logo

One Password Mistake Helped Hackers Access Chick-fil-A Account

ID: b8b680c7-de15-50d8-9d82-92fd8407c4ca

STIX ID: report--b8b680c7-de15-50d8-9d82-92fd8407c4ca

Feed Name: TechRepublic Security

Threat Score
50/100

Date Published: 2026-07-23

Date Updated: 2026-07-24

Author: Joseph Ofonagoro

...
...

Chick-fil-A disclosed that an automated credential-stuffing campaign from June 17–19 used credentials obtained from a third-party source to access a limited number of customer accounts across 10 U.S. states, exposing names, emails, Chick-fil-A One membership numbers, mobile pay numbers/QR codes, partial card numbers, gift card balances, and other customer-supplied details; the company invalidated sessions, restored affected loyalty balances, notified impacted customers beginning July 20, and recommended password changes and stronger authentication (MFA/passkeys).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.