As one of the biggest fast-food sandwich companies in the US, Arby's Restaurant Group acknowledged that thieves had compromised its point-of-sale systems.
When industry partners notified Arby's Restaurants of the security vulnerability, the company found out in mid-January.
The corporation claims that only now, in response to a specific request from the FBI, has the card hack been made public.
In order to eliminate malware, clean up its systems, and look into the credit card hack, the corporation engaged Mandiant and other security specialists.
Source: https://securityaffairs.com/56149/data-breach/arbys-restaurant-group-card-breach.html
TPRM report: https://scoringcyber.rankiteo.com/company/arby's
"id": "arb525191123",
"linkid": "arby's",
"type": "Breach",
"date": "02/2017",
"severity": "50",
"impact": "",
"explanation": "Loss of bank statements, self-assessment details, and other people's National Insurance numbers"
{'affected_entities': [{'industry': 'Food and Beverage',
'location': 'US',
'name': "Arby's Restaurant Group",
'size': 'Large',
'type': 'Fast-Food Sandwich Company'}],
'attack_vector': 'Point-of-Sale Systems',
'data_breach': {'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Credit Card Information']},
'date_detected': 'mid-January',
'description': "Thieves compromised the point-of-sale systems of Arby's "
'Restaurant Group, one of the biggest fast-food sandwich '
'companies in the US.',
'impact': {'data_compromised': ['Credit Card Information'],
'payment_information_risk': 'High',
'systems_affected': ['Point-of-Sale Systems']},
'initial_access_broker': {'entry_point': 'Point-of-Sale Systems'},
'investigation_status': 'Ongoing',
'motivation': 'Financial Gain',
'references': [{'source': 'Cyber Incident Description'}],
'response': {'containment_measures': ['Eliminate Malware', 'Clean Up Systems'],
'law_enforcement_notified': ['FBI'],
'third_party_assistance': ['Mandiant',
'Other Security Specialists']},
'threat_actor': 'Thieves',
'title': "Arby's Point-of-Sale Systems Compromised",
'type': 'Data Breach'}