Skip to main content
Security

Chick-fil-A data breach affects more than 13,000 customers

Chick-fil-A data breach affects more than 13,000 customers Image: Primary
Chick-fil-A confirmed that more than 13,000 customers had their data stolen in credential stuffing attacks targeting its website and mobile app between June 17 and June 19, the company said in breach notification letters filed with multiple attorney general offices. The fast food chain detected the suspicious login activity after attackers used automated tools and credentials obtained from a third-party source to access Chick-fil-A One accounts. The breach exposed customer names, email addresses, membership numbers, Chick-fil-A credit amounts, mobile pay numbers and the last four digits of credit or debit cards. Birth dates, phone numbers and addresses may also have been accessed if stored in the accounts. A filing with the Maine Attorney General shared with BleepingComputer on Wednesday said the breach affected 13,322 people in total. Separate filings indicated 2,182 Texans and 39 Massachusetts residents were impacted. Chick-fil-A said it logged out all impacted accounts, removed payment methods, restored account balances and added rewards to affected accounts. The company advised customers to change their passwords because the accounts were compromised using credentials stolen from third-party services. Chick-fil-A disclosed a separate credential stuffing breach in March 2023 that affected over 71,000 customers.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from Bleeping Computer, The Star and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security
Security

Microsoft fixes 974 flaws, including two exploited Windows zero-days

Microsoft released patches for 974 CVEs across its products, including two Windows zero-days reported as exploited in the wild. One is an ALPC heap-buffer-overflow flaw that can let a local attacker escape a low-privilege AppCont...

Security
Security

N-able issues hotfix for N-central zero-day

N-able released an urgent hotfix for CVE-2026-86218, a critical unauthenticated remote-code-execution vulnerability in its N-central endpoint-management platform. The company said the flaw had been exploited as a zero-day and that...

Security
Security

CISA adds exploited Chromium V8 flaw to KEV catalog

CISA has added CVE-2026-85046, a Chromium V8 type-confusion vulnerability, to its Known Exploited Vulnerabilities catalog, saying it is actively exploited. The flaw can be triggered when a target loads a specially crafted HTML pag...

Security
Security

Natural Resources Wales discloses employee diversity-data exposure

Natural Resources Wales disclosed that a spreadsheet containing equality-monitoring and diversity information for former and current employees was inadvertently published online and later removed. The affected group covers people...

Security Products
Security Products

Liquid sidechain pauses after reported 4,000 BTC withdrawal

Liquid says purported white-hat hackers withdrew about 4,000 BTC, valued in its statement at roughly $320 million, from the Liquid Federation wallet. The company says the funds left through the SideSwap Peg-out Authorization Key, ...