Chick-fil-A confirmed that credential stuffing attacks against its website and mobile app exposed data from 13,322 customers, using credentials obtained from third-party sources. The incident affected Chick-fil-A One accounts and led the company to log out impacted users, remove payment methods, restore balances, and advise password changes. #ChickfilA #ChickfilAOne
Keypoints
- Chick-fil-A detected suspicious login activity between June 17 and June 19.
- Attackers used automated tools and stolen third-party credentials to access Chick-fil-A One accounts.
- The breach exposed names, email addresses, membership numbers, payment data, and possibly birth dates, phone numbers, and addresses.
- The company said the incident affected 13,322 people, including residents in several U.S. states and Washington, D.C.
- Chick-fil-A logged out affected accounts, removed payment methods, restored balances, and urged customers to change passwords.