Cotti Foods California, Inc. (Wendy's) reported a breach involving malware deployed on point-of-sale systems at franchisee locations. The attack resulted from compromised remote access credentials of a service provider, allowing attackers to install malware that captured payment card data (cardholder name, card number, expiration date, CVV, service code) between December 2, 2015, and June 28, 2016. Wendy's disabled the malware and offered one year of fraud consultation and identity restoration services to affected customers.