← Chipotle

2017 Payment card breach (2,220 locations)

2017 Unknown records affected Share on X

Data compromised

Payment card numbers, expiration, CVV, cardholder names

Technical writeup

Mar 24–Apr 18, 2017. Malware on POS devices at ~2,220 Chipotle and Pizzeria Locale locations (most of 2,250 locations nationwide). Extracted track data: card numbers, expiration dates, CVV, cardholder names. No other customer info. Chipotle removed malware and implemented enhancements. 2019 settlement: up to $250 per affected customer.

Root cause

POS malware; payment card skimming.

References