental Hotels Group as well as Wendy's, Arby's and Landry's restaurants.

Shares in Chipotle Mexican Grill ended marginally lower at $480.15 on Friday following the announcement.

© Thomson Reuters 2017

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. Motorola Edge 70 Fusion Renders Leaked Again: See Design and Colourways
  2. Samsung Galaxy S26 Series Will Be Available via These E-Commerce Platforms
  3. Realme Narzo 90x 5G Gets a New Colour Option Ahead of Valentine's Day
  4. Sony WF-1000XM6 Spotted in Comparison Images With These Design Changes
  5. Microsoft Says AI Tools With Too Many Privileges Can Become 'Double Agents'
  6. Nothing Phone 4a Pro Listed on UAE's TDRA Database, Might Launch Soon
  7. Google Maps' New AI Feature Could Let You Chat About Places and Routes
  8. Samsung Galaxy S26 Series Pricing, Specs Leak As Galaxy Unpacked Nears
  9. Samsung Announces Galaxy S26 Series Launch Date as Pre-Reservations Begin
  10. SPHEREx Captures Dramatic Outburst of Interstellar Comet 3I/ATLAS
  1. James Webb Telescope Finds Galaxies Nearly as Old as the Early Universe
  2. SPHEREx Captures Dramatic Outburst of Interstellar Comet 3I/ATLAS
  3. Microsoft Warns AI Tools With Excessive Privileges Could Act as ‘Double Agents’
  4. Sony WF‑1000XM6 Leak Reveals Size Differences With WF‑1000XM5 and WF‑1000XM4
  5. Android 17 Beta 1 Expected to Roll Out to Eligible Pixel Devices Soon: Expected UI Changes, Features
  6. Lumio Vision TVs to Receive Android 14 Update With Performance Improvements; Arc Projector to Follow
  7. Maruva Tarama OTT Release Date: When and Where to Watch it Online?
  8. Hackers Use ClickFix Scam to Target Crypto Executive via Fake Zoom Meetings
  9. Heated Rivalry OTT Release Date Revealed: Know When and Where to Watch it Online
  10. The Maadhar Streaming Now on OTTPlus: Know Everything About This Tamil Short Thriller Film
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.