/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Report: payment card details of 3M+ Dickey's Barbecue Pit customers, stolen in a POS breach between July 2019 and Aug. 2020, were posted on a fraud marketplace

Dickey's Barbecue Pit, the largest barbecue restaurant chain in the US, suffered a POS breach between July 2019 and August 2020.

ZDNet Catalin Cimpanu

Context & Ripple Effects

The Dickey's listing is the latest stop in a well-documented pipeline: mag-stripe data skimmed from restaurant POS systems surfaces weeks later on fraud bazaars. That is exactly how the related coverage played out before — the Wawa breach's 30M+ cards were listed on a fraud marketplace in January, and a 5.3M-card dump tied to Hy-Vee gas pumps and eateries followed the same route in 2019.

What distinguishes the Dickey's incident is duration: a 13-month collection window spanning July 2019 to August 2020 means compromised terminals sat inside the largest US barbecue chain through an entire pandemic year of shifted ordering patterns, echoing the franchise-model exposure seen when Earl of Sandwich and Planet Hollywood's franchise operator admitted a 2M+-card POS breach in early 2019.

First-order effects

  • Customers who paid at affected Dickey's locations during the 14-month window now face active card-fraud risk, pushing issuing banks toward reissuance and chargeback handling at scale.
  • Dickey's carries investigation, notification, and brand costs stretched across a franchised footprint, where individual operators — not just headquarters — own the compromised terminals.

Second-order effects

  • Payment processors and acquirers serving franchised restaurant brands face rising fraud losses from this merchant category, tightening security requirements and pricing for small franchise operators.
  • Rival franchise chains get a fresh compliance benchmark: after Wawa, Hy-Vee, and Earl of Sandwich, a fourth multi-million-card POS case makes terminal-level encryption audits a board-level item rather than an IT line item.

Third-order effects

  • If the breach-to-bazaar pattern holds, the structural fix is making captured card data inert at the point of sale — tokenization and end-to-end encryption shift from optional hardening to the default cost of operating a card-accepting franchise.
  • Fraud marketplaces functioning as a reliable monetization layer effectively set the disclosure clock for victims: chains learn of intrusions when their customers' cards are listed, compressing the gap between compromise and public knowledge.

The trend: US restaurant and convenience-chain POS intrusions are feeding an industrialized fraud-marketplace supply chain, turning each franchise breach into bulk card listings within weeks.

Discussion

  • @campuscodi Catalin Cimpanu on x
    156 of Dickey's 469 locations were impacted - this includes restaurants across 30 states - card data is now sold for $17 a pop - breach appears to have taken place between July 2019 and August 2020 - card data now sold on Joker's Stash https://www.zdnet.com/... https://twitter.co…