Chick-fil-A discloses data breach after credential stuffing attacks

Chick-fil-A Discloses Data Breach After Credential Stuffing Attacks Expose Customer Info

Fast food giant Chick-fil-A has revealed a data breach affecting an undisclosed number of customers after their accounts were compromised in a series of credential stuffing attacks. The company, which operates over 3,000 restaurants across the US and internationally, detected suspicious login activity to certain Chick-fil-A One accounts in June.

Credential stuffing is a type of attack where hackers use automated tools to breach user accounts with stolen username/password pairs. This tactic takes advantage of users who reuse their credentials across multiple platforms, making it easier for attackers to gain access to sensitive information. In this case, the attackers targeted Chick-fil-A’s website and mobile app, using stolen credentials obtained from a third-party source.

The breach exposed a combination of customers’ names, email addresses, Chick-fil-A One membership numbers, mobile pay numbers, QR codes, and last four digits of credit/debit card numbers. Additionally, birth dates, phone numbers, and addresses may have been accessed if stored in the compromised accounts. While Chick-fil-A didn’t disclose the exact number of affected customers, the company informed the Texas Attorney General that 2,182 Texans were impacted.

The incident is not an isolated case for Chick-fil-A. In March 2023, the company confirmed that threat actors accessed the personal information and used stored rewards balances of over 71,000 customers after hacking their accounts in a similar wave of credential stuffing attacks between December 2022 and February 2023.

In response to the recent breach, Chick-fil-A took steps to protect affected customers by logging out all impacted accounts, removing payment methods, restoring account balances, and adding rewards as an apology. The company also advised users to change their passwords as soon as possible since the accounts were compromised using stolen credentials.

The data breach serves as a reminder of the importance of securing online accounts and being mindful of password reuse. Users are encouraged to implement robust security measures, such as multi-factor authentication and unique passwords for each account. By taking proactive steps to protect their digital lives, individuals can reduce the risk of falling victim to credential stuffing attacks.

As consumers become increasingly dependent on online services, it’s essential for companies like Chick-fil-A to prioritize cybersecurity and educate customers about potential risks. By doing so, they can foster trust and ensure a safer online experience for everyone involved.


Source: Bleeping Computer — 2026-07-22