17 ms·
Chipotle Reports Findings from Investigation of Payment Card Security Incident
- frikk 9y agoMy area was hit, and I did get hit with credit card fraud. I suspected a different vector (shady medical vendor and coincidental timing). The card that got hit was indeed used at Chipotle, but a week after the supposed "time range" indicated on the security site. Maybe the time range isn't absolute.
- tyingq 9y agoTypically, the hackers that get the data sell it off, versus using it personally. That can take a while.
- frikk 9y agoI just mean that I didn't use my card during the time period, but a week later.
- heartbreak 9y agoI used my card multiple times at multiple affected locations in four states, and I haven't seen any fraud on the card. Just a datapoint. Perhaps yours really was that shady medical provider.
- shoover 9y agoWhat was that thing? It looks like all the stores in my area were hit.
- mark_element 9y agoAgreed. Looks like this a big deal™. Would love to know the method of spreading across all their point of sales, were they running on windows?
- bhhaskin 9y agoA ton of POS systems run on windows. Most on windows xp embedded
- heywire 9y agoIn the industry I am in (mostly grocery, convenience, some specialty retail), most have moved to at least POSReady 7, and some are looking at Windows 10, though there are other concerns with PCI compliance there. Most of the large retailers are pretty good about keeping these things away from the general Internet, but once an attacker is in your network, most bets are off. The most important thing to do is to look for retailers who are using the standalone pinpad devices (i.e., they don't take your card and swipe it in the keyboard or on the display). These standalone devices encrypt card data before that Windows-based point-of-sale ever sees it. You can't steal card data from a POS which never sees card data.
- shoover 9y ago> Windows 10 I'd be worried about the system rebooting to do a system update while I turn my back for a minute to help a customer.
- heywire 9y agoDomain credentials, an understanding of the IP or hostname scheme and a simple batch file could distribute something like this pretty easily, provided the proper controls aren't in place.
- adjkant 9y agoI checked my home and all of the places where I know Chipotle is at in 4 different states. Every single one was on there. Would be nice if they said what percentage of stores were hit. The language implies a minority, but this looks like it could be most of them.
- heywire 9y agoIn the past there have been a mix of "off-the-shelf" memory scrapers as well as custom written targeted malware. Generally they'll get inside the network and push out an exe/dll to all of the POS machines from some compromised machine. Depending on how locked down the POS machines are, there are various methods for either getting read access to the POS application process memory or having the dll injected into its memory. From there they find a way to extricate the data, either manually or automatic, depending on how locked down the network is. Application whitelisting solutions can really help block this kind of attack, but they're not perfect either. If an attacker can figure out how to get root on the machines, game over. This is why stand alone point-to-point encrypted EMV card readers are the way to go. You can't scrape the process memory for data it doesn't have, and the card readers themselves are pretty tamper resistant (if you don't count external skimmers)
- heywire 9y agoHopefully this pushes more and more restaurants towards using separate chip-reader (EMV) pinpad devices. I've noticed several area restaurants switching lately (Arby's, Wendy's), and I hope it continues. These devices use point-to-point encryption, meaning that even if the POS machine is comprimised, no sensitive card data can be stolen. The POS machine never sees raw card data.
- toomuchtodo 9y agoWould you suggest reporting a card lost to get a new number issued if it was used at one of these locations?
- heywire 9y agoDefinitely if you used a debit card, since it could take a couple days to get any fraudulent charges reversed. Probably less important if you used a credit card, since you'll not have to pay for those charges and they'll just send you a new card at that point. I guess it just depends on if you want to be inconvenienced now or later :) I personally used my credit card at one of the affected stores, and I do not plan on calling in to have my card number changed. I'll just keep a close eye on my statements (that, and I have alerts sent to my phone via SMS for any charge over $0.01, so I'd know pretty quickly)
- toomuchtodo 9y agoI have an Amex charge card with push notifications, so I'm going to let it ride. Thank you for the reply!
- heywire 9y agoAmex is probably the company I'd trust the most to handle the situation. I've never been let down by their customer service.
