Krystal, a fast-food restaurant chain based in Atlanta, Georgia, informed customers recently that it has launched an investigation into a cybersecurity incident involving the payment processing systems used by some of its restaurants.
The investigation is ongoing, but so far the company has determined that one of the payment processing systems it uses may have been compromised.
“Krystal uses multiple payment processing systems and, as a result, not all Krystal restaurants have been impacted by this incident,” the company said.
Krystal has set up a webpage on its official website where it lists all the restaurants apparently affected by the incident. This page currently lists roughly 220 locations in Alabama, Arkansas, Florida, Georgia, Kentucky, Mississippi, North Carolina, South Carolina and Tennessee.
In a press release, the company said approximately a third of its locations do not appear to be impacted — Krystal has roughly 320 restaurants across 10 states.
Customers have been informed that the incident could impact payment cards used at affected locations between July and September 2019.
Law enforcement and payment card issuers have been notified of the incident. Until the investigation is completed, Krystal customers have been advised to keep an eye out for any suspicious activity on their cards.
Several major restaurant companies informed customers of payment card breaches in the past year, including Focus Brands (Moe’s, McAlister’s and Schlotzsky’s), Checkers Drive-In Restaurants, Earl Enterprises, Huddle House, Chili’s, Applebee’s, and Cheddar’s Scratch Kitchen.
Related: Buca di Beppo, Planet Hollywood Restaurants Hit by Card Breach
Related: Breach at PoS Firm Hits Hundreds of U.S. Restaurants, Hotels

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.
More from Eduard Kovacs
- Industrial Giant ABB Confirms Ransomware Attack, Data Theft
- Zyxel Firewalls Hacked by Mirai Botnet
- New Russia-Linked CosmicEnergy ICS Malware Could Disrupt Electric Grids
- Drop in Insider Breaches Drives Decline in Intrusions at OT Organizations
- Zero-Day Vulnerability Exploited to Hack Barracuda Email Security Gateway Appliances
- OAuth Vulnerabilities in Widely Used Expo Framework Allowed Account Takeovers
- New Honeywell OT Cybersecurity Solution Helps Identify Vulnerabilities, Threats
- Rheinmetall Says Military Business Not Impacted by Ransomware Attack
Latest News
- Industrial Giant ABB Confirms Ransomware Attack, Data Theft
- Organizations Worldwide Targeted in Rapidly Evolving Buhti Ransomware Operation
- Google Cloud Users Can Now Automate TLS Certificate Lifecycle
- Zyxel Firewalls Hacked by Mirai Botnet
- Watch Now: Threat Detection and Incident Response Virtual Summit
- NCC Group Releases Open Source Tools for Developers, Pentesters
- Memcyco Raises $10 Million in Seed Funding to Prevent Website Impersonation
- New Russia-Linked CosmicEnergy ICS Malware Could Disrupt Electric Grids
