Chick-fil-A Accounts Get Fried in Credential Stuffing Attack

Chick-fil-A Accounts Get Fried in Credential Stuffing Attack
Chick-fil-A disclosed a data breach after a credential stuffing attack targeted Chick-fil-A One customer accounts on its mobile app and website. The attackers may have accessed personal and payment-related data, and the company reset passwords, logged out affected users, and restored drained balances. #ChickfilA #ChickfilAOne

Keypoints

  • Chick-fil-A confirmed a breach tied to credential stuffing attacks.
  • The attacks targeted Chick-fil-A One accounts between June 17 and June 19.
  • Stolen credentials came from third-party sources, including breaches and infostealers.
  • Exposed data may include names, emails, payment details, and account balances.
  • Chick-fil-A reset passwords, logged out accounts, and restored drained rewards balances.

Read More: https://www.securityweek.com/chick-fil-a-accounts-get-fried-in-credential-stuffing-attack/