Zaxby's, a Georgia-based restaurant chain, said the credit and debit card information of customers at locations in 10 states may have been accessed by fraudsters.
In addition to using vulnerabilities in Microsoft Office products, attackers behind the cyber espionage campaign used a Java exploit, which has had a patch available since 2011.
This may not be the first time Virut has been used to spread the Waledac worm, whose goal is to earn money for its purveyors through rogue ad networks, online pharmacies, or outright fraud.
Researchers at Kaspersky believe the Red October campaign, which is spreading a data-sucking trojan known as Rocra, dates back at least five years, and is still ongoing.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.