MalwareRansomwareData ExfiltratedCustomer Data InvolvedMulti-Stage ChainSupply Chain (3P Vendor)FINANCIAL_ACCOUNTPIILowContained
Wendy's
bd_d08b42b228651f10 · schema v1 · pii pii-v1
Full breach record for Wendy's →Wendy's of Fresno, Inc. reported a cybersecurity incident involving malicious cyber activity targeting payment card information at franchisee-operated restaurants. The breach resulted from compromised service provider remote access credentials, allowing deployment of malware on POS systems. Affected data included cardholder names, card numbers, expiration dates, and verification values. Wendy's disabled the malware, engaged forensic experts and law enforcement, and offered one year of fraud consultation and identity restoration services to affected customers.
California clockDiscovered May 1, 2016 → Notified Jul 7, 201667d ✗ CA 60-day late10 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_0cb8339e139fc8edSouth Carolina State AGfiled 2016-07-07Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-62722
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 7, 2016
- Raw hash
- eb27ed6a4f63a9014361936aa96d3c42ddab869832b750e41c52505c569c2de2
Reporting entity
- Name
- Wendy'snorm: wendy s
- Domain
- wendys.com
Victim entity
- Name
- Wendy'snorm: wendy s
- Domain
- wendys.com
Incident
- Discovered
- May 1, 2016
- Materiality determined
- —
- Notification sent
- Jul 7, 2016
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTPII
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- Submitted breach notification to California Office of the Attorney General
- Initial access
- supply_chain
Compliance
- Time to disclose
- 10 weeks(67 days from discovery to filing)
- Compliance flags
- CA 60-day late · 67d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 1, 2016→ Notified: Jul 7, 201667d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.