Chick-fil-A Loyalty Account Breach Exposes Customer Data in Credential-Stuffing Attack
A chick fil a loyalty account breach allowed unauthorized parties to access customer personal information across multiple states.

Chick-fil-A discovered a security incident affecting its One Loyalty program after hackers used stolen usernames and passwords to gain unauthorized access to customer accounts in 10 states. The fast-food chain identified suspicious login activity on certain accounts and launched an investigation that revealed attackers had conducted a credential-stuffing attack between mid-June and mid-July. The company has since notified affected customers and implemented security measures including forced logouts and restoration of account balances.
İçindekiler ›
How the Attack Unfolded
Between June 17 and June 19, unauthorized parties leveraged account credentials obtained from a third-party source to conduct an automated credential-stuffing campaign against Chick-fil-A's website and mobile application. The attackers used these stolen usernames and passwords in a systematic attempt to gain access to customer accounts. Chick-fil-A confirmed on July 13 that the breach may have resulted in unauthorized access to affected accounts, leading the company to notify customers in the District of Columbia, Iowa, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Rhode Island, and Vermont.
What Customer Information Was Exposed
The compromised data included customers' names, email addresses, Chick-fil-A One membership numbers, Mobile Pay numbers, QR codes, and the last four digits of payment card numbers. Additionally, account gift card balances were accessible to attackers. For customers who had stored additional information within their loyalty accounts, the breach also exposed month and day of birth, phone numbers, and addresses. However, full payment card numbers and CVV codes were not compromised, limiting the immediate financial exposure for affected customers.
Company Response and Customer Protection Measures
Upon discovering the incident, Chick-fil-A took immediate action to secure affected accounts. The company forced logouts on all impacted accounts, removed any stored payment methods, and restored One Loyalty program balances. As compensation for the inconvenience and security concern, Chick-fil-A added rewards credits to affected customer accounts. The company also stated it continues to enhance its security monitoring and fraud controls to prevent similar incidents in the future.
Chick-fil-A has recommended that customers reset their account passwords immediately using strong, unique credentials not used on other websites. The company also encourages customers to review their account activity, bank statements, credit card statements, and credit reports for any suspicious transactions or unauthorized access.
What is credential stuffing and how does it work?+
How many customers were affected by the chick fil a loyalty account breach?+
Were full credit card numbers exposed in the chick fil a loyalty account breach?+
What should I do if I have a Chick-fil-A loyalty account?+
How did Chick-fil-A compensate affected customers?+
Bülten Aboneliği
Haftada bir, teknoloji ve dijital dünyadan seçtiklerimiz e-postanda. Spam yok, sadece içerik.


