Reading: Chick-fil-a Loyalty Account Breach sent alerts to customers in 10 states

Chick-fil-a Loyalty Account Breach sent alerts to customers in 10 states

Published
3 min read
Advertisement

Chick-fil-A said a credential-stuffing cyberattack may have exposed personal information in some Chick-fil-A One loyalty accounts, and the company has begun alerting customers in 10 states and the District of Columbia. The incident led to forced logouts, removal of stored payment methods and a reset of impacted balances while the company says it worked to secure the accounts.

The disclosure lands now because Chick-fil-A concluded on July 13 that attackers may have accessed account information after suspicious login activity showed up in a cluster of customer accounts. Between June 17 and June 19, unauthorized parties used usernames and passwords obtained from a third-party source to try to break into the website and mobile app, a pattern that fits credential stuffing rather than a direct breach of one password database.

The information that may have been exposed reaches beyond a basic loyalty profile. It includes names, email addresses, Chick-fil-A One membership numbers, Mobile Pay numbers and QR codes, the last four digits of payment card numbers and gift card balances. If customers had stored it in their accounts, attackers also may have seen birth month and day, phone number and address. That mix can be enough to help with account takeover or fraud, even if no single field looks especially sensitive on its own.

- Advertisement -

Chick-fil-A said the security incident may have affected only a limited number of Chick-fil-A One Loyalty accounts, yet notification letters were sent to customers in Iowa, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Rhode Island and Vermont, along with the District of Columbia. The company said it recently identified the issue, but the broad warning suggests it could not rule out which accounts were touched simply by geography. That leaves one key gap in the disclosure: how many accounts were actually compromised.

The company said it is advising customers to reset Chick-fil-A passwords right away and to use strong, unique passwords not reused elsewhere. It is also urging them to review account activity, bank and credit card statements and credit reports for anything unusual. For now, Chick-fil-A says it has restored impacted balances and added rewards to affected accounts for the inconvenience, but the real test will be whether customers can trust that a loyalty login will stay just that: a loyalty login.

Advertisement
Share This Article