MalwareSkimmerSupply Chain (3P Vendor)Customer Data InvolvedFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
FAST CASUAL CONCEPTS, INC.
bd_675c168752664299 · schema v1 · pii pii-v1
Full breach record for FAST CASUAL CONCEPTS, INC. →LYFE Kitchen Companies, LLC experienced a data breach involving malware on a third-party POS vendor's network. The malware was programmed to access data from the magnetic stripe of payment cards (card number, expiration date, verification code) at five corporate restaurants in California, Tennessee, and Nevada between November 2, 2016, and January 6, 2017. The malware has been removed. No evidence suggests data was exported. Complimentary credit monitoring is offered.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-67060
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 21, 2017
- Raw hash
- cf3c678b6a73d1d3137f13062db3ae6f181e82cdee71d57937e8e32f86783114
Reporting entity
- Name
- FAST CASUAL CONCEPTS, INC.norm: fast casual concepts
Victim entity
- Name
- FAST CASUAL CONCEPTS, INC.norm: fast casual concepts
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- ExternalFinancial
- Third party
- via third-party point of sale (POS) vendor
- Initial access
- supply_chain
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.