Credential theft β›“ Supply Chain

Wendy's POS Malware Breach (1,025 Franchise Locations)

πŸ“… 2015-10-01 🦠 POS malware (two distinct strains)
Primary Source β†—

Incident Details

Between approximately fall 2015 and spring 2016, POS malware was deployed at Wendy’s franchise restaurant locations in the United States. Wendy’s first disclosed the breach in May 2016 affecting approximately 300 franchise locations, then expanded the disclosure in July 2016 to 1,025 locations after discovering a second distinct malware strain. The breach was initiated via compromised remote-access credentials of a third-party service provider with access to Wendy’s franchisee POS systems β€” a supply chain attack vector similar to the Target 2013 breach. Two separate malware strains were identified: the first affecting ~300 locations, and a second affecting additional corporate-owned locations. Exposed data included cardholder names, card numbers, expiration dates, service codes, and CVV data from magnetic stripe reads. The breach prompted class-action lawsuits and an investigation. Wendy’s franchise locations and corporate-owned locations used different POS systems, which contributed to the scope differences in the two disclosure waves.

Technical Details

Initial Attack Vector
Attackers compromised remote access credentials belonging to a third-party service provider with access to Wendy's franchisee POS systems, then installed POS malware across multiple franchise locations; a second distinct malware strain was also discovered affecting additional locations
Malware Family
POS malware (two distinct strains)
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2015-10-01 Breach occurred
  2. 2016-05-11 Publicly disclosed
  3. 2016-07-01 Customers notified