Earl of Sandwich and Planet Hollywood restaurant franchise owner admits a breach of its PoS systems where 2M+ credit and debit card details may have been stolen
Brian Krebs / Krebs on Security :
Context & Ripple Effects
Krebs on Security's disclosure that the Earl of Sandwich and Planet Hollywood franchise owner lost 2M+ payment cards from its PoS systems is one entry in a long-running pattern he has documented: Hyatt's 300-hotel malware infection in 2016, Staples' 115-store breach in 2014, and later the 5.3M-card dump tied to Hy-Vee gas pumps and restaurants. Each case follows the same shape — malware planted at the point of sale harvesting track data in bulk.
What makes this disclosure notable is scale relative to brand footprint: a single franchise operator spanning two national restaurant brands now sits in the same tier of exposure as national chains, and the stolen data feeds the same fraud-marketplace supply chain that later surfaced Dickey's Barbecue Pit's 3M+ stolen cards.
First-order effects
- Cardholders who ate at affected Earl of Sandwich or Planet Hollywood locations face immediate fraud risk on their accounts, forcing issuing banks into reissue-and-monitor cycles.
- The franchisor brands absorb reputational damage for a security failure they did not directly control, since the compromised systems belonged to the franchise operator.
Second-order effects
- Other restaurant and hotel franchisors are pushed to audit franchisee PoS environments, because a single operator's lapse becomes a brand-wide liability.
- Fraud marketplaces gain fresh bulk card inventory, sustaining the resale economics that make PoS malware campaigns profitable enough to repeat.
Third-order effects
- If franchise operators keep proving to be the weakest link, payment security obligations will migrate up the franchise contract — pushing chains toward standardized, centrally managed PoS terminals rather than operator-owned systems.
- The steady drumbeat of multi-million-card breaches strengthens the case for card networks and regulators to mandate end-to-end encryption or tokenization at the terminal, shrinking the value of harvested track data.
The trend: Hospitality and retail chains remain the recurring source of bulk payment-card theft through PoS malware, with franchise structures repeatedly turning one operator's compromise into a brand-scale incident.