← Chipotle Mexican Grill

2017 Chipotle — POS malware; magnetic-stripe track data (Chipotle & Pizzeria Locale)

2017 Unknown records affected Share on X

Data compromised

Payment-card track data; other profile fields not indicated in vendor findings

Technical writeup

After detecting unauthorized payment-network activity in April 2017, Chipotle Mexican Grill completed forensics showing POS malware active March 24–April 18, 2017 at selected Chipotle and Pizzeria Locale stores, harvesting mag-stripe track data—sometimes including cardholder name, PAN, expiration, and CVC. The company published per-location exposure windows, stripped the malware, and coordinated with card brands for issuer monitoring—typical fast-casual POS incident response for that era.

Root cause

Retail point-of-sale malware capturing track data in flight

References