Chipotle has published an update following a security incident announced April 25. It has confirmed malware was used to obtain payment card data from point-of-sale (POS) devices at certain outlets between March 24, 2017 and April 18, 2017.
The Mexican chain restaurant says the malware read payment cards' magnetic stripes as they were routed through POS devices. Malware was designed to search for track data on each card; this includes the card number, expiration date, internal verification code, and sometimes the cardholder's name. There is no sign other customer data was affected in the attack.
Not all restaurants were involved in the breach, and the timeframes of attack vary by location. Chipotle will continue to work with law enforcement and payment card networks so the banks issuing cards can increase monitoring.
Read more details and check affected locations here.