Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Wawa Agrees to Payment, Security Changes for ’19 Data Breach

A Pennsylvania-based convenience store chain will pay $8 million to several states over a 2019 data breach that involved some 34 million payment cards, authorities announced Tuesday.

A Pennsylvania-based convenience store chain will pay $8 million to several states over a 2019 data breach that involved some 34 million payment cards, authorities announced Tuesday.

The Pennsylvania attorney general’s office said Wawa Inc. did not take reasonable security measures to prevent hackers from installing malware that is thought to have collected card numbers, customer names and other data.

The company said in December 2019 that its information security team discovered the malware and two days later were able to stop the breach, which affected hundreds of Wawa locations along the East Coast, from Pennsylvania to Florida. In-store payments and payments at fuel dispensers were affected but ATM machines were not.

In a statement Tuesday, Wawa said it notified authorities, cooperated with investigators and has assisted those affected by the breach.

“From the outset, our focus has been to make this right for our customers and communities,” the company’s news release said. “We continue to take the necessary steps to safeguard our information security systems.”

Pennsylvania Attorney General Josh Shapiro said Wawa has agreed to new policies to toughen its security efforts to combat data breaches.

Advertisement. Scroll to continue reading.

The settlement was made with attorneys general in Delaware, Florida, Maryland, New Jersey, Pennsylvania Virginia, and Washington, D.C.

Related: T-Mobile Settles to Pay $350M to Customers in Data Breach

Related: Wawa Facing Lawsuits Over Data Breach

Written By

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice.

Register

Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.

Register

People on the Move

Lumen Technologies has named Kim Keever as CSO.

Quantum Secure Encryption Corp. has appointed Joseph Hall as CIO.

David Cass has joined Grayscale Investments as Chief Risk Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.