Chick-fil-A Confirms Data Breach Affecting Over 13,000 Customers After Credential Stuffing Attacks
Fast-food giant **Chick-fil-A** has disclosed a data breach impacting more than 13,000 customers, stemming from a series of credential stuffing attacks between June 17 and June 19. Threat actors leveraged previously compromised credentials from third-party sources to access **Chick-fil-A One** accounts, stealing personal and financial information. This incident marks the second major credential stuffing attack against the company in less than two years.
### Credential Stuffing Targets Chick-fil-A One Accounts
**Chick-fil-A** recently confirmed a data breach affecting 13,322 customers. The incident, which occurred between June 17 and June 19, involved sophisticated credential stuffing attacks targeting the company's website and mobile application. Attackers utilized automated tools and credentials obtained from external breaches to gain unauthorized access to **Chick-fil-A One** loyalty accounts.
### Scope of Compromised Data
The information accessed by the threat actors includes customers' names, email addresses, **Chick-fil-A One** membership numbers, loyalty credit balances, mobile pay numbers, and the last four digits of credit/debit card numbers. For some accounts, birth dates, phone numbers, and physical addresses may also have been exposed if stored within the compromised profiles.
Filings with various state Attorney General offices, including Maine (13,322 individuals), Texas (2,182 individuals), and Massachusetts (39 residents), confirm the widespread nature of the breach. Notification letters have also been dispatched to affected residents in the District of Columbia, Iowa, Maryland, New Mexico, New York, North Carolina, Oregon, Vermont, and Rhode Island.
### Company Response and Mitigation
In response to the breach, **Chick-fil-A** has taken several immediate actions. All impacted accounts have been logged out, associated payment methods removed, and all affected **Chick-fil-A One** account balances restored. Additionally, the company has offered loyalty rewards to affected customers as a gesture of apology.
Customers whose accounts were compromised have been strongly advised to change their passwords immediately, especially if they reuse credentials across multiple online services. This recommendation underscores the critical importance of strong, unique passwords to mitigate the risks associated with credential stuffing attacks.
### A Recurring Security Challenge
This is not the first time **Chick-fil-A** has faced such a challenge. In March 2023, the company disclosed a similar incident where over 71,000 customer accounts were compromised between December 2022 and February 2023, also due to credential stuffing attacks. The repeated nature of these incidents highlights the persistent threat that credential stuffing poses to organizations, particularly those with large customer bases and loyalty programs.