Menu
Browse

Cyber Incident Victim: PDQ

Date:

May 2017

Location:

United States of America

Summary

A fast-casual restaurant chain experienced a cyber attack compromising customers' credit card information during payment transactions at multiple locations. The breach persisted for nearly a year before being discovered, with attackers gaining unauthorized access to payment systems. The establishment publicly disclosed the incident via its website, confirming that hackers acquired or accessed personal data from card-paying patrons. The compromised information included sensitive financial details used at affected outlets during the intrusion period.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

PDQ, a fast-casual restaurant chain operating multiple locations in North Carolina's Triangle region, publicly disclosed a cybersecurity incident involving unauthorized access to customer payment card data. The breach spanned nearly eleven months, with attackers compromising systems between May 19, 2017, and April 20, 2018. Hackers successfully accessed or acquired personal information belonging to customers who made credit card purchases at affected establishments during this period. The company confirmed the intrusion through forensic investigations but did not specify the exact number of impacted individuals or locations. PDQ issued a formal statement via its corporate website to notify the public about the data compromise approximately two months after containing the breach.

Cyber Incident Image

The incident exposed sensitive customer payment information, though the restaurant chain did not elaborate on specific data elements beyond confirming credit card details were targeted. No evidence suggested theft of other personal identifiers like Social Security numbers or addresses. PDQ initiated customer notifications in compliance with regulatory obligations but provided no details regarding complimentary credit monitoring services or financial remediation measures. The company's public disclosure occurred on June 22, 2018, when media outlets including WRAL reported the breach, citing the restaurant's official statement. Forensic investigations determined the intrusion timeframe but did not identify the attackers' methodologies or origins. The breach resolution involved securing affected systems by April 20, 2018, though PDQ did not describe specific containment measures or system modifications implemented post-incident.

Sources
Sources available to members
1 source