Chick-fil-A Accounts Get Fried in Credential Stuffing Attack
Chick-fil-A suffers credential stuffing attack on loyalty program accounts affecting thousands.
Summary
Chick-fil-A disclosed a credential stuffing attack on its Chick-fil-A One loyalty program that occurred June 17-19, where threat actors used stolen credentials from other sources to gain unauthorized access. Thousands to tens of thousands of accounts were compromised, exposing names, emails, membership numbers, partial payment card data, and other personal information. The company has reset passwords, removed stored payment methods, restored drained balances, and added rewards to affected accounts.
Full text
US fast-food chain Chick-fil-A has disclosed a data breach stemming from a credential stuffing attack targeting its customers’ online accounts. According to notifications sent to affected individuals, the attack targeted accounts on the Chick-fil-A One loyalty and rewards program. Threat actors conducted credential stuffing attacks against the Chick-fil-A mobile app and website on June 17-19, using credentials obtained from third-party sources, which can include data breaches at other companies, phishing campaigns, and data collected by infostealer malware. On July 13, the fast-food chain determined that the attackers may have obtained data stored in the compromised accounts. Stolen data can include names, email addresses, Chick-fil-A membership numbers and mobile pay numbers, partial payment card numbers, account balances, and in some cases phone numbers, addresses, and dates of birth. Affected accounts have been forcefully logged out, their passwords have been reset, and payment methods stored in them have been removed. For accounts drained by the attackers, balances have been restored and additional rewards have been added. Advertisement. Scroll to continue reading. It’s unclear how many individuals are affected, but based on the numbers submitted to the attorneys general in Texas and Massachusetts, thousands or tens of thousands may be affected. SecurityWeek has reached out to Chick-fil-A for information on how many people are impacted and will update this article if the company responds. Chick-fil-A has more than 3,000 restaurants and over 200,000 team members. Credential stuffing attacks can be highly lucrative for cybercriminals. The 2022 DraftKings attack enabled three hackers to make hundreds of thousands of dollars. However, they have all been identified and sentenced to prison. Related: Upbound Group Says Data Breach Led to $13 Million in Fraudulent Contract Losses Related: Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts Related: Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Suno, Paidwork Data Breaches Affect Tens of Millions of AccountsFlaw in Adobe Extension With 300M Installs Enabled WhatsApp Data TheftFourth SharePoint Vulnerability Exploited in Past Month’s Wave of AttacksOracle Patches Over 1,400 Vulnerabilities With Quarterly Security UpdatesRansomware Group Threatening to Leak Data Stolen From Coca-Cola’s FairlifeOpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support DataExploitation of ServiceNow Vulnerability Seen Days After Disclosure Latest News OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI InsiderIs Patching Dead? Vulnerability Management in the Post-Mythos EraAbstract Raises $25 Million to Expand Composable Security Operations PlatformNuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI ModelsUpbound Group Says Data Breach Led to $13 Million in Fraudulent Contract LossesAssaf Keren Appointed New CISO of MetaNew Check Point Zero-Day Vulnerability Exploited in the WildUS Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Closing the Exploitation Gap July 22, 2026 Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the MoveJohn DeSimone, the former CEO of Nightwing, has been named Chief Operating Officer at Everfox.Sectigo has appointed Prem Hareesh as Corporate Chief Technology Officer.Assaf Keren, who previously served as CSO/CISO at Qualtrics and PayPal, is Meta's new CISO.More People On The MoveExpert Insights Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Legacy Systems, Real-World Impacts: The Reality of OT Security Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. (Tod Beardsley) The Shift Toward Business-Aligned Risk Management Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. (Steve Durbin) How to Conduct a Successful Audit of AI-Driven Software Development As AI-generated code becomes commonplace, CISOs need new audit strategies to measure developer practices, govern AI tool usage, and identify software risks before they reach production. (Matias Madou) Flipboard Reddit Whatsapp Whatsapp Email