Earl of Sandwich and Planet Hollywood restaurant franchise owner admits a breach of its PoS systems where 2M+ credit and debit card details may have been stolen
Brian Krebs / Krebs on Security :
Context & Ripple Effects
Krebs on Security's disclosure that the franchise operator behind Earl of Sandwich and Planet Hollywood lost 2M+ card details to PoS malware slots into a well-documented crime pattern rather than standing alone: Hyatt disclosed malware across some 300 hotels in 54 countries back in 2016, and Staples detailed 115 stores and 1.16M compromised cards in 2014. The common thread is memory-scraping malware on point-of-sale terminals at high-volume, low-margin food and retail chains.
What makes this installment notable is scale relative to the brand footprint — a single franchise owner accounting for a seven-figure card exposure — and that Krebs' sourcing has repeatedly preceded larger dumps, as when his reporting foreshadowed the 5.3M-account dump tied to Hy-Vee gas pumps, coffee shops, and restaurants months later.
First-order effects
- Cardholders who paid at affected Earl of Sandwich and Planet Hollywood locations face fraud risk on those cards, while issuing banks bear the immediate cost of monitoring, reissuing, and reimbursing fraudulent charges.
- The franchise owner must run forensic investigation, card-brand notification, and potentially indemnification obligations under PCI and network rules — costs that land on a franchisee rather than the brand licensor.
Second-order effects
- Stolen tracks from restaurant PoS breaches feed dedicated fraud marketplaces — the same pipeline that later surfaced 3M+ Dickey's Barbecue Pit cards for sale — so this breach's data likely becomes inventory for carding shops, driving downstream counterfeit-card losses.
- Acquiring banks and card networks respond by pressuring hospitality merchants toward terminal-level encryption and EMV compliance, raising equipment and integration costs for small franchise operators already operating on thin margins.
Third-order effects
- If the pattern holds — Hyatt, Staples, Earl of Sandwich/Planet Hollywood, Hy-Vee, Dickey's — PoS malware becomes a recurring tax on franchised food and hospitality, accelerating consolidation around payment platforms with point-to-point encryption baked in rather than bolt-on terminals.
- Breach-by-breach disclosure normalizes a liability structure where franchisees absorb the security debt of legacy PoS estates, sharpening the split between brands that mandate modern payment infrastructure and those that leave it to individual operators.
The trend: Point-of-sale malware against restaurant and retail chains is settling into a chronic, industrialized breach category whose real fix — encrypted card data at the terminal — is being forced on merchants one disclosure at a time.