2017 Chipotle — POS malware; magnetic-stripe track data (Chipotle & Pizzeria Locale)
Data compromised
Payment-card track data; other profile fields not indicated in vendor findings
Technical writeup
After detecting unauthorized payment-network activity in April 2017, Chipotle Mexican Grill completed forensics showing POS malware active March 24–April 18, 2017 at selected Chipotle and Pizzeria Locale stores, harvesting mag-stripe track data—sometimes including cardholder name, PAN, expiration, and CVC. The company published per-location exposure windows, stripped the malware, and coordinated with card brands for issuer monitoring—typical fast-casual POS incident response for that era.
Root cause
Retail point-of-sale malware capturing track data in flight