HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedFINANCIAL_ACCOUNTLowContained
Cheddar's Scratch Kitchen (a concept acquired by Darden Restaurants in 2017)
bd_f2728b56e66f0bad · schema v1 · pii pii-v1
Full breach record for Cheddar's Scratch Kitchen (a concept acquired by Darden Restaurants in 2017) →Cheddar's Scratch Kitchen experienced a cyberattack between November 3, 2017, and January 2, 2018, resulting in unauthorized access to payment card information. The incident affected customers in 23 states. The company engaged a third-party cybersecurity firm, disabled the compromised network, and offered identity protection services to affected individuals.
California clockDiscovered Aug 16, 2018 → Notified Nov 22, 201898d ✗ CA 60-day late7 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-139169
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 23, 2018
- Raw hash
- b0379fe400d6a9c7991a3e5153ce0d419d957f1143e015951ed3650822d7a6fc
Reporting entity
- Name
- Cheddar's Scratch Kitchen (a concept acquired by Darden Restaurants in 2017)norm: cheddar s scratch kitchen a concept acquired by darden restaurants in 2017
Victim entity
- Name
- Cheddar's Scratch Kitchen (a concept acquired by Darden Restaurants in 2017)norm: cheddar s scratch kitchen a concept acquired by darden restaurants in 2017
Incident
- Discovered
- Aug 16, 2018
- Materiality determined
- —
- Notification sent
- Nov 22, 2018
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Submitted breach notification to California Office of the Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 7 days(7 days from discovery to filing)
- Compliance flags
- CA 60-day late · 98d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 16, 2018→ Notified: Nov 22, 201898d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.