Applebee’s restaurant chain suffered a point-of-sale (POS) breach involving customers’ payment card data.
It launched an investigation with the help of more than one digital forensics firm.
It determined that someone had installed unauthorized software on the point-of-sale (POS) systems at some of its managed Applebee’s locations.
The incident might have exposed customers’ names and payment card details “processed during limited time periods.”
The breach didn’t affect customers who paid online or used tabletop self-pay terminals during that period, RMH revealed.
TPRM report: https://scoringcyber.rankiteo.com/company/applebee's
"id": "app1749622",
"linkid": "applebee's",
"type": "Breach",
"date": "03/2018",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Food and Beverage',
'location': 'Various Locations',
'name': 'Applebee’s',
'type': 'Restaurant Chain'}],
'attack_vector': 'Point-of-Sale (POS) Systems',
'data_breach': {'personally_identifiable_information': ['Customers’ names'],
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Payment card details',
'Customers’ names']},
'description': 'Applebee’s restaurant chain suffered a point-of-sale (POS) '
'breach involving customers’ payment card data. An '
'investigation determined that unauthorized software was '
'installed on POS systems at some managed locations, '
'potentially exposing customers’ names and payment card '
'details processed during limited time periods.',
'impact': {'data_compromised': ['Customers’ names', 'Payment card details'],
'payment_information_risk': True,
'systems_affected': ['Point-of-Sale (POS) systems']},
'initial_access_broker': {'entry_point': 'Point-of-Sale (POS) Systems'},
'investigation_status': 'Ongoing',
'post_incident_analysis': {'root_causes': 'Unauthorized Software '
'Installation'},
'response': {'incident_response_plan_activated': True,
'third_party_assistance': ['More than one digital forensics '
'firm']},
'title': 'Applebee’s POS Breach',
'type': 'Data Breach',
'vulnerability_exploited': 'Unauthorized Software Installation'}