Threat Intelligence

5/14/2018
11:10 AM
50%
50%

Chili's Suffers Data Breach

The restaurant believes malware was used to collect payment card data including names and credit or debit numbers.

Chili's Grill & Bar, a restaurant brand owned by Dallas-based Brinker International, said some of its restaurants were hit with a cyberattack which may have resulted in compromise of users' payment card data. It believes the incident was limited to March and April 2018.

The company first learned of the compromise on May 11, 2018 and launched an investigation to learn more. Based on the details so far, it seems malware was used to collect credit and debit card numbers, as well as the cardholders' names, from payment systems used for in-restaurant purchases. Chili's doesn't collect social security numbers, full birthdays, or federal or state identification numbers, so none of this type of information was affected.

Officials report they have contacted both law enforcement and third-party forensic experts as part of the investigation. Chili's reports it's trying to provide fraud resolution and credit monitoring services for affected customers and it will share more info as it's available. In the meantime, it has provided guidance for those who may have been compromised on its website.

Read more details here.

 

 

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
White House Cybersecurity Strategy at a Crossroads
Kelly Jackson Higgins, Executive Editor at Dark Reading,  7/17/2018
Mueller Probe Yields Hacking Indictments for 12 Russian Military Officers
Kelly Jackson Higgins, Executive Editor at Dark Reading,  7/13/2018
10 Ways to Protect Protocols That Aren't DNS
Curtis Franklin Jr., Senior Editor at Dark Reading,  7/16/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2016-10727
PUBLISHED: 2018-07-20
camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME evolution-data-server before 3.21.2 proceeds with cleartext data containing a password if the client wishes to use STARTTLS but the server will not use STARTTLS, which makes it easier for remote attackers to obtain sensitive ...
CVE-2018-8018
PUBLISHED: 2018-07-20
Apache Ignite 2.5 and earlier serialization mechanism does not have a list of classes allowed for serialization/deserialization, which makes it possible to run arbitrary code when 3-rd party vulnerable classes are present in Ignite classpath. The vulnerability can be exploited if the one sends a spe...
CVE-2018-14415
PUBLISHED: 2018-07-20
An issue was discovered in idreamsoft iCMS before 7.0.10. XSS exists via the fourth and fifth input elements on the admincp.php?app=prop&do=add screen.
CVE-2018-14418
PUBLISHED: 2018-07-20
In Msvod Cms v10, SQL Injection exists via an images/lists?cid= URI.
CVE-2018-14419
PUBLISHED: 2018-07-20
MetInfo 6.0.0 allows XSS via a modified name of the navigation bar on the home page.