LIVE · cybersecurity feed
Live wire
breach

Chick-fil-A data breach affects more than 13,000 customers

Chick-fil-A has confirmed that over 13,000 customers had their accounts breached in a wave of credential stuffing attacks targeting its website and mobile app between June 17 and June 19. [...]

zeroday.news · 8d ago

Chick-fil-A has confirmed that a recent credential stuffing attack compromised the personal data of over 13,000 customers. The fast-food chain detected suspicious login activity on its website and mobile app, specifically targeting Chick-fil-A One loyalty accounts, between June 17 and June 19.

The company stated in data breach notification letters filed with various attorney general offices that attackers utilized automated tools and credentials acquired from a third-party source to gain unauthorized access to customer accounts. Upon discovery, Chick-fil-A immediately took steps to secure and restore affected accounts and is directly notifying all potentially impacted customers.

The breach affected a total of 13,322 individuals, according to a filing with the Office of the Maine Attorney General. Specific state filings indicate 2,182 Texans and 39 Massachusetts residents were impacted. Notification letters have also been sent to residents in the District of Columbia, Iowa, Maryland, New Mexico, New York, North Carolina, Oregon, Vermont, and Rhode Island.

Information accessed by the threat actors included customers' names, email addresses, Chick-fil-A One membership numbers, the amount of Chick-fil-A credit, mobile pay numbers, and the last four digits of credit or debit card numbers. Additionally, if stored in the compromised accounts, birth dates, phone numbers, and addresses may also have been exposed.

In response to the incident, Chick-fil-A logged out all affected accounts, removed associated payment methods, and restored all compromised Chick-fil-A One account balances. As an apology, the company also added rewards to the affected accounts.

Given that the account compromises stemmed from credentials stolen from external services, Chick-fil-A has advised all impacted customers to change their passwords promptly.

This incident marks the second time in recent years that Chick-fil-A has disclosed a data breach due to credential stuffing attacks. In March 2023, the company reported that hackers stole personal information from over 71,000 customers through similar attacks conducted between December 2022 and February 2023.

breach
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]

security

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]

security

BGP ORIGIN attribute manipulation and its impact on the Internet

By doing in-depth testing, we found nearly 70% of BGP paths experience ORIGIN attribute rewrites by transit providers seeking traffic advantages. We examine the global impact of this practice and argue for deprecating ORIGIN in route selection.

security

Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry

The new British prime minister is retaining Liz Lloyd in a cyber policy role, making her one of the few Keir Starmer allies remaining in government.

security

'Wrench' attacks against crypto holders appear to be on the rise

There are more reports than ever before of strong-arm tactics like home invasions and kidnappings against cryptocurrency holders, researchers say.

vulnerability

Microsoft blames massive Microsoft 365 outage on maintenance bug

Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services. [...]