DisclosureLens
MalwareRetail & ConsumerRetailRansomwareSupply Chain (3P Vendor)Data ExfiltratedFinancial accountPIILowActive

Huddle House, Inc.

bd_e97c3e992d96708e · schema v1 · pii pii-v1

Severity

Low

Discovered

Jan 1, 2019

Filed

Feb 1, 2019

To disclose

4 weeks

Affected

Not disclosed

Confidence

65%
Full breach record for Huddle House, Inc.

Huddle House, Inc. notified customers of a malware intrusion affecting POS systems at corporate and franchise locations. Criminals compromised a third-party POS vendor to deploy malware. Payment card data (magnetic stripe info) was at risk for transactions between August 1, 2017, and January 2019. The company engaged forensic experts and law enforcement; investigation was ongoing.

Incident timeline

undetected · 518 days
discovery → filing · 4 weeks / 31 days

Aug 1, 2017

Begins

Jan 1, 2019

Discovered

Feb 1, 2019

Filed

vs. sector median

3 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.