MalwarePCIFINANCIAL_ACCOUNTLowContained
CHIPOTLE MEXICAN GRILL, INC.
bd_4e513ecdc7403535 · schema v1 · pii pii-v1
Full breach record for CHIPOTLE MEXICAN GRILL, INC. →Chipotle Mexican Grill, Inc. reported a payment card security incident involving malware operating on POS devices at certain restaurants between March 24, 2017, and April 18, 2017. The malware accessed track data from magnetic stripe cards. Chipotle removed the malware, engaged forensic firms, and notified law enforcement and payment card networks. No other customer information was affected. The breach was reported to the California Attorney General's office on May 26, 2017.
California clockDiscovered Apr 18, 2017 → Notified May 26, 201738d ✓ CA 60-day OK5 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_f910c3c2c36eafa8Oregon State AGfiled 2017-05-26Candidate
- bd_adb56249b3ae6635Montana State AGfiled 2017-06-05(10d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-69120
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 26, 2017
- Raw hash
- ace8be4b3498d6eddd3f2264eb4ad6caafa33f6aed9591323a5b9a219cd053d1
Reporting entity
- Name
- CHIPOTLE MEXICAN GRILL, INC.norm: chipotle mexican grill
- Domain
- chipotle.com
- Industry
- retail_consumer
Victim entity
- Name
- CHIPOTLE MEXICAN GRILL, INC.norm: chipotle mexican grill
- Domain
- chipotle.com
- Industry
- retail_consumer
Incident
- Discovered
- Apr 18, 2017
- Materiality determined
- May 26, 2017
- Notification sent
- May 26, 2017
- Affected individuals
- Not disclosed
- Data types
- PCIFINANCIAL_ACCOUNT
- Attack vector
- Unknown
- MITRE ATT&CK
- T1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- support law enforcement’s investigation
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(38 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 38d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 18, 2017→ Notified: May 26, 201738d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.