Wendy's disclosed a malware attack on franchisee POS systems. The attack resulted from compromised remote access credentials of a service provider, allowing attackers to deploy malware targeting payment card data (cardholder name, card number, expiration date, CVV, service code) starting in late fall 2015. Wendy's first reported unusual activity in February 2016 and confirmed malware in May 2016. The malware was disabled. Affected customers were offered one year of fraud consultation and identity restoration services.