Cheddar's Scratch Kitchen
bd_f2728b56e66f0bad · schema v1 · pii pii-v1
Full breach record for Cheddar's Scratch Kitchen →2 incidents on fileCheddar's Scratch Kitchen disclosed that between November 3, 2017, and January 2, 2018, an unauthorized party gained access to its network, potentially obtaining payment card information from guests at restaurants in 23 states. The company learned of the incident on August 16, 2018. The affected network was disabled and replaced by April 10, 2018. The company engaged a third-party cybersecurity firm and offered identity protection services to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 3, 2017
Begins
Aug 16, 2018
Discovered
Aug 23, 2018
Filed
vs. sector median
7 wks faster
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Oregon State AGbd_4f996fc23fae99ef2018-08-23Verified by operator
- New Hampshire State AGbd_0c8c7dd41ed820792018-08-24 · +1dVerified
- Washington State AGbd_bf44ec2af98916752018-08-22 · +1dVerified by operator
- South Carolina State AGbd_fd0b017b0faa47282018-08-28 · +5dVerified
Show 1 more filing ↓Show fewer ↑up to 7d gap
- Montana State AGbd_4124c4909d33b7c12018-08-16 · +7dCandidate
Filing propagation · 6 filings · 6 states
View merged incident ↗Pattern: first filing Aug 16 (MT), last Aug 28 (SC) — a 12-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.