Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Incident Response

P.F. Chang’s Provides Data Breach Update, Confirms Compromised Locations

P.F. Chang’s China Bistro has been investigating a breach involving its payment card processing system since the US. Secret Service alerted the company of a possible compromise back on June 10, 2014.

P.F. Chang’s China Bistro has been investigating a breach involving its payment card processing system since the US. Secret Service alerted the company of a possible compromise back on June 10, 2014.

 While the investigation is ongoing, the restaurant chain said on Monday that the security compromise has been contained, and that P.F. Chang’s has been “processing credit and debit card data securely” since June 11, 2014.

“We have determined that the security of our card processing systems was compromised, and we have reason to believe that the intruder may have stolen some data from certain credit and debit cards that were used during specified time frames at 33 P.F. Chang’s China Bistro branded restaurant locations in the continental United States,” Rick Federico CEO of P.F. Chang’s wrote in a statement issued Monday. “The potentially stolen credit and debit card data includes the card number and in some cases also the cardholder’s name and/or the card’s expiration date. However, we have not determined that any specific cardholder’s credit or debit card data was stolen by the intruder.”

The company also provided a list of the 33 restaurant locations from which they believe credit and debit card data may have been compromised, along with a time frame during which cards used at those locations may have been at risk.

On June 13, the company said that it temporarily ditched its electronic Point-of-Sale System in favor of old-school “imprinting devices” to process payments while the company gets the situation under control and understands the scope of the attack. “All P.F. Chang’s China Bistro branded restaurants in the continental U.S. are using manual credit card imprinting devices to handle our credit and debit card transactions,” the company said at the time.

According to P.F. Chang’s, certain cards used at the following restaurant locations during the dates listed may have been compromised:

Address City State Dates  
7135 E. Camelback Rd. Scottsdale AZ 10/19/2013 – 6/11/2014
2015 Birch Road Chula Vista CA 10/19/2013 – 6/11/2014
3525 Carson St. Torrance CA 10/19/2013 – 6/11/2014
436 North Orlando Avenue Winter Park FL 10/19/2013 – 6/11/2014
125 Westchester Avenue White Plains NY 10/19/2013 – 6/11/2014
10 Providence Town Center Collegeville PA 10/19/2013 – 6/11/2014
2110 Hamilton Place Blvd. Chattanooga TN 10/19/2013 – 6/11/2014
15151 Potomac Town Place Woodbridge VA 10/19/2013 – 6/11/2014
16170 N. 83rd Ave. Peoria AZ 2/21/2014 – 6/11/2014
5621 Paseo Del Norte Carlsbad CA 2/21/2014 – 6/11/2014
3101 PGA Boulevard Palm Beach Gardens FL 2/21/2014 – 6/11/2014
1295 Chesterfield Parkway East Chesterfield MO 2/21/2014 – 6/11/2014
6801 Fayetteville Rd Durham NC 2/21/2014 – 6/11/2014
3545 US Highway 1 Princeton NJ 2/21/2014 – 6/11/2014
2626 Miamisburg-Centerville Rd. Dayton OH 2/21/2014 – 6/11/2014
1978 E. 21st Street Tulsa OK 2/21/2014 – 6/11/2014
40762 Winchester Road Temecula CA 4/10/2014 – 6/11/2014
900 Stanford Shopping Center Palo Alto CA 4/10/2014 – 6/11/2014
15301 Ventura Boulevard Sherman Oaks CA 4/10/2014 – 6/11/2014
7870 Monticello Ave. Rancho Cucumonga CA 4/10/2014 – 6/11/2014
7210 W. Alameda Ave Lakewood CO 4/10/2014 – 6/11/2014
27001 US Highway 19 N, Ste #1150 Clearwater FL 4/10/2014 – 6/11/2014
5 Woodfield Mall Schaumburg IL 4/10/2014 – 6/11/2014
600 E. Pratt Street Baltimore MD 4/10/2014 – 6/11/2014
25 The Boulevard Saint Louis St. Louis MO 4/10/2014 – 6/11/2014
3667 Las Vegas Boulevard South Las Vegas NV 4/10/2014 – 6/11/2014
1600 Settlers Ridge Center Dr; Bldg. 1300 Pittsburgh PA 4/10/2014 – 6/11/2014
983 Baltimore Pike Glen Mills PA 4/10/2014 – 6/11/2014
10114 Jollyville Road Austin TX 4/10/2014 – 6/11/2014
525 Bellevue Square Bellevue WA 4/10/2014 – 6/11/2014
3000 184th St. Lynnwood WA 4/10/2014 – 6/11/2014
1145 Newport Center Drive Newport Beach CA 10/19/2013 – 4/10/2014
10325 Perimeter Parkway Charlotte NC 10/19/2013 – 10/26/2013
Written By

For more than 15 years, Mike Lennon has been closely monitoring the threat landscape and analyzing trends in the National Security and enterprise cybersecurity space. In his role at SecurityWeek, he oversees the editorial direction of the publication and is the Director of several leading security industry conferences around the world.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Cody Barrow has been appointed as CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

Attack detection firm Vectra AI has appointed Jeff Reed to the newly created role of Chief Product Officer.

More People On The Move

Expert Insights

Related Content

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

Data Breaches

LastPass DevOp engineer's home computer hacked and implanted with keylogging malware as part of a sustained cyberattack that exfiltrated corporate data from the cloud...

Incident Response

Microsoft has rolled out a preview version of Security Copilot, a ChatGPT-powered tool to help organizations automate cybersecurity tasks.

Data Breaches

GoTo said an unidentified threat actor stole encrypted backups and an encryption key for a portion of that data during a 2022 breach.

Application Security

GitHub this week announced the revocation of three certificates used for the GitHub Desktop and Atom applications.

Incident Response

Meta has developed a ten-phase cyber kill chain model that it believes will be more inclusive and more effective than the existing range of...

Cloud Security

VMware described the bug as an out-of-bounds write issue in its implementation of the DCE/RPC protocol. CVSS severity score of 9.8/10.