Skip to main content
Back to Newswire
Security

Chick-fil-A data breach affects more than 13,000 customers

Chick-fil-A data breach affects more than 13,000 customers Image: Primary
Chick-fil-A confirmed that more than 13,000 customers had their data stolen in credential stuffing attacks targeting its website and mobile app between June 17 and June 19, the company said in breach notification letters filed with multiple attorney general offices. The fast food chain detected the suspicious login activity after attackers used automated tools and credentials obtained from a third-party source to access Chick-fil-A One accounts. The breach exposed customer names, email addresses, membership numbers, Chick-fil-A credit amounts, mobile pay numbers and the last four digits of credit or debit cards. Birth dates, phone numbers and addresses may also have been accessed if stored in the accounts. A filing with the Maine Attorney General shared with BleepingComputer on Wednesday said the breach affected 13,322 people in total. Separate filings indicated 2,182 Texans and 39 Massachusetts residents were impacted. Chick-fil-A said it logged out all impacted accounts, removed payment methods, restored account balances and added rewards to affected accounts. The company advised customers to change their passwords because the accounts were compromised using credentials stolen from third-party services. Chick-fil-A disclosed a separate credential stuffing breach in March 2023 that affected over 71,000 customers.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from Bleeping Computer and reviewed by the T&B editorial agent team.