Cybersecurity protects your systems. Cybersecurity risk management protects your business.®

Hello World

U.S. Food Chain Alerts Customers of Payment Card Incident

 U.S. fast-food restaurant chain Krystal disclosed a security incident involving one of its payment processing systems and affecting some of its restaurants between July and September 2019.

Krystal was founded back in 1932, currently has 342 locations in the Southern United States and "is the original quick-service restaurant chain in the South" according to a press release published on Friday.

 

One-third of Krystal restaurants not impacted

At the moment the number of customers impacted by this security incident and the type of payment information that was exposed is not yet known because the investigation is still in its early stages.

Krystal says that "the security incident may have involved payment cards processed by a payment processing system used at certain restaurants" and that not all of its locations have been affected by this incident seeing that the restaurant chain "uses multiple payment processing systems" and only one of them was compromised.

"We have already taken steps to contain and remediate the incident.  We are working hard to determine the specific locations and dates for each restaurant involved in the attack," says Krystal's notice of potential payment card incident.

The fast-food chain's notice also says that "to date, our investigation has determined that about a third of our restaurants that are not impacted."

Our company has retained a leading forensics firm and is conducting an investigation to determine the extent to which information in Krystal's systems may have been impacted. We are cooperating with law enforcement and have also notified the payment card networks of the investigation. - Krystal

 

Cause behind security incident not yet known

The company has also set up a web-based lookup tool to allow customers to search for restaurant locations that were impacted by this security incident at krystal.com/security/.

"If you do not see a specific restaurant location when searching this tool, that restaurant has not been identified as potentially impacted," says Krystal.

Customers can also call Krystal's 24/7 call center at 1-800-457-9782 for more information. The company also reminds "guests to be vigilant and that it is always good practice to review your payment card statements regularly and report any unusual or unauthorized purchases to your financial institution."

At the moment it's not yet known if the payment processing system's database was exposed/breached or if Point-of-sale (PoS) malware is responsible, or what specific payment card information was involved.

BleepingComputer reached out to Krystal for more information but had not received an answer at the time of this publication. This article will be updated when a response is received.

Krystal will provide updates to guests once we have completed our investigation and know more about payment cards that may have been impacted.

 

US food industry under attack

Krystal is the latest company from the U.S. food industry that fell victim to attackers aiming to steal their customers' payment card information.

During early October, four restaurant chains in the U.S. disclosed that they were the victim of hackers who compromised their payment systems over the summer using PoS malware that stole customers' payment card information.

Hy-Vee, McAlister's Deli, Moe’s Southwest Grill, and Schlotzsky’s said that their networks were infected with point-of-sale malware that copied data from cards used by customers in person at some of their corporate and franchised restaurants [123].

Hy-Vee is an employee-owned company that operates in the retail (fuel pumps, grocery, convenience, drug stores) business and it has over 245 locations in the U.S. with $10 billion in revenue in 2018.

McAlister's, Moe's, and Schlotzsky’s together have roughly 1,500 U.S. locations and are all owned by the same parent company, Focus Brands.

In June, online food ordering service EatStreet announced that it was also impacted by a security incident in May which led to a data breach involving customer payment card information, and sensitive info of restaurant and delivery partners.

According to its website, EatStreet is currently "servicing over 15,000 restaurants in more than 1,100 cities" and it is a "one-stop-shop for online ordering and marketing" offering partnered restaurants "web, mobile, and social products for online ordering."