Wake up. Break the cycle. Teach your children.
Joined Oct 24, 2016
1,143 Blog Posts

Chipotle Hacked In Massive Breach – Customer Payment Data Stolen From Thousands Of Restaurants $CMG

Chipotle announced late Friday that Hackers used malware to infiltrate Chipotle Mexigan Grill Inc’s ($CMG) payment system over a three week period beginning in late March – stealing sensitive customer banking information, including account numbers and internal verification codes that could be used to drain debit-card linked bank accounts.

The announcement was made following an investigation into an incident first reported on April 25th of “unauthorized activity” detected in some of their Canadian restaurants.

The malware searched for track data (which sometimes has cardholder name in addition to card number, expiration date, and internal verification code) read from the magnetic stripe of a payment card as it was being routed through the POS device.

No word on how many customers are affected, however Chipotle said most of their 2,250 or so restaurants were hit between March 24th and April 18th. Click here to see the list of affected restaurants by state.

Chipotle refused to upgrade to chip readers in 2015

The malware used in the attack steals data found within the magnetic stripe of payment cards. Although it is not clear if EMV (chipped) payment cards would have been susceptible to the hack, Chipotle notably declined to use them in 2015 – citing inefficiencies caused by delays in the authentication process in a fast paced food service environment.

The breach could mean big trouble for shares of Chipotle, which have only partially recovered from an E.coli outbreak in late 2015. According to Reuters, security analysts say Chipotle will likely face a fine based on the size of the breach and number of records compromised.

“If your data was stolen through a data breach that means you were somewhere out of compliance” with payment industry data security standards, Julie Conroy, research director at Aite Group, a research and advisory firm.

“In this case, the card companies will fine Chipotle and also hold them liable for any fraud that results directly from their breach,” said Avivah Litan, a vice president at Gartner Inc (IT.N) specializing in security and privacy.

It is uncertain if and how Chipotle’s decision not to adopt chipped card payments will factor into fines levied against the company by credit card companies.

Poor $CMG just can’t catch a break!



If you enjoy the content at iBankCoin, please follow us on Twitter


  1. ferd

    Am I the only one who’s noticed that the one, most vocal, national food purveyor promoting their food as free of the poison Roundup, has had unrelentingly bad luck?

    Don’t fuck with Monsanto.

    • 0
    • 0
    • 0 Deem this to be "Fake News"
  2. Metalleg

    But it was their decision not to go with chip readers.

    • 0
    • 0
    • 0 Deem this to be "Fake News"
  3. sarcrilege

    Sounds and looks very much like sabotage than a hack to steal customer data. There’s going to be more to it than can be seen. Why Chipotle now and not some other vendor? Perhaps somebody shorted their stock prior to the hack? Could Monsanto be behind it as ferd noted?

    • 0
    • 0
    • 0 Deem this to be "Fake News"

Leave a Reply

Your email address will not be published. Required fields are marked *