Chipotle Says 'Most' of Its Restaurants Were Infected With Credit Card Stealing Malware (theverge.com)
Earlier this year, Chipotle announced that the their payment processing system was hacked. Today, the company has released more information about the hack, identifying the malware that was responsible and releasing a new tool to help customers check whether the restaurant they visited was involved. The company did not say how many restaurants were affected, but it did tell The Verge that "most" locations nationwide may have been involved. The Verge reports: "The malware searched for track data (which sometimes has cardholder name in addition to card number, expiration date, and internal verification code) read from the magnetic stripe of a payment card as it was being routed through the POS device," Chipotle said in a statement. "There is no indication that other customer information was affected." We browsed through the tool and found that every state Chipotle operates in had restaurants that were breached, including most major cities. The restaurants were vulnerable in various time frames between March 24th and April 18th, 2017. Chipotle also operates another chain called Pizzeria Locale, which was affected by the hack as well. (The list of identified restaurants can be found here, which includes locations in Kansas, Missouri, Colorado, and Ohio.) Chipotle noted that not all locations have been identified, but it's a starting guide to check whether your visit lines up with the breached period.
At least their food wasn't infected,
Of course news about a fake are Fake News.
You're going to need your credit card when you go buy more underwear after eating Chipotle. (south park)
I can't find the malware, or how the hack happened. Does anyone have real information about this hack?
"First they came for the slanderers and i said nothing."
new tool: don't eat there again.
I can avoid diarrhea AND credit card fraud!
Chas - The one, the only.
THANK GOD!!!
Nice web tool to see if you were at risk - I was able to confirm from my cc records that i didn't use it there on any of the at-risk dates. Thanks to their doing the right thing, I can relax. (If I there was a hit I would have replaced my CC.)
Too many companies either cover up this stuff, or don't give you the info needed to act. I'm looking at you Target, T J Max, ...
So they are seriously just saying "our bad", call the credit bureaus and place fraud alerts on your credit reports? Many of the places I've had this happen offer free credit monitoring. I get that credit monitoring is pretty worthless, but at least they aren't just walking away "scott free".
Is there any kind of virus, bacteria or alike, analog or digital, that chipotle doesn't get infected with?!
A puff of the vape and a tip of the fedora to you, Sir Edgy!
Well, in most first world, civilized, countries the reason to pay with card (debit, credit, doesn't matter) is twofold: less paper, force companies to declare all earnings (transaction traceability... follow the money baby, follow the money... it's easy to have it on paper and every odd receipt be a dud, hard to explain money flowing from one account to the other directly to the company's account and not being theirs and not matching their tax declaration). But then again, that's in first world, civilized, countries.
Is Chipotle on the chip, or are their readers still strip based? My cards have chips these days, but I usually don't watch to see who uses which scan technology. Chip tech is supposed to combat this sort of thing, isn't it?
How'd that work out?
-- "Oh. This guy again."
Cash? So I have to go to a bank periodically (once a week?) and wait in line to withdraw paper currency. So your solution is I should have yet another chore in my life.
“Common sense is not so common.” — Voltaire
the good news is, we didn't food poison you.
Fortunately the food is already infected to the point of supersaturation with cilantro; so I have no worries.
Cash? So I have to go to a bank periodically (once a week?) and wait in line to withdraw paper currency. So your solution is I should have yet another chore in my life.
The AC probably only accepts cash as payment and may well not even have a bank account.
My wife complains that I'm always carrying cash so my wallet is always bulky and I'm missing out on credit card rewards.
Yeah ATMs are really crowded and they take forever to give you cash. Like I mean you might have to wait up to five minutes in your air conditioned or heated car while inserting a card, punching a few numbers, and grabbing that dough. And those fees! $3 just to get cash once a week. Really terrible. It's almost like it's nothing but it feels like thousands of dollars in fees.
by law you can't be held liable for more than $50 bucks of fraud and I've never seen anyone held for that (maybe on the really crappy cards you use to rebuild credit after a messy divorce?). As long as you read your statement once a month the one who's gonna lose out here is Chipotle. Especially since they're not doing chip 'n pin.
