CSIDB logo
Incident

Bowlmor AMF

Incident posture

Attack window
Feb 2017
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-12-08 00:00

Linked entities

Victim
Bowlmor AMF
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2017
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A major bowling center operator experienced a cybersecurity incident involving payment card data-snatching malware discovered on systems at 21 of its domestic locations across 12 states, including three specific Virginia sites. The malicious software compromised customer payment information during a multi-week period, affecting a subset of the organization's extensive national network of venues. The breach investigation confirmed unauthorized access to transactional data through point-of-sale systems at the impacted bowling alleys.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

Bowlmor AMF, identified as the world's largest bowling center operator, disclosed a potential payment card data breach on a Friday in January 2017. The incident impacted 21 of the company's 300+ U.S. locations across 12 states, with confirmed malware presence on point-of-sale systems between February 4 and March 19, 2017. The malicious software specifically targeted payment card information processed through affected computers during this seven-week period. Security personnel discovered the data-snatching malware during routine system monitoring, though the exact intrusion method remained unspecified in public disclosures. No evidence suggested broader corporate network compromise beyond the 21 identified bowling centers. The company initiated forensic investigations upon detection to assess data exposure scope and malware functionality.

Three affected Virginia locations included AMF Sunset Lanes in Henrico County's West Broad Street, AMF Dale City Lanes in Woodbridge, and AMF Hilltop Lanes in Roanoke. Bowlmor AMF's public notification occurred approximately ten months after the malware's earliest known activation date, though the disclosure timeline relative to internal discovery remained unclear. The breach window indicated continuous malware operation across multiple weekends and holiday periods when bowling centers typically experience high transaction volumes. Forensic analysis confirmed the malware's design focused on capturing payment card details during processing, but the company did not specify whether customer names, PINs, or other personal identifiers were compromised. No quantitative estimates of affected customers or fraudulent activity traces were included in the initial breach notification.

Sources

Sources available to members: 1 source.

CSIDB