HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedPCIFINANCIAL_ACCOUNTLowContained
McAlister’s Corporation, Moe’s Stores LLC, Schlotzsky’s Stores LLC, as well as entities that are franchisees
bd_9822a343ac8f8f57 · schema v1 · pii pii-v1
Full breach record for McAlister’s Corporation, Moe’s Stores LLC, Schlotzsky’s Stores LLC, as well as entities that are franchisees →McAlister’s, Moe’s, and Schlotzsky’s restaurants reported a payment card security incident where unauthorized code was installed on POS systems between April 11 and July 22, 2019. The malware captured payment card track data (card numbers, expiration dates, verification codes). Forensic firms were engaged, law enforcement notified, and substitute notice was provided to customers on October 2, 2019.
California clockDiscovered Aug 20, 2019 → Notified Oct 2, 201943d ✓ CA 60-day OK6 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-183110
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 2, 2019
- Raw hash
- 465675b5e06f633425fa112eee4f24695ab8f1ae16673013836f7a0f044db37a
Reporting entity
- Name
- McAlister’s Corporation, Moe’s Stores LLC, Schlotzsky’s Stores LLC, as well as entities that are franchiseesnorm: mcalister s corporation moe s stores llc schlotzsky s stores llc as well as entities that are franchisees
Victim entity
- Name
- McAlister’s Corporation, Moe’s Stores LLC, Schlotzsky’s Stores LLC, as well as entities that are franchiseesnorm: mcalister s corporation moe s stores llc schlotzsky s stores llc as well as entities that are franchisees
Incident
- Discovered
- Aug 20, 2019
- Materiality determined
- —
- Notification sent
- Oct 2, 2019
- Affected individuals
- Not disclosed
- Data types
- PCIFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(43 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 43d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 20, 2019→ Notified: Oct 2, 201943d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.