Two men admit to $10 million hacking spree on Subway sandwich shops
The Romanians admitted their role in ring that compromised some 146,000 cards. — Two Romanian men have admitted to participating in an international conspiracy that hacked into credit-card payment terminals …
Context & Ripple Effects
This plea closes a chapter that opened last December, when Ars Technica detailed how hackers gave Subway a $3 million lesson in point-of-sale security — a breach of the chain's franchise payment terminals that at the time stood as one of the largest PoS compromises disclosed. The two Romanian defendants' admissions confirm the scale: roughly 146,000 compromised cards and about $10 million in losses.
The story's travel is notable for a criminal-justice item — the Associated Press and Computerworld both carried it alongside Ars Technica, reflecting how franchise point-of-sale breaches had become mainstream news by late 2012 rather than a trade-press curiosity.
First-order effects
- The two men now face sentencing exposure in a US court for an admitted international conspiracy, while Subway's corporate network absorbs renewed scrutiny over how its independently operated franchise terminals were compromised at this scale.
- Issuers holding the 146,000 affected cards carry reissue and fraud-loss costs, and acquirers serving Subway franchisees face chargeback fallout from the $10 million in fraudulent transactions.
Second-order effects
- Franchisors across fast food now confront the structural weakness the case exposed: thousands of individually owned stores running payment terminals outside direct corporate control, pushing brand owners toward mandated terminal upgrades and tighter PCI DSS enforcement on franchisees.
- Payment processors and POS vendors gain a sales argument for encrypted or tokenized card readers aimed at small merchants, who otherwise bear breach costs they cannot absorb.
Third-order effects
- If the pattern holds, franchise restaurant chains will consolidate payment security centrally — validating devices, segmenting networks, and standardizing terminals — because the Subway case shows the weakest franchisee store sets the brand-wide risk floor.
- Internationally sourced crews hitting US retail PoS systems also pressure US authorities to keep pursuing cross-border prosecutions, making extradition and joint operations a recurring cost of card-fraud policing.
The trend: Point-of-sale malware against franchise retail chains is hardening into a repeatable criminal business model, with prosecutions like this one marking the start of a sustained cat-and-mouse over payment-terminal security.