Intelligence Alert

Chick-fil-A discloses customer data breach following automated credential stuffing attacks

Risk level: Low Country: United States

As per reports, Chick-fil-A issued data breach notification letters to affected customers following automated credential stuffing attacks targeting its website and mobile application between 17 June and Friday 19 June.

Following are the details:

• Unauthorized parties conducted automated login attempts using account credentials obtained from third-party sources to gain access to Chick-fil-A One loyalty accounts.
• Investigations completed on Monday (13 July) confirmed that unauthorized parties accessed stored customer information within affected accounts.
• Potentially exposed information includes names, email addresses, Chick-fil-A One membership numbers, mobile pay numbers, Quick Response codes, rewards balances, store credit, dates of birth, phone numbers, addresses, and the last 04 digits of payment cards.
• Chick-fil-A initiated security responses including forced account log-outs, removal of stored payment methods, restoration of account balances, and issuance of bonus rewards to impacted customers.
• The restaurant chain advised affected account holders to update account passwords across the platform and any external services sharing identical login credentials.

Share on WhatsApp
Related

More from United States

See why global leaders trust Datasurfr.

A walkthrough tailored to your industry and threat profile.