A massive credential stuffing attack has hit US fast-food chain Chick-fil-A, compromising the online accounts of thousands of customers. The attackers targeted the Chick-fil-A One loyalty and rewards program, using stolen login credentials obtained from third-party sources to breach user accounts on both the mobile app and website.
The attack took place between June 17-19, with Chick-fil-A only discovering the extent of the breach on July 13. According to notifications sent to affected individuals, the attackers may have accessed a range of sensitive information, including names, email addresses, membership numbers, partial payment card numbers, account balances, and in some cases phone numbers, addresses, and dates of birth.
Credential stuffing attacks work by using stolen login credentials from one online service against another. The attackers use these credentials to try multiple logins at once, hoping that some will be successful. In this case, the attackers used credentials obtained from third-party sources, which can include data breaches at other companies, phishing campaigns, and data collected by infostealer malware.
The impact of the attack is significant, with thousands or tens of thousands of customers potentially affected. Chick-fil-A has a massive customer base, with over 3,000 restaurants and more than 200,000 team members. The company has taken steps to mitigate the damage, forcing affected accounts to be logged out and resetting passwords. Payment methods stored in compromised accounts have also been removed.
The financial impact of credential stuffing attacks can be substantial. In 2022, a similar attack on online sportsbook DraftKings enabled three hackers to make hundreds of thousands of dollars before they were identified and sentenced to prison. The attackers used stolen login credentials to access user accounts, then used the information to make unauthorized bets.
The Chick-fil-A breach serves as a reminder that credential stuffing attacks are a growing threat in the cybersecurity landscape. These types of attacks can be highly lucrative for cybercriminals, who use stolen login credentials to gain access to sensitive information and commit financial crimes.
For customers affected by the breach, it’s essential to remain vigilant and monitor their accounts closely. If you haven’t already done so, change your password and keep an eye on your bank statements for any signs of unauthorized activity. Additionally, be cautious when receiving emails or notifications that ask you to log in or provide sensitive information.
In light of this incident, it’s also worth considering using two-factor authentication (2FA) whenever possible to add an extra layer of security to your online accounts. This can help prevent credential stuffing attacks by requiring both a password and a verification code sent to your phone or email to access your account.
Source: SecurityWeek — 2026-07-23