MalwareStolen CredentialsData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)PCIFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSIDENTITY_BASICLowContained
BMP/Pennant Holdings, LLC
bd_bc3d18143c546b3d · schema v1 · pii pii-v1
Full breach record for BMP/Pennant Holdings, LLC →Wendy's disclosed a malware attack on franchisee POS systems. The attack resulted from compromised remote access credentials of a service provider, allowing attackers to deploy malware targeting payment card data (cardholder name, card number, expiration date, CVV, service code) starting in late fall 2015. Wendy's first reported unusual activity in February 2016 and confirmed malware in May 2016. The malware was disabled. Affected customers were offered one year of fraud consultation and identity restoration services.
California clockDiscovered Feb 1, 2016 → Notified Jul 7, 2016157d ✗ CA 60-day late22 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-62712
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 7, 2016
- Raw hash
- 6f09522d30ce7ca8fecdc6dbd58c3f0f79a2e24009aabe59149ad271ee198f83
Reporting entity
- Name
- BMP/Pennant Holdings, LLCnorm: bmp pennant
Victim entity
- Name
- BMP/Pennant Holdings, LLCnorm: bmp pennant
- Domain
- wendys.com
Incident
- Discovered
- Feb 1, 2016
- Materiality determined
- —
- Notification sent
- Jul 7, 2016
- Affected individuals
- Not disclosed
- Data types
- PCIFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1078 Valid AccountsT1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Third party
- via Service Provider
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 22 weeks(157 days from discovery to filing)
- Compliance flags
- CA 60-day late · 157d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 1, 2016→ Notified: Jul 7, 2016157d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.