
DUBLIN, OHIO – Some Wendy’s restaurants have been the victim of malicious cyber activity targeting customers’ payment card information, and Iowa is on the list of places it could have happened.
The company first reported unusual payment card activity affecting some franchise-owned restaurants in February 2016. Subsequently, on June 9, 2016, the Company reported that an additional malware variant had been identified and disabled. Today, the company, on behalf of affected franchise locations, is providing information about specific restaurant locations that may have been impacted by these attacks, all of which are located in the U.S., along with support for customers who may have been affected by the malware variants.
The Company believes this criminal cyberattack resulted from a service provider’s remote access credentials being compromised, allowing access – and the ability to deploy malware – to some franchisees’ POS systems. Soon after detecting the malware, Wendy’s identified a method of disabling it and thereafter has disabled the malware in all franchisee restaurants where it has been discovered. The investigation has confirmed that criminals used malware believed to have been effectively deployed on some Wendy’s franchisee systems starting in late fall 2015.
“We are committed to protecting our customers and keeping them informed. We sincerely apologize to anyone who has been inconvenienced as a result of these highly sophisticated, criminal cyberattacks involving some Wendy’s restaurants,” said Todd Penegor, President and Chief Executive Officer. “We have conducted a rigorous investigation to understand what has occurred and apply those learnings to further strengthen our data security measures.”
The potentially affected sites are organized by state and Iowa was one of them. If you made a purchase using a payment card at one of the listed restaurants during the relevant timeframe, your information may have been affected.
However, the company has so far failed to list all the exact sites where the breaches occurred; the site says “SITE LIST COMING SOON”.
For Iowa residents, you may obtain information about preventing and avoiding identity theft from the Iowa Attorney General’s Office, whose contact information is as follows:
- Iowa Attorney General’s OfficeDirector of Consumer Protection Division
1305 E. Walnut Street
Des Moines, IA 50319
(515) 281-5926
Here is a link to the website to check. Mason City is not currently on the list.
https://payment.wendys.com/paymentcardcheck.html