CSIDB logo
Incident

Whole Foods Market

Incident posture

Attack window
Sep 2017
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-01-10 18:18

Linked entities

Victim
Whole Foods Market
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Sep 2017
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Whole Foods Market experienced a payment card data breach affecting in-store taprooms, restaurants, and similar venues, though its primary point-of-sale systems across stores remained uncompromised. The incident did not involve connected Amazon systems or transactions. The company initiated an investigation with cybersecurity forensic support, notified law enforcement, and implemented measures to address the breach.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On September 28, 2017, Whole Foods Market, recently acquired by Amazon.com Inc. for $13.7 billion, disclosed a cybersecurity incident involving unauthorized access to payment card information at specific venues within some of its stores. The breach affected taprooms, restaurants, and other food service establishments operating inside select Whole Foods locations, where attackers compromised point-of-sale systems. The company clarified that its primary grocery store point-of-sale infrastructure—used across approximately 450 U.S. stores—remained unaffected by the intrusion. Whole Foods further confirmed that neither Amazon.com’s systems nor Amazon.com transactions were connected to or impacted by the breach, maintaining separation between the parent company’s infrastructure and the compromised venues. While over 40 Whole Foods locations were known to feature taprooms serving beer, the company did not immediately specify the total number of in-store restaurants affected or the timeframe during which the breach occurred.

Whole Foods initiated a multi-faceted response upon discovering the incident, including launching an internal investigation and engaging a leading cybersecurity forensics firm to analyze the breach. The company notified law enforcement agencies but did not disclose specific details about the forensic findings, attacker methodologies, or the exact number of compromised payment cards. Remediation efforts focused on implementing "appropriate measures" to secure the affected point-of-sale systems, though technical specifics were not publicly elaborated. The disclosure emphasized the localized nature of the breach, confined to ancillary food service venues rather than core grocery operations, and reaffirmed the operational independence of Amazon’s systems from Whole Foods’ compromised segments. No additional information regarding customer notifications, financial penalties, or long-term operational impacts was provided in the initial announcement.

Sources

Sources available to members: 1 source.

CSIDB