Menu
Browse

Cyber Incident Victim: Swiss Cleaners

Date:

Dec 2014

Location:

United States of America

Summary

Swiss Cleaners experienced a prolonged point-of-sale malware attack compromising payment card data across all eight locations, affecting customers who used cards during the incident period. The breach exposed cardholder names, numbers, expiration dates, and verification codes from magnetic stripe data during transaction processing. Unauthorized charges reported by customers prompted an investigation leading to malware removal, replacement of the compromised system with a more secure dial-up payment terminal network, and collaboration with security experts and credit card companies to address vulnerabilities and notify potential victims.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

Swiss Cleaners, a Rockville, Connecticut-based dry cleaning chain operating eight locations, experienced a point-of-sale (POS) system breach affecting payment card data between December 30, 2014, and December 23, 2015. The company became aware of the incident after customers reported unauthorized charges on payment cards recently used at their stores. An investigation revealed that malware had been installed on the company’s payment card server, capturing data from every payment card processed during the 10-month intrusion period. The compromised information included cardholder names, card numbers, expiration dates, and verification codes stored on the magnetic strips of cards swiped at POS terminals across all eight Connecticut locations. This breach exposed all customers who used payment cards at any Swiss Cleaners store during the affected timeframe, though the exact number of impacted individuals was not disclosed.

Cyber Incident Image

Upon discovery, Swiss Cleaners removed the malicious code from its server and implemented a stand-alone payment system using dial-up connections at all stores to enhance security, despite acknowledging this method increased transaction processing times. The company engaged a computer security firm to review its payment procedures and collaborated with credit card companies to notify potential victims. Swiss Cleaners publicly stated the breach investigation began immediately after banks identified patterns of fraudulent charges linked to cards used at their stores, emphasizing their commitment to protecting customer relationships and payment card information. No evidence suggested theft of non-payment data or compromise of systems beyond the POS server. The company did not disclose whether law enforcement investigations occurred or if regulatory penalties resulted from the incident.

Sources
Sources available to members
1 source