Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity

    Chipotle Breach Exposes Continued Point-of-Sale Cyber-Security Risks

    Written by

    Sean Michael Kerner
    Published May 30, 2017
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Restaurant chain Chipotle Mexican Grill is the latest to reveal that its payment card systems were breached, exposing users to cyber-crime risks.

      Chipotle first began to investigate the possibility of a Point-of-Sale (PoS) breach on April 25 and has now confirmed that many of its restaurants were in fact exploited by PoS malware between March 24 and April 18.

      “The malware searched for track data (which sometimes has cardholder name in addition to card number, expiration date, and internal verification code) read from the magnetic stripe of a payment card as it was being routed through the POS device,” Chipotle wrote in a security advisory. “There is no indication that other customer information was affected.”

      Chipotle has not publicly identified the specific strain of PoS malware that infected its systems, though it has stated that the malware has been removed. Chipotle has also stated that it is working with undisclosed cyber-security firms to help improve the company’s security.

      The incident at Chipotle is far from unique and follows a series of restaurant and retail breaches that have occurred in recent years. Thus far in 2017 restaurant chain Arbys disclosed a breach in February and retailer Brooks Brothers reported a breach in May.

      PoS Is Inviting Target

      PoS security incidents have been occurring on seemingly regular basis since at least December 2013 when retailer Target first disclosed that its systems were breached. After the Target breach there was increased scrutiny over PoS security as the retail chain tried to determine the root cause.  

      Though the Target breach should have served as a wake-up call to other retailers, other big name store chains also fell victim to PoS security incidents including Home Depot, which revealed a breach in September 2014.  Among the major sources of retail breaches in 2014 was a malware family known as Backoff, which the U.S Secret Service reported had infected more than 600 businesses.

      Retail and restaurant chains that handle credit cards are supposed to be compliant with the Payment Card Industry Data Security Standard (PCI-DSS), yet despite that compliance, breaches are still regularly reported. PCI-DSS defines best practices and operational procedures that are intended to help to keep payment card data secure.

      Despite the fact that the cause of PoS breaches have been examined and debated since at least 2014 and the fact that PCI-DSS compliance should limit the risk of breaches, incidents like the one at Chipotle, continue to occur.

      Though it is possible that some retail and restaurant PoS breaches involved zero-day malware, it’s more likely that the malware was already known, but perhaps just not yet patched by the victim. Having patched software is important to limit the risk of PoS malware, but so too are having multiple layers of monitoring in place.

      Just because malware gets onto a system, doesn’t mean that data has to get out. A Data Loss Prevention (DLP) type of technology platform can be used to further limit data loss risks. Watching administrative user credentials and activity for potentially malicious activity is another good best practice to help harden cyber-security defenses.

      The simple truth is that PoS malware is not new and the way PoS malware infiltrates a system and exfiltrates data is well understood by the cyber-security profession. Not every retailer however understands PoS attacks, or takes all the necessary steps to limit risks, which is why new PoS breaches  will continue to occur in the months ahead.

      Sean Michael Kerner
      Sean Michael Kerner
      Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×