Original Release Date: 12/30/2019
Point-of-sale (POS) malware was found on Wawa’s payment processing systems on December 10, 2019 and is believed to have first been installed on March 4, 2019. The malware collected payment data such as credit and debit card numbers, expiration dates, and cardholder names but did not collect debit card PIN numbers, credit card CVV2 numbers, or driver’s license information. ATM transactions were unaffected. Wawa released a data breach letter regarding the incident.