Fast-food chain Chick-fil-A disclosed a data breach stemming from a credential stuffing attack on its Chick-fil-A One loyalty program. Threat actors targeted the mobile app and website between June 17 and 19 using credentials obtained from third-party data breaches, phishing campaigns, and infostealer malware. The company determined on July 13 that attackers accessed customer account data.
Stolen data may include names, email addresses, Chick-fil-A membership numbers, partial payment card numbers, account balances, and in some cases phone numbers, addresses, and dates of birth. The company has forcibly logged out affected accounts, reset passwords, removed stored payment methods, and restored drained account balances. Chick-fil-A submitted notifications to attorneys general in Texas and Massachusetts, suggesting thousands or tens of thousands of customers were affected.
Credential stuffing remains a lucrative attack vector because so many users reuse passwords across services. The 2022 DraftKings credential stuffing attack enabled hackers to steal hundreds of thousands of dollars before all three perpetrators were identified and sentenced to prison. Chick-fil-A operates more than 3,000 restaurants with over 200,000 team members, making its loyalty program a high-value target for credential-based attacks.
