2017 Payment card breach (2,220 locations)
Data compromised
Payment card numbers, expiration, CVV, cardholder names
Technical writeup
Mar 24–Apr 18, 2017. Malware on POS devices at ~2,220 Chipotle and Pizzeria Locale locations (most of 2,250 locations nationwide). Extracted track data: card numbers, expiration dates, CVV, cardholder names. No other customer info. Chipotle removed malware and implemented enhancements. 2019 settlement: up to $250 per affected customer.
Root cause
POS malware; payment card skimming.