Whole Foods Market Payment Card
Investigation Update

California residents please click here.

AUSTIN, Texas (October 20, 2017) – Whole Foods Market has resolved the incident previously announced on September 28, 2017, involving unauthorized access of payment card information used at certain venues such as tap rooms and full table-service restaurants located within some stores. These venues use a different point of sale system than the company’s primary store checkout systems, and payment cards used at the primary store checkout systems were not affected. Whole Foods Market learned of the unauthorized access on September 23, 2017. The company conducted an investigation, obtained the help of a leading cyber security forensics firm, and contacted law enforcement. Whole Foods Market replaced these point of sale systems for payment card transactions and stopped the unauthorized activity. Whole Foods Market apologizes to customers for any inconvenience or concern this may have caused.

The investigation determined that unauthorized software was present on the point of sale system at certain venues. The software copied payment card information—which could have included payment card account number, card expiration date, internal verification code, and cardholder name—of customers who used a payment card at these venues at dates that vary by venue but are no earlier than March 10, 2017 and no later than September 28, 2017.

The Amazon.com systems do not connect to these systems at Whole Foods Market. Transactions on Amazon.com have not been impacted.

Whole Foods Market has been working closely with the payment card companies. Payment card network rules generally state that cardholders are not responsible for fraudulent charges that are reported in a timely manner. Customers should promptly report any unauthorized charges to the bank that issued their card. The phone number to call is usually on the back of the payment card.

Please see the section that follows this notice for additional steps you may take to protect yourself. The drop-down form below contains a list of the venues involved, although not all cards used at all venues listed were affected.

If you have any questions, please call 1-888-818-7100 Monday through Friday from 7:00 a.m. to 10:00 p.m. C.T., or Sunday and Saturday from 8:00 a.m. to 6:00 p.m. C.T.

Update - January 26, 2018 - The initial notification included a list of restaurant and taproom venues involved. After further analysis, the investigation determined that no venues were involved at six stores on the initial notification list, and that one venue that was not initially listed was involved. The venue added is the N4 restaurant and taproom at 238 Bedford Ave., Brooklyn, N.Y. 11249. The six stores that were removed are: 600 H St. NE, Washington, D.C.; 2748 Green Bay Rd., Evanston, Ill.; 81 S. Elliot Rd., Chapel Hill, N.C.; 1255 Raritan Rd., Clark, N.J.; 270 Greenwich St., New York, N.Y.; 11 S. State St., Lake Oswego, Ore.

Venues That Relate To This Notification

This list is updated to include only those venues potentially affected.

Store Name Address Venues

More Information On Ways to Protect Yourself

We remind you to remain vigilant for incidents of fraud or identity theft by reviewing your account statements and free credit reports for any unauthorized activity. You may obtain a copy of your credit report, free of charge, once every 12 months from each of the three nationwide credit reporting companies. To order your annual free credit report, please visit www.annualcreditreport.com or call toll free at 1-877-322-8228. Contact information for the three nationwide credit reporting companies is as follows:

Experian, PO Box 2002, Allen, TX 75013, www.experian.com,1-888-397-3742

TransUnion, PO Box 2000, Chester, PA 19016, www.transunion.com, 1-800-916-8800

Equifax, PO Box 740241, Atlanta, GA 30374, www.equifax.com, 1-800-685-1111

If you believe you are the victim of identity theft or have reason to believe your personal information has been misused, you should immediately contact the Federal Trade Commission and/or the Attorney General’s office in your state. You can obtain information from these sources about steps an individual can take to avoid identity theft as well as information about fraud alerts and security freezes. You should also contact your local law enforcement authorities and file a police report. Obtain a copy of the police report in case you are asked to provide copies to creditors to correct your records. Contact information for the Federal Trade Commission is as follows:

Federal Trade Commission, Consumer Response Center, 600 Pennsylvania Avenue, NW Washington, DC 20580, 1-877-IDTHEFT (438-4338), www.ftc.gov/idtheft

If you are a resident of Maryland or North Carolina, you may contact and obtain information from your state attorney general at:

Maryland Attorney General’s Office, 200 St. Paul Place, Baltimore, MD 21202, www.oag.state.md.us, 1-888-743-0023 (toll free when calling within Maryland) (410) 576-6300 (for calls originating outside Maryland)

North Carolina Attorney General’s Office, 9001 Mail Service Center, Raleigh, NC 27699, www.ncdoj.gov, 1-877-566-7226

Fair Credit Reporting Act: You also have rights under the federal Fair Credit Reporting Act, which promotes the accuracy, fairness, and privacy of information in the files of consumer reporting agencies. The FTC has published a list of the primary rights created by the FCRA (https://www.consumer.ftc.gov/articles/pdf-0096-fair-credit-reporting-act.pdf), and that article refers individuals seeking more information to visit www.ftc.gov/credit. The FTC’s list of FCRA rights includes:

  • You have the right to receive a copy of your credit report. The copy of your report must contain all the information in your file at the time of your request.
  • Each of the nationwide credit reporting companies – Experian, TransUnion, and Equifax – is required to provide you with a free copy of your credit report, at your request, once every 12 months.
  • You are also entitled to a free report if a company takes adverse action against you, like denying your application for credit, insurance, or employment, and you ask for your report within 60 days of receiving notice of the action. The notice will give you the name, address, and phone number of the credit reporting company. You’re also entitled to one free report a year if you’re unemployed and plan to look for a job within 60 days; if you’re on welfare; or if your report is inaccurate because of fraud, including identity theft.
  • You have the right to ask for a credit score.
  • You have the right to dispute incomplete or inaccurate information.
  • Consumer reporting agencies must correct or delete inaccurate, incomplete, or unverifiable information.
  • Consumer reporting agencies may not report outdated negative information.
  • Access to your file is limited. And you must give your consent for reports to be provided to employers.
  • You may limit “prescreened” offers of credit and insurance you get based on information in your credit report.
  • You may seek damages from violators.
  • Identity theft victims and active duty military personnel have additional rights.