Chick-fil-A warns of June 17-19 breach in 10 states — Chick-fil-a Loyalty Account Breach

Chick-fil-A says a June 17-19 credential-stuffing attack may have exposed loyalty account data in 10 states and Washington, D.C.

Published
2 Min Read
Chick-fil-A warns of June 17-19 breach in 10 states — Chick-fil-a Loyalty Account Breach

Chick-fil-A said a Chick-fil-a Loyalty Account Breach may have exposed information in some Chick-fil-A One accounts after an automated credential-stuffing attack ran between June 17 and June 19. The company said it later concluded on July 13 that attackers may have accessed data in affected accounts.

- Advertisement -

Chick-fil-A One accounts

The incident involved login attempts using usernames and passwords taken from a third-party source. That is the core risk in credential stuffing: one reused password can open an account even when the site itself has not been directly guessed or cracked.

Chick-fil-A said it detected suspicious login activity involving certain customer accounts and launched an investigation. It also said it recently identified a security incident that may have affected a limited number of Chick-fil-A One Loyalty accounts.

District of Columbia to Vermont

Notification letters went to customers in 10 jurisdictions: the District of Columbia, Iowa, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Rhode Island and Vermont. The same notice covered accounts that may have exposed names, email addresses, Chick-fil-A One membership numbers, Mobile Pay numbers and QR codes.

If customers stored more information in their accounts, attackers also may have accessed the month and day they were born, phone number and address. The company forced affected customers to log out and remove stored payment methods while it restored impacted Chick-fil-A One balances.

- Advertisement -

Payment data

Chick-fil-A said the exposed details also included the last four digits of payment card numbers and Chick-fil-A gift card balances. The company added rewards to affected accounts for the inconvenience.

That leaves a practical split for customers. A person may have only a login issue, or may also need to watch for account activity tied to saved payment details and gift card balances.

Chick-fil-A told customers to reset their passwords immediately and use a strong, unique password that is not used on other websites. It also told them to review account activity, bank and credit card statements, and credit reports for suspicious activity.

The open question is scale. Chick-fil-A said the incident may have affected only a limited number of Chick-fil-A One Loyalty accounts, but its notice still reached customers across 10 jurisdictions and included payment-related data.

Advertisement
Share This Article
Tech writer covering AI, cloud infrastructure, and enterprise software. Former software engineer at Google with 7 years in technology journalism.