Convenience store giant Wawa Inc. said Tuesday it is responding to reports that hacked information from its customers’ credit cards may be being sold on the dark web.
The company said in a news release that customers who may be affected can obtain free credit monitoring and identity theft protection.
Malware discovered last month affected payment card information and was contained within three days, Wawa said.
Cybersecurity firm Gemini Advisory said information from the Wawa theft began to show up for sale on the dark web this week. Gemini said the data breach ranks among the largest ever, potentially exposing 30 million sets of payment records.
The breach affected all of Pennsylvania-based Wawa’s stores, which stretch along the East Coast.
Police are investigating, and the company has said a forensics firm is conducting an internal investigation.
Related: U.S. Fast-Food Chain Krystal Investigating Payment Card Breach
Related: Malware Found on Payment System Used by On The Border Restaurants
Related: Church’s Chicken Restaurants Hit by Payment Card Breach

More from Associated Press
- Germany Appoints Central Bank IT Chief to Head Cybersecurity
- US Downs Chinese Balloon Off Carolina Coast
- Microsoft: Iran Unit Behind Charlie Hebdo Hack-and-Leak Op
- Feds Say Cyberattack Caused Suicide Helpline’s Outage
- Big China Spy Balloon Moving East Over US, Pentagon Says
- China Says It’s Looking Into Report of Spy Balloon Over US
- Russian Millionaire on Trial in Hack, Insider Trade Scheme
- US Infiltrates Big Ransomware Gang: ‘We Hacked the Hackers’
Latest News
- Germany Appoints Central Bank IT Chief to Head Cybersecurity
- OpenSSL Ships Patch for High-Severity Flaws
- Software Supply Chain Security Firm Lineaje Raises $7 Million
- ICS Cybersecurity Firm Opscura Launches With $9.4 Million in Series A Funding
- Vulnerability Provided Access to Toyota Supplier Management Network
- Patch Released for Actively Exploited GoAnywhere MFT Zero-Day
- Linux Variant of Cl0p Ransomware Emerges
- VMware Says No Evidence of Zero-Day Exploitation in ESXiArgs Ransomware Attacks
