EXHIBIT 101 / THE HANDBOOK
EXHIBIT#22HIGH
Management & OwnershipComposite score: 73/100

Cybersecurity Breach & Data Theft

Customer and payment data get harvested from underprotected systems, then sold to the highest bidder on the dark web. A single unpatched POS vulnerability can expose every card swiped for months.

Risk Scores

Frequency50
Financial Loss90
Detection Difficulty80
Prevention Ease60
Composite Score73/100

Perpetrator Roles

IT / Tech

Affected Formats

QSRFast CasualCloud Kitchen

Detection Difficulty

Extremely difficult to detect without automated monitoring. Manual audits rarely catch this scheme.

HOW IT WORKS
Premium item ordered
Lower-cost item substituted
Customer charged full price
Difference pocketed
Customer rarely notices
Handbook Chapter · F-022

Ingredient Substitution Fraud

Full chapter with identity card, real examples, warning signs, detection and prevention guidance.

Exhibit AI Detection

AI-Powered Detection Design

Actively monitor dark web listings for brand-associated customer data, and watch for unusual, large-volume database export activity internally.

Prevention Guidance

Audit Controls

Enhanced audit controls required. Standard procedures are insufficient — implement layered verification.

Technology

Automated POS monitoring, real-time exception reporting, and AI-driven anomaly detection significantly reduce exposure.

Culture & Training

Staff awareness programs, anonymous reporting channels, and clear consequence policies deter opportunistic fraud.

Seen this in your operation?

Submit an anonymous report to help build the next edition of the handbook.

Report This Scheme