MalwareRansomwareData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)FINANCIAL_ACCOUNTPIILowContained
U.S. Restaurants, Inc.
bd_2814256c1385ebae · schema v1 · pii pii-v1
Full breach record for U.S. Restaurants, Inc. →Select Restaurants, Inc. disclosed a data security incident involving a third-party vendor where malware compromised payment card data (cardholder name, number, expiration, CVV) at multiple restaurant locations between October 2016 and February 2017. The company engaged forensic experts and the U.S. Secret Service, confirmed malware activity, and notified affected guests.
California clockDiscovered Mar 30, 2017 → Notified Jun 9, 201771d ✗ CA 60-day late10 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-72488
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 9, 2017
- Raw hash
- e64b59f4cd7cbd194c1e92c892edd512b6da1f51ffdff707f3e4f489e2c81d71
Reporting entity
- Name
- U.S. Restaurants, Inc.norm: us restaurants
Victim entity
- Name
- U.S. Restaurants, Inc.norm: us restaurants
Incident
- Discovered
- Mar 30, 2017
- Materiality determined
- —
- Notification sent
- Jun 9, 2017
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTPII
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- working with the United States Secret Service to investigate this incident
- Initial access
- supply_chain
Compliance
- Time to disclose
- 10 weeks(71 days from discovery to filing)
- Compliance flags
- CA 60-day late · 71d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 30, 2017→ Notified: Jun 9, 201771d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.