MalwareStolen CredentialsSkimmerCustomer Data InvolvedData ExfiltratedMulti-Stage ChainPCIFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSIDENTITY_BASICLowContained
COTTI FOODS CALIFORNIA, INC.
bd_0bc2b41d1115b93c · schema v1 · pii pii-v1
Full breach record for COTTI FOODS CALIFORNIA, INC. →Cotti Foods California, Inc. (Wendy's) reported a breach involving malware deployed on point-of-sale systems at franchisee locations. The attack resulted from compromised remote access credentials of a service provider, allowing attackers to install malware that captured payment card data (cardholder name, card number, expiration date, CVV, service code) between December 2, 2015, and June 28, 2016. Wendy's disabled the malware and offered one year of fraud consultation and identity restoration services to affected customers.
California clockDiscovered Feb 1, 2016 → Notified Jul 7, 2016157d ✗ CA 60-day late22 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-62713
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 7, 2016
- Raw hash
- 3324aefeb37a4054eaf617aaa469df924566f95e5e225d3b8267f2cadd8d7d4c
Reporting entity
- Name
- COTTI FOODS CALIFORNIA, INC.norm: cotti foods california
Victim entity
- Name
- COTTI FOODS CALIFORNIA, INC.norm: cotti foods california
Incident
- Discovered
- Feb 1, 2016
- Materiality determined
- —
- Notification sent
- Jul 7, 2016
- Affected individuals
- Not disclosed
- Data types
- PCIFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1078 Valid AccountsT1190 Exploit Public-Facing ApplicationT1056 Input Capture
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified federal law enforcement
- Third party
- via Service Provider
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 22 weeks(157 days from discovery to filing)
- Compliance flags
- CA 60-day late · 157d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 1, 2016→ Notified: Jul 7, 2016157d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.