CSIDB logo
Incident

Schlotzsky's

Incident posture

Attack window
Apr 2019
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-12-16 00:00

Linked entities

Victim
Schlotzsky's
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Apr 2019
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A U.S. restaurant chain experienced a payment card breach after point-of-sale malware infected systems at select corporate and franchised locations, compromising card numbers, expiration dates, verification codes, and occasionally cardholder names. The malware operated for varying durations across affected establishments, with some locations impacted for several weeks before the intrusion was halted in late July. Customers were notified approximately one month after malicious activity ceased, and the parent company provided a tool to check specific location involvement. The incident impacted multiple subsidiaries under the same ownership, though not all sites were affected.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

The Schlotzsky's restaurant chain experienced a payment card data breach in 2019 resulting from point-of-sale (PoS) malware infections across certain locations. The incident was disclosed alongside two other Focus Brands subsidiaries—McAlister's Deli and Moe's Southwest Grill—on August 20, 2019, though initial unauthorized access began earlier at Schlotzsky's. Attackers first compromised Schlotzsky's systems on April 11, 2019, nearly three weeks prior to the April 29 breach start dates at Moe's and McAlister's. The malware operated until July 22, 2019, when Focus Brands terminated the intrusion across all three chains. While not all corporate and franchised locations were affected, most compromised sites had the malicious code active for only a few weeks during July. The malware targeted payment card data as it processed through restaurant servers, capturing magnetic stripe details including card numbers, expiration dates, and internal verification codes, with cardholder names also exposed in some instances.

Focus Brands initiated an investigation with cybersecurity experts, confirming the breach scope impacted a subset of their combined 1,500 U.S. locations. The company provided location-specific lookup tools for customers to verify exposure but did not publish a full list of compromised sites. Notification letters confirmed the malware's data exfiltration method but did not disclose the number of affected cards or customers. The breach duration varied across locations, with Schlotzsky's sustaining the longest potential exposure window among the three chains at over three months. No fraudulent use estimates or financial impact disclosures accompanied the notifications. Focus Brands emphasized remediation efforts had eliminated the malware by late July, prior to the August customer alerts.

Sources

Sources available to members: 1 source.

CSIDB