- mmanfrin 9y agoChipreaders are terribly slow, I don't understand how they could not develop a secure payment system without 10-second~ delay times. My local grocery store installed new chip readers and within a week had taped over time in favor of the more-expensive but quicker stripe processing.
- icelancer 9y agoWhy is there no legal recourse here outside of spending my own time/resources to cancel cards and deal with all the BS that occurs with that whenever this happens? There should be financial repercussions, each affected individual should be awarded monetary compensation for their time.
- brians 9y agoYou agreed not to get that when you got the card. And they agreed to pay you any money damages without arguing much. It's a good deal, but you can choose to use cash if you pref
- icelancer 9y agoNot the card issuer. Chipotle.
- ryanlol 9y agoWhy do you need to cancel your cards?
- icelancer 9y agoIf card data was stolen.
- pasbesoin 9y agoAnyone have the whole list? (I hate enforced drill-down selection for such things.) How many locations?
- heywire 9y agoA quick look at the chrome dev tools will point to a us.json which has what you're looking for.
- pasbesoin 9y agoThank you.
- bpicolo 9y agoThat's a massive list. 2249 restaurants.
- acemv 9y agoI am appalled at the attempt by Chipotle to downplay the scope and scale of the incident. The sentence which reads, " Not all locations were involved, and the specific time frames vary by location", is a blatant attempt to deflate the significance of the problem. This public disclosure should have been more direct, and disclose in plain language the number of stores affected. Chipotle should explain the full impact in plain language: "2,249 out of X,XXX Chipotle restaurants were compromised."
- nandhp 9y agoWell, they basically have no idea -- it says in bold letters "Please note that not all locations were identified." For reference, Wikipedia claims Chipotle has 3,010 restaurants. So at least 75%.
- pasbesoin 9y agoThey are international now, right? I at least think I have memory of running across them in Canada. The file name in question (thanks, heywire) is "us.json". I'm left wondering whether and how much of an international scope there might be to this. While the version of their web site that I'm receiving by default seems to be geo-centric to the U.S. and doesn't mention foreign locations, Wikipedia has: https://en.wikipedia.org/wiki/Chipotle_Mexican_Grill https://en.wikipedia.org/wiki/Chipotle_Mexican_Grill Chipotle Mexican Grill, Inc. (/tʃᵻˈpoʊtleɪ/)[6] is an American chain of fast casual restaurants in the United States, United Kingdom,[7] Canada,[8][9] Germany,[10] and France
- Splendor 9y agoNo doubt the timing of releasing this news on the holiday weekend was deliberate; intended to reach as few people as possible.
- gnicholas 9y ago> The malware searched for track data (which sometimes has cardholder name in addition to card number, expiration date, and internal verification code) ... There is no indication that other customer information was affected. What other customer information could have been affected? Kudos on the masterful PR spin — I guess by now Chipotle has had a lot of practice at this...
- torturedcardboy 9y agoJust because someone is forcing you use the chip DOES NOT MEAN THAT IT'S AN EMV TRANSACTION There is no way too know if you are actually doing and EMV transaction. The EMV spec has nothing at all to do with security. PCI controls security. I can read the card data via the chip and it's all in the clear. EMV is about process integrity, and the integrity testing is ridiculous. Chip cards are harder to forge, but that's about it. The new rules about liability puts the liability for processing a forged card on the merchant, if the transaction isn't done with EMV.
- heywire 9y agoAre you saying that you know of systems which use the tag 57 (track 2 equivalent data) to read an EMV chip and process the transaction manually? I'd be surprised if most banks would even approve those transactions (no CVV/CVV2, etc).
- robbiemitchell 9y agoHere's a list of all US locations affected: https://docs.google.com/spreadsheets/d/1_lFhMPaRBn8JbqxR9rEqRgtezp3wM9ZPF-23Z-NomDU/edit?usp=sharing https://docs.google.com/spreadsheets/d/1_lFhMPaRBn8JbqxR9rEq...