The sandwich shops in Illinois, Jimmy Johns seem to have learned of the breach on July 30 and immediately hired security specialists to help with the investigation.
In July, Brian Krebs reported that multiple financial institutions had detected card frauds that had all been recently used at Jimmy Johns locations. He also noted that the stores use POS systems from the company Systems A.E. At that time, the breach was not confirmed. After almost two months, the company confirmed it.
According to the company's statement, hackers stole log-in credentials from the company that provided the POS and used them to gain access to Jimmy Johns' POS systems
Signature Systems also confirmed the breach and that the attackers obtained access to usernames and passwords used for remote access to the POS systems.
The attackers then installed malware designed to capture payment card data from cards scanned through the terminals.
The information, including the card number, verification code, expiration date, and the cardholder's name, is at risk. The company states that the information entered online, such as email addresses and passwords, is not affected.
The incident affects approximately 216 Jimmy Johns stores.

