MalwareRansomwareBackoffData EncryptedSupply Chain (3P Vendor)PCIFINANCIAL_ACCOUNTLowContained
International Dairy Queen, Inc. (“IDQ”) on behalf of 9 Dairy Queen franchise locations in California listed in the attached addendum.
bd_531839a434b36466 · schema v1 · pii pii-v1
Full breach record for International Dairy Queen, Inc. (“IDQ”) on behalf of 9 Dairy Queen franchise locations in California listed in the attached addendum. →International Dairy Queen, Inc. (IDQ) reported a malware intrusion affecting 395 U.S. locations, including 9 California franchises. The Backoff malware targeted payment card systems, exposing customer names, card numbers, and expiration dates. The incident was caused by a third-party vendor's compromised credentials. IDQ retained forensic experts, contained the malware, and offered one year of free identity repair services to affected customers.
California clockDiscovered Aug 6, 2014 → Notified Oct 9, 201464d ✗ CA 60-day late9 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-46950
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 9, 2014
- Raw hash
- a994974c5cf418814a053ccf530e11b06f385d480bcf5364f80b07a6e69c3eab
Reporting entity
- Name
- International Dairy Queen, Inc.norm: international dairy queen
Victim entity
- Name
- International Dairy Queen, Inc. (“IDQ”) on behalf of 9 Dairy Queen franchise locations in California listed in the attached addendum.norm: international dairy queen inc idq on behalf of 9 dairy queen franchise locations in california listed in the attached addendum
Incident
- Discovered
- Aug 6, 2014
- Materiality determined
- Oct 9, 2014
- Notification sent
- Oct 9, 2014
- Affected individuals
- Not disclosed
- Data types
- PCIFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Initial access
- supply_chain
Compliance
- Time to disclose
- 9 weeks(64 days from discovery to filing)
- Compliance flags
- CA 60-day late · 64d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 6, 2014→ Notified: Oct 9, 201464d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.