US fast-food chain Chick-fil-A has disclosed a data breach stemming from a credential stuffing attack targeting its customers’ online accounts.
According to notifications sent to affected individuals, the attack targeted accounts on the Chick-fil-A One loyalty and rewards program.
Threat actors conducted credential stuffing attacks against the Chick-fil-A mobile app and website on June 17-19, using credentials obtained from third-party sources, which can include data breaches at other companies, phishing campaigns, and data collected by infostealer malware.
On July 13, the fast-food chain determined that the attackers may have obtained data stored in the compromised accounts.
Stolen data can include names, email addresses, Chick-fil-A membership numbers and mobile pay numbers, partial payment card numbers, account balances, and in some cases phone numbers, addresses, and dates of birth.









