Cyber Incident Victim: Schlotzsky's
Date:
Apr 2019
Location:
United States of America
Summary
A U.S. restaurant chain experienced a payment card breach after point-of-sale malware infected systems at select corporate and franchised locations, compromising card numbers, expiration dates, verification codes, and occasionally cardholder names. The malware operated for varying durations across affected establishments, with some locations impacted for several weeks before the intrusion was halted in late July. Customers were notified approximately one month after malicious activity ceased, and the parent company provided a tool to check specific location involvement. The incident impacted multiple subsidiaries under the same ownership, though not all sites were affected.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 2 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
The Schlotzsky's restaurant chain experienced a payment card data breach in 2019 resulting from point-of-sale (PoS) malware infections across certain locations. The incident was disclosed alongside two other Focus Brands subsidiaries—McAlister's Deli and Moe's Southwest Grill—on August 20, 2019, though initial unauthorized access began earlier at Schlotzsky's. Attackers first compromised Schlotzsky's systems on April 11, 2019, nearly three weeks prior to the April 29 breach start dates at Moe's and McAlister's. The malware operated until July 22, 2019, when Focus Brands terminated the intrusion across all three chains. While not all corporate and franchised locations were affected, most compromised sites had the malicious code active for only a few weeks during July. The malware targeted payment card data as it processed through restaurant servers, capturing magnetic stripe details including card numbers, expiration dates, and internal verification codes, with cardholder names also exposed in some instances.

Focus Brands initiated an investigation with cybersecurity experts, confirming the breach scope impacted a subset of their combined 1,500 U.S. locations. The company provided location-specific lookup tools for customers to verify exposure but did not publish a full list of compromised sites. Notification letters confirmed the malware's data exfiltration method but did not disclose the number of affected cards or customers. The breach duration varied across locations, with Schlotzsky's sustaining the longest potential exposure window among the three chains at over three months. No fraudulent use estimates or financial impact disclosures accompanied the notifications. Focus Brands emphasized remediation efforts had eliminated the malware by late July, prior to the August customer alerts.
