Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

Chick-fil-A Accounts Get Fried in Credential Stuffing Attack

Threat actors used credentials obtained from other companies to hack into Chick-fil-A One accounts.

Chick-fil-A data breach

US fast-food chain Chick-fil-A has disclosed a data breach stemming from a credential stuffing attack targeting its customers’ online accounts. 

According to notifications sent to affected individuals, the attack targeted accounts on the Chick-fil-A One loyalty and rewards program.

Threat actors conducted credential stuffing attacks against the Chick-fil-A mobile app and website on June 17-19, using credentials obtained from third-party sources, which can include data breaches at other companies, phishing campaigns, and data collected by infostealer malware. 

On July 13, the fast-food chain determined that the attackers may have obtained data stored in the compromised accounts.

Stolen data can include names, email addresses, Chick-fil-A membership numbers and mobile pay numbers, partial payment card numbers, account balances, and in some cases phone numbers, addresses, and dates of birth. 

Affected accounts have been forcefully logged out, their passwords have been reset, and payment methods stored in them have been removed. For accounts drained by the attackers, balances have been restored and additional rewards have been added. 

Advertisement. Scroll to continue reading.

It’s unclear how many individuals are affected, but based on the numbers submitted to the attorneys general in Texas and Massachusetts, thousands or tens of thousands may be affected. 

SecurityWeek has reached out to Chick-fil-A for information on how many people are impacted and will update this article if the company responds.

Chick-fil-A has more than 3,000 restaurants and over 200,000 team members. 

Credential stuffing attacks can be highly lucrative for cybercriminals. The 2022 DraftKings attack enabled three hackers to make hundreds of thousands of dollars. However, they have all been identified and sentenced to prison. 

Related: Upbound Group Says Data Breach Led to $13 Million in Fraudulent Contract Losses

Related: Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts

Related: Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Barry Childe has joined data sciences tech company Datavault AI as Chief Information Security Officer.

John DeSimone, the former CEO of Nightwing, has been named Chief Operating Officer at Everfox.

Sectigo has appointed Prem Hareesh as Corporate Chief Technology Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.