Skip to content

Condition: Post with Page_List

Listen
Search
Please enter at least 3 characters.

Latest Stories

Chick-fil-A discloses data breach exposing customer names, emails, payment details, more

Chick-fil-A chicken restaurant. With its chicken meals and waffle potato fries, Chick-fil-A is wildly popular.
Mason - November 23, 2023: Chick-fil-A chicken restaurant. With its chicken meals and waffle potato fries, Chick-fil-A is wildly popular.
Getty Images


Signing up for yet another rewards app isn’t as harmless as it might seem. Even downloading a loyalty app for your favorite fast food can come with risks.

For example, hackers might have gained access to Chick-fil-A One loyalty account holder information in a recent attack, according to multiple reports.

CBS News reported that Georgia-based Chick-fil-A alerted customers in the District of Columbia, Iowa, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Rhode Island and Vermont about the attack. It said that the company concluded July 13 that unauthorized parties used user names and passwords obtained from a third-party source in an automated “credential stuffing” attack.

“Credential stuffing” refers to hackers acquiring a large quantity of usernames and passwords, “potentially from a previous attack or a website that publishes exfiltrated data, often found on the Dark Web,” explained the National Security Agency. Then, the hacker runs the stolen credentials through tools to test them across multiple websites. If people use the same username and password across multiple sites, they could be especially vulnerable to this type of attack, the agency said.

Targeting customers of a fast food restaurant might seem like a strange move for hackers. However, Dray Agha, senior manager of security operations at Huntress, told Davey Winder for Forbes that the Chick-fil-A breach “perfectly illustrates that cybercriminals don’t just target banks or governments; they go wherever consumers reuse passwords.”

Agha added that “fast-food and retail apps are a lucrative treasure trove of stored payment data and loyalty rewards.”

“We recently identified suspicious login activity to certain Chick-fil-A One accounts,” said a July 20 letter Chick-fil-A sent to customers, as cited by Forbes. “Following a careful investigation, we determined that unauthorized parties launched an automated attack against our website and mobile application between June 17 and June 19, 2026 using account credentials (e.g., email addresses and passwords) obtained from a third-party source.”

After noticing suspicious login activity involving certain customer accounts, Chick-fil-A launched its investigation. In the data breach notification letters, it said information accessed by hackers might have included: customers’ names, email addresses, phone numbers, street addresses, birth months and days, Chick-fil-A One membership numbers, Mobile Pay numbers and QR codes, the last four digits of payment card numbers and Chick-fil-A gift card balances, CBS News said.

“Chick-fil-A continues to enhance its security, monitoring, and fraud controls as appropriate to minimize the risk of any similar incident in the future,” the letters stated, according to the outlet. Furthermore, the company forced affected customers to log out of their accounts and remove stored payment methods.

Forbes noted that Chick-fil-A has not released the number of accounts included in the breach. Customers, even those not impacted by the hack, are encouraged to reset their Chick-fil-A One passwords, using a strong, unique password not used for other accounts.

Rewards were added to affected accounts for the inconvenience, Chick-fil-A said. It recommends that customers also review account activity, bank statements and credit card statements for suspicious activity.