The Wendy's Company
bd_bc3d18143c546b3d · schema v1 · pii pii-v1
Wendy's disclosed a malware attack on franchisee POS systems. The attack resulted from compromised remote access credentials of a service provider, allowing attackers to deploy malware targeting payment card data (cardholder name, card number, expiration date, CVV, service code) starting in late fall 2015. Wendy's first reported unusual activity in February 2016 and confirmed malware in May 2016. The malware was disabled. Affected customers were offered one year of fraud consultation and identity restoration services.
J jump to incidentP pin to compareR raw source
Incident timeline
Oct 1, 2015
Begins
Feb 1, 2016
Discovered
Jul 7, 2016
Filed
vs. sector median
+14 wks slower
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.