Hi! I make Firefox Plug-ins. Check 'em out @ https://addons.mozilla.org/en-US/firefox/addon/youtube-mp3-podcaster/
"Earlier this year, Chipotle announced that the their payment processing system was hacked."
Jesus fuckin' christ, will shit ever end? Is there one god damn business that can secure their shit to keep their customer's information safe?
I am SO glad that I never ate at Chipotle, but that's just down to pure luck more than anything else. If I had, and my credit card info had been hacked, I would pissed off beyond beyond all reason.
Fucking clowns. After you hear about the 1,000th data breach you start to realize that none of these fucking companies give a shit about security. They couldn't program their way out of a wet paper bag with a chainsaw in each hand. For fuck's sake.
Just cruising through this digital world at 33 1/3 rpm...
Yeah ATMs are really crowded and they take forever to give you cash. Like I mean you might have to wait up to five minutes in your air conditioned or heated car while inserting a card, punching a few numbers, and grabbing that dough. And those fees! $3 just to get cash once a week. Really terrible. It's almost like it's nothing but it feels like thousands of dollars in fees.
$150/year is "nothing" to you? Yet you also consider that your time has no value either since you don't mind spending an extra 5 - 10 minutes/week driving to the bank to retrieve cash (that's 4 - 8 hours/year).
I would like to know when are consumers going to had they have and enough of this crap and burn the business to the ground?
Just wondering...
Chipotle researchers have found a way to imprint the giardia genome into customers' credit card strips. This can cause it to jump to rival restaurants.
I can't consider your statement relevant until you've completely documented the micro optimization of your life
No other explanation worthy of consideration. Never go there.
shit your brains out after eating
but now
it sucks your wallet dry..
is that a Shit n Blow??
Cash?
That's what I do. I do my best to use only cash at restaurants, including fast food and sit down restaurants. For multiple reasons.
One, computer security is truly deep in the dark ages these days. Both of the Chipotle restaurants I frequent were included in the hack, so I just saved myself a bunch of trouble getting a new card, changing some of my automatic payments for things like Netflix, etc.
Two, I don't have to wait for the server to pick up my credit card, process it, and return it.
Three, I'm pretty sure last year a server skimmed my card on purpose.
Four, it helps keep my spending down. I visit the bank once a month for that month's "fun money". If I spend it all, it's gone. Helps keep me on budget.
My location was not affected, or so the website says.
But an ATM could have the same malware problems. Best not to use those either.
(you probably won't get E. Coli from the ATM, so it has that going for it)
“Common sense is not so common.” — Voltaire
No per diem ? I don't have to present receipts for basic food and lodging provided I stay under the companies estimated costs for the market area I am working in. X amount of dollars per day for food and a basic lodging rate. If something exceeds that limit I either call and get authorization or retain and file the receipts. Most of my lodgings are arranged ahead of time and paid for by corporate accounting and I don't even have to do a thing besides show ID and sleep.
errr....umm...*whooosh* *whoosh* Is this thing on ?
Avoiding paying $3 to a machine is not a micro optimization, it's more of not wanting to pay a lot for what seems like a trivial service on their end.
An ATM business is what, load money into a busy machine once a day and collect $500? Pay $3 seems steep compared to their effort.
“Common sense is not so common.” — Voltaire
obviously if you're running an ATM business but are using another company for the processing, then the interchange fees are being set by the processing company and they're the ones making the most money in this. Like most other businesses, the best option is to be the bank.
You've been conned. Here in the U.K. people refused this and the banks gave up, leaving most of out ATMs free. The banks make money in plenty of other ways, but giving you access to your own cash should be free.
The banks and the networks doing the processing are separate. Many people here pay two fees, one at the ATM that is split by the processing company and machine owner, and another fee their bank secretly charges. My bank charges me $5 a month if i use any out-of-network ATMs that month, rather sneaky.
To fix this in the US, I think we'd have to restructure our networks to eliminate the need for these interchange networks. Putting an entire industry out of business is politically difficult, especially in a nation primarily ran by lobbyists.
As individuals we don't get to refuse fees, we can refuse to use the service entirely, but that is mighty difficult and not really effective. I'm not calling you a liar, but I don't think grousing about issues is normally how problems are solved.
