MalwareData ExfiltratedCustomer Data InvolvedPCIFINANCIAL_ACCOUNTLowContained
Consolidated Restaurant Operations, Inc.
bd_a20dea545d6f4ae3 · schema v1 · pii pii-v1
Full breach record for Consolidated Restaurant Operations, Inc. →Checkers Drive-In Restaurants, Inc. disclosed a data security incident involving malware installed on point-of-sale systems at approximately 15% of its Checkers and Rally’s locations. The malware collected payment card data (cardholder name, number, verification code, expiration date) from magnetic stripes. The incident affected guests who visited impacted locations between late 2015 and April 2019. Checkers engaged security experts and law enforcement, contained the malware, and notified affected guests.
California clockDiscovered May 29, 2019 → Notified May 29, 20190d ✓ CA 60-day OK≤1 day discovery → filing
⚠ notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_6de4c6543868287eDelaware State AGfiled 2019-05-29Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-147626
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 29, 2019
- Raw hash
- da53dd7e20e0197de4ab12dffc4014688fcedd7d87b30a4770ebc302843c1fc8
Reporting entity
- Name
- Consolidated Restaurant Operations, Inc.norm: consolidated restaurant operations
- Domain
- croinc.com
Victim entity
- Name
- Consolidated Restaurant Operations, Inc.norm: consolidated restaurant operations
- Domain
- croinc.com
Incident
- Discovered
- May 29, 2019
- Materiality determined
- —
- Notification sent
- May 29, 2019
- Affected individuals
- Not disclosed
- Data types
- PCIFINANCIAL_ACCOUNT
- Attack vector
- Unknown
- MITRE ATT&CK
- T1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Coordinated with federal law enforcement authorities
Compliance
- Time to disclose
- ≤1 day(0 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 0d
- Discovery-date grounding
- notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 29, 2019→ Notified: May 29, 20190d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.