Chick-fil-A Says Cyberattack May Have Exposed Loyalty Account Data
Want more insights like this?
Chick-fil-A began notifying customers across 11 jurisdictions in late July after a credential-stuffing attack on its loyalty program between June 17 and 19. Thieves used usernames and passwords stolen from a third-party source to break into Chick-fil-A One accounts through the website and app. The company had concluded on July 13 that data may have been accessed.
Data that may have been accessed includes names, email addresses, membership numbers, Mobile Pay numbers, partial payment card digits, gift card balances, and QR codes. Customers who had saved more to their accounts may also have had their birth month and day, phone number, and address accessed.
Chick-fil-A calls it a limited number of accounts and hasn't given a total; filings show 2,182 in Texas and 39 in Massachusetts. It's the second credential-stuffing hit on Chick-fil-A One — an earlier one in 2023 reached more than 71,000 customers.
The company logged out affected users, removed stored payment methods, restored balances, and added rewards as compensation. Customers should reset their passwords and make them unique — reuse is what credential stuffing runs on — then check account activity. A law firm has been investigating a possible class action since early August.
Source: CBS News