Saturday, February 22, 2025
HomeData BreachPOS Malware Steals Users Payment Card Details from Checkers Drive-In Restaurants

POS Malware Steals Users Payment Card Details from Checkers Drive-In Restaurants

Published on

SIEM as a Service

Follow Us on Google News

The Checkers and Rally’s Restaurants, Inc disclosed a security breach that involved with malware on point-of-sale terminals which allowed hackers to steal payment data.

Checkers and Rally’s restaurants operate in 28 states, and it is one of the largest double drive-thru restaurants in the United States. The company operates nearly 900 restaurants across the country.

According to the companies investigation, they determined malware was installed on approximately 15% of restaurants point-of-sale systems and an unauthorized third party accessed the customer payment card details.

The malware was designed to collect the following information form payment cards that include cardholder name, payment card number, card verification code, and expiration date.

“After discovering the issue, we quickly engaged leading data security experts to conduct an extensive investigation and coordinated with affected restaurants and federal law enforcement authorities to address the matter.”

Out of 900 restaurants, 102 being impacted with the security breach, you can find the list of the impacted locations and their respective estimated dates of exposure is available here.

Most of the affected restaurants in the list are between 2018 and 2019, some of them in 2017 and 2 restaurants since 2016.

“Not all Checkers and Rally’s restaurants and not all guests who visited the impacted restaurants during the relevant time periods were affected by this issue,” reads breach report.

“Checkers encourages guests to review their account statements and contact their financial institution or card issuer immediately if they identify an unauthorized charge on their card.”

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

U.S. Charges China-Based Hacking Group for Massive 2015 Anthem Data Breach that Affected 78 Million People

Top Reasons Let Hackers Compromise the Healthcare Industry that Leads to Data Breaches

Bodybuilding.com Data Breach, Resulting from Phishing Attack Via Email

5 Best Workplace Practices To Prevent Data Breach

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

SPAWNCHIMERA Malware Exploits Ivanti Buffer Overflow Vulnerability by Applying a Critical Fix

In a recent development, the SPAWNCHIMERA malware family has been identified exploiting the buffer...

Sitevision Auto-Generated Password Vulnerability Lets Hackers Steal Signing Key

A significant vulnerability in Sitevision CMS, versions 10.3.1 and earlier, has been identified, allowing...

NSA Allegedly Hacked Northwestern Polytechnical University, China Claims

Chinese cybersecurity entities have accused the U.S. National Security Agency (NSA) of orchestrating a...

ACRStealer Malware Abuses Google Docs as C2 to Steal Login Credentials

The ACRStealer malware, an infostealer disguised as illegal software such as cracks and keygens,...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Raymond IT Systems Hit by Cyber Attack, Authorities Investigating

Textile and apparel conglomerate Raymond Limited confirmed a cybersecurity breach affecting portions of its...

Zacks Investment Data Breach Exposes 12 Million Emails and Phone Numbers

A cybersecurity incident at Zacks Investment Research has exposed sensitive data belonging to 12...

Indian Post Office Portal Leak Exposes Thousands of KYC Records

The Indian Post Office portal recently exposed the sensitive Know Your Customer (KYC) data...