Sonic Confirms Data Breach

QSR says that attack has left some customer credit and debit card numbers at risk.

September 28, 2017

NEW YORK – The Wall Street Journal reports that drive-in fast-food chain Sonic has confirmed that its credit-card processor notified the company last week of unusual activity with cards that had been used at Sonic locations.

Krebsonsecurity.com, which first reported the breach earlier this week, says on its website that Oklahoma City-based Sonic has nearly 3,600 locations in 45 states, and that the data breach may have led to a “fire sale on millions of stolen credit and debit card accounts that are now being peddled in shadowy underground cybercrime stores.”

Krebs says he began hearing from sources at multiple financial institutions last week who noticed a pattern of fraudulent transactions on cards that had all previously been used at Sonic. He directed several of those sources to look at a new batch of about five million credit and debit card accounts put up for sale on Sept. 18 in a credit card theft bazaar called Joker’s Stash. “Sure enough, two sources who agreed to purchase a handful of cards from that batch of accounts on sale at Joker’s discovered they all had been recently used at Sonic locations,” he says.

Christi Woodworth, vice president of public relations at Sonic, told Krebs that the investigation is in its early stages, and that the company does not yet know how many or which of its stores may be impacted. Per a company statement: “We are working to understand the nature and scope of this issue, as we know how important this is to our guests. We immediately engaged third-party forensic experts and law enforcement when we heard from our processor. While law enforcement limits the information we can share, we will communicate additional information as we are able.”

The Journal notes that accounting firm Deloitte also acknowledged this week that it was the target of a data breach, saying a hacker accessed data of “a few” of its clients.

Advertisement
Advertisement
Advertisement