THE WENDY'S COMPANY
ent_019e5eeb246e1d358e30e8440daa76f5
Disclosures
8
State AG · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
1,092
nationwide · State AG NH
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- THE WENDY'S COMPANY
- Normalized
- the wendy s— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 529900M0JIUCMWVKHG76
- SEC EDGAR CIK
- 0000030697
- Domain
- wendys.com
Disclosure history (8)newest first
- South Carolina State AGas victim2016-07-07
The Wendy's Company reported malicious cyber activity targeting payment card information at franchise locations in the US and Canada. The incident involved malware installed on point-of-sale systems via compromised service provider credentials. Wendy's disabled the malware and offered one year of fraud consultation and identity restoration services to affected customers.
- Montana State AGas victim2016-07-07
Wendy's filed a supplemental notice in Montana regarding malicious cyber activity targeting payment card data at franchisee POS systems. The attack exploited compromised service provider credentials to deploy malware starting in late fall 2015. Wendy's disabled the malware and is offering fraud consultation services. Investigation is ongoing.
- California State AGas victim2016-07-07
Wendy's of Fresno, Inc. reported a data breach affecting payment card information at some franchisee-operated restaurants in the U.S. The incident occurred between December 2, 2015, and June 8, 2016, with unusual activity first reported in February 2016. Malware was deployed on point-of-sale systems after a service provider's remote access credentials were compromised. Affected data included cardholder name, card number, expiration date, CVV, and service code. Wendy's disabled the malware and offered one year of fraud consultation and identity restoration services.
- New Hampshire State AGas victim2016-07-05
The Wendy's Company notified the New Hampshire Attorney General of a payment card security incident affecting franchisee POS systems. Malware was deployed between late fall 2015 and June 8, 2016, via compromised service provider credentials. Payment card data (names, numbers, CVV) was at risk. Wendy's disabled the malware and offered one year of fraud consultation and identity restoration services. No specific affected individual count was provided.
- New Hampshire State AGas victim2015-03-26
Supplemental notice from The Wendy's Company to NH DOJ regarding the Anthem breach. Wendy's sponsors an ERISA plan administered by Anthem. 51 NH residents (former/existing plan members) were affected. Initial notice was Feb 13, 2015.
- New Hampshire State AGas victim2015-03-03
Wendy's (via third-party plan administrator Anthem) notified NH DOJ of a cyber attack on Anthem's systems. Attack occurred starting Dec 10, 2014; discovered Jan 29, 2015. Data accessed included names, SSNs, DOBs, health IDs, addresses, emails, and employment/income data. Wendy's is a sponsor of the ERISA plan; Anthem is the custodian. Wendy's has not yet received the affected member list from Anthem.
- New Hampshire State AGas victim2008-01-29
Wendy's International Inc. notified the NH Attorney General of an administrative error by third-party benefits administrator Life Choices Service Center. On Nov 29, 2007, printed 2008 Benefit Confirmation Statements incorrectly included dependent information (names, SSNs, DOBs) for other employees. Wendy's discovered the breach when employees reported incorrect statements. Corrected statements were mailed on Dec 21, 2007. Approximately 1,006 individuals were affected nationwide, including 4 in New Hampshire. Kroll Inc. was engaged to provide identity safeguards.
- New Hampshire State AGas victim2007-12-21
Wendy's International reported the theft of a company-issued laptop from an employee's residence in a car burglary on Dec 1, 2007. The laptop contained PII (SSN, salary, etc.) of ~1,092 employees. Wendy's notified law enforcement, retained TransUnion for credit monitoring, and mailed notices to affected individuals on Dec 21, 2007.
Supply-chain cascadesreviewed and confirmed
- THE WENDY'S COMPANY’s filing is one of at least 12 in the ANTHEM INSURANCE COMPANIES, INC. supply-chain incident (2015).