“Common sense is not so common.” — Voltaire
I can't consider your statement relevant until you've completely documented the micro optimization of your life
I don't want to waste 5 minutes at an ATM every week, I'm certainly not going to write a detailed thesis on my life's micro optimizations so an Anonymous Coward too lazy to create or log in to a Slashdot account will consider my statement relevant. But I'll tell you another of my micro optimizations - I don't waste 10 - 15 minutes every week driving to the gas station to buy gas.
This Turkey American hacker by the name WILLIAM HOLLIS saved me. He helped change my driving records and clear some implicating records i had online. This is no joke, i tried it and it has worked for me. If you are in need of a professional hacker, William is the man for the job. Other services he offers are below::
-Tracking calls
-Facebook,whatsapp,twitter,gmail hack
-Cloning of phones
-Clearing criminal records without leaving traces
-Changing school grades without leaving traces
-Website hack
-Retrieval of lost or hacked social media accounts and so many other services not mentioned here.
Contact us @ willtrusthack830@fastservice.com OR trusthacker830@gmail.com
Call +1 (201) 719-5274
WhatsApp +1 (847) 497-0407
ICQ: 704422091
Thank me later
Please ensure to tell him Peter Blom referred you. Good luck. you won't be disappointed, cheap and fast
^^This^^
Plus anonymity.
Cash is king.
Chipotle's latest problem is why restaurant and retailers need to offer Android Pay and Apple Pay support.
Why? Because under Android Pay and Apple Pay, you transact using a specially encrypted code that is not anywhere close to your credit card number. As such, there's no such thing as "skimming for card number," and it's extremely difficult--even if the hacker could intercept the data stream--to use it for credit card fraud.
$150/year is "nothing" to you?
Yep. I make a decent living.
Maybe you should go back to school?
This Turkey American hacker by the name WILLIAM HOLLIS saved me. He helped change my driving records and clear some implicating records i had online. This is no joke, i tried it and it has worked for me. If you are in need of a professional hacker, William is the man for the job. Other services he offers are below::
-Tracking calls
-Facebook,whatsapp,twitter,gmail hack
-Cloning of phones
-Clearing criminal records without leaving traces
-Changing school grades without leaving traces
-Website hack
-Retrieval of lost or hacked social media accounts and so many other services not mentioned here.
Contact us @ willtrusthack830 at fastservice dot com OR trusthacker830 at gmail dot com
Call +1 (201) 719-5274
Skype: +1 (847) 497-0407
ICQ: 704422091
Thank me later
Please ensure to tell him Peter blom referred you. Good luck. you won't be disappointed, cheap and fast
Banks want your money because they use it to make more money.
If you're paying somebody to store or access your money, you're doing something wrong. Drop whatever lousy excuse for a bank you're using and find one that won't charge you.
How can we continue to believe in a just universe and freedom to eat crackers if we have no ale?
$150/year is "nothing" to you?
Yep. I make a decent living.
Maybe you should go back to school?
Then why would you pay hundreds of dollars to spend hours in line at the bank each year? Did you learn that in school?
FYI o sheltered manchildren, servers (the human kind, who manually cater to your every gastronomical whim) like cash tips. They get to take it home at the end of the night and tip out the indentured cooks under the table.
Banks want your money because they use it to make more money.
If you're paying somebody to store or access your money, you're doing something wrong. Drop whatever lousy excuse for a bank you're using and find one that won't charge you.
They don't exist in the US.
“Common sense is not so common.” — Voltaire
If you're paying somebody to store or access your money, you're doing something wrong. Drop whatever lousy excuse for a bank you're using and find one that won't charge you.
They don't exist in the US.
You're talking utter nonsense. If you actually believe this, then you've obviously never compared financial institutions.
How can we continue to believe in a just universe and freedom to eat crackers if we have no ale?
I use credit cards at restaurants and get reimbursed when someone steals from me. It's a 20 minute phone call the my credit card company and hasn't happened to me in 3 years. But it couldn't be simpler, assuming you like to review your monthly statements as part of tracking your personal budget.
Don't use an ATM/Debit card for anything, banks are a huge pain in the ass about fraud and it will take about 90 days to get your money back into your account.
My "fun money" is also my lunch money, and I can't really go without lunch for weeks.
“Common sense is not so common.” — Voltaire