Chick-fil-A discloses data breach after credential stuffing attacks
ID: 93386e1f-098a-5515-b058-0cd63f07f447
STIX ID: report--93386e1f-098a-5515-b058-0cd63f07f447
Feed Name: Bleeping Computer
Chick‑fil‑A detected an automated credential‑stuffing attack against its website and mobile app between June 17–19, 2026 that allowed unauthorized parties, using credentials from a third‑party source, to access Chick‑fil‑A One accounts and potentially expose customer data (names, emails, membership and mobile pay numbers, QR codes, credit balances, last four card digits, and possibly birthdates, phones, and addresses). The company logged out impacted accounts, removed payment methods, restored balances, added rewards, and sent breach notifications to affected customers across multiple states.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
