Breach report
RetailWawa
Wawa Breach May Have Compromised More Than 30 Million Payment Cards
Malware on payment systems at Wawa's roughly 850 convenience stores and gas stations captured card data for about nine months in 2019, and weeks after disclosure a batch billed as more than 30 million cards went on sale on a criminal marketplace.
Reported by Krebs on Security
Records exposed
30M
More than 30 million payment cards (estimated)
Scale vs. largest on file
- When
- 2019
- How they got in
- Point-of-sale malware on in-store registers and fuel dispensers
- Sector
- Retail
On December 19, 2019, Wawa, the Pennsylvania-based chain of convenience stores and gas stations, announced that malware had been found on its payment processing systems. The company said the malicious software had begun running at different points starting around March 4, 2019, and had reached most of its roughly 850 locations by April, infecting in-store registers and fuel dispensers. Wawa's security team discovered the malware on December 10 and said it was contained two days later.
According to Wawa, the malware captured payment card numbers, expiration dates and cardholder names from cards used during the affected period. The company said debit card PINs, card security codes and other personal information were not exposed, and that its ATM cash machines were not involved. Chief executive Chris Gheysens published an open letter apologizing to customers and offered free credit monitoring and identity theft protection.
Weeks later, the scale of the theft became clearer. In late January 2020, security journalist Brian Krebs and fraud intelligence firm Gemini Advisory reported that Joker's Stash, then one of the largest underground marketplaces for stolen card data, had begun selling a batch labeled BIGBADABOOM-III. The sellers claimed it contained more than 30 million card records from a new nationwide breach, and analysts tied the cards to Wawa based on where they had been used, with heavy concentrations in Pennsylvania and Florida.
The breach led to lawsuits from consumers and from banks and credit unions that had to reissue cards, as well as scrutiny from state attorneys general. Wawa settled the consumer class action with an offer of gift cards and reimbursement for documented losses, reached a separate settlement with financial institutions and later agreed to a multistate settlement with attorneys general that required it to strengthen its payment security.
The Wawa incident was among the largest card breaches of its period and highlighted the particular exposure of fuel pumps, which in the United States lagged behind other terminals in adopting chip-based payment readers. It also showed that point-of-sale malware remained effective against retailers years after the Target and Home Depot breaches. For consumers, the case illustrated why monitoring statements and using contactless or mobile wallets, which transmit one-time tokens instead of card numbers, can limit the damage of such attacks.