
The Capital Grille
I recently made a dinner reservation at The Capital Grille. My friends and I really enjoy their meal. While a bit pricey, the food, wait-staff, and general dining experience is amazing. My praise for The Capital Grille is not the point of this post.
When I made the reservation I used a newly created email address, unique to The Capital Grille, something like: CAPITALGRILLE@my_domain.com. This is a common practice of mine and allows me to track how spammers are obtaining my email address.
This morning, I received the following spam:
To: CAPITALGRILLE@mydomain.com
From: thabo mbazima <t-mbazima@hotmail.com>
Subject: REPLY
Dear Friend
I am the manager of bill and exchange at the foreign remittance department
of African Developent bank(ADB) here in Johannesburg,South Africa
...
This is your standard 419 scam. What’s interesting is that it was sent to the email address that I had supplied to The Capital Grille. The only way that a spammer could be using that email address is if either the restaurants database was hacked, or sold.
Using their website’s feedback form, I sent them a strong, yet polite message explaining the situation. While I no longer have a copy of that message, I pointed out that either their database was hacked or they sold my email address. Either way, I was upset. Here is their response:
From: "Matthew Milewski" <xxxx@tcgdine.com>
To: CAPITALGRILLE@mydomain.com
Subject: Your Capital Grille Account
Mr. Lehrer,
Thank you for contacting us at The Capital Grille. I just received your letter, and you are
correct, our database was recently partially compromised. While we know that no vital guest
information was taken, since we do not keep any sensitive data (such as credit card numbers)
in our system, we do apologize for the inconvenience. Please rest assured that we do not sell
our database information.
Since learning of the breach, we have taken steps to increase our security measures to better
protect our guests’ privacy, including the requirement of stronger passwords. I will have your
current account deleted from our system, and ask that you re-register with us at your
convenience.
To thank you for your patience and loyalty to our restaurant, I would like to have a gift card
sent to you for your next visit with us. Please confirm that this is the correct address to use,
and I will have something sent out immediately:
-- mailing address removed --
Sincerely,
Matthew Milewski
Brand Manager
___________________________________
6880 Lake Ellenor Drive i Orlando , FL 32809
thecapitalgrille.com i xxxxx@tcgdine.com
___________________________________
THE CAPITAL GRILLE ®
Needless to say, I was shocked. I thought for sure they would either ignore my message, send me an automated response, deny my allegations, or tell me I was crazy.
While I may be crazy, I appreciate their honesty and will enjoy whatever gift card they send me. I just won’t make the reservation online.
UPDATE – My gift cards have arrived. Two $50 certificates. Not bad for less than an hour’s work.