Chick-fil-A disclosed a data breach after a credential stuffing attack targeted Chick-fil-A One customer accounts on its mobile app and website. The attackers may have accessed personal and payment-related data, and the company reset passwords, logged out affected users, and restored drained balances. #ChickfilA #ChickfilAOne
Keypoints
- Chick-fil-A confirmed a breach tied to credential stuffing attacks.
- The attacks targeted Chick-fil-A One accounts between June 17 and June 19.
- Stolen credentials came from third-party sources, including breaches and infostealers.
- Exposed data may include names, emails, payment details, and account balances.
- Chick-fil-A reset passwords, logged out accounts, and restored drained rewards balances.
Read More: https://www.securityweek.com/chick-fil-a-accounts-get-fried-in-credential-stuffing-attack/