CSIDB logo
Incident

Pizza Hut

Incident posture

Attack window
Oct 2017
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-30 00:00

Linked entities

Victim
Pizza Hut
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Oct 2017
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A Pizza Hut data breach exposed payment card details of customers who placed orders through its website or mobile app during a 28-hour intrusion. The company stated the incident impacted less than one percent of visitors during the relevant period and was quickly contained, but multiple users reported fraudulent transactions occurring prior to notification. Affected customers criticized delayed disclosure, with some confirming unauthorized charges on their cards days before receiving official breach alerts.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

Pizza Hut experienced a security breach impacting customers who placed orders through its website or mobile application during a 28-hour period from the morning of October 1, 2017, through midday on October 2, 2017. The company detected the intrusion promptly and took immediate action to contain it, according to an email notification sent to affected customers on October 14, 2017. Pizza Hut characterized the incident as a "temporary security intrusion" that compromised payment card details and other information from a limited subset of users. The organization estimated that less than one percent of website visitors during the relevant week were affected, though it did not disclose the absolute number of compromised accounts. This marked Pizza Hut's second publicly disclosed payment card breach, following a 2012 incident affecting 240,000 customers.

Multiple customers reported unauthorized transactions on their payment cards in the week preceding Pizza Hut's notification. At least five users publicly attributed fraudulent charges to the breach through Twitter complaints, with some stating they had to cancel compromised cards. Customers criticized the delayed disclosure timeline, noting fraudulent activity occurred approximately one week before receiving official notification from Pizza Hut. The company faced public accusations of inadequate security measures and insufficiently prompt breach disclosure based on social media reactions. While Pizza Hut confirmed the breach's occurrence and containment, the total number of affected individuals remained unclear at the time of reporting, with external attempts to obtain additional metrics unsuccessful. The incident demonstrated recurring security challenges for the organization across multiple years.

Sources

Sources available to members: 1 source.

CSIDB