HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedPCIFINANCIAL_ACCOUNTLowContained
Dickey's Barbecue Pit
bd_587f27fda101e825 · schema v1 · pii pii-v1
Full breach record for Dickey's Barbecue Pit →Dickey's Barbecue Pit reported a payment card security incident affecting approximately 55 franchised locations in California. Unauthorized code was installed on payment servers between June 9, 2019, and November 24, 2020, capturing payment card track data (names, account numbers, expiration dates). Dickey's engaged forensic investigators, notified law enforcement and card networks, and removed the code. This filing serves as a supplemental notice to the initial disclosure made in November 2020.
California clockDiscovered Oct 13, 2020 → Notified Nov 20, 202038d ✓ CA 60-day OK11 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_813ff0e564c50f68Delaware State AGfiled 2020-12-29Verified
- bd_999eced63eb08322Montana State AGfiled 2020-12-29Verified
- bd_f1fed28338edbe20Oregon State AGfiled 2020-12-29Candidate
- bd_c3bd7239ed078983South Carolina State AGfiled 2020-12-30(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-197607
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 29, 2020
- Raw hash
- 32676d917c850876b8895f065e69980c9902e8ac3ce02740d34ee44e5322509f
Reporting entity
- Name
- Dickey's Barbecue Pitnorm: dickey s barbecue pit
- Domain
- dickeys.com
Victim entity
- Name
- Dickey's Barbecue Pitnorm: dickey s barbecue pit
- Domain
- dickeys.com
Incident
- Discovered
- Oct 13, 2020
- Materiality determined
- —
- Notification sent
- Nov 20, 2020
- Affected individuals
- Not disclosed
- Data types
- PCIFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 11 weeks(77 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 38d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Oct 13, 2020→ Notified: Nov 20, 202038d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.