Chick-fil-A loyalty accounts hijacked using stolen passwords
ID: 8d308af2-7e5f-5a6b-9192-ff14ed646f7b
STIX ID: report--8d308af2-7e5f-5a6b-9192-ff14ed646f7b
Feed Name: Malwarebytes Blog
Chick‑fil‑A detected automated credential stuffing activity against Chick‑fil‑A One accounts from June 17–19, 2026, using credentials obtained from prior breaches or third‑party sources; attackers accessed account details such as names, emails, membership and mobile pay numbers, QR codes, reward balances, and potentially birthdate, phone number, and partial card digits. The company reset affected account passwords, terminated active sessions, and advised customers to set unique passwords, enable MFA, and follow recovery processes; the report also explains how credential stuffing works and offers consumer remediation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
