Cyber Incident Victim: Mizado Cocina
Timeline
Summary
A New Orleans restaurant experienced a cybersecurity breach where a hacker installed Backoff malware on its point-of-sale system, compromising customers' names, credit/debit card numbers, expiration dates, and CVV security codes. The intrusion was discovered following reports of fraudulent charges from patrons, prompting an investigation that identified the malware and led to the replacement of affected hardware. Approximately 8,000 customers who made card payments during the compromise period were impacted by the data exposure.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 2 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
In mid-2014, Mizado Cocina, a New Orleans restaurant located at 5080 Pontchartrain Boulevard, disclosed a cybersecurity incident involving unauthorized access to customer payment card data. The breach occurred between May 9 and July 18, 2014, when an attacker installed malware called Backoff on the restaurant's point-of-sale (POS) systems. This malware specifically targeted payment processing infrastructure, enabling the theft of customers' credit and debit card information. Compromised data included cardholders' names, credit/debit card numbers, expiration dates, and CVV security codes. The restaurant first became aware of potential issues after receiving multiple reports from guests about fraudulent charges appearing on their accounts shortly after dining at the establishment. These reports prompted an internal investigation that led to the discovery of the malware infection.

Mizado Cocina engaged its IT company to analyze the POS systems, where technicians identified and confirmed the presence of the Backoff malware. In response, the restaurant immediately replaced all affected computer hardware to eliminate the malicious software and prevent further data exfiltration. A restaurant spokeswoman confirmed approximately 8,000 customers who made card payments during the 71-day breach window were potentially affected by the data compromise. The establishment issued a public news release detailing the breach timeline, nature of the compromised data, and remediation steps taken. No additional information was provided regarding whether law enforcement investigations occurred, whether stolen data appeared in underground markets, or if affected customers received identity protection services. The incident marked one of the early reported cases involving Backoff malware, which would later be identified by US-CERT as a significant threat to POS systems nationwide.
