One Password Mistake Helped Hackers Access Chick-fil-A Account
ID: b8b680c7-de15-50d8-9d82-92fd8407c4ca
STIX ID: report--b8b680c7-de15-50d8-9d82-92fd8407c4ca
Feed Name: TechRepublic Security
Chick-fil-A disclosed that an automated credential-stuffing campaign from June 17–19 used credentials obtained from a third-party source to access a limited number of customer accounts across 10 U.S. states, exposing names, emails, Chick-fil-A One membership numbers, mobile pay numbers/QR codes, partial card numbers, gift card balances, and other customer-supplied details; the company invalidated sessions, restored affected loyalty balances, notified impacted customers beginning July 20, and recommended password changes and stronger authentication (MFA/passkeys).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
