logo

Chick-fil-A discloses data breach after credential stuffing attacks

ID: 93386e1f-098a-5515-b058-0cd63f07f447

STIX ID: report--93386e1f-098a-5515-b058-0cd63f07f447

Feed Name: Bleeping Computer

Threat Score
60/100

Date Published: 2026-07-22

Date Updated: 2026-07-22

Author: Sergiu Gatlan

...
...

Chick‑fil‑A detected an automated credential‑stuffing attack against its website and mobile app between June 17–19, 2026 that allowed unauthorized parties, using credentials from a third‑party source, to access Chick‑fil‑A One accounts and potentially expose customer data (names, emails, membership and mobile pay numbers, QR codes, credit balances, last four card digits, and possibly birthdates, phones, and addresses). The company logged out impacted accounts, removed payment methods, restored balances, added rewards, and sent breach notifications to affected customers across multiple states.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.