Menu
Browse

Cyber Incident Victim: CCC Restaurant Enterprises, LLC

Date:

May 2016

Location:

United States of America

Summary

CCC Restaurant Enterprises, LLC experienced a malware attack compromising payment card data at 10 of its Popeyes locations across Texas, North Carolina, and Georgia. The breach exposed customers' cardholder names, card numbers, expiration dates, and security codes during the affected period. The company initiated an investigation after detecting unusual activity reported by its credit card processor, engaging third-party forensic experts to identify and remove the malware from compromised systems. Measures were implemented to secure customer data and prevent future incidents, with confirmation that payment cards used after containment were no longer at risk. A dedicated assistance line was established to address customer inquiries regarding the breach.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

The incident involving CCC Restaurant Enterprises, LLC, operating as POPEYES, began with the compromise of payment systems at 10 specific restaurant locations between May 5, 2016, and August 18, 2016. On July 9, 2016, the company initiated an investigation after its credit card processor reported unusual activity. CCC Restaurant engaged a third-party forensic expert to examine its systems, leading to the discovery of malware designed to capture customer payment card data. The malware operated undetected for over three months across the affected locations before investigators confirmed its presence and functionality. The breach timeline spanned 105 days, with the malicious software actively harvesting cardholder information until containment measures were implemented in August 2016. Forensic analysis determined that the malware targeted transactional systems at the point of sale, enabling unauthorized data collection during card processing activities.

Cyber Incident Image

The compromised data included cardholder names, credit/debit card numbers, expiration dates, and security codes. Ten locations were confirmed as affected: seven in Texas (Houston, Liberty, Friendswood, Texas City, Baytown, and League City), two in North Carolina (Fayetteville and Tarboro), and one in Georgia (East Dublin). CCC Restaurant publicly disclosed the breach on January 18, 2017, after completing forensic analysis and remediation. Response actions included complete removal of the malware from all systems, implementation of enhanced security protocols, and establishment of a dedicated customer assistance hotline (844-299-6984) operational on weekdays. The company confirmed that cards used at affected locations after August 18, 2016, faced no ongoing risk from this specific malware. No estimates of impacted customers or financial losses were disclosed in the available information.

Sources
Sources available to members
1 source