← Whole Foods Market

2017 Taproom/restaurant payment card breach

2017 Unknown records affected Share on X

Data compromised

Payment card numbers, expiration, CVV, cardholder names

Technical writeup

Mar 10–Sep 28, 2017. Unauthorized software on POS systems at ~100 taprooms and restaurants located within some Whole Foods stores (~96 stores, ~30 states). Affected venues used separate POS from main grocery checkout. Card numbers, expiration, CVV, cardholder names exposed. Primary grocery and Amazon transactions not affected.

Root cause

POS malware; payment card skimming.

References