05-27-2017, 11:06 AM
An update to this thread a month ago, Chipotle has updated their previous PSA from "certain Chipotle restaurants" to "most Chipotle restaurants".
http://www.reuters.com/article/us-chipot...SKBN18M2BY
Read more: http://www.nasdaq.com/article/chipotle-s...z4iHB4efiZ
http://www.reuters.com/article/us-chipot...SKBN18M2BY
Chipotle is not offering credit monitoring or notifying affected customers directly, as many other chains have in the past. A handful of Canadian restaurants were also hit.
"Credit monitoring is only designed to let you know when someone is opening a new credit account using your information. Credit monitoring does not alert you when a fraudulent charge is made on a payment card," Arnold said. He also said that Chipotle could not alert customers directly as it did not collect their names and mailing addresses at the time of purchase. The company said it had posted a notification on the Chipotle and Pizzeria Locale websites and issued a press release to make customers aware of the incident.
Linn Freedman, an attorney at Robinson & Cole LLP specializing in data breaches, said Chipotle was putting the burden on the consumer to discover possible fraudulent transactions by notifying them through the websites. "I don't think you will get to all of the customers who might have been affected," she said.
Read more: http://www.nasdaq.com/article/chipotle-s...z4iHB4efiZ