Threat Intelligence

5/14/2018
11:10 AM
50%
50%

Chili's Suffers Data Breach

The restaurant believes malware was used to collect payment card data including names and credit or debit numbers.

Chili's Grill & Bar, a restaurant brand owned by Dallas-based Brinker International, said some of its restaurants were hit with a cyberattack which may have resulted in compromise of users' payment card data. It believes the incident was limited to March and April 2018.

The company first learned of the compromise on May 11, 2018 and launched an investigation to learn more. Based on the details so far, it seems malware was used to collect credit and debit card numbers, as well as the cardholders' names, from payment systems used for in-restaurant purchases. Chili's doesn't collect social security numbers, full birthdays, or federal or state identification numbers, so none of this type of information was affected.

Officials report they have contacted both law enforcement and third-party forensic experts as part of the investigation. Chili's reports it's trying to provide fraud resolution and credit monitoring services for affected customers and it will share more info as it's available. In the meantime, it has provided guidance for those who may have been compromised on its website.

Read more details here.

 

 

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
12 Free, Ready-to-Use Security Tools
Steve Zurier, Freelance Writer,  10/12/2018
Most IT Security Pros Want to Change Jobs
Dark Reading Staff 10/12/2018
Most Malware Arrives Via Email
Dark Reading Staff 10/11/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Flash Poll
The Risk Management Struggle
The Risk Management Struggle
The majority of organizations are struggling to implement a risk-based approach to security even though risk reduction has become the primary metric for measuring the effectiveness of enterprise security strategies. Read the report and get more details today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-18374
PUBLISHED: 2018-10-16
XSS exists in the MetInfo 6.1.2 admin/index.php page via the anyid parameter.
CVE-2018-18375
PUBLISHED: 2018-10-16
goform/getProfileList in Orange AirBox Y858_FL_01.16_04 allows attackers to extract APN data (name, number, username, and password) via the rand parameter.
CVE-2018-18376
PUBLISHED: 2018-10-16
goform/getWlanClientInfo in Orange AirBox Y858_FL_01.16_04 allows remote attackers to discover information about currently connected devices (hostnames, IP addresses, MAC addresses, and connection time) via the rand parameter.
CVE-2018-18377
PUBLISHED: 2018-10-16
goform/setReset on Orange AirBox Y858_FL_01.16_04 devices allows attackers to reset a router to factory settings, which can be used to login using the default admin:admin credentials.
CVE-2018-17534
PUBLISHED: 2018-10-15
Teltonika RUT9XX routers with firmware before 00.04.233 provide a root terminal on a serial interface without proper access control. This allows attackers with physical access to execute arbitrary commands with root privileges.