Chick-fil-A data breach affects more than 13,000 customers
ID: 8f3dd5f2-b6dd-5993-99e4-904ff1eb4146
STIX ID: report--8f3dd5f2-b6dd-5993-99e4-904ff1eb4146
Feed Name: Bleeping Computer
Chick-fil-A confirmed a credential-stuffing attack on its website and mobile app that occurred June 17–19, resulting in unauthorized access to 13,322 Chick‑fil‑A One accounts. Attackers used third-party credentials and automated tools to steal names, emails, membership numbers, Chick‑fil‑A credit balances, mobile pay numbers, last four digits of payment cards, and potentially birth dates, phone numbers, and addresses; the company logged out impacted accounts, removed payment methods, restored balances, notified affected customers, and advised password changes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
