Chick-fil-a Data Breach Exposed 10 States in Loyalty Accounts

Chick-fil-A data breach may have exposed Chick-fil-A One Loyalty data in 10 states after a credential-stuffing attack between June 17 and June 19.

Published
2 Min Read
Chick-fil-a Data Breach Exposed 10 States in Loyalty Accounts

Chick-fil-A data breach notices say a credential-stuffing attack may have exposed information from a limited number of Chick-fil-A One Loyalty accounts. The accounts were in 10 states, including Maryland. The company said it secured and restored impacted accounts after the incident.

- Advertisement -

Chick-fil-A One Loyalty accounts

Between June 17 and June 19, unauthorized parties used usernames and passwords from a third-party source in an automated attack against Chick-fil-A's website and mobile app.

On July 13, Chick-fil-A concluded that attackers may have accessed names, email addresses, Chick-fil-A One membership numbers, Mobile Pay numbers and QR codes, the last four digits of payment card numbers, and Chick-fil-A gift card balances.

Maryland customers and direct notice

The company said the hack affected a limited number of loyalty accounts, but it did not say how many. It also said it is communicating directly with customers who may have been impacted.

Anton Dahbura said this kind of scam keeps working because people reuse login credentials across multiple sites. “They know about one place, then they try other places to see if they can get in with the same username and password,” he said. “They're collecting pieces of information,” he said. “They might not get everything from one place from you for it to be helpful for them, but it's the combination of places. They patiently collect information about you, and pretty soon, they have enough information to do things that can be quite damaging.”

- Advertisement -

Isabel Maloney on the app

Isabel Maloney said the incident changed how she sees app-based loyalty programs. “It definitely makes me hesitate to get another app like this for sure,” she said. “I probably won't use it moving forward just after hearing about that.”

What matters most now is whether any of the exposed account details were used for fraud or other misuse after the June 17 to June 19 attack window. Chick-fil-A has said it restored affected accounts, but it has not said how many customers were involved.

Advertisement
Share This Article
Technology analyst writing on semiconductors, cybersecurity, and Big Tech regulation. Holds a master's degree in Computer Science from MIT.