CSIDB logo
Incident

Earl Enterprises

Incident posture

Attack window
May 2018
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-29 00:00

Linked entities

Victim
Earl Enterprises
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
May 2018
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cybersecurity breach impacted multiple restaurant brands under a hospitality company, involving point-of-sale malware that harvested payment card details including card numbers, expiration dates, and cardholder names. The incident affected U.S. locations of Buca di Beppo, Earl of Sandwich, Planet Hollywood, Chicken Guy!, Mixology, and Tequila Taqueria over a ten-month period, with nearly all Buca di Beppo outlets compromised. Planet Hollywood hotels, Bertucci’s, Seaside on the Pier, and Café Hollywood were unaffected, as were international locations. The company initiated an investigation with cybersecurity experts and law enforcement after external notification, confirming unauthorized access to payment systems but excluding non-restaurant entities from exposure.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In May 2018, Earl Enterprises discovered a payment card data breach affecting multiple restaurant brands under its ownership, including Buca di Beppo, Earl of Sandwich, Planet Hollywood, Chicken Guy!, Mixology, and Tequila Taqueria. Attackers deployed point-of-sale (PoS) malware designed to capture payment card numbers, expiration dates, and cardholder names from compromised systems. The breach persisted for approximately 10 months, with unauthorized access occurring between May 23, 2018, and March 2019. Forensic investigations confirmed that nearly all Buca di Beppo locations across the United States were compromised, along with numerous locations of the other affected brands. The malware specifically targeted PoS systems at restaurant premises, though Planet Hollywood hotels, Bertucci’s stores, Seaside on the Pier, and Café Hollywood locations were explicitly excluded from the impact. International operations remained unaffected.

Earl Enterprises initiated an investigation after external notification of suspicious activity, engaging two cybersecurity firms and federal law enforcement. The company issued a public breach notification acknowledging the theft of payment card data from a "limited number of guests" and provided guidance to affected customers regarding protective measures. While the exact volume of stolen records was not disclosed, the compromise exposed sensitive financial information across dozens of U.S. locations. No evidence confirmed misuse of the data at the time of disclosure, but the incident necessitated widespread fraud monitoring for impacted individuals. The company emphasized ongoing efforts to enhance security protocols but did not specify technical containment measures or malware attribution in available disclosures.

Sources

Sources available to members: 1 source.

CSIDB