Restaurant chain Checkers says hackers breached its systems to install malware on PoS systems across 102 stores between December 2015 and April 2019
The popular Checkers and Rally's drive-through restaurant chain was attacked by Point of Sale (POS) malware impacting 15 percent of its stores across the U.S.
Context & Ripple Effects
Checkers and Rally's is disclosing that attackers planted PoS malware across 102 U.S. stores — about 15% of its footprint — and that it went undetected from December 2015 to April 2019, a dwell time measured in years rather than weeks. The disclosure lands two months after the Earl of Sandwich and Planet Hollywood franchisee admitted its own PoS breach, where more than 2 million card details were potentially stolen.
The pattern is well established by now: Hilton eradicated similar PoS malware in late 2015 after roughly a year of collection, and later in 2019 a [[a:945125|5.3M-card dump was linked to compromised gas pumps, coffee shops, and restaurants run by Hy-Vee]]. Restaurant and hospitality PoS estates are being harvested as a category, not hit one-off.
First-order effects
- Customers who paid at any of the 102 affected Checkers and Rally's locations during the three-and-a-half-year window face potential card-data theft, and the chain now carries breach-response costs and disclosure obligations across 15% of its U.S. store base.
- Card issuers and payment networks must identify exposed accounts from the affected terminals and decide on reissuance, absorbing fraud losses for transactions that may date back to December 2015.
Second-order effects
- Rival restaurant chains — including the franchisee behind Earl of Sandwich and Planet Hollywood, which disclosed a comparable breach earlier in 2019 — face pressure to audit their own PoS fleets and harden terminal software before regulators or card brands force the issue.
- PoS vendors and payment processors gain leverage to sell encryption-at-the-terminal and tokenization upgrades, since every new disclosure like Checkers' reprices the risk of legacy swipe-based setups.
Third-order effects
- If multi-year dwell times keep recurring across franchised restaurants and hotels, liability will keep migrating toward whoever controls the terminal estate — pushing chains toward centrally managed, encrypted PoS platforms and away from store-level autonomy over payments hardware.
- A sustained cadence of these disclosures gives card networks and state regulators grounds to mandate stronger authentication at the point of sale, turning what is now a reputational cost into a compliance requirement.
The trend: Restaurant and hospitality chains are disclosing PoS malware campaigns with multi-year undetected dwell times, making card-data harvesting at the point of sale a structural, industry-wide problem rather than isolated incidents.