Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - US Fast Food Chain, Wendy’s Investigating PoS Breach
News & Analysis

US Fast Food Chain, Wendy’s Investigating PoS Breach

ISBuzz TeamBy ISBuzz TeamJanuary 29, 2016Updated:December 4, 20243 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Wendy's Investigating PoS Breach
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Krebs on Security is reporting that US chain of fast food burger restaurants, Wendy’s, is investigating claims of a possible credit card breach at some locations. The acknowledgment comes in response to questions from KrebsOnSecurity about banking industry sources who discovered a pattern of fraud on cards that were all recently used at various Wendy’s locations. Security experts from VASCO Data Security, Lastline, Tripwire, STEALTHbits Technologies and InfoArmor have the following comments on it.

[su_note note_color=”#ffffcc” text_color=”#00000″]Travis Smith, Senior Security Research Engineer at Tripwire :

“Cyber criminals continue to feast on point of sale devices.  The primary function of these computers and networks are to process customer orders as quickly as possible.  Security is often an afterthought which is added on later.  Although details of the Wendy’s breach are not yet publicly known , there are some quick steps that organizations with point of sale devices can take to protect their customers with little to no cost.

Most of the credit card stealing malware sends the customer card data to a location on the Internet.  Lock down the point of sale devices to prevent them from accessing the Internet.  Second, these devices typically are little to no change outside of known Windows.  Monitoring for changes to the devices can alert the staff to take appropriate steps to contain a possible breach before it spreads.”[/su_note]

[su_note note_color=”#ffffcc” text_color=”#00000″]John Gunn, Vice President of Communications, VASCO Data Security:

“You can expect that the breach will be massive when it is ultimately disclosed. It is very easy for hackers to rapidly scale an attack, so whatever vulnerability or security weakness they exploited was undoubtedly quickly applied in attacks nationwide.

“You can see an unfortunate pattern here where retail firms are making a large investment in IT security forensics after a breach has occurred, instead of investing in prevention beforehand.

“Consumers are perhaps too fast with their forgiveness. Home Depot and Target now have significantly higher market values than before their infamous data breaches. The surveys that show consumers will not do business with a retailer that loses their data are wildly inaccurate.”[/su_note]

[su_note note_color=”#ffffcc” text_color=”#00000″]Giovanni Vigna, Co-Founder & CTO, Lastline:

“It is very challenging to protect a large distributed system with thousands of location, each with multiple POS devices. Certain attacks, such as POS malware, can be prevented using state-of-the-art malware detection systems, but it is much more difficult to control physical processes and devices.”[/su_note]

[su_note note_color=”#ffffcc” text_color=”#00000″]Jeff Hill, Channels Manager, STEALTHbits Technologies:

“The breach at Wendy’s is yet another example of how effective and difficult-to-detect today’s cyber threats can be.  Like many other breaches, it was discovered not by the company’s internal security team, but rather an outside entity, in this case, credit card fraud algorithms that detected the anomalous use of the card numbers after they’d been stolen.  The challenge posed by the current generation of cyber criminals is by no means unique to Wendy’s.  The bottom line is that it’s extraordinarily difficult to detect a well-designed attack with a patient criminal at the controls.”[/su_note]

[su_note note_color=”#ffffcc” text_color=”#00000″]Andrew Komarov, Chief Intelligence Officer, InfoArmor:

“Point-of-Sales infections are a very visible trend that’s taken off over the past few years. Keeping in mind that traditionally, big corporations and retailers use franchised-based models, in many cases their security in different branches is absolutely decentralized on practice. This allows bad actors to take advantage of such insecurities and successfully distribute malware on terminals in order to collect Track 2 data, and to perform intrusions into their targeted networks for data exfiltration.”[/su_note]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Roundcube RCE Vulnerability Disclosed Early Amid Active Exploitation

June 10, 20255 Mins Read

Fake Indian Government Portal Used to Spread Cross-Platform Malware in Suspected APT36 Campaign

May 13, 20253 Mins Read

New Federal Alert Warns U.S. Businesses of Medusa Ransomware Surge

March 13, 20254